A new baseline for cardholder security

Michael Owen, Colin Dixon · Network Security · 2007

The Payment Card Industry Data Security Standard (PCI DSS) is the security standard that the major players in the credit card industry are imposing on their operating partners. With a UK deadline for compliance at the end of this month, companies are scurrying to check their security status, but what lies in store for them? The regulatory requirements could leave many retailers scurrying to audit their own security systems and bring them into compliance with the new code. Michael Owen and Colin Dixon of security consultancy Information Risk Management plc (which recently obtained its VISA Europe Payment Application Best Practice certification) take us through the ins and outs of the standard, and explain how its compliance requirement map onto real-world practices. They also discuss the applicability of the standard's requirements to more generic corporate security practices. This article discusses the Payment Card Industry Data Security Standard, also known as the PCI DSS. This standard has been assembled by the PCI group as a security baseline for all processors, handlers, or collectors of cardholder data bearing the mark of any of the members of the PCI. We will first consider what issues the standard attempts to address, issues of compliance, and penalties for non-compliance, before going on to explore some of the issues encountered in compliance, some details around the data being protected, and how the PCI DSS might be applied to other areas of business.

Read the paper · More papers on PaperTik