ArticleTrader.com
  

 Main Menu

  Home
  Member Login
  Forum
  Submit Article
  Membership
  RSS Feeds
  Contact Us
  About

 Services

  Article Distribution
  Link Building

 Tools

  ArticleMS
  Directory Tracker

 Categories

  Automotive
  Business
  Computers
  » Games
  » Hardware
  » Software
  Entertainment
  Finance
  Food
  Health
  Home and Family
  Internet
  Legal
  Science
  Self Improvement
  Shopping
  Society
  Sports
  Technology
  Travel
  Writing

187 users online.



 
  » Category Sponsors
  Get Your Link Here - Limited Time Bargain at only $11/month!

Home » Computers » Software » Achieving PCI DSS Compliance

brianw
Article written by brianw

View Full Profile
Get Html Code
PDF | Print View | Post to your Site

Achieving PCI DSS Compliance

Submitted by brianw
Mon, 31 Jan 2011

The Payment Card Industry- Data Security Standard (PCI-DSS) is a worldwide information security standard defined by the Payment Card Industry Security Standards Council. The main objective behind the formulation of this standard is to prevent credit card fraud and to protect card holder information. This standard is applicable to all organizations which accept card payments, and store, process, or exchange card holder information.

However, from the perspective of organizations, achieving PCI-DSS compliance can be quite a challenging affair. Even a minor slip or compromise could result in huge financial losses as well as loss of reputation. While organizations have been employing various methods to ensure compliance with PCI-DSS, these methods suffer certain serious inadequacies :

• In most organizations, encryption across computer networks is inconsistent. Therefore, credit card data are protected in some cases, but not in others
• Some merchants store credit card data unnecessarily, and also fail to prevent them from being transmitted to less secure parts of the network
• Some organizations fail to maintain a log of network activity, which can help reveal instances of attempted hacking. Hence, it becomes impossible to track unauthorized access to credit card data
• Compliance management systems deployed by some companies are not proactive but reactive. So they do not scan for vulnerabilities or abnormal system activities. Hence they fail to completely protect the system from security attacks
• Certain organizations employ disparate systems for compliance to HIPAA, SOX and other regulations, but fail to understand that these systems do not address PCI-DSS requirements

Therefore, achieving PCI-DSS compliance necessitates the adoption of a fool-proof method with 12 basic requirements:

• Installation and maintenance of a firewall configuration to protect card holder data
• Preventing usage of vendor-supplied defaults for system passwords and other security parameters
• Protection of stored card holder data
• Encrypted transmission of card holder data across open, public networks
• Usage and frequent update of anti-virus software
• Development and maintenance of secure systems and applications
• Restriction of access to card holder data
• Assignment of a unique ID to each person with system access
• Restriction of physical access to card holder information
• Tracking and monitoring of all access to network resources and card holder information
• Regular testing of security systems and processes
• Formulation and maintenance of a policy that addresses IT complianceand security

However, using disparate systems to meet these multiple requirements is not the answer. It is important for organizations to resort to an integrated compliance management software solution, which offers key features to support these requirements. By doing this, organizations can not only ensure secured storage, processing and exchange of card holder information but also safeguard their brand image and reputation.

 

Writing is my hobby……………………………..


Source: ArticleTrader.com
Creative Commons License

Comments

No comments posted.

Add Comment

You do not have permission to comment. If you log in, you may be able to comment.

 Top Authors

 1 Stebee (3270)
 2 limalan88 (2920)
 3 alien82 (2756)
 4 kajuba (2508)
 5 sverdlow (1712)
 6 jamiehanson (1705)
 7 juliet (1691)
 8 MarkeD (1296)
 9 robertoms2003 (1296)
 10 AnthonyF (1244)
 11 articles (1205)
 12 artavia.seo (1148)
 13 spinxwebdesign (1119)
 14 gprather (1071)
 15 LouieLiu (1069)

 Distribution

Article Distribution

  
  Affiliate Program 2Checkout.com, Inc. is an authorized retailer of ArticleTrader.com

0.08s