<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>WDTalk &#187; PCI Compliance</title>
	<atom:link href="http://wdtalk.com/archives/category/web-hosting/pci-compliance/feed" rel="self" type="application/rss+xml" />
	<link>http://wdtalk.com</link>
	<description>Web Development, SEO, Business and Hosting</description>
	<lastBuildDate>Fri, 03 Feb 2012 21:50:48 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>eCommerce and PCI DSS requirements</title>
		<link>http://wdtalk.com/archives/877</link>
		<comments>http://wdtalk.com/archives/877#comments</comments>
		<pubDate>Thu, 12 Mar 2009 16:21:39 +0000</pubDate>
		<dc:creator>Editor</dc:creator>
				<category><![CDATA[eCommerce Hosting]]></category>
		<category><![CDATA[PCI Compliance]]></category>

		<guid isPermaLink="false">http://hostirian.com/blog/?p=877</guid>
		<description><![CDATA[One of the most misunderstood requirements as a merchant offering any type of credit or debit card services are the new security standards released by the Payment Card Industry. Essentially, the PCI DSS (Payment Card Industry Data Security Standard) must be met by all organizations (merchants and service providers) that transmit, process or store credit card data. The [...]]]></description>
			<content:encoded><![CDATA[<div class="plus-one-wrap"><g:plusone href="http://wdtalk.com/archives/877"></g:plusone></div><p>One of the most misunderstood requirements as a merchant offering any type of credit or debit card services are the new security standards released by the Payment Card Industry.</p>
<p>Essentially, the PCI DSS (Payment Card Industry Data Security Standard) must be met by all organizations (merchants and service providers) that transmit, process or store credit card data. The PCI DSS (sometimes referred to as a compliance standard) is not a law, rather a contractual obligation applied and enforced (by means of fines or other restrictions) directly by the payment providers (e.g., Visa &amp; MasterCard) themselves. See a list of validated service providers <a href="http://usa.visa.com/download/merchants/cisp-list-of-pcidss-compliant-service-providers.pdf">here</a>.</p>
<p>PCI security standards are technical and operational requirements that were created to help organizations that process card payments prevent credit card fraud, hacking and various other security vulnerabilities and threats.<br />
The core of the PCI DSS is a group of principles and accompanying requirements, around which the specific elements of the DSS are organized:</p>
<p><strong>Build and Maintain a Secure Network</strong></p>
<p>Requirement 1: Install and maintain a firewall configuration to protect cardholder data<br />
Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters</p>
<p><strong>Protect Cardholder Data</strong></p>
<p>Requirement 3: Protect stored cardholder data<br />
Requirement 4: Encrypt transmission of cardholder data across open, public networks</p>
<p><strong>Maintain a Vulnerability Management Program</strong></p>
<p>Requirement 5: Use and regularly update anti-virus software<br />
Requirement 6: Develop and maintain secure systems and applications</p>
<p><strong>Implement Strong Access Control Measures</strong></p>
<p>Requirement 7: Restrict access to cardholder data by business need-to-know<br />
Requirement 8: Assign a unique ID to each person with computer access<br />
Requirement 9: Restrict physical access to cardholder data</p>
<p><strong>Regularly Monitor and Test Networks</strong></p>
<p>Requirement 10: Track and monitor all access to network resources and cardholder data<br />
Requirement 11: Regularly test security systems and processes</p>
<p style="line-height: 10.95pt;"><strong>Compliance requirements are dependent on a merchant&#8217;s activity level.</strong></p>
<p style="line-height: 10.95pt;">There are four activity levels, based on the annual number of credit/debit card transactions.</p>
<p style="line-height: 10.95pt;">In general:</p>
<p style="margin-bottom: 0pt; line-height: 10.95pt;"><strong>Level 1 Criteria<br />
