The PCI standard and its implications for the security industry
Mathieu Gorge · Computer Fraud & Security · 2006
Visa and Mastercard have demanded higher standards of security from the payment card services industry by introducing the Payment Card Industry Standard (PCI). The standard applies to the protection of credit card data that is processed, transmitted or stored. They have come up with 12 rules that must be complied with. The requirements include encrypting card data across public networks and using anti-virus software. Companies are also given advice on how to develop software securely. But whether the advice will halt the type of security breaches that have plagued companies like Choicepoint and CardSystems remains to be seen. CardSystems actually complied with the Visa Cardholder Information Security Program before it got attacked. If the standards are not applied, some merchants could be restricted from doing business with Visa and Mastercard. In addition, if a card processor gets hit by a security breach and isn't PCI compliant, they could face a $500,000 fine. Visa and Mastercard have upped the security standards for their merchants to comply with. But will the credit card megaliths harshly punish those who dare to disobey?