Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Payment Card Industry

Posted on 2011-03-23
5
550 Views
Last Modified: 2012-05-11
I wanted to know where I can get information about Payment Card Industry complaince?  Specifically in PCI DSS?

Where can I get help on this?
0
Comment
Question by:vulture714
5 Comments
 
LVL 83

Expert Comment

by:Dave Baldwin
ID: 35204839
0
 
LVL 18

Expert Comment

by:liddler
ID: 35205158
There are many QSAs (Qualified Security Assessors) who will be only to happy to assist you in this, obviously they all cost money.  
The amount of work you will need to do depends on what level of merchant you are, I think level 1 is >$1bn revenue pa, level 2 is $500k--$1bn down to level 4.
A level 1 needs external assessment and audit, level 2 has a mixture of self and external assessment and audit.

The standards are updated each year, usually in October and PCI DSS compliance does require a lot of work (I work for a level 2 merchant)
0
 

Author Comment

by:vulture714
ID: 35210440
What about some type of a checklist for the office.   What I need is a checklist of what do to and what not to do when it comes to information technology.
0
 
LVL 18

Expert Comment

by:liddler
ID: 35213074
I'm not sure there is a simple checklist, the PCI DSS is pretty long and detailed and there are many many controls you need to adhere to.
I can give you a few starters:
Store credit card information in as few places as possibly, preferably none
Firewall all CC data from everything else
encrypt all CC traffic
Keep all systems patched up-to-date and if windows anti-virused up-to-date
Complex passwords that change regularly
2 factor authentication, especially for external access
audit log everything related to CC info and review logs for suspicious activity
0
 
LVL 63

Accepted Solution

by:
btan earned 500 total points
ID: 35221049
Pls see the below resources

a) List of PCI DSS Audit Questions and Checklist
@ http://www.compliancesforum.com/download-pci-dss-audit-questions-and-checklist

b) Scanner tool to check compliance (just an example)
@ http://www.manageengine.com/products/security-manager/index.html

c) Other useful reference - check out specific security device specification checklist to comply with PSI-DSS. In particular see the Requirements for Approved Scanning Vendors (under pg 3)
@ http://www.compliancesforum.com/tag/pci-dss
0

Featured Post

Three Reasons Why Backup is Strategic

Backup is strategic to your business because your data is strategic to your business. Without backup, your business will fail. This white paper explains why it is vital for you to design and immediately execute a backup strategy to protect 100 percent of your data.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

It’s the first day of March, the weather is starting to warm up and the excitement of the upcoming St. Patrick’s Day holiday can be felt throughout the world.
The related questions "How do I recover the passwords for my Q-See DVR" and "How can I reset my Q-See DVR to eliminate a password" are seen several times a week.  Here we discuss the grim reality of the situation.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question