
|
PCI Compliance Recommendations
PCI Compliance is increasingly important to all online store owners, and NetzBiz can be implemented to meet this strict standard.
What is PCI Compliance?
The PCI Data Security Standard (PCI DSS) was created by the major credit card companies to ensure the adoption of consistent security measures by all merchants. There are 12 requirements for meeting the PCI DSS, broken into 6 groups:
Our servers are 100% PCI-DSS Compliance and get scanned by 3rd parties scanners monthly to verify any new issues.
- Build and Maintain a Secure Network
Requirement 1: Install and maintain a firewall configuration to protect cardholder data
(Server Side - Done By Us)
Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters
(Done On Your End)
- Protect Cardholder Data
Requirement 3: Protect stored cardholder data
(Done By Us - when using LIVE GATEWAY)
Requirement 4: Encrypt transmission of cardholder data across open, public networks
(Server Side - Done By Us)
- Maintain a Vulnerability Management Program
Requirement 5: Use and regularly update anti-virus software
(Done By Us on server, need to be Done On Your End) as well)
Requirement 6: Develop and maintain secure systems and applications
(Server Side - Done By Us)
- Implement Strong Access Control Measures
Requirement 7: Restrict access to cardholder data by business need-to-know
(Done On Your End)
Requirement 8: Assign a unique ID to each person with computer access
(Server Side - Done By Us)
Requirement 9: Restrict physical access to cardholder data
(Done On Your End)
- Regularly Monitor and Test Networks
Requirement 10: Track and monitor all access to network resources and cardholder data
(Server Side - Done By Us)
Requirement 11: Regularly test security systems and processes
(Server Side - Done By Us)
- Maintain an Information Security Policy
Requirement 12: Maintain a policy that addresses information security
(Done By Us on server, need to be Done On Your End as well)
Configuring NetzCart to meet PCI DSS
There are a few very important steps to take when implementing NetzCart in a PCI compliant manner. The main two are:
- Do not use the Simple Validation Credit Card method in a production environment (live site).
- Make sure you follow Requirements 2,5,7,9 and 12 as they are related to your end.
It is important to note that while NetzCart is an integral part of the chain in obtaining PCI Compliance, it is necessary to implement NetzCart the correct way
as we have given recommendations here to meet the PCI-DSS.
For more information on PCI Compliance please visit the PCI Security Standards Council web site:
https://www.pcisecuritystandards.org/ |
|
|