</strong>Merchants with over 6 million transactions a year, or merchants whose data has previously been compromised<br />
Level 1 Validation Requirements<br />
Annual Onsite Security Audit (reviewed by a QSA or Internal Audit if signed by officer of merchant company and pre-approved by acquirer) and quarterly network security scan</p>
<p><strong>Level 2 Criteria<br />
</strong>Merchants with 1,000,000 to 6 million transactions a year<br />
Level 2 Validation Requirements<br />
Annual Self Assessment Questionnaire<br />
Quarterly Scan by an Approved Scanning Vendor (ASV)</p>
<p><strong>Level 3 Criteria<br />
</strong>Merchants with 20,000 to 1,000,000 transactions a year<br />
Level 3 Validation Requirements<br />
Quarterly Scan by an Approved Scanning Vendor (ASV)<br />
Annual Self Assessment Questionnaire</p>
<p><strong>Level 4 Criteria<br />
</strong>Merchants with less than 20,000 transactions<br />
Level 4 Validation Requirements<br />
Annual Self Assessment Questionnaire</p>
<p>Quarterly Scan by an Approved Scanning Vendor (may be recommended or required, depending on acquirer compliance criteria)</p>
<p>For further information</p>
<p>For comprehensive information about eCommerce and PCI DSS requirements, please visit the PCI Security Standards Council <a href="https://www.pcisecuritystandards.org/about/resources.shtml">website</a>.</p>
<script type="text/javascript">  linkscolor = "000000";  highlightscolor = "888888";  backgroundcolor = "FFFFFF";  channel = "none";   </script><script type="text/javascript" src="http://www.addmarx.com/dynamicbookmark_compressed.php"></script><span><a onClick="clickDynamic1(this); return false;" href="http://www.addmarx.com"><img style="padding:0px; margin:0px" src="http://www.wdtalk.com/wp-content/plugins/addmarx/sharebookmarx.png" border="0"></a></span><span style="position:absolute; z-index:1000001; margin-top:24px; margin-left:-127px; visibility:hidden;"><iframe id="addmarx_empty" scrolling="no" frameborder="0"></iframe></span><p class="addmarx_spacer"></p><!-- Please place the above code into your site where you want to have a bookmark/share/publicize link. Please do not change any of the code aside from the link text or image, or else the code may not work properly.  --><script type="text/javascript">
var Taggable_iWpVersion = '3.3.1';
var Taggable_sUrlOfPage = 'http://wdtalk.com/archives/877';
var Taggable_sDisplayStyle = '';
var Taggable_bTaggableIcon = true;

</script>
<script src="http://taggable.com/js/button.js" type="text/javascript"></script>]]></content:encoded>
			<wfw:commentRss>http://wdtalk.com/archives/877/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Extended Validation (EV) SSL Certificates – Go Green</title>
		<link>http://wdtalk.com/archives/811</link>
		<comments>http://wdtalk.com/archives/811#comments</comments>
		<pubDate>Fri, 06 Mar 2009 20:00:01 +0000</pubDate>
		<dc:creator>Editor</dc:creator>
				<category><![CDATA[eCommerce Hosting]]></category>
		<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://hostirian.com/blog/?p=811</guid>
		<description><![CDATA[Extended Validation (EV) SSL Certificates meet the highest standard in the Internet security industry for Web site authentication. EV SSL Certificates give high-security Web browsers information to clearly display a Web site&#8217;s organizational identity. The high-security Web browser&#8217;s address bar turns GREEN and reveals the name of the organization that owns the SSL Certificate and the [...]]]></description>
			<content:encoded><![CDATA[<div class="plus-one-wrap"><g:plusone href="http://wdtalk.com/archives/811"></g:plusone></div><p><strong>Extended Validation (EV) SSL Certificates</strong> meet the highest standard in the Internet security industry for Web site authentication. EV SSL Certificates give high-security Web browsers information to clearly display a Web site&#8217;s organizational identity. The high-security Web browser&#8217;s address bar turns <strong>GREEN</strong> and reveals the name of the organization that owns the SSL Certificate and the SSL Certificate Authority that issued it. Why is this important? It gives Web site visitors an easy and reliable way to establish trust online.</p>
