PCI Related Links
PCI Requirements
- PCI DSS Requirements
- PCI Security Standards Council
-
Official Payment Card Sites:
PCI DSS provides organizations the guidance they need to ensure that credit cardholder information is kept secure from possible security breaches
The last several years have seen an unprecedented assault on personal and financial data that customers have knowingly or unwittingly entrusted to retailers, banks, service providers and credit card companies. Several large, well-known institutions and brands have been boldly exposed in the media and pummeled in the financial markets after major data security breaches within their organization were revealed.
In response, the payment card industry countered the criminal onslaught with a homegrown security initiative that is at once broader in scope and more granular in its requirements than any measures additional government regulation might have imposed. The Payment Card Industry Data Security Standard is a comprehensive security standard that establishes common processes and precautions for handling, processing, storing and transmitting credit card data.
In September of 2006, a group of five leading payment brands including American Express, Discover Financial Services, JCB, MasterCard Worldwide and Visa International jointly announced formation of the PCI Security Standards Council, an independent council established to manage ongoing evolution of the PCI standard. Concurrent with the announcement, the council released version 1.1 of the PCI standard.
Compliance Requirements
The PCI Data Security Standard requirements apply to all payment card network members, merchants and service providers that store, process or transmit cardholder data, and affect all payment channels, including retail (brick-and-mortar), mail/telephone order and e-commerce. The core requirements are organized in six categories as outlined in the figure below.
While the newly-established PCI Security Standards Council will manage the underlying data security standard, compliance requirements are set independently by individual payment card brands. While requirements vary between card networks, MasterCard's Site Data Protection Plan and Visa's Cardholder Information Security Program are representative. They stipulate separate compliance validation requirements for merchants and service providers, which vary depending on the size of the company. Compliance levels are defined based on annual transaction volume and corresponding risk exposure as outlined in the figure below.
Validation Enforcement
While non-compliance penalties also vary among major credit card networks, they can be substantial. Participating companies can be barred from processing credit card transactions, higher processing fees can be applied; and in the event of a serious security breach, fines of up to $500,000 can be levied for each instance of non-compliance.
Since compliance validation requirements and enforcement measures are subject to change, merchants and service providers should closely monitor the requirements of all card networks in which they participate.
Solution: QualysGuard PCI
At first exposure, PCI compliance and validation requirements can appear daunting, particularly the external scan requirement. Merchants and service providers can simplify the selection process by establishing a few key selection criteria:
QualysGuard PCI — On Demand PCI
As an approved PCI scanning vendor, Qualys is fully certified to help merchants and service providers assess and achieve continuous compliance with the PCI DSS. Delivered as an on demand Web application with no hardware or software to be installed and maintained, QualysGuard PCI is the most accurate, easiest to use tool for PCI compliance testing, reporting and submission. QualysGuard PCI draws upon the same highly accurate scanning infrastructure and technology as Qualys' flagship solution, QualysGuard — used by thousands of organizations around the world to protect their networks from security vulnerabilities that make attacks against networks possible. It allows merchants and service providers to complete all validation requirements. Using QualysGuard PCI users can easily complete and submit the PCI self-assessment questionnaire online, and perform pre-defined PCI scans on all external systems to identify and resolve network and system vulnerabilities as required by the PCI standard.
Key features of QualysGuard PCI:
Since QualysGuard PCI is delivered as a Web service, our engineering team continuously updates and enhances the accuracy of the service and vulnerability signatures, without requiring any software upgrades or manual updates. This dedication to accuracy and quality means that you won't be wasting time chasing false-positives, a common problem with software-based vulnerability scanners.




