 |
|
|
|
 |
Categories |
 |
|
|
|
2008-04-28 08:10:02
|
 |
Article by Andy Eliason |
 |
|
The PCI DSS, or Payment Card Industry Data Security Standard, is a set of standardized requirements that merchants who store, transmit, or process sensitive information must adhere to. These requirements can be complex and time consuming, but if you take a more methodical approach to PCI compliance, some of those mandated procedures might not be so bad.
The fist step is to analyze your priorities. How important is PCI compliance to you? But before you answer that question, you need to understand some of the recent happenings in the payment card industry.
More and more, stories of security breaches are reaching the public notice. The poster-child for huge losses of sensitive information is the TJX company. Beginning in July of 2005, hackers spent nearly 18 months exploiting weaknesses in their system and stealing countless credit card numbers.
The financial damage to TJX has been estimated in the hundreds of millions of dollars by some companies. The damage to their reputation, on the other hand, is no less detrimental to the company, even if it is a little harder to put an exact figure on.
So, have you properly prioritized PCI compliance? It's a number one priority, now? Good. Let's move on.
The next step is to identify the people in your company that will be responsible for PCI compliance measures. Assemble this team and make sure they understand their responsibilities. There has to be a dedicated person (or team) to oversee the compliance procedures or it will not get done. Let's face it, responsibilities that are not specifically assigned are very easily shifted around until no one knows who was supposed to what, or when it was supposed to be done.
You must then determine your merchant level. There are four different levels, and each have different requirements for PCI compliance depending on the size of your company - or, in other words, the volume of transactions your company processes.
Once these items have been addressed, you need to make sure that everyone in your organization is aware of your Informations Security Policy and that it is strictly enforced. This is, in fact, one of the specific requirements of PCI compliance.
Specifically, requirement 12 states that merchants must: "Maintain a policy that addresses information security." The reason for this requirement is simple. The strictest measures in the world don't mean much if the individual employees in the company don't understand the sensitive nature of the information they are supposed to protect, and their own responsibilities toward it.
This requirement encompasses practices such as developing daily operational security procedures, developing usage policies (how and when to access networks, etc), and making sure that all employees and contractors understand these policies.
Next, as you come closer to PCI compliance you will likely discover many areas where you security procedures are somewhat lacking. Address these issues immediately and employ the necessary corrective measures.
Finally, you are going to want to record and document all your self-assessments, scans, and follow up activities for later use. For full PCI compliance you will be required to validate your compliance with the Payment Card Industry Data Security Standard, and properly kept records will make this process much easier.
The 12 requirements of the PCI DSS can, at times, seem overwhelming and overly complex. Because of that, many merchants are postponing their work toward PCI compliance. Yet, given the dangers of security breaches and the damage that can be done to your finances and reputation, there really is no excuse for extended procrastination. And a simple, methodical approach to compliance with the PCI DSS is all it takes to get things started.
|
| Specialized in: |
Methodical Approach
-
Pci Compliance
|
| URL: |
|
|
 |
Related Articles |
 |
Business Plan - Setting Realistic Business Goals (Popularity: ): As you begin to make decisions about becoming an entrepreneur, you will want to think about setting the goals that will help sustain your drive and vision. Remember, a lot of successful businessmen do not remain stagnant. In fact starting up and running a business involves continuous learning. A lot of this learning occurs from mistakes that you will make along the way and some mistakes you will inadvertently repeat. ...
Create A Beautiful Hair Salon Business Plan (Popularity: ): Getting a new hair salon business off the ground can be quite a difficult undertaking, but the rewards of all that hard work can be quite significant as well.
The first step for those considering such a move should be the creation of a hair salon business plan.
It is important that the hair salon business plan you create provide all would be lenders, investors and business partners with the information they ...
Planning for Success - Part 2 (Popularity: ): If you're a coach, student coach, business owner or someone with a desire to get into business, take careful note of the powerful tips and development strategies presented within this series and GET READY to make the leap to ultimate success.
Plan for Success
For the purposes of the Business Development Program, we assume that you have your business structure in place and are ready to operate or are already operating your ...
Location Accuracy at Target (Popularity: ): Anyone who works at Target will tell you that a very large part of Target's logistical system is making sure that things are stored in the backroom correctly and in an orderly fashion. At Target a very important evaluation tool is something called location accuracy. In order to understand the concept of location accuracy you need to understand how the LRT works. The LRT is a device used at Target ...
Relaxing As You Create A Great Hotel Business Plan (Popularity: ): There are many excellent businesses which can provide a very good living for smart business owners and entrepreneurs, but given the right location a hotel business can be one of the best.
Before swinging the doors of the hotel open, however, it is important to sit down and work out a solid and professional hotel business plan.
Using Your Hotel Business To Provide A Guideline For Success
Having such a hotel business plan ...
|
 |
Related Business |
 |
Office of Enforcement and Compliance Assurance (Popularity: ): Ensures compliance with the nation's environmental laws by employing an integrated approach of assistance, incentives and innovative civil and criminal enforcement.
August Compliance Solutions, Inc. - Regulatory Compliance (Popularity: ): Environmental, health, and safety consultants and engineers specializing in compliance management, training, safety programs, and engineering design. OSHA compliance specialists. Expert testimony.
The American Compliance Institute (Popularity: ): National membership organization of individuals and organizations involved in compliance, dedicated to promoting the principles of sound compliance with all applicable laws, regulations, standards and ethics in the conduct of business.
Bridger Tracker Compliance Software (Popularity: ): Compliance software solutions to assist any business with OFAC and USA PATRIOT Act compliance. Download 45-day free trial.
The Air Toxic Compliance Consortium (Popularity: ): Information on the status of air toxic regulations and compliance requirements, and natural gas compliance technologies and vendors, and links to related web sites.
Peterson investigation slow, methodical (Popularity: ): [CNN]
Witnesses describe methodical, calm capture (Popularity: ): [CNN]
IDEC Validation Ltd (Popularity: ): Provider of Quality & Compliance services to the Pharmaceutical / Biotechnology sector. Primarily assist organisations in the CSV field satisfy Regulatory and Compliance requirements. IVL has extensive field knowledge in the implementation of compliance solutions.
Compliance Assurance Program (Popularity: ): Compliance insurance for physicians, health maintenance organizations, home health agencies, and hospitals. Protects against Medicare fraud and abuse charges, as well as compliance with HIPAA, STARK, and EMTALA regulations.
R. M. Baldwin, Inc (Popularity: ): Multi-Disciplinary Engineering Services For Medicine & Industry. A truly unique consulting firm that offers a comprehensive approach to product development, regulatory compliance and engineering.
|
|
|
 |
|
 |
| |
| | |
|
|
|
© 2003-2008 ABC Directory. All Rights Reserved
|
|
|
 |
|
 |
|