The major payment card brands (Visa, MasterCard, Discover and American Express)
have come together to established twelve basic data security standards to help fight
fraud. These standards apply to all entities that accept, process or store card
information. The standards are called the Payment Card Industry Data Security Standards
(PCI DSS).
What does this mean to you?
How you handle and store card data may require some changes in order to comply with
the standards. If you are not compliant, you are subject to fines and/or penalties
from the card associations.
|
PCI Data Security Standards
|
|
Build and Maintain a Secure Network
|
- Install and maintain a firewall configuration to protect data
- Do not use vendor-supplied defaults for system passwords and other security parameters
|
|
Protect Cardholder Data
|
- Protect stored data
- Encrypt transmission of cardholder data and sensitive information across public
networks
|
|
Maintain a Vulnerability Management Program
|
- Use and regularly update anti-virus software
- Develop and maintain secure systems and applications
|
|
Implement Strong Access Control Measures
|
- Restrict access to data by business need-to-know
- Assign a unique ID to each person with computer access
- Restrict physical access to cardholder data
|
|
Regularly Monitor and Test Networks
|
- Track and monitor all access to network resources and cardholder data
- Regularly test security systems and processes
|
|
Maintain an Information Security Policy
|
- Maintain a policy that addresses information security
|
Data Security Compliance
If a merchant does not comply with or fails to correct a security issue, the merchant
may be subject to steep fines and operating restrictions.
Avoid Penalties and Expensive Fines
If a merchant knows or suspects a security breach, the merchant must take immediate
action to investigate the incident, limit the exposure of cardholder data and notify
INTRUST Card Center.
If the merchant fails to notify INTRUST Card Center of the incident, you will be
subject to penalties of $100,000 per incident.
If the merchants' card transaction data is compromised and not compliant at the
time of the incident, the merchant is subject to fines, up to $500,000 per incident.
Are you compliant?
Many merchants are asking how the standards will affect their business. INTRUST
Card Center works with merchants to address your questions about the standards and
how to comply. Statement messages and statement inserts contain helpful information
about how to be compliant.
Learn more
about the PCI Data Security Standards.