Have Questions About Payment Card Industry (PCI) Compliance? Sign up and Join the PCI DSS Forum

) February 5, 2009 -- Payment Card Industry Data Security Standards compliance, commonly known as PCI DSS to many, is fast becoming a mandatory requirement for many merchants, service providers, and other third party processors and providers that are directly involved in the processing, storage, or transmission of transaction data or cardholder data. The who, what, when, where, and why of PCI DSS compliance can be daunting at times, as a vast amount of information must be read, comprehended and distilled for truly understanding the dynamics of Payment Card Industry Data Security Standards (PCI DSS) compliance.


Many entities being mandated to become PCI DSS compliant are frustrated by the lack of transparency in truly understanding what compliance entails. Questions abound, such as the following: 1. Do I need to be PCI compliant from a Qualified Security Assessor (QSA). Can I self-assess for PCI compliance, and if so, how does one go about doing this? Do I need penetration tests and scanning done on my network? These are just a small sample of questions we field every week from companies desperately trying to understand the complexities of PCI compliance.


NDB Advisory, a Qualified Security Assessor Company (QSAC), specializes in helping organizations meet the rigorous requirements of PCI compliance, and as such, we've built a handy, easy and simple to use forum on PCI compliance where you can post any question you want, resulting in a timely response from one of the industry's leading QSA auditors, Mr. Charles Denyer.


To learn more about Payment Card Industry Data Security Standards (PCI DSS) compliance, visit pciassessment.org and start posting your questions. We'll get right back to you with the answer you need.


###

<!--

Similar entries

  • ) June 25, 2009 -- Element Payment Services announces the launch of the PCI Compliance Quiz Widget, created to help widen the knowledge base of Payment Card Industry (PCI) compliance.

    The PCI compliance standards were developed by the major payment card brands, under the umbrella of the Payment Card Industry Security Standards Council, in response to a recent growth in data security breaches. They apply to all businesses that handle payment cards.

  • ) December 15, 2008 -- Adeptra, (www.adeptra.com) the global market leader in auto-resolution services, has re-validated its compliance with the Payment Card Industry Data Security Standard (PCI DSS), the industry standard for the protection of payment card customer account data. Adeptra was the first company in its field to gain external certification, following an initial audit in November 2007. This latest review reconfirms the company's position as the sole auto-resolution provider recognized as compliant by an external Qualified Security Assessor in both the US and Europe.

  • ) March 30, 2009 -- Verrus Mobile Technologies Inc, a global leader in the mobile payment industry, is pleased to announce it has achieved compliance validation as a Level 1 service provider with the Payment Card Industry Data Security Standard (PCI DSS) - the industry's highest level of payment account data security certification.

    Verrus Mobile Technologies, Inc.

  • TimesofMoney, a leading online remittance and payment service provider has successfully completed the assessment procedure to validate its compliance with Payment Card Industry Data Security Standard

  • ) December 18, 2008 - Element Payment Services™, Inc. (Element) announced today that Marathon Data Systems has adopted Hosted Payments, the first payment processing solution to take software providers out-of-scope for PA-DSS (PABP) compliance requirements.

  • ) December 15, 2008 -- Nodus Technologies, Inc. (www.nodus.com), a leading electronic payment solution provider is pleased to announce the completion of VISA PABP 2008 certification for their Credit Card Advantage product line, the leading integrated credit card payment application software platform in Microsoft Dynamics GP market.

  • Data integrity and protection assured for New Zealand credit card transaction.

  • YesPCI, the nation’s leading of Payment Card Industry (PCI) all-in-one solution, today named Rey Pasinli its chief compliance officer, charged with developing and implementing PCI compliance strategies for YesPCI’s online merchants.

  • Barcelona, 24th November, 2008- Cashtronics announces its obtainment of the PCI-DSS (Payment Card Industry – Data Security Standard) certification at the highest level.

