Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Complying with payment card security requirements

Talking Tech By Jeremy Disse , Network World , 05/22/2008

Compliance is one of those words that send chills down the spine, inspiring nightmares that involve blood-thirsty lawyers, courtrooms and large amounts of money. Handling customer credit card data is a serious responsibility with some attending requirements that are well worth understanding, but it needs not be all that scary for small retailers.

The Payment Card Industry (PCI) compliance regulation affects almost all merchants that accept credit and debit card payments, with the goal of securing cardholders against vulnerabilities to card data theft, misuse or loss. The driving forces behind PCI compliance policies are the major credit card payment processors – Visa, MasterCard, American Express, Discover Card and JCB International – which formed the PCI Security Standards Council to define how retailers should protect transactional data and monitor their data security performance.

Each PCI Council member has defined categories of merchants based on the number of transactions submitted per year, along with PCI audit and reporting requirements pertaining to each category. The precise definition of each category varies between the credit card companies, but we will use Visa's categories to illustrate the scale (MasterCard and American Express generally have lower thresholds for each category):

* Level 1: The highest volume merchants, which submit 6 million or more transactions per year, as well as merchants that have had a data incident or have been classified as Level 1 by another credit card company.

* Level 2: Merchants that submit 1-6 million transactions per year.

* Level 3: Merchants that submit 20,000 to 1 million e-commerce transactions per year.

* Level 4: Merchants submitting less than 20,000 e-commerce transactions per year, and all other merchants up to 1 million transactions per year

Rightfully, merchants submitting higher volumes of transactions face the most stringent PCI compliance standards and penalties, due to the risks associated with the quantity of data they possess. However, Visa reports that cardholder data is compromised more frequently among Level 4 merchants than by Levels 1, 2 and 3 combined – small wonder, because 99% of the merchants that accept Visa cards are Level 4 merchants.

Security assessment requirements for smaller merchants

Level 3 merchants are required to perform and submit an annual PCI self-assessment questionnaire, as well as to have a qualifying vendor perform a quarterly network scan and report on compliance. Acquiring banks for Level 4 merchants may require the same self-assessment and network scan – merchants should contact their acquiring bank to determine what it requires.

Partner Content

Company Description

Emerson Network Power and its Liebert power and cooling technologies increase IT system flexibility and availability, while lowering the total cost of ownership.

Power and Cooling Guidelines

Learn how to optimize power and cooling in network access rooms to keep equipment operating at peak performance and proactively monitor changes.

Download this white paper

Business-Critical Continuity

Read about Sequent and how they implemented a new data center to meet current requirements while easily scaling to support projected growth.

Download this case study

Cutting Energy Costs

Reduce cooling system energy costs by 30 to 45 percent through five data center efficiency strategies.

Download this white paper

Comments (1)
Login
Forgot your account info?

Adhering to standards while Protecting your ClientsBy Anonymous on May 22, 2008, 4:41 pmCapturing an encrypted file only poses a problem if the encryption has been hacked. There are multiple solutions on the market today that team encryption with different...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed

IT Buyer's Guides
These guides cover more than 70 product categories to bring you information, insight, and comparisons on the latest in key networking technology.

 

Save The Date!
What They Are Saying

and there is always a but... firebug doesnt work :(- Anonymous

Join the Discussion