Solved

Payment Card Industry

Posted on 2011-03-23
5
542 Views
Last Modified: 2012-05-11
I wanted to know where I can get information about Payment Card Industry complaince?  Specifically in PCI DSS?

Where can I get help on this?
0
Comment
Question by:vulture714
5 Comments
 
LVL 82

Expert Comment

by:Dave Baldwin
ID: 35204839
0
 
LVL 18

Expert Comment

by:liddler
ID: 35205158
There are many QSAs (Qualified Security Assessors) who will be only to happy to assist you in this, obviously they all cost money.  
The amount of work you will need to do depends on what level of merchant you are, I think level 1 is >$1bn revenue pa, level 2 is $500k--$1bn down to level 4.
A level 1 needs external assessment and audit, level 2 has a mixture of self and external assessment and audit.

The standards are updated each year, usually in October and PCI DSS compliance does require a lot of work (I work for a level 2 merchant)
0
 

Author Comment

by:vulture714
ID: 35210440
What about some type of a checklist for the office.   What I need is a checklist of what do to and what not to do when it comes to information technology.
0
 
LVL 18

Expert Comment

by:liddler
ID: 35213074
I'm not sure there is a simple checklist, the PCI DSS is pretty long and detailed and there are many many controls you need to adhere to.
I can give you a few starters:
Store credit card information in as few places as possibly, preferably none
Firewall all CC data from everything else
encrypt all CC traffic
Keep all systems patched up-to-date and if windows anti-virused up-to-date
Complex passwords that change regularly
2 factor authentication, especially for external access
audit log everything related to CC info and review logs for suspicious activity
0
 
LVL 61

Accepted Solution

by:
btan earned 500 total points
ID: 35221049
Pls see the below resources

a) List of PCI DSS Audit Questions and Checklist
@ http://www.compliancesforum.com/download-pci-dss-audit-questions-and-checklist

b) Scanner tool to check compliance (just an example)
@ http://www.manageengine.com/products/security-manager/index.html

c) Other useful reference - check out specific security device specification checklist to comply with PSI-DSS. In particular see the Requirements for Approved Scanning Vendors (under pg 3)
@ http://www.compliancesforum.com/tag/pci-dss
0

Featured Post

Backup Your Microsoft Windows Server®

Backup all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

Join & Write a Comment

It’s a strangely common occurrence that when you send someone their login details for a system, they can’t get in. This article will help you understand why it happens, and what you can do about it.
By this time the large percentage of day-to-day transactions have shifted to mobile banking; here are some overriding areas QAs must investigate while testing mobile banking apps.  
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now