  • ) June 25, 2009 -- Merchant Data Systems (merchantdatasystems.com), a full service payment processing company, has joined forces with ControlScan (controlscan.com), a leading provider of Payment Card Industry (PCI) compliance and security solutions exclusively focused on small- to medium-sized merchants, to help its merchants meet mandatory requirements set forth by the PCI Security Standards Council (PCI SSC).

    PCI Compliance Solutions Provider, ControlScan

  • ) August 18, 2009 -- First American Payment Systems, L.P. ("First American"), one of the fastest growing electronic payments processors in the U.S., has partnered with Trustwave to create a program called PCI Smart in order to help merchants achieve and maintain compliance with the Payment Card Industry Data Security Standard (PCI DSS). Trustwave is the leading provider of on-demand data security and payment card industry compliance management solutions to businesses and organizations throughout the world.

  • ) May 11, 2009 -- HostMySite announced today that it has successfully completed a Payment Card Industry Data Security Standard (PCI DSS) Report on Compliance (ROC) and has established itself as a PCI compliant service provider, meaning lower costs and lessened responsibilities to customers who utilize HostMySite dedicated server and colocation solutions. HostMySite contracted with Trustwave, a PCI Qualified Security Assessor, to perform a third party assessment of service offerings to customers looking for PCI security solutions.

  • ) May 5, 2009 -- NeoSpire, Inc. announced that it has joined the PCI Security Standards Council as a participating organization. Over the past four years NeoSpire has been working with all levels of merchants and service providers to remove the burden of security and compliance through our fully-managed hosting solutions. Now as a Participating Organization, NeoSpire will work with the Council to evolve the PCI Data Security Standard (DSS) and other payment card data protection standards.

  • ) May 4, 2009 -- GreenSoft Solutions, Inc. ("GSI") has successfully completed its annual security assessment and has again been validated as a compliant Level 1 Service Provider under the Payment Card Industry (PCI) Data Security Standard (DSS). This extensive examination by a Qualified Security Assessor covered the operations and management of GSI's CompliantHost systems including its virtual infrastructure.

  • Bentley Walker are pleased to announce a secure online payment portal powered by Protx. Protx has achieved the highest level of compliance under the Payment Card Industry Data Security Standard (PCI).

  • Sophrona Solutions, the leader in online patient communication solutions for ophthalmology, announces it has completed a year long security initiative to become fully compliant with the Payment Card Industry's Data Security Standard (PCI-DSS). Sophrona has passed all 230 security criteria set by the Payment Card Industry and undergone rigorous systems vulnerability scans and penetration "attacks" performed by TrustWave. In doing so, Sophrona again demonstrates its committment to the security of its patient portal and ecommerce applications. (PRWeb Mar 9, 2009)

    Read the full story at http://www.prweb.com/releases/2009/03/prweb2192434.htm

  • ) July 15, 2009 -- T-Gate LLC, a pioneering provider of PCI PA-DSS secure payment platforms announces the launch of PayLink. PayLink is an industry first single web interface for all processing needs, PayLink offers a secure, smooth integration between the POS and T-Gate's PCI compliant universal payment gateway. PayLink removes the transaction from the POS ensuring the most secure transaction processing available.

  • ) October 6, 2009 -- As the remaining Payment Card Industry Data Security Standard (PCI DSS) deadlines approach, e-commerce merchants must quickly determine how to bring their checkout process into alignment with the new required standards for protecting sensitive cardholder data. To ease the burden, CRE Secure Payments, LLC has unveiled a Hosted Payment Page technology aimed at reducing the scope and cost of PCI Compliance for e-commerce merchants by moving the storage, processing and transmittal of payment information from the merchant's environment to a PCI-Compliant data center without interrupting checkout flow.

  • INetU Managed Hosting (www.inetu.net) and Trustwave (www.trustwave.com) have partnered to deliver a security program for merchants seeking compliance with the PCI DSS, HIPAA, and other standards in a managed hosting environment. Together, INetU's industry-leading managed hosting services and Trustwave's managed security solutions put merchants who engage both companies in an excellent position to validate compliance with the PCI DSS and other regulatory standards. (PRWeb May 14, 2009)

    Read the full story at http://www.prweb.com/releases/2009/05/prweb2404594.htm

  • ) November 21, 2008 -- As Australian businesses face a looming deadline to achieve and report compliance with Payment Card Industry Data Security Standards (PCI DSS), Macquarie Hosting, a division of Macquarie Telecom today announced it has achieved its Report On Compliance (ROC) to the highest level of PCI DSS for its Sydney data center, the Intellicentre.