<p>I&#8217;ve started noticing more and more green EV SSL certificates lately, but I was on a local Credit Union&#8217;s site yesterday afternoon and noticed their SSL didn&#8217;t even show that the site was encrypted. I was stunned. I&#8217;ve been in that Credit Union a number of times and know their IT security to be first rate.  Their site was recently revamped, so I suspect their new host cut costs by installing a cheap SSL certificate, as they can be found online for less than ten dollars.</p>
<p>Secure Sockets Layer (SSL) technology protects your Web site and makes it easy for your Web site visitors to trust you in <strong>three</strong> essential ways:</p>
<ul>
<li>1. An SSL Certificate enables <strong>encryption</strong> of sensitive information during online transactions.</li>
<li>2. Each SSL Certificate contains unique, <strong>authenticated</strong> information about the certificate owner.</li>
<li>3. A Certificate Authority <strong>verifies</strong> the identity of the certificate owner when it is issued.</li>
</ul>
<p>You need SSL if&#8230;</p>
<ul>
<li>You have an online store or accept online orders and credit cards</li>
<li>You offer a login or sign in on your site</li>
<li>You process sensitive data such as address, birth date, license or ID numbers</li>
<li>You need to comply with privacy and security requirements</li>
<li>You value privacy and expect others to trust you.</li>
</ul>
<p>Extended Validation SSL Certificates give high-security Web browsers information to clearly identify a Web site&#8217;s organizational identity. For example, if you use Microsoft® Internet Explorer 7 to go to a Web site secured with an SSL Certificate that meets the Extended Validation Standard, IE7 will cause the URL address bar to turn green. A display next to the green bar will toggle between the organization name listed in the certificate and the Certificate Authority (<strong>VeriSign</strong>, for example). Firefox 3 also supports Extended Validation SSL.</p>
<script type="text/javascript">  linkscolor = "000000";  highlightscolor = "888888";  backgroundcolor = "FFFFFF";  channel = "none";   </script><script type="text/javascript" src="http://www.addmarx.com/dynamicbookmark_compressed.php"></script><span><a onClick="clickDynamic1(this); return false;" href="http://www.addmarx.com"><img style="padding:0px; margin:0px" src="http://www.wdtalk.com/wp-content/plugins/addmarx/sharebookmarx.png" border="0"></a></span><span style="position:absolute; z-index:1000001; margin-top:24px; margin-left:-127px; visibility:hidden;"><iframe id="addmarx_empty" scrolling="no" frameborder="0"></iframe></span><p class="addmarx_spacer"></p><!-- Please place the above code into your site where you want to have a bookmark/share/publicize link. Please do not change any of the code aside from the link text or image, or else the code may not work properly.  --><script type="text/javascript">
var Taggable_iWpVersion = '3.3.1';
var Taggable_sUrlOfPage = 'http://wdtalk.com/archives/811';
var Taggable_sDisplayStyle = '';
var Taggable_bTaggableIcon = true;

</script>
<script src="http://taggable.com/js/button.js" type="text/javascript"></script>]]></content:encoded>
			<wfw:commentRss>http://wdtalk.com/archives/811/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hosting Providers &amp; Merchant Accounts – PCI Compliance Explained</title>
		<link>http://wdtalk.com/archives/685</link>
		<comments>http://wdtalk.com/archives/685#comments</comments>
		<pubDate>Mon, 23 Feb 2009 22:47:50 +0000</pubDate>
		<dc:creator>Editor</dc:creator>
				<category><![CDATA[PCI Compliance]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://rss.rcig.net/?p=685</guid>
		<description><![CDATA[There seems to be a great deal of confusion about PCI compliance, on the part of merchants and hosting providers. Who&#8217;s responsible for what? First, the merchant (web host) always remains responsible for compliance &#8211; to be certified. Their hosting provider (data center) is responsible within the scope of the infrastructure and services they provide [...]]]></description>
