New security standards from credit card companies come into force at the end of next month; all merchants must abide by them, and larger ones will be audited.
The Payment Card Industry Data Security Standard, which is accepted by Visa, Mastercard, Amex and Diners Club, represents a concerted effort to tackle identity theft and on-line fraud. It sets out procedures for handling cardholder information in a secure manner, and requires that merchants carry out a quarterly compliance check. All merchants are covered by the standard, although only those carrying out more than 20,000 transactions per year will be obliged to have their compliance verified.
Sanctions for errant merchants include heavy fines and the threat of the withdrawal of credit card processing facilities. By using a single standard and enforcing it strongly the credit card industry hopes to stem the tide of identity theft and on-line fraud. Recent security breaches include the loss of backup tapes containing the credit card information of 1.2 million federal workers by Bank of America, the loss of around 310,000 sets of customer information at a subsidiary of LexisNexis, and the loss of transaction data belonging to around 180,000 customers of Polo Ralph Lauren.
The requirements of the standard include:
These Payment Card Industry (PCI) Data Security Requirements apply to all members, merchants, and service providers that store, process or transmit cardholder data. Additionally, these security requirements apply to all “system components” which is defined as any network component, server, or application included in, or connected to, the cardholder data environment. Network components, include, but are not limited to, firewalls, switches, routers, wireless access points, network appliances, and other security appliances. Servers include, but are not limited to, Web, database, authentication, Domain Name Service (DNS), mail, proxy, and Network Time Protocol (NTP). Applications include all purchased and custom applications, including internal and external (Web) applications.
.
|
Archive | Resources | Partners | Site Map | Links | Newsletter Archive | Contact | RSS Feeds | About | Syndication | Advertising & Marketing | Recruitment | Terms & Conditions | Privacy & Cookies
Copyright © 2012 - All Rights Reserved - Tax-News.com
IMPORTANT NOTICE: Tax-News.com has taken reasonable care in sourcing and presenting the information contained on this site, but accepts no responsibility for any financial or other loss or damage that may result from its use. In particular, users of the site are advised to take appropriate professional advice before committing themselves to involvement in offshore jurisdictions, offshore trusts or offshore investments.
Write a comment