  • ) April 28, 2009 -- Signature Card Services (signaturecard.com), a leading provider of credit and debit card payment processing services, has joined forces with ControlScan (controlscan.com), a leading provider of Payment Card Industry (PCI) compliance and security solutions. The partnership allows Signature Card to take a proactive approach in assisting their small and medium-sized merchants in meeting the Payment Card Industry Data Security Standard.

  • ) August 5, 2009 -- INetU Managed Hosting (http://www.inetu.net/), an enterprise managed hosting provider, announced today that it has joined the PCI Security Standards Council as a new participating organization. As a Participating Organization, INetU will work with the Council to evolve the PCI Data Security Standard (DSS) and other payment card data protection standards.

  • ) May 14, 2009 -- PDG Software, Inc., a leading provider of internet storefront and eCommerce shopping cart solutions, announced today the certification of PDG Commerce Version 5 as a PCI PA-DSS certified payment application. PDG Commerce now becomes the first internet shopping cart and storefront solution currently recommended for new deployments to achieve validation and certification with the Payment Card Industry Standard Security Council's (PCI SSC) Payment Application Data Security Standards (PA-DSS) program.

  • ) August 4, 2009 -- CRE Secure, the first cloud-based security payment system that is fully compliant with new credit card security rules, announces today that it has expanded its PCI compliant credit card processing security service with a new integrated connection to Authorize.net, the most popular payment gateway in North America. Online retailers and web based applications who take credit and debit cards using Authorize.net as their payment gateway can now sign up for CRE Secure PCI Security and still keep their existing connection to Authorize.net and their existing merchant banking relationships.

  • ) March 1, 2009 -- Merchant Card Services, a division of Columbia Bank (merchantcardsvcs.com), a leading provider of card deposit processing, has joined forces with ControlScan (controlscan.com), a leading provider of PCI compliance and security solutions exclusively focused on small- to medium-sized merchants, to help its merchants meet mandatory requirements set forth by the PCI Security Standards Council (PCI SSC).

  • ) August 17, 2009 -- Unifying IT controls simplifies compliance and cuts costs, as demonstrated by the recent release of The PCI Security Standards Council's "Wireless Security Guide," created in response to feedback from retailers and other businesses claiming that wireless guidance in the Payment Card Industry Data Security Standard (PCI DSS) was too ambiguous.

  • ) March 29, 2009 -- ControlScan, Inc. (controlscan.com), the leading provider of PCI compliance and security solutions exclusively focused on small merchants, today announced the launch of version 2.0 of its PCI compliance offering, PCI 1-2-3. In addition to its core PCI compliance offerings, ControlScan's latest version includes a more robust Self Assessment Questionnaire (SAQ) and features a new Policy Builder to help small merchants achieve all requirements specified in the PCI Data Security Standards (PCI DSS).

  • ) November 19, 2008 -- Managed hosting provider Fpweb.net now offers Microsoft Office SharePoint Server hosting solutions that are compliant with the Department of Defense (DOD) Directive 5015.2.

    DOD 5015.2 establishes the policies and responsibilities required for electronic records management. All products awarded with DOD 5015.2 compliance have undergone rigorous testing to meet the standards and ensure compliance. As of May 2007, Microsoft Office SharePoint Server (MOSS) 2007 passed the necessary testing to achieve compliance with DOD 5015.2 as a records management application.