			<content:encoded><![CDATA[<div class="plus-one-wrap"><g:plusone href="http://wdtalk.com/archives/685"></g:plusone></div><p>There seems to be a great deal of confusion about PCI compliance, on the part of merchants and hosting providers. Who&#8217;s responsible for what?</p>
<p>First, the merchant (web host) always remains responsible for compliance &#8211; to be certified. Their hosting provider (data center) is responsible within the scope of the infrastructure and services they provide to the merchant &#8211; for example, real estate (floor, electricity and controlled physical access). If a hosting provider also manages the merchant&#8217;s network, then they&#8217;re responsible for that specific scope of compliance.</p>
<p>Having said that, the merchant is required to monitor compliance of their service providers and manage any non-compliant risks, but a hosting provider&#8217;s PCI compliance isn&#8217;t mandatory for merchants to use that provider.  As a merchant who accepts card payments for products or services, you are obligated to be PCI compliant &#8211; but not for the environment in it&#8217;s entirety, rather limited to the processing of the credit cards, storage of that data and their respective transmission gateways. To that end, PCI is technology neutral, meaning you don&#8217;t have to build out with specific infrastructure.</p>
<p>So what are the minimum requirements? A couple of servers. a firewall, logging, monitoring and IDS / IPS (intrusion detection and intrusion prevention systems) capabilities.</p>
<script type="text/javascript">  linkscolor = "000000";  highlightscolor = "888888";  backgroundcolor = "FFFFFF";  channel = "none";   </script><script type="text/javascript" src="http://www.addmarx.com/dynamicbookmark_compressed.php"></script><span><a onClick="clickDynamic1(this); return false;" href="http://www.addmarx.com"><img style="padding:0px; margin:0px" src="http://www.wdtalk.com/wp-content/plugins/addmarx/sharebookmarx.png" border="0"></a></span><span style="position:absolute; z-index:1000001; margin-top:24px; margin-left:-127px; visibility:hidden;"><iframe id="addmarx_empty" scrolling="no" frameborder="0"></iframe></span><p class="addmarx_spacer"></p><!-- Please place the above code into your site where you want to have a bookmark/share/publicize link. Please do not change any of the code aside from the link text or image, or else the code may not work properly.  --><script type="text/javascript">
var Taggable_iWpVersion = '3.3.1';
var Taggable_sUrlOfPage = 'http://wdtalk.com/archives/685';
var Taggable_sDisplayStyle = '';
var Taggable_bTaggableIcon = true;

</script>
<script src="http://taggable.com/js/button.js" type="text/javascript"></script>]]></content:encoded>
			<wfw:commentRss>http://wdtalk.com/archives/685/feed</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>More on PCI compliance for credit card security</title>
		<link>http://wdtalk.com/archives/563</link>
		<comments>http://wdtalk.com/archives/563#comments</comments>
		<pubDate>Thu, 05 Feb 2009 23:00:05 +0000</pubDate>
		<dc:creator>Editor</dc:creator>
				<category><![CDATA[PCI Compliance]]></category>

		<guid isPermaLink="false">http://rss.rcig.net/?p=563</guid>
		<description><![CDATA[There is a CISP list of providers that have been validated as PCI compliant. That list doesn&#8217;t include all providers that have been validated though. To be listed, those providers must also pay VISA an additional fee every year to remain on that list &#8211; sort of an advertising fee. That fee can run into [...]]]></description>
