PCI DSS

Payment Card Industry Device Security Standards

 

PCI DSS stands for “Payment Card Industry Device Security Standards”. Essentially it’s an IT security standard for companies that handle credit or debit card transactions and aims to reduce card fraud. This is done through enforcing controls around the storage, transmission and processing of cardholder data.

PCI DSS compliance is split into six categories, which can be briefly described below:

Contact us today to find out more

R

BUILD AND MAINTAIN A SECURE NETWORK

Install and maintain a firewall configuration to protect data.

Do not use the manufacturer’s default password and other parameters.

R

PROTECT CARDHOLDER DATA

Protect stored data by the use of encryption.

Encrypt cardholder data and other secure information during transmission across the Internet.

R

MANAGEMENT PROGRAMME

Use and regularly update anti-virus software.

Develop and maintain secure systems and applications.

Ensure security updates are applied.

R

MAINTAIN AN INFO SECURITY POLICY

Maintain a policy that addresses information security.

Ensure that all staff are aware of their obligations under this policy.

R

MONITOR YOUR NETWORKS REGULARLY

Track and monitor all access to network resources and cardholder data.

Regularly test the security systems and also the processes.

R

IMPLEMENT STRONG ACCESS CONTROL

Restrict data access on a need-to-know basis.

Make sure that everyone uses their own logins.

Restrict physical access to card data.

How can we help?

As a company that processes credit cards, you will receive letters from your PSP (payment services provider) stating that you need to answer questionnaires and attest to things that you might not really understand, in order to maintain compliance.

Quite often the card processing environment will have been incorrectly profiled and as a result, the questionnaires that need to be submitted will be far more complex than are necessary for the environment.

We are able to assist with this. First of all we will ensure that your environment is profiled correctly.

Next we will interpret these questionnaires in plain English for you and explain how they relate to your business. Lastly, we will ensure that the responses that we submit are correct.

Similarly, your network may require segmentation in order to ensure that the cardholder data environment is compliant. We are able to assist you with this, ensuring that cardholder data is processed using infrastructure that is compliant.

We can take these headaches away from you, simply get in touch, we are here to help. 

Contact Us

Want to know more? Get in touch with us today.

Fully managed IT

IT Security

Networking

Disaster Recovery

Telephony