ArticleTrader.com
  

 Main Menu

  Home
  Member Login
  Forum
  Submit Article
  RSS Feeds
  Contact Us
  About

 Services

  Article Distribution
  Link Building

 Tools

  ArticleMS
  Directory Tracker

 Categories

  Automotive
  Business
  » Advertising
  » Branding
  » Career
  » Communication
  » Customer Service
  » Management
  » Marketing
  » Networking
  » PR
  » Sales
  » Small Business
  Computers
  Entertainment
  Finance
  Food
  Health
  Home and Family
  Internet
  Legal
  Science
  Self Improvement
  Shopping
  Society
  Sports
  Technology
  Travel
  Writing

89 users online.



 
  » Category Sponsors
  Get Your Link Here - Limited Time Bargain at only $14/month!

Home » Business » How Tokenization Affects PCI Compliance
Article Stats:
18 Views
681 Words

Get Html Code
PDF | Print View | Post to your Site

How Tokenization Affects PCI Compliance

Submitted by andyeliason
Fri, 2 May 2008

PCI compliance - the security measures mandated by the Payment Card Industry of any merchant stores, processes, or transmits sensitive credit card information. The PCI DSS (Data Security Standard) is a set of 12 requirements that merchants must adhere to, or risk some hefty fines and penalties.

PCI compliance is not, unfortunately, a quick and easy standard to reach. The reason for this should be obvious: the data that you are responsible for protecting is sensitive in the extreme, and anything less than the strongest possible protection will result in breaches, loss of data, and loss of reputation.

What, then, is a company to do if PCI compliance is such a complicated matter?

Recently, outsourcing of payment processing has become a popular option. This eliminates the massive changes in your business practices that would otherwise be required, and it leaves this sensitive information with a company that (hopefully) specializes in providing PCI compliant security.

Still, the problem with outsourcing payment processing lies in the fact that you have now greatly increased the number of electronic transmissions that must be made. And a hacker could attempt to interrupt, intercept, divert, or otherwise manipulate those transmissions.

The answer that has begun to surface is a new technology called tokenization. By employing this method, merchants can safely transfer their data without the risk of it falling into the wrong hands.

Tokenization is an affordable option for merchants who are looking to reach PCI compliance because it can generally be integrated with a merchant's existing procedures with minimum interruptions or changes to the company's normal way of doing business.

Tokenization works like this: a merchant accepts a payment card or the associated sensitive information from a customer. In other words, this process can be applied to retail outlets or in card-not-present transactions. Initially, the customers information is sent to the service providers - the company providing the tokenization or payment processing - who, in turn, provide a randomly generated, totally unique ID number and return it to the merchant.

Now, with this number - or token - in place, it is the only information that a merchant needs to store on-site. This number is all they need to access customer records, conduct multiple transactions, or even institute recurring billing procedures.

The most obvious benefit from this is that, with nothing but a list of randomized 16-digit numbers on your own system, there is nothing of value for a thief to take. Even if they managed to intercept a token in transmission, decrypted the signals and everything, there is, in truth, nothing for them to do with the numbers. They are meaningless to everyone but the merchant.

Methods like tokenization become a great way to reach PCI compliance because of the responsibility shift to a company that is prepared to spend the time and resources to protect card holder data. Guarding this information is a constant battle, and the only way to ensure its safety is through perpetual vigilance. Many merchants, unfortunately, aren't prepared to do this. It's not that they have no interest in PCI compliance, or that they don't care about customer data, because they do. It is simply that, given the demands of maintaining every-day aspects of their regular business, they dimply don't have the necessary resources to deal with compliance.

The does not, however, change the fact that the PCI DSS is a requirement and cannot be ignored.

The Payment Card Industry will continue to evolve, as will the tactics used by hackers to gain access to your systems. This will, of course, prompt the industry to evolve yet again. This has created a type of disheartening effect among some merchants, as these requirements seem more and more unattainable.

But the truth is, PCI compliance is within reach. And if you have to outsource certain aspects of your payment processing or employ tokenization techniques, then do it now, and find the safety that comes with being compliant.

About the Author

Andy Eliason is a writer at Main10, Inc. If you'd like to learn more about PCI compliance, or using tokenization, visit Braintree Payment Solutions today.


Source: ArticleTrader.com
Creative Commons License

Comments

No comments posted.

Add Comment

Your Name:


Your Email:


Comment

Enter the code shown

Visual CAPTCHA

 Top Authors

 1 stickystebee (3078)
 2 alien82 (2756)
 3 kajuba (2359)
 4 limalan88 (2226)
 5 sverdlow (1712)
 6 juliet (1683)
 7 AnthonyF (1244)
 8 artavia.seo (1138)
 9 MarkeD (1101)
 10 isolvum (1019)
 11 cj (946)
 12 IC (935)
 13 jkhbraveheart (847)
 14 lets_j2top@ya.. (825)
 15 Osborne (801)

 Latest Forum

» Total Views Shows As Zero
» Articles Directory
» I give up!
» Getting Traffic With Content
» I need Your Opinion
» earache pain relief Las Vegas gav

 Distribution

Article Distribution

  
  Affiliate Program 2Checkout.com, Inc. is an authorized retailer of ArticleTrader.com

3.57s