			<content:encoded><![CDATA[<div class="plus-one-wrap"><g:plusone href="http://wdtalk.com/archives/563"></g:plusone></div><p>There is a <a href="http://usa.visa.com/download/merchants/cisp_list_of_cisp_compliant_service_providers.pdf">CISP list of providers </a>that have been validated as PCI compliant. That list doesn&#8217;t include all providers that have been validated though. To be listed, those providers must also pay VISA an additional fee every year to remain on that list &#8211; sort of an advertising fee. That fee can run into the thousands of dollars.  </p>
<p>On the Self Assessment Questionnaire that providers must submit, there are countless items of concern. Just a brief scan of this <a href="https://www.pcisecuritystandards.org/pdfs/navigating_pci_dss_v1-1.pdf">PDF</a> from the PCI Security Standards Council validates the concerns many vendors face concerning their liability.  </p>
<p><strong>PCI compliance is requires so much more than servers and a firewall.</strong></p>
<p>Following is a brief list of requirements:  </p>
<ul type="disc">
<li>Establish firewall configuration standards that include the following:</li>
<li>A formal process for approving and testing all external network connections and changes to the firewall configuration</li>
<li>A current network diagram with all connections to cardholder data, including any wireless networks</li>
<li>Requirements for a firewall at each Internet connection and between any demilitarized zone (DMZ) and the internal network zone</li>
</ul>
<p>The list of requirements goes on and on addressing intrusion detection, internal and external penetration testing, etc.</p>
<script type="text/javascript">  linkscolor = "000000";  highlightscolor = "888888";  backgroundcolor = "FFFFFF";  channel = "none";   </script><script type="text/javascript" src="http://www.addmarx.com/dynamicbookmark_compressed.php"></script><span><a onClick="clickDynamic1(this); return false;" href="http://www.addmarx.com"><img style="padding:0px; margin:0px" src="http://www.wdtalk.com/wp-content/plugins/addmarx/sharebookmarx.png" border="0"></a></span><span style="position:absolute; z-index:1000001; margin-top:24px; margin-left:-127px; visibility:hidden;"><iframe id="addmarx_empty" scrolling="no" frameborder="0"></iframe></span><p class="addmarx_spacer"></p><!-- Please place the above code into your site where you want to have a bookmark/share/publicize link. Please do not change any of the code aside from the link text or image, or else the code may not work properly.  --><script type="text/javascript">
var Taggable_iWpVersion = '3.3.1';
var Taggable_sUrlOfPage = 'http://wdtalk.com/archives/563';
var Taggable_sDisplayStyle = '';
var Taggable_bTaggableIcon = true;

</script>
<script src="http://taggable.com/js/button.js" type="text/javascript"></script>]]></content:encoded>
			<wfw:commentRss>http://wdtalk.com/archives/563/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI Compliance .. What is it? .. Does it apply to YOU?</title>
		<link>http://wdtalk.com/archives/458</link>
		<comments>http://wdtalk.com/archives/458#comments</comments>
		<pubDate>Wed, 21 Jan 2009 17:55:54 +0000</pubDate>
		<dc:creator>Editor</dc:creator>
				<category><![CDATA[PCI Compliance]]></category>

		<guid isPermaLink="false">http://rss.rcig.net/?p=458</guid>
		<description><![CDATA[ I read an interesting thread this morning about PCI compliance. As a merchant, I have some knowledge of PCI regulations, but not as much as I should. I leave that to more knowledgeable members of our staff (COO, legal and accounting departments). It seems the rules are constantly changing, so much so that I wonder [...]]]></description>
			<content:encoded><![CDATA[<div class="plus-one-wrap"><g:plusone href="http://wdtalk.com/archives/458"></g:plusone></div><p><strong> </strong>I read an interesting thread this morning about PCI compliance. As a merchant, I have some knowledge of PCI regulations, but not as much as I should. I leave that to more knowledgeable members of our staff (COO, legal and accounting departments). It seems the rules are constantly changing, so much so that I wonder how many small hosts keep up with all these changes and new requirements. In the posts that followed this thread, misconceptions ran rampid. One member even posted he was proud to be non-compliant. OUCH! I don&#8217;t think I&#8217;ll go there.  The fines for being non-compliant are astronomical!</p>
