|
PCI ComplianceThe payment card industry (PCI) mandates PCI compliance for everyone that captures, processes or stores credit card numbers. Card Issuers and processors incur large losses each year resulting from credit card fraud and identity theft from merchants that process credit cards online and on-premises. The Payment Card Industry (PCI) have created stringent data security standards (DSS) for retailers to address this growing problem. FASTTRAK users that have a Cloud or On-Premise application have the capability to make credit card payments to a merchant account gateway such as VeriSign (PayPal payflow pro),CBS or eBizCharge, etc... or offline via terminal credit card processing and therefore must comply with the PCI DSS controls and processes. Costly fines have been issued where a breach occurred on the part of the merchant. There are 12 core requirements for meeting the PCI DSS, divided up into 6 key groups: Build and Maintain a Secure Network
Protect Cardholder Data
Maintain a Vulnerability Management Program
Implement Strong Access Control Measures
Regularly Monitor and Test Networks
Maintain an Information Security Policy
It is important to note that while FASTTRAK utilizes multiple layers of encryption to protect you and your customer's personal credit card data and we an integral part of the chain in obtaining PCI Compliance, the majority of the above rules relate to your local area network in the case of On-Premise installations and the Microsoft SQL Azure hosting environment and staff procedures.
The above information relative to PCI Compliance should be used as a guide only and FASTTRAK Technologies, llc makes no warranty of any kind for the correctness or accuracy of this information. The merchant should seek what ever additional advice it considers appropriate.
|



