PCI Compliance
PCI DSS is the Payment Card Industry
Data Security Standard developed by
the major credit card companies to
assist organizations that accept credit
in reducing security issues. Any company
that processes, stores, or transmits
credit card numbers must be PCI DSS
compliant or risk losing their ability
to process credit card transactions.
At this time, there are 12 specific
requirements for compliance organized
into six control objectives. These
include:
| PCI Compliance Data
Security Standards (PCI DSS) |
| Build and Maintain a Secure
Network |
1. Install and maintain a firewall
configuration to protect data
2. Do not use vendor-supplied
defaults for system passwords
and other security parameters
|
| Protect Cardholder Data |
3. Protect stored data
4. Encrypt transmission of cardholder
data and sensitive information
across public networks |
| Maintain a Vulnerability Management
Program |
5. Use and regularly update
anti-virus software
6. Develop and maintain secure
systems and applications |
| Implement Strong Access Control
Measures |
7. Restrict access to data by
business need-to-know
8. Assign a unique ID to each
person with computer access
9. Restrict physical access to
cardholder data |
| Regularly Monitor and Test Networks |
10. Track and monitor all access
to network resources and cardholder
data
11. Regularly test security systems
and processes |
| Maintain an Information Security
Policy |
12. Maintain a policy that addresses
information security |
BHI Advanced Internet is able to address
every objective that applies to firewalls,
anti-virus, configurations, and on-going
management with SecureConnect.
SecureConnect addresses the specific
requirements of installing and maintaining
a firewall; configuring a firewall
without using defaults for system
passwords or other security parameters;
encrypting transmission of outgoing
cardholder data; using and updating
anti-virus software; and regularly
testing security systems. In managing
the outward facing technology, SecureConnect
allows users the opportunity to focus
on implementing stronger controls
for managing internal processes. This
partnership reduces the overall liability
associated with the Internet and works
towards meeting the PCI DSS requirements.
|