PCI: The Standard for Credit Data Safety



Email    print   
March 1, 2007 —  In September 2006, American Express, Discover Financial Services, JCB International, MasterCard Worldwide and Visa International jointly announced the formation of the PCI Security Standards Council.

Made up of companies that issue credit cards, the council was established to manage ongoing evolution of the PCI standard, earlier managed informally. The council’s mission is to improve payment account security by fostering broad adoption of the PCI Data Security Standard. The standard specifies processes and precautions for handling, processing, storing and transmitting credit card data across all payment channels, including retail stores, mail order and e-commerce.

Released in September 2006, PCI Data Security Standard 1.1 outlines 12 broad-based requirements, grouped under six categories. Many address network security and access control issues. But requirement 11—to regularly test security systems and processes—also deals with application security concerns.

It specifies, among other things, that Web applications are subjected to quarterly vulnerability scans performed by an outside vendor qualified by PCI. (ScanAlert is one such vendor; Qualys is another.) Requirement 11 also mandates application-layer penetration tests at least once a year, and after any significant application or modification.

Failure to meet the PCI Data Security Standard 1.1 by June 2007 could result in a fine as high as US$500,000, and could also bar a business from processing credit card transactions. Penalties can vary from one credit card company to another.





Share this link: http://sdt.bz/30267
 
Most Read Latest News Blog Resources

Add comment


Name*
Email*  
Country     


  • Comment
Loading




close
NEXT ARTICLE
Mobile developers must sidestep data limitations
Bandwidth constrictions from carriers and mobile devices require different measures to bypass Read More...
 
 
 
 
News on Monday
more>>
SharePoint Tech Report
more>>


   

 
 

Download Current Issue
FEBRUARY 2012 PDF ISSUE

Need Back Issues?
DOWNLOAD HERE

Want to subscribe?


 
blogs tab
Agility, mom, and apple pie
If we're to evaluate the state-of-the-art in software development, we should start with the values espoused in the Agile Manifesto.
02/07/2012 11:57 AM EST

RIM woos developers with free tablet
How do you get more apps ported to the BlackBerry PlayBook? By giving every developer a free tablet, of course!
02/04/2012 01:57 PM EST

GitHire: Use Headhunters to Find Your Perfect Programmer
Are you a hiring manager tired of scouring the job boards? Check out this new service that will find 5 people interested in your jobs.
02/03/2012 12:17 PM EST

Facebook claims hacker cred
Facebook's SEC S-1 filing form includes a short essay on the Hacker Way by Mark Zuckerberg himself.
02/02/2012 08:26 AM EST

Ryan Dahl steps down
Ryan Dahl, creator of Node.js, steps back from his position as gatekeeper for the project.
02/01/2012 04:58 PM EST

Bloomberg opens its API
Bloomberg's APIs could lead to a future standard for accessing market data.
02/01/2012 04:41 PM EST

 
Events calendar tab
2/13/2012 to 2/16/2012
Santa Clara
TechWeb

2/26/2012 to 2/29/2012
San Francisco
BZ Media

2/27/2012 to 3/2/2012
San Francisco
RSA

3/4/2012 to 3/7/2012
Las Vegas
IBM Tivoli

3/5/2012 to 3/9/2012
San Francisco
TechWeb