<p>With so many breaches of credit card security lately, it was inevitable change was forthcoming. I&#8217;m certainly not an expert on the topic, so I leave you with some links to sites that clarify PCI compliance. Enjoy!</p>
<p><strong>Industry Links:</strong></p>
<ul>
<li><a title="blocked::http://www.pcisecuritystandards.org/" href="http://www.pcisecuritystandards.org/" target="_blank">pcisecuritystandards.org</a></li>
<li>pcisecuritystandards.org/saq/instructions.shtml</li>
<li><a title="blocked::https://www.pcisecuritystandards.org/security_standards/ped/index.shtml" href="https://www.pcisecuritystandards.org/security_standards/ped/index.shtml" target="_blank">pcisecuritystandards.org/security_standards/ped/index.shtml</a></li>
<li><a title="blocked::https://www.pcisecuritystandards.org/security_standards/pa_dss.shtml" href="https://www.pcisecuritystandards.org/security_standards/pa_dss.shtml" target="_blank">pcisecuritystandards.org/security_standards/pa_dss.shtml</a></li>
<li><a title="blocked::http://usa.visa.com/download/merchants/cisp_what_to_do_if_compromised.pdf" href="http://usa.visa.com/download/merchants/cisp_what_to_do_if_compromised.pdf" target="_blank">usa.visa.com/download/merchants/cisp_what_to_do_if_compromised.pdf</a></li>
<li><a title="blocked::http://www.mastercard.com/us/sdp/index.html" href="http://www.mastercard.com/us/sdp/index.html" target="_blank"><span title="blocked::http://www.mastercard.com/us/sdp/index.html">mastercard.com/us/sdp/index.html</span>Payment Card Industry Data Security Standard &#8211; Wikipedia, the free encyclopedia</a></li>
<li><a title="blocked::http://www.americanexpress.com/merchant" href="http://www.americanexpress.com/merchant" target="_blank">Approved Scanning Vendors<span title="blocked::http://www.americanexpress.com/merchant">americanexpress.com/merchant</span></a></li>
<li><a title="blocked::http://www.wikipedia.org/wiki/PCI_DSS" href="http://www.wikipedia.org/wiki/PCI_DSS" target="_blank">Society of Payment Security Professionals &#8211; Payment Security Blog <span title="blocked::http://www.wikipedia.org/wiki/PCI_DSS">wikipedia.org/wiki/PCI_DSS</span>Treasury Institute PCI/DSS Blog Redirect</a></li>
<li><a title="blocked::https://www.pcisecuritystandards.org/pdfs/pci_qsa_list.pdf" href="https://www.pcisecuritystandards.org/pdfs/pci_qsa_list.pdf" target="_blank">pcisecuritystandards.org/pdfs/pci_qsa_list.pdf</a></li>
<li><a title="blocked::https://www.pcisecuritystandards.org/pdfs/asv_report.html" href="https://www.pcisecuritystandards.org/pdfs/asv_report.html" target="_blank">pcisecuritystandards.org/pdfs/asv_report.html</a></li>
</ul>
<script type="text/javascript">  linkscolor = "000000";  highlightscolor = "888888";  backgroundcolor = "FFFFFF";  channel = "none";   </script><script type="text/javascript" src="http://www.addmarx.com/dynamicbookmark_compressed.php"></script><span><a onClick="clickDynamic1(this); return false;" href="http://www.addmarx.com"><img style="padding:0px; margin:0px" src="http://www.wdtalk.com/wp-content/plugins/addmarx/sharebookmarx.png" border="0"></a></span><span style="position:absolute; z-index:1000001; margin-top:24px; margin-left:-127px; visibility:hidden;"><iframe id="addmarx_empty" scrolling="no" frameborder="0"></iframe></span><p class="addmarx_spacer"></p><!-- Please place the above code into your site where you want to have a bookmark/share/publicize link. Please do not change any of the code aside from the link text or image, or else the code may not work properly.  --><script type="text/javascript">
var Taggable_iWpVersion = '3.3.1';
var Taggable_sUrlOfPage = 'http://wdtalk.com/archives/458';
var Taggable_sDisplayStyle = '';
var Taggable_bTaggableIcon = true;

</script>
<script src="http://taggable.com/js/button.js" type="text/javascript"></script>]]></content:encoded>
			<wfw:commentRss>http://wdtalk.com/archives/458/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

