Welcome, Guest |   Sign In   |   Register  
 
Print Email Page RSS Feeds

Posted Date: 2/1/2013

PCI Security Standards Council Releases Guide for Choosing Secure Payment Tech

The PCI Security Standards Council (PCI SSC), has published the PCI DSS E-commerce Guidelines Information Supplement, a product of the E-commerce Security Special Interest Group (SIG). Businesses selling goods and services over the Internet can use this resource as a guide for choosing e-commerce technologies and third-party service providers that will help them secure customer payment data and support PCI DSS compliance efforts.
 
PCI Special Interest Groups (SIGs) are community-driven initiatives that provide additional guidance and clarifications or improvements to the PCI Standards and supporting programs.
 
In 2012, PCI Participating Organizations selected e-commerce security as a key area to address via the SIG process. More than 60 global organizations representing banks, merchants, security assessors and technology vendors collaborated to produce  guidance that will help organizations better understand their responsibilities when it comes to PCI DSS;  the risks they need to evaluate when considering ecommerce solutions; and how to determine their PCI DSS scope.
 
“Take SQL injections as an example. This is not a new attack, and something we’ve known about in the industry for years. Yet it continues to be one of the most common methods by which e-commerce websites are compromised, said Bob Russo, general manager, PCI Security Standards Council. “This can be addressed through simple, prudent coding practices, but merchants often don’t know where to start. These guidelines will help them better understand their responsibilities and the kinds of questions they need to ask of their service providers. In the case of SQL injections, one of the most important items to request of an e-commerce service provider is a description of the security controls and methods it has in place to protect websites against these vulