PCI COMPLIANCE -
ARE YOU READY?
Obviously there has been a constant stream of news regarding
Credit Card breaches during the last couple years. We could
fill a book with all of the major companies who's Credit Card
information has been compromised. The most recent being the
HANNAFORD problem. Every time these happen, I have to replace
my Card. This happened in both the TJ MAXX case and the
HANNAFORD case. I am just one of the lucky ones who didn't
loose money, just a little frustration.
Okay, so I am the customer and I got compromised.
But what about the Merchant? YOU! How would
you respond if you discovered that all of your customers
Credit Card information had been stolen out of your system?
Guess what? It doesn't matter how you would feel, what matters
is that you ALLOWED THIS TO HAPPEN and YOU ARE NOW LIABLE
for FINES - perhaps Thousands of Dollars in
fines. Unable to pay? The Credit Card Companies have the
right to hold all of your Credit Card receipts in payment.
Know The Key PCI Terms And Who They Apply
To Within the payment processing debate are several
acronyms that are bandied around. The first one VARs should be aware
of is PCI DSS (data security standard). According to Visa, which
collaborated with MasterCard to create PCI DSS (which other U.S.
card companies are adopting), this is an industry security
requirement for payment processing application users that comprises
12 requirements:
1. Install and maintain a firewall configuration to protect
data. 2. Do not use vendor-supplied defaults for system passwords
and other security parameters. 3. Protect stored cardholder
data. 4. Encrypt transmission of cardholder data and sensitive
information across open public networks. 5. Use and regularly
update antivirus software. 6. Develop and maintain secure systems
and applications. 7. Restrict access to data by business
need-to-know (i.e. ensure critical data can only be accessed by
authorized personnel). 8. Assign a unique ID to each person with
computer access. 9. Restrict physical access to cardholder
data. 10. Track and monitor all access to network resources and
cardholder data. 11. Regularly test security systems and
processes. 12. Maintain a policy that addresses information
security.
In many cases among our customers and thousands of others out
there with POS systems the software works great; the systems keep
running day after day; they may be completely paid for; and
ARE A MAJOR CREDIT CARD SECURITY PROBLEM WAITING TO BE
'HACKED'.
We can tell you that if your POS system was purchased more than
2 years ago and you have not Upgraded the Software, Kept the
Anti-Virus updated, Checked your Firewall settings - you could have
problems, BIG PROBLEMS SPELLED $$$$$$$$$
Call us today 877-627-0636 for a
free Question - Answer Session.
We're not trying to scare you, we are trying to
save you.
By the way, you only have until Oct. 2008 to get
into compliance. |