<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PCI Compliance Requirements &#187; website security</title>
	<atom:link href="http://www.pci-compliance-requirements.net/tag/website-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pci-compliance-requirements.net</link>
	<description>PCI Compliance Requirements</description>
	<lastBuildDate>Wed, 26 May 2010 16:39:08 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>PCI Standards</title>
		<link>http://www.pci-compliance-requirements.net/pci-standards/</link>
		<comments>http://www.pci-compliance-requirements.net/pci-standards/#comments</comments>
		<pubDate>Tue, 07 Apr 2009 21:38:41 +0000</pubDate>
		<dc:creator>PCI Compliance Mentor</dc:creator>
				<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[PCI Scanning]]></category>
		<category><![CDATA[PCI Standards]]></category>
		<category><![CDATA[compliant]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[website security]]></category>

		<guid isPermaLink="false">http://www.pci-compliance-requirements.net/?p=25</guid>
		<description><![CDATA[The PCI Standards mandated by the PCI Security Council aims at protecting you as a business and the consumer. In this age of technological progress almost every transaction is carried on over the internet, online.]]></description>
			<content:encoded><![CDATA[<p>More than once we&#8217;ve talked about <strong>PCI compliance standard</strong>s and PCI guidelines.  Basically, PCI standards are one and the same with PCI compliance and PCI guidelines.  The Payment Card Industry Security Standards Council has set forth a list of criteria were &#8220;standards&#8221; to which business owners must adhere in order to continue with e-commerce.</p>
<p>Are you in compliance with the current standards that are set in these times of needed security? You must ask this question daily. You and your business needs to be in charge of security for yourself and your customers.</p>
<p>Why has the PCI Council set forth a series of <strong>PCI standard</strong>s?  The answer is pretty clear cut &#8212; because identity theft has become one of the most rapidly growing and problematic issues to date.  In fact, identity theft is a problem crime that&#8217;s growing at astronomical rates worldwide.  As such, the development of PCI standards seeks only to protect businesses and consumers from would be ID thieves.</p>
<p>PCI standards vary from merchant to merchant based on specific merchant levels.  These merchant levels are derived from a series of criteria that were compiled by the PCI Council.  Depending upon which merchant level your business carries, you&#8217;re PCI standards may vary from that of a different merchant.  However, if you plan to continue in e-commerce or you have aspirations of accepting credit card or debit card payments through your website, you will be required to know and adhere to your specific PCI standards.</p>
<p>Today, there is a wide variety of tools designed to help businesses comply to PCI standards.  PCI scanners and PCI vulnerability tools are relatively easy to find and can end up saving merchants lots of money and heartache in the long run.  In as much as PCI scanning can protect merchants from these scams, it can also protect and save you and your consumers a substantial amount of time and money over the long haul as well.</p>
<p>Statistics indicate that victims of identity theft spend around 600 hours trying to correct all of the problems caused by the crime.  This is an increase of over 2000% in the last three years.  With technology becoming more advanced, crime is becoming more advanced as well.  As such, in order to stay ahead of the thieves, the PCI standards set forth by the PCI Council are becoming mandatory.</p>
<p>It&#8217;s also notable that the utilization of tools to help businesses adhere to the PCI standards set forth by the PCI Council is also an excellent marketing tool.  In fact, many consumers agree that if a company can provide them constant and consistent safe and secure transactions, they will very likely become repeat customers.  It stands to reason that protecting your customers is an act of good faith and also helps to instill confidence in the consumer that you are a reputable business owner, who cares about the client’s needs.</p>
<p>It is possible to learn more about PCI standards and what it takes to be PCI compliant.  You will find that, especially as a merchant, questions are readily answered in order to help you best serve yourself and your customers.  It&#8217;s also important to note that even if you are a sole proprietor, any transaction made over the Internet must adhere to <a href="http://www.trust-guard.com/PCI-Scanning-s/39.htm">PCI standards</a>.</p>
<p>The time is now, and if not today then tomorrow. It is time to be in charge of your security and to be in compliance with the current standards set forth.</p>
<p><script type="text/javascript" src="http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/js/lgs-js-init.js"></script><script>var domainAddress   = "http://www.letsgetsocialnow.com/";
					 var bookmarkPage    = "bookmarkthis.php";
					 var url     = "http://www.pci-compliance-requirements.net/pci-standards/";
					 var title   = "PCI Standards";
					 var js_path = "http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/";
					 var css_path = "http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/";
					 var img_path = "http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/";
					 var bookmark_button_id = "bookmark_button_25";
					 </script><script type="text/javascript" src="http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/js/lgs-js-end.js"></script></p>]]></content:encoded>
			<wfw:commentRss>http://www.pci-compliance-requirements.net/pci-standards/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI Compliance Explained</title>
		<link>http://www.pci-compliance-requirements.net/pci-compliance-explained/</link>
