Whether you are a Startup or an International organization, Payment Card Industry Data Security Standard (PCI DSS) is essential for you, if you are handling card holders’ data., and your compliance must be validated annually. It is generally mandated by credit card companies and discussed in credit card network agreements.
So, what is PCI DSS ?
The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards developed in 2004 by Visa, MasterCard, Discover Financial Services, JCB International and American Express. Regulated by the Payment Card Industry Security Standards Council (PCI SSC), the compliance scheme plans to safeguard credit and debit card transactions against data stealing and fraud.
While the PCI SSC has no legal mandate to induce compliance, it is a necessity for any business that handles credit or debit card transactions. PCI certification is also considered the safest way to protect sensitive data and information, thereby helping businesses build long lasting and trusting relationships with their customers. The PCI Standards Council (SSC) is responsible for the development of the standards for PCI compliance. Its purpose is to help secure and protect the entire payment card ecosystem. These standards apply for merchants, service providers processing credit/debit card payment transactions.
THE 12 OBLIGATIONS OF PCI DSS
The requirements set forth by the PCI SSC are both operational and technical, and the fundamental aim of these rules is always to protect cardholder data.
The 12 requirements of PCI DSS are:
- Install and keep a firewall configuration to safeguard cardholder data.
- Do not use vendor-supplied defaults for system passwords and other security structures.
- Shield stored cardholder data.
- Encrypt spread of cardholder data across open, public networks.
- Use and frequently update anti-virus software or programs.
- Build Up and maintain secure systems and functions.
- Restrict gain access to cardholder data by business need to know.
- Assign a unique ID to each person with computer access.
- Restrict physical contact to cardholder data.
- Track and observe all access to network reserves and cardholder data.
- Systematically test security techniques and processes.
- Maintain a policy that focuses information security for all personnel.
PCI DSS 12 requirements are a group of security controls that companies are required to implement to guard mastercard data and suits the Payment Card Industry Data Security Standard (PCI DSS).