You are currently browsing the Electronic Payment Security weblog archives for the day October 13, 2006.
- February 7, 2007: New Techniques for Guarding Financial Data
- February 6, 2007: Increased Scrutiny From Card Associations in 2007
- January 28, 2007: The State of PCI Compliance 2007
- January 23, 2007: Background Checks on IT Personnel
- January 5, 2007: 100 Million Notifications of Data Breaches in US
- December 17, 2006: Inside Jobs: The Risk of Data Breach From Insider Threats
- December 12, 2006: Card Associations Step Up PCI Enforcement
- December 1, 2006: CompTIA Survey Emphasizes Importance of Security Training
- December 1, 2006: CompTIA Survey Emphasizes Importance of Security Training
- November 16, 2006: Average data breach costs $5 million
Credit Card Companies
FAQ
Helpful Sites
Archive for October 13, 2006
The Impact of Payment Card Industry Security Requirements on Payment Software Applications
October 13, 2006 by tim.
There is a great article in today’s edition of InfoWorld that talks about how the new credit card security requirements will have “repercussions across the entire high-tech industry,” according to writer Ephraim Schwartz. He specifically talks about how Visa’s Payment Application Best Practices (PABP) ”will quickly turn into de facto VISA requirements, as users of the software, such as merchants or card processors, face stiff fines for using noncompliant software.”
As a merchant, Visa mandates that it is your responsibility to use software applications that are PABP compliant. In fact, your merchant services agreement likely has already been revised with such language. However, simply choosing an application from the list does not satisfy the PCI Data Security Standards — the entire environment must be compliant, not just the application. This means that the server and entire network on which the payment application resides must comply with all of the PCI DSS.
Alternatively, merchants can outsource their payment processing to a Service Provider that has been recognized as fully PCI compliant by being included on Visa’s List of Compliant Service Providers.
Posted in Payment Card Industry / Credit Card Security | No Comments »