border
border leftborder right
Webmaster resources, webmaster tools  - Article Details
CATEGORIES
Statistics
  • Active Links: 10724
  • Pending Links: 3
  • Todays Links: 0
  • Total Articles: 60
  • Total Categories: 13
  • Sub Categories: 546
top left cornertop right corner

Self-assessing Your Pci Compliance

Date Added: September 17, 2008 09:00:58 AM
Author: Phil Williams
Category: eCommerce



Self-assessing Your Pci Compliance



Author: Vijayanand


No matter how large or small your business is, if you take credit/debit cards or paycards from American Express, Discover, MasterCard and/or Visa, you will have to meet PCI Data Security Standards. These preventative measures are used to protect cardholders from security breaches that could lead to identity theft. If you do not met, these standards per your contractual obligations, you can be fined and/or sanctioned by the credit card company and/or acquiring bank.

The requirements for proving PCI compliance vary depending on the number of transactions a merchant handles per year. Merchants are placed in different levels from 1 to 4 depending on the volume of their transactions. Various payment brands and acquiring banks use different criteria to categorize merchants. In general, however, those merchants who have over 6 million transactions or who have had previous incidences of security breaches will be required to have an annual on-site assessment of their PCI compliance. This assessment is done by a Qualified Security Assessor (QSA). Additionally, a network scan is required on a regular basis by an Approved Scanning Vendor (ASV).

Merchants who handle a lesser volume of transactions may qualify to use the PCI Self-Assessment Questionnaire for validation. The questionnaire is like a checklist the requirements listed by the PCI DSS. In order to complete the questionnaire, you must go through each of the 12 requirements and answer either “Yes” or “N/A.” A “No” answer to any of the requirements will make you non-compliant. In order to become compliant, all of the requirements must be achieved.

Another part of the self-assessment validation process is the PCI Scan Compliancy. Level 2, 3 and 4 merchants must also have a network scan by an ASV. This scan can identify areas of vulnerability if there are any. These security threats should match up with any “No” answers on your self-assessment questionnaire. The ASV that does your scan can provide recommendations for how to resolve any security threats so that you can complete your questionnaire. The completed questionnaire and successful PCI scan report from the ASV should be sent to the acquiring bank for validation. Additional documentation may also be requested and required.

The frequency of PCI Compliance validation depends on the number of transactions your company handles. The various payment brands and acquiring banks have their own requirements. You may have to be validated quarterly or annually. Those merchants who pose a higher risk are usually validated more frequently.

HackerGuardian from Comodo provides PCI Scan Compliancy services for merchants of all sizes. Services are available for business with multiple IP addresses and those with just 1 IP address. HackerGuardian even offers a free PCI scan. The free Painless PCI program walks e-merchants through the process of becoming PCI compliant. Designed specifically for level 3 and 4 merchants who are sometimes overlooked by PCI solutions, the Painless PCI program makes it easy for e-merchants to navigate the sometimes-confusing self-assessment questionnaire. It also supplies a list of recommendations to resolve any compliance issues.



Article Source: Link



About the Author:

Vijayanand working as a online marketing co-ordinator in ID Theft team in Comodo, a leading internet security provider, offers a real time Identity Theft Prevention and Identity Fraud restoration services among others.


Ratings:

You must be logged in to leave a rating.

Average rating: ( votes)

Comments:

No Comments Yet.

You must be logged in to leave a comment.


bottom corner leftbottom corner right
Search
Users & Authors
Login  |  Register
Articles
5 Reasons Why an Internet Business is Rewarding
The idea of setting up a website has been rolling around in your head for quite some time, but you are still a little nervous. The Internet is waiting for you and here are some reasons that will give you the nudge you need to get started....
What’s a Fair Price for Your Internet Ebiz Item?
If you charge too much you will probably miss your Internet audience or only snag a few of them, however, if you charge too little, you'll leave money on the website table, this article gives you practicle advice on how to price your items....
5 Traits That Can Kill Your Internet Business
If you can avoid some of the common mistakes of Internet marketing and website building, you'll have a much better chance of having an Internet business that will succeed, despite all of the competition, here a few traits that you should avoid if...
Self-assessing Your Pci Compliance
No matter how large or small your business is, if you take credit/debit cards or paycards from American Express, Discover, MasterCard and/or Visa, you will have to meet PCI Data Security Standards. These preventative measures are used to protect...
Pci Compliance for Dummies
The Payment Card Industry Data Security Standard (PCI DSS) is a protocol set up by the major credit card companies to help protect against security threats when payment cards are processed. The major credit card companies formed the PCI Security...