PCI Compliance Standards and Credit Card Processing
- By: Karen Carter
The Payment Card Industry Data Security Standard (PCI DSS) applies to companies of any size that accept credit card payments. If your company intends to accept card payment, and store, process or transmit cardholder data, you need to host your data securely with a PCI compliance hosting provider. According to the PCI Security Standards Council, there are 12 PCI compliant requirements that meet a variety of security goals. These goals include things like building and maintaining a secure network, protecting card holder data, maintaining a vulnerability management program, implementing strong access control measures and maintaining an information security policy.
The cards can actually be issued by one of these companies or by a bank that has a contract with one of these companies. Now the companies will also make deals with some merchants and even some online merchants in order to make sure that they accept their card and their logo. Keep in mind that there is always going to be a PCI compliance deadline to consider. As a merchant when you accept credit cards then you are required to operate under certain PCI compliance requirements. All of these will be outlines in your merchant agreement that you signed when you started accepting credit cards.
Level 3: Your company has 20,000 to 1 million Visa and/or Mastercard e-commerce transactions processed per year. You must complete a Self-Assessment Questionnaire (SAQ) annually, and this level also requires a network scan with an approved scanning vendor. Level 4: You have less than 20,000 Visa and/or Mastercard e-commerce transactions processed per year. Must complete a Self-Assessment Questionnaire (SAQ) annually, and requires a network scan with an approved scanning vendor.
Following PCI DSS will give you guidelines to protect your own data. Moreover, by merging your own security measures with the measures to satisfy PCI data security standards compliance, the PCI DSS fulfillment will become just an incremental burden, much easier to implement. You may not have a choice in following the PCI standards. No matter how you slice it, PCI is a monopoly of sorts. If you are found non-compliant, and unable to process credit card, debit cards with one of the five logos, you may not be able to process many online transactions at all. Yes, there is PayPal, eJunkie, and other online processors, but they usually operate in very specialized markets, and do not have as broad a reach as Visa and Mastercard.
By narrowing down what level and type of merchant you are, you're well on your way to becoming PCI compliant! PCI Compliance is so important to your business as it protects you and your clients.
Article Source :
Author Resource :
Learn more about PCI Compliance¬. Stop by Karen Carter's site where you can find out all about the PCI Compliance Standards¬ and what it can do for you.