May 2010
M T W T F S S
« Apr   Jun »
 12
3456789
10111213141516
17181920212223
24252627282930
31  

Categories

What’s Insteresting?

Start Processing Credit Cards Today. Get A FREE Quote.

Business Type

Majority of CC

Name

Email

Phone Number

Comments

captcha

PCI Compliance Doesn’t Have To Be Painful

Monday, May 24, 2010 @ 06:05 PM  posted by

Two technologies–end-to-end encryption and tokenization–may go a long way toward protecting credit-card data.
By Andrew Conry-Murray

InformationWeek
May 22, 2010 12:00 AM (From the May 24, 2010 issue)

Security pros have a love-hate relationship with PCI. On one hand, the standard compels management to invest in security and mandates operational best practices. Failure to toe the line can result in fines and penalties, including increased costs for credit card transactions. Visa, MasterCard, and other card brands could go so far as to revoke a company’s right to process cards, effectively killing the business.

Such consequences get noticed by executives. “We have a security operation because of PCI,” says Bob Kemp, manager of IT security for Sheetz, a chain of gas stations and convenience stores. Sheetz is a Level 1 merchant, which means it processes at least 6 million credit card transactions every year. As such, Sheetz is required by PCI to be assessed by a third-party entity called a Qualified Security Assessor, or QSA, to ensure it complies with the standard.

But on the other hand, security pros also have beefs with the standard. At the top of the list is the notion of safe harbor–or the lack of it. While PCI is mostly sticks, one carrot for merchants is that the card brands can’t fine them if they’re breached, provided the merchants were compliant at the time of the breach. This safe harbor is offered as an incentive to promote compliance. Visa’s Web site includes this statement: “Visa may waive fines in the event of a data compromise if there is no evidence of noncompliance with PCI DSS and Visa rules. To prevent fines a member, merchant, or service provider must maintain full compliance at all times, including at the time of breach.”

The key phrase is “full compliance at all times.” On the surface, that’s reasonable, until you understand that an company is technically compliant only at the time of the assessment. Once the QSA leaves, the company’s status falls into a zone of uncertainty.

How to overcome manual, fragmented ERP budget management

7 Ways To Rein In Spending On SAP

Two technologies–end-to-end encryption and tokenization–may go a long way toward protecting card data and ending this uncertainty. As we’ll discuss in detail in our full report, available free for a limited time at information week.com/analytics/pciupdate, several large card processors offer, or will soon offer, devices that can encrypt card data at the point of sale.

For instance, Merchant Warehouse offers encrypted card readers, which the company says are being used in about 1,000 locations. The system can also return tokens rather than card data to merchants and retailers, which can be used for common transaction requirements such as voiding or refunding a purchase. In 2009, payment processor First Data announced Secure Transaction Management, a service that encrypts card data at the PoS application and sends it to First Data to be decrypted. And Heartland Payment Systems will soon launch E3, a program for point-to-point encryption and tokenization. The processor is offering PoS terminals that have a hardware-based encryption module from Thales.

Shifting liability is a key selling point of end-to-end encryption and tokenization. If these technologies can reduce the scope of PCI and lower the risk of card data being stolen at the retailer’s site, widespread adoption is virtually assured. And that’s good for all of us.

5 AREAS TO VET CRYPTO, TOKEN VENDORS

1. Depth of knowledge:Ensure the vendor can demonstrateits products adhere to PCI guidelines.

2. Level of commitment:You could end up locked in to the payment processor that provides your encryption or tokenization service. Can you live with that?

3. Hard trumps soft:Systems that encrypt card data at the point of swipe using a hardware module are superior to point-of-sale terminals that perform encryption using only software.

4. Ask for assurance:Therearemany potential points of failure.Shoddy key management,places in the processing chain whereencrypted data is decrypted and re-encrypted,caches of clear-text card data outside your boundaries.Get audit results.

5. Don’t get complacent: Adopting end-to-end encryption and tokenization won’t magically make you PCI compliant. Any business process that demands card data in the clear should raise a red flag.

64 Responses to “PCI Compliance Doesn’t Have To Be Painful”

  1. JUAN says:


    PillSpot.org. Canadian Health&Care.No prescription online pharmacy.Best quality drugs.Special Internet Prices. No prescription drugs. Buy drugs online

    Buy:Tramadol.Soma.Levitra.Viagra Super Force.Super Active ED Pack.VPXL.Cialis Soft Tabs.Viagra.Maxaman.Viagra Super Active+.Cialis.Cialis Super Active+.Viagra Soft Tabs.Zithromax.Cialis Professional.Propecia.Viagra Professional….

  2. KEN says:


    CheapTabletsOnline.Com. Canadian Health&Care.Best quality drugs.Special Internet Prices.No prescription online pharmacy. Online Pharmacy. Buy drugs online

    Buy:Acomplia.Lipothin.Benicar.Buspar.Zocor.SleepWell.Female Pink Viagra.Cozaar.Lasix.Wellbutrin SR.Nymphomax.Female Cialis.Advair.Lipitor.Prozac.Seroquel.Zetia.Amoxicillin.Ventolin.Aricept….

  3. JAIME says:


    CheapTabletsOnline.com. Canadian Health&Care.No prescription online pharmacy.Special Internet Prices.Best quality drugs. High quality drugs. Buy pills online

    Buy:Prednisolone.Human Growth Hormone.Petcam (Metacam) Oral Suspension.Zyban.Prevacid.Retin-A.100% Pure Okinawan Coral Calcium.Valtrex.Mega Hoodia.Arimidex.Zovirax.Lumigan.Synthroid.Accutane.Actos.Nexium….

  4. CARLOS says:

    ████████►BUY CIALIS◀████████…

    ▲▲▲▲▲▲▲▲▲▲▲▲▲▲▲▲▲▲▲▲▲▲▲▲▲…

  5. JUAN says:

    Accupril

    Buygeneric drugs…

  6. GABRIEL says:

    Abilify

    Buygeneric pills…

  7. KARL says:

    Abilify

    Buygeneric pills…

  8. WALTER says:

    Abilify@official.site” rel=”nofollow”>…

    Buyno prescription…

  9. LAWRENCE says:

    Buygeneric meds…

  10. JOHN says:

    shimmy@adalat.simone” rel=”nofollow”>..

    Buyit now…

  11. SHAWN says:

    fruite@of.the.earth.aloe.vera.juice.sale” rel=”nofollow”>…

    Buynow…

  12. CLAUDE says:

    Allegra@official.site” rel=”nofollow”>…

    Buygeneric pills…

  13. BRIAN says:

    buy@cheap.viagra.in.uk” rel=”nofollow”>.

    Buywithout prescription…

  14. ROLAND says:

    prozac@dangers.now” rel=”nofollow”>..

    Buygeneric drugs…

  15. LEE says:

    cephalexin@use.now” rel=”nofollow”>…

    Buygeneric drugs…

  16. GABRIEL says:

    Benuryl

    Buywithout prescription…

  17. GLENN says:

    Zyrtec

    Buygeneric pills…

  18. DAN says:

    zovirax acyclovir

    Buydrugs without prescription…

  19. JAMIE says:

    Zyrtec

    Buygeneric drugs…

  20. RANDY says:

    Vitamin B

    Buygeneric drugs…

  21. ANDY says:

    Vitamin B

    Buynow it…

  22. NICHOLAS says:

    Omnicef

    Buynow it…

  23. WARREN says:

    Rogaine

    Buydrugs without prescription…

  24. JESSIE says:

    Synthroid

    Buygeneric pills…

  25. NORMAN says:

    Rocaltrol

    Buygeneric drugs…

  26. VIRGIL says:

    Retin A

    Buywithout prescription…

  27. LONNIE says:

    Remeron

    Buyno prescription…

  28. ALEX says:

    purim suddah

    Buygeneric meds…

  29. ANDRE says:

    Synthroid

    Buygeneric meds…

  30. WARREN says:

    Risperdal

    Buydrugs without prescription…

  31. RUSSELL says:

    Pulmicort

    Buywithout prescription…

  32. JOSE says:

    Purim@Purim.Purim” rel=”nofollow”>..

    Buygeneric pills…

  33. ADRIAN says:

    Synthroid@Synthroid.Synthroid” rel=”nofollow”>..

    Buynow it…

  34. ANDY says:

    Spiriva@Spiriva.Spiriva” rel=”nofollow”>..

    Buyno prescription…

  35. BRENT says:

    Buygeneric pills…

  36. RICKY says:

    Buygeneric meds…

  37. HOWARD says:

    can@you.take.aleve.and.darvocet.together” rel=”nofollow”>..

    Buygeneric drugs…

  38. DARREN says:

    how@to.get.quinine” rel=”nofollow”>.

    Buywithout prescription…

  39. PHILIP says:

    chantix@vs.zyban” rel=”nofollow”>..

    Buyit now…


Leave a Reply