Sponsored Ads


« Review on ProCurve Switch 2610 Series | Main | Intel-Powered Classmate PC for children’s education »

An Analysis on PCI Standards

By webmaster | April 3, 2008

Do you run a business which requires storing your Customer’s Credit Card? Or Do you run an ecommerce/ online website that require accepting credit/debit card payments. If yes, it is really essential for you to know about the PCI DSS(Payment Card Industry Data Security Standard). By adhering to these PCI Standards - Merchants, Vendors, Small scale or Large Scale Businesses can ensure the safety of their customer’s account data and mitigate losses arising due to identity theft because of weak security practices.

The Formation of PCI

PCI Council was formed by 5 major credit card brands - Visa, MasterCard, American Express, DiscoverCard, JCB International. The council works on providing a common security practice, enhance payment data security and manage training and certification programs for Qualified Security Assessors and Approved Scanning Vendors. It also publishes a list of certified assessors and vendors.

PCI Compliance

Each card issuer has its own criteria for assigning a merchant level and validation compliance classification level for a merchant, third party or service provider for PCI Compliance. The merchant level is based on volume of transactions and the validation compliance level on merchant level and validation actions.

PCI Certifications

The certification for QSA (Qualified Security Assessor) is based on a two-tier structure. The first being that the Security Company must possess security assessment experience similar or related to the PCI data security assessment. The QSA must have a dedicated security practice that includes staff with specific job functions that support the security practice. And the second is that the QSA employees must have sufficient knowledge and experience in conducting security assessments, and must possess industry recognized security certifications or equivalent work experience. All QSA and its employees must re-quality on an annual basis.

Topics: Internet |

Comments