		<comments>http://www.pci-compliance-requirements.net/pci-compliance-explained/#comments</comments>
		<pubDate>Wed, 11 Feb 2009 20:05:38 +0000</pubDate>
		<dc:creator>PCI Compliance Mentor</dc:creator>
				<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[PCI Scanning]]></category>
		<category><![CDATA[Business]]></category>
		<category><![CDATA[Credit card]]></category>
		<category><![CDATA[Financial services]]></category>
		<category><![CDATA[Merchant Services]]></category>
		<category><![CDATA[Payment Card Industry]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[website security]]></category>

		<guid isPermaLink="false">http://www.pci-compliance-requirements.net/?p=8</guid>
		<description><![CDATA[PCI Compliance Explained in easy to understand terms for your website security. Learn more about PCI DSS Compliance today!]]></description>
			<content:encoded><![CDATA[<p>IF you ever wanted to learn more about <strong>PCI Complianc</strong>e then here is a great video transcript below by Ward Spangenberg of IOActive. You can also watch the original video from Youtube at the bottom of this post. <a href="http://www.trust-guard.com/PCI-Compliance-s/65.htm">PCI Compliance</a> seems to be very difficult to understand but really doesn&#8217;t have to be. If you are ready to start learning then I suggest you start reading everything you can to learn and understand the real importance of PCI Compliance Scanning.</p>
<p>&#8220;Hi, my name is Ward Spangenberg.  I&#8217;m a Delivery Director with IOActive, in Seattle, Washington.  Today, I&#8217;m going to talk about PCI and what it means to Europe and how it&#8217;s affecting operations in Europe.  The first question you might ask is &#8220;What is PCI?&#8221;  PCI stands for Payment Card Industry.  That doesn&#8217;t mean much.  What we&#8217;re really talking about are the Data Security Standards, so PCI DSS.</p>
<p>These are twelve standards requirements that are required by companies that process credit cards.  We have three different types of companies that do this.  We have Level 1, Level 2, and Level 3 merchants.<br />
The merchant is based upon the number of credit card transactions that occur during a year&#8217;s span.  You have anywhere from anything less than a million cards would be considered a Level 3 merchant.  Anything from one million to five million is going to be a Level 2 merchant.  Anything beyond five million is going to be a Level 1 merchant.</p>
<p>With Level 1 merchants, those are required to have a third party come in and perform an audit.  That&#8217;s what I do.  I&#8217;m the auditor.  What happens is I have to understand all twelve of those requirements and sub-points underneath those requirements.  We have things like understanding firewalls and the firewall rule sets, to actual compliance regulations.  Do you have HR?  Are you doing things like background checks on your employees?  It&#8217;s a comprehensive baseline.  This is really important to understand with PCI.  It&#8217;s not the end-all/be-all of security.  It&#8217;s the start of a good security program.</p>
<p>Why is this important to you?  The big thing is a merchant, a retailer, or anybody who takes credit cards, this is important to you because it allows you to have the baseline, the beginning of a security program.  As I said, it&#8217;s the requirements.  We can talk about the requirements.</p>
<p>Requirement number one is having network diagrams.  It&#8217;s amazing, today, how many companies don&#8217;t know what their networks look like.  One of the first requirements is sitting down and documenting, and understanding what your network is all about, understanding what your firewalls are doing, understanding what your rules sets involved in this firewall.  Are we protecting credit card data that is coming in and out through our Web applications?  Are we segregating databases properly between what&#8217;s exposed on the Internet from what&#8217;s protected in the background?</p>
<p>You might be asking yourself, &#8220;What does this mean if I&#8217;m a grocery store or a shoe retailer?&#8221;  You may not have a Web presence if you&#8217;re a grocery store, but you do still process credit cards.  You&#8217;ve got a couple of hundred stores and you may be processing credit cards.  You still have to follow that methodology as to how do you protect those credit cards.  </p>
<p>Look at each store as sort of your remote branch.  Are you protecting the credit card information locally, at that remote branch, and are you protecting in transit, and &#8220;in store&#8221; at your corporate headquarters before you do your batch processing? </p>
<p>When we look at PCI, it&#8217;s spread.  It goes across merchants.  If you&#8217;re processing credit cards, it&#8217;s really recommended that you understand what&#8217;s required of it.  Now, you may question, &#8220;I&#8217;m interested in PCI.  I think I process credit cards.  Do I need to go through the PCI certification process?&#8221;</p>
<p>That&#8217;s pretty easy.  If you&#8217;re a Level 1 merchant, then you do.  You have to contact a third party.  Once a year that third party will send an assessor onsite, or a group of assessors, and they will perform what should be a very exhaustive process.  We&#8217;ll cover that in a second.  They should cover this very exhaustive process and ask questions, and gather evidence, and at the end of that, they will write what&#8217;s called a ROC, or Report On Compliance.  </p>
<p>The Report On Compliance is then turned in to your credit card processor, your requiring bank.  They are the ones that when a credit card is swiped in your store, they&#8217;re the ones that give you authorization on that credit card.  They are also the ones that move the money into your account after the sale has occurred.<br />
If you are a Level 2, Level 3 or below, you get something kind of fun.  It&#8217;s call the &#8220;Self Assessment Questionnaire&#8221;.  For those in the SAQ, there are two versions of it.  The newest version just came out this year and is sort of the 1.1 version of the Self Assessment Questionnaire.  </p>
<p>Because it just came out, companies have the choice of doing compliancy to the 1.0 version or to the 1.1 version.  Your first question is &#8220;What&#8217;s the difference?&#8221;  The difference is that the 1.1 version is a lot more comprehensive and a lot more reflective of what a Level 1 merchant will go through. </p>
<p>The belief is that as Level 2 merchants grow – the whole idea is to grow our companies.  As Level 2 merchants grow, they are going to become Level 1 merchants.  The more comprehensive you are about your security the easier it will be, as your corporation grows, to establish yourself as a compliant Level 1 merchant.</p>
<p>Let&#8217;s get back to this Level 1 merchant.  Once a quarter, they have this auditor come in.  The auditor comes in and performs, we hope, a quality, comprehensive assessment of your organization.  What does that mean?  Again, it&#8217;s the twelve requirements with the subsets of those.  I believe it&#8217;s 256 requirements, total, if you mean everything.</p>
<p>What should happen with an auditor, they should first ask the question, and then once you give them the answer, they should ask for proof.  The process could include sitting down with HR and going through with HR and determining whether the process includes background checks on anyone who has access to credit card data.  We can sit down with the encryption experts within your company, or your database administrators, and review how credit card information is processed, how it enters into the database, how it is dumped into the batch settlement reports, which are then transmitted to the credit card companies – usually at close of business or midnight, or however the business is transacted to occur.</p>
<p>That&#8217;s the comprehensive approach.  There are &#8211; in the questions I receive when I speak about PCI is &#8220;We&#8217;ve had what we call check box auditors.  Is that good?  Is that bad?&#8221;  It&#8217;s all about what risk you&#8217;re willing, and your company is willing to except.  PCI is really, truthfully a risk mitigation tool.  It&#8217;s not going to be the end-all/be-all to the security for your organization.  It&#8217;s also not the stopping point, either.  As you&#8217;ll see, each year there will be standards and new requirements associated.  By having that growth pattern, where at least there is a good baseline to work with, you need to continue to process your security.<br />
That&#8217;s some interesting things about your ROC.  You&#8217;ve passed it.  Everybody has signed off.  You&#8217;re done.  What happens?  Once a ROC has been submitted and the payment inquirer, your merchant bank, has accepted the ROC as your compliance, some paperwork is exchanged and you get a certificate.  You can say, &#8220;I&#8217;m PCI compliant&#8221;.  What happens if, after that&#8217;s all gone through, someone gets hacked?  </p>
<p>The first thing that happens is that you&#8217;re told by your merchant bank to contact a forensic investigator.  There is a group of certain forensic investigators that are allowed to come in and perform an assessment.  The first thing they do is pull that handy-dandy ROC back out and they start looking at it.  They look to determine whether compensating controls that were accepted were strong enough, in terms of if the hack was associated to that.  These are some important things to think about.  </p>
<p>Again, it&#8217;s risk mitigation.  Are you willing to accept the risk associated with a compensating control?  Those are the things.  Again, you start off; you have a baseline.  You get audited to it and then you work from that.  It&#8217;s a good place to start.  I highly encourage companies that are processing credit cards to try to hold the standards of the PCIDSS 1.1 and to hire an external company to come in and help you determine your compliancy level, and to work with you to achieve those.  Eventually, everything will be moving to those levels.  The brick and mortar stores will be required to be just as safe as an online company is.<br />
Thank you for your time.&#8221;</p>
<p>So there it is <a href="http://www.trust-guard.com/PCI-Compliance-s/65.htm">PCI Compliance</a> all explained. Now of course there is more to it than that but having a PCI Compliant site will be the best thing you can do for your company and customers.</p>
<p><center><object width="425" height="344"><param name="movie" value="http://www.youtube.com/v/1FuA39Iia9A&amp;hl=en&amp;fs=1"><param name="allowFullScreen" value="true"><param name="allowscriptaccess" value="always"><embed src="http://www.youtube.com/v/1FuA39Iia9A&amp;hl=en&amp;fs=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"></object></center></p>
<p><script type="text/javascript" src="http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/js/lgs-js-init.js"></script><script>var domainAddress   = "http://www.letsgetsocialnow.com/";
					 var bookmarkPage    = "bookmarkthis.php";
					 var url     = "http://www.pci-compliance-requirements.net/pci-compliance-explained/";
					 var title   = "PCI Compliance Explained";
					 var js_path = "http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/";
					 var css_path = "http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/";
					 var img_path = "http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/";
					 var bookmark_button_id = "bookmark_button_8";
					 </script><script type="text/javascript" src="http://www.pci-compliance-requirements.net/wp-content/plugins/letsgetsocial-wpplugin/js/lgs-js-end.js"></script></p>]]></content:encoded>
			<wfw:commentRss>http://www.pci-compliance-requirements.net/pci-compliance-explained/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
