Card Processing and PCI Compliance
PCI-DSS has been around for several
years now, in case you are just learning about PCI, here is a short breakdown
on PCI compliance.
- PCI is a security framework created to help
prevent/curb the loss of credit card data. It covers some of the more
basic aspects of data security, but is not security itself.
PCI compliance ≠ Security. - If you accept credit cards, you must be PCI compliant. No ifs, ands, or buts.
- Most data breaches occur at small to medium size retail businesses. You are a soft target and thieves know it! This is especially true if you have a POS computer system.
- Being PCI compliant does not remove liability in case you still suffer a data breach. It “may” reduce or eliminate fines but will not eliminate actual costs resulting from a data breach.
- With respect to the actual process, gaining PCI compliance requires you to fill out a self assessment questionnaire (SAQ), and scan your networks periodically using an approved scanning vendor (ASV). Your exact requirements depend on which PCI level your business is.
- You can find a list of ASV’s here. Most ASV’s can also assist in helping you fill out the correct SAQ.
- If you store credit card numbers electronically, you must fill out SAQ – D. Have fun…
- If you are PCI compliant, it does not mean that your networks and data are secure. Security is something that requires constant administration and vigilance, and requires far more than what PCI outlines.
- If you don’t have the ability or expertise to be secure, hire or outsource to someone that does.
Rob Olson
Quantum Merchant Services
1-888-881-0657 ext 707
Quantum Merchant Services
1-888-881-0657 ext 707
Comments
Post a Comment