Cutecra - Home     Lifecycle Solutions     Technology Solutions     Service Solutions     PCI DSS Services     About Us     Contact Us      
PCI DSS Services

Responsible Card Processing

Contact


T 0845 224 0693

E enquiries@cutecra.com


 

The Payment Card Industry Data Security Standards (PCI DSS) version 1.1 is a set of comprehensive requirements for enhancing payment account data security developed by the founding payment brands of the PCI Security Standards Council, including American Express, Discover Financial Services, JCB International, MasterCard Worldwide and Visa Inc., to help facilitate the broad adoption of consistent data security measures on a global basis.

The PCI DSS is a multifaceted security standard that includes requirements for security management, policies, procedures, network architecture, software design and other critical protective measures. This comprehensive standard is intended to help organizations proactively protect customer account data.
An outline of the standard is as follows:
 

Build and Maintain a Secure Network

  • Requirement 1: Install and maintain a firewall configuration to protect cardholder data
  • Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters
Protect Cardholder Data
  • Requirement 3: Protect stored cardholder data
  • Requirement 4: Encrypt transmission of cardholder data across open, public networks

 

Maintain a Vulnerability Management Program
  • Requirement 5: Use and regularly update anti-virus software
  • Requirement 6: Develop and maintain secure systems and applications

 

Implement Strong Access Control Measures
  • Requirement 7: Restrict access to cardholder data by business need-to-know
  • Requirement 8: Assign a unique ID to each person with computer access
  • Requirement 9: Restrict physical access to cardholder data
 
Regularly Monitor and Test Networks
  • Requirement 10: Track and monitor all access to network resources and cardholder data
  • Requirement 11: Regularly test security systems and processes

 

Maintain an Information Security Policy
  • Requirement 12: Maintain a policy that addresses information security

 

The PCI DSS must be met by all organizations (merchants and service providers) that transmit, process or store payment card data. The PCI DSS (sometimes referred to as a compliance standard) is not a law. It is a contractual obligation applied and enforced - by means of fines or other restrictions - directly by the payment providers themselves.
 
Cutecra can assist your business with all aspects of preparation for and remediation of a PCI audit from an authorised PCI Qualified Security Assessor (QSA) including:
 
  • Assistance to complete the PCI DSS Self Assessment Questionnaire (SAQ)
  • Gap analysis - help you understand what you need to do to to comply
  • Technology solutions - help you procure and implement the requirements

 

For advice and assistance regards PCI DSS compliance contact us now.