  • Aurora, a leading IT company offering state-of-the-art security and compliance solutions for business critical applications, has partnered with Lumension Security™, Inc. to deliver comprehensive data protection and endpoint protection for its customers. Lumension Security is a recognized, global security software company that provides unified protection and control of enterprise endpoints for more than 5,100 customers and 14 million nodes worldwide. By combining Aurora's state-of-the-art data security and compliance solutions with Lumension Security's best-of-breed, policy-based solutions, customers will be able to mitigate risks and fully protect business critical data while ensuring compliance needs are met. (PRWeb Sep 22, 2008)

  • ) August 17, 2009 -- Document Technologies, Inc. (DTI), the nation's largest independent provider of litigation support services and document outsourcing, announced today the company's achievement of ISO/IEC 27001:2005 compliance. DTI worked with the consulting company Pivot Group LLC to complete the steps necessary for compliance. Pivot Group is a technology-neutral information security services firm also based in Atlanta that assists companies like DTI in achieving compliance to information security management system (ISMS) standards.

  • ) August 26, 2009 -- Fusepoint Managed Services, a leading provider of outsourced IT services and infrastructure, today announced it has been selected by MiraTel Solutions Inc., a payment processing application service provider, to fully manage and host the company's new online lottery ticket sales application.


    MiraTel, which currently provides back office support for the Canadian lottery industry by supplying full service, help desk, credit card processing, and ticket sales, is now developing an online presence for the lottery industry to sell tickets. However, the site must adhere to stringent PCI compliance rules and regulations and be operational in less than a month.

  • Application Security, Inc., the leading provider of database security, risk, and compliance solutions for the enterprise, announced it will share its recommended “best practices” for comprehensive database protection at six leading industry events.

  • ) June 23, 2009 -- Avangate, full service provider of electronic software distribution and reseller management solutions for software vendors, today announced to have obtained for its services the Level 1 PCI DSS certification (Payment Card Industry Data Security Standard), the most important security standard for the card payment industry. The PCI DSS includes a set of comprehensive requirements for security management, policies, procedures, network architecture, software design and other critical protective measures.

  • ) September 1, 2009 -- Consider the very serious threat of identity theft. According to Javelin Strategy and Research Center, close to 10 million people become victims each year, which equates to 19 people every minute.


    "Data security is paramount in the data recovery industry," says Sean Wade, CEO of 24 Hour Data, a Dallas data recovery company. He argues it's not enough to manage internal security protocols; those seeking data recovery must also perform due diligence on any company with whom they work.

  • ) December 1, 2008 -- New West Technologies, Inc. has announced its Mobile Retail Platform (MRP) has been approved by VISA to be Compliant with PCI Standards.

    NWT - PCI DSS Compliant

    Payment Card Industry (PCI) compliance is a complex and ever evolving subject affecting millions of businesses - acquiring banks, Independent Sales Organizations (ISOs), processors, hosts, shopping carts, e-commerce and retail merchants and other merchant services providers.

  • The Brussels Airport Company recently signed up to CMO COMPLIANCE software, to manage safety, security & regulatory compliance.

  • FERC Compliance best Practices discussed at round table discussion led by MetricStream’s CEO Shellye Archambeau at the FERC Compliance Summit 2009 in Washington D.C.

  • ) February 16, 2009 -- A few years ago the world's five leading payment card brands - American Express, Discover Financial Services, JCB, MasterCard and Visa collaborated to create a world-wide standard for protecting consumer cardholder data.

  • ) October 7, 2008 -- EC Suite.com faced a dilemma of protecting their endpoints from data leakage, malware attacks, viruses, worms, spyware, and other external threats using the traditional security model. How could it identify vulnerabilities, deploy patches, lock down USB thumb drives and other removable media, prevent users from downloading unwanted software and still take a proactive approach to security?

  • ) June 1, 2009 -- Assessors certified by the Payment Card Industry (PCI), a coalition of the world's leading credit card companies, have validated that the CRE Loaded ecommerce system is compliant with the newest data security standards.


    These standards were enacted in response to the growing number of expensive data breaches. Starting Oct. 1, online retailers will no longer be allowed to host credit card transactions in non PCI-approved environments. Stores that aren't compliant can be fined, have their transaction fees raised, or even have their merchant accounts frozen.