PCI DSS Solutions from SECURE COMPUTING®
PCI DSS Security on your Credit Transactions
Some high-profile security breaches, in which customer credit card information became exposed, have cast shadows over the widespread acceptance of ecommerce. The PCI DSS (Payment Card Industry Data Security Standard) was created to minimize the incidence of credit card fraud, by creating a standard set of best practices for overcoming security shortcomings.
Created by major credit card companies, the PCI DSS standard includes a set of requirements for security management, policies, procedures, network architecture, software design, and other security measures. Merchants accepting credit cards will have to comply with the PCI DSS standard; fortunately, doing so should not be overly burdensome for those who already have security measures in place. PCI DSS compliance involves adhering to a set of 12 requirements, all meant to secure cardholder data that is either processed by, or stored by retailers. Those requirements, which start with the installation and maintenance of a firewall configuration, are for the most part, requirements that security experts say should already be in force on all corporate networks.
Compliance with PCI DSS will soon become mandatory. Retailers who do not comply may face fines from the card companies and possible fees from member banking institutions. In some cases, a non-compliant merchant may lose their ability to process credit card transactions completely.
The general focus of the PCI DSS requirements revolve around building and maintaining a secure network, protecting cardholder data, maintaining a vulnerability management program and strong access control measures, monitoring and testing networks regularly, and maintaining an information security policy.
Deploying a firewall that is compliant with PCI DSS standards is the best place to start, and even small merchants can comply without burdensome expense by installing PCI DSS firewalls designed for the SMB market, such as Secure Computing's SnapGear. Secure Computing's gateway security appliances allow organizations of any size to impose controls that will bring them into compliance with the PCI DSS standard.
Compliance with the PCI DSS standards means following a set of common-sense best practices that should be followed by any organization that deals with consumer data.
Download white paper Embracing PCI Making it work for you
Visit the PCI site or Secure Computing's home page at http://www.securecomputing.com.