Monday, September 17, 2012

A Guide to the PCI Compliance Standards

By Kate Bailey


We are in the midst of a 'shop online' trend explosion. Internet retailers are continuously reinventing how we [customers] shop online. Whether it's via our mobile devices, PCs, or in-store kiosks, there is a myriad of new options for transacting business that carry both positive and negative implications for the consumer and the retailers themselves. We need to know that our online stores are following the pci compliance standards.

One of the internet's biggest issues is security; as an e-retailer you need to ensure that your online shop is safe and secure throughout the payment process, handling sensitive information efficiently and securely. This brings me on to this week's blog topic; PCI Data Security Standards (PCI DSS). In laymen's terms this is the framework and set of regulations compiled by the PCI Security Standards Council within which online merchants must operate in order to be compliant. It demands that merchants develop a tenacious online card payment system, incorporating processes for prevention, detection and appropriate responses to security incidents.

Level 1: Your company has over 6 million Visa and/or Mastercard transactions processed per year. This level requires yearly on-site reviews by an internal auditor, and a network scan by an approved scanning vendor (ASV). Level 2: You have 1 million to 6 million Visa and/or Mastercard transactions processed per year. You must complete a Self-Assessment Questionnaire (SAQ) annually, and this level requires a network scan with an approved scanning vendor.

Confident customers are more likely to be repeat customers, and to recommend you to others. Compliance improves your reputation with acquirers and payment brands -- the partners you need in order to do business. Compliance is an ongoing process, not a one-time event. It helps prevent security breaches and theft of payment card data, not just today, but in the future. As data compromise becomes ever more sophisticated, it becomes ever more difficult for an individual merchant to stay ahead of the threats. The PCI Security Standards Council is constantly working to monitor threats and improve the industry's means of dealing with them, through enhancements to Security Standards and by the training of security professionals.

Aside from escaping monetary losses, there are numerous advantages to keeping your business compliant. Improving organizational security will help fend off hackers so that you can rest assured that cardholders' information is safe from harm. This will help build up your customer base, as happy and confident shoppers turn into repeat customers. Your overall brand image will be positive, showing your company as a responsible and productive member in the market that not only adheres to but also promotes PCI compliance. Business partners and investors will become confident in your capabilities as a company, and you will sleep more soundly at night knowing that you are doing everything in your power to protect your firm.




About the Author:



No comments:

Post a Comment