Redspin
Redspin Research
Redspin Presentations
Redspin Videos
Redspin Data Sheets
Redspin White Papers
Technical Resources
Regulatory Resources
Security Management
Advisory
Contact Us Toll Free - 800-721-9177
Redspin SMA Sign Up!
Sign yourself or a colleague up for our free Redspin Security Management Advisory monthly newsletter. We will not share your email address.
* = Required Information
Name:
* Email:
Request A Quote
Security Blog
Assessment Services Assessment Tools Security Research About Us Contact Us
Security Management Advisory

Back To Redspin Security Management Advisory Headlines
Security Management Advisory Volume 5 |  August 6, 2008
PCI-DSS: 90 second overview of the Payment Card Industry Data Security Standard
What is the PCI DSS?
PCI DSS stands for the Payment Card Industry Data Security Standard. It is a set of security standards developed by the credit card companies, including Mastercard, Visa and American Express, to protect sensitive data related to credit cards and credit card transactions.
Who is affected by the PCI DSS?
Any organization that transmits, stores, or processes credit card information is required to comply with the PCI DSS. This includes merchants and service providers.
What is required by the PCI DSS?
The PCI DSS includes specific security requirements which are organized under 6 broad security objectives:
Objective 1: Build and Maintain a Secure Network
Objective 2: Protect Cardholder Data
Objective 3: Maintain a Vulnerability Management Program
Objective 4: Implement Strong Access Control Measures
Objective 5: Regularly Monitor and Test Networks
Objective 6: Maintain an Information Security Policy
What do I have to do?
Every organization that transmits, stores, or processes credit card information is required to comply with the PCI DSS. However, the extent to which you are required to report on your compliance depends on the volume of card transactions you handle. If you're Level 1 (high volume/millions of transactions), you need a full PCI audit to validate compliance. If you're level 4 (low volume/just a few transactions), the completion of a self assessment questionnaire from PCI is usually enough.
Does PCI have teeth?
Yes, there are fines and penalties for non-compliance, in addition to the possible revocation of the right to process credit card transactions.
Are there any deadlines?
Most of the PCI compliance deadlines have already passed, although the card brands are still in the process of notifying their customers about compliance. You may hear from one of the brands that you need to be in compliance, or you may get notification from your processor if you have a relationship with them rather than the card brand directly.
What is the typical compliance process?
Most organizations are not in compliance with the PCI DSS before doing a PCI audit, so the typical life cycle of compliance involves 3 steps:
Step 1 - Pre-audit:
A gap analysis between what you are doing and full PCI compliance
Step 2 - Remediation:
Fix any security issues.
Step 3 - Final Audit:
Self assessment or 3rd-party audit (depending on your level) to validate compliance.
The Big Gotchas
The biggest cost by far is upgrading your security program to be PCI compliant. So from a cost and compliance perspective, two important considerations are:
Network Segmentation: Many of the PCI DSS requirements only apply to the portions of your network that transmit, store, or process credit card information. Segmenting your network so that these functions are isolated greatly simplifies the compliance process.
Objectivity of Audit Process: Because the biggest compliance expense by far is remediation (buying and implementing IT solutions can cost 10-times the cost of an audit) it is very important to understand the relationship (and profit motive) between the person doing your PCI audit and the person doing your remediation.
For More Information:
View Redspin PCI FAQ
View PCI Website
Schedule a Free 30-Minute PCI Consultation With a Redspin Consultant
* = Required Information
Contact Information:
* Your Name:
* Company:
* Email:
* Telephone:
Questions?
Would you like to submit a question to the "A" Team
Security Experts?

Home  |  Assessment Services  |  Assessment Tools  |  Security Research  |  About Us  |  Contact Us  |  Site Map
©2009 Redspin, Inc. | Privacy Policy
Site Design and Development by Petro Design Co.

External Network Security Assessments

Internal Network Security Assessments

Website Security Audit

Financial Services

Healthcare Security Audit

Social Engineering

Special Security Assessment Services

PCI Services

Casino IT Audits

Testing and Certification Program

NMap XML2SQL

fTrace

Crackulator

Redspin Research

Redspin Presentations

Redspin Videos

Redspin Data Sheets

Redspin White Papers

Technical Resources

Regulatory Resources

Security Management Advisory

Corporate Ethos

Environmental Ethos

Redspin In The News

Press Releases

Upcoming Events

Careers

Contact Us

Request Pricing