Solved

Payment Card Industry

Posted on 2011-03-23
5
554 Views
Last Modified: 2012-05-11
I wanted to know where I can get information about Payment Card Industry complaince?  Specifically in PCI DSS?

Where can I get help on this?
0
Comment
Question by:vulture714
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 83

Expert Comment

by:Dave Baldwin
ID: 35204839
0
 
LVL 18

Expert Comment

by:liddler
ID: 35205158
There are many QSAs (Qualified Security Assessors) who will be only to happy to assist you in this, obviously they all cost money.  
The amount of work you will need to do depends on what level of merchant you are, I think level 1 is >$1bn revenue pa, level 2 is $500k--$1bn down to level 4.
A level 1 needs external assessment and audit, level 2 has a mixture of self and external assessment and audit.

The standards are updated each year, usually in October and PCI DSS compliance does require a lot of work (I work for a level 2 merchant)
0
 

Author Comment

by:vulture714
ID: 35210440
What about some type of a checklist for the office.   What I need is a checklist of what do to and what not to do when it comes to information technology.
0
 
LVL 18

Expert Comment

by:liddler
ID: 35213074
I'm not sure there is a simple checklist, the PCI DSS is pretty long and detailed and there are many many controls you need to adhere to.
I can give you a few starters:
Store credit card information in as few places as possibly, preferably none
Firewall all CC data from everything else
encrypt all CC traffic
Keep all systems patched up-to-date and if windows anti-virused up-to-date
Complex passwords that change regularly
2 factor authentication, especially for external access
audit log everything related to CC info and review logs for suspicious activity
0
 
LVL 64

Accepted Solution

by:
btan earned 500 total points
ID: 35221049
Pls see the below resources

a) List of PCI DSS Audit Questions and Checklist
@ http://www.compliancesforum.com/download-pci-dss-audit-questions-and-checklist

b) Scanner tool to check compliance (just an example)
@ http://www.manageengine.com/products/security-manager/index.html

c) Other useful reference - check out specific security device specification checklist to comply with PSI-DSS. In particular see the Requirements for Approved Scanning Vendors (under pg 3)
@ http://www.compliancesforum.com/tag/pci-dss
0

Featured Post

Retailers - Is your network secure?

With the prevalence of social media & networking tools, for retailers, reputation is critical. Have you considered the impact your network security could have in your customer's experience? Learn more in our Retail Security Resource Kit Today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Email attacks are the most common methods for initiating ransomware and phishing scams. Attackers want you to open an infected attachment or click a malicious link, and unwittingly download malware to your machine. Here are 7 ways you can stay safe.
Make the most of your online learning experience.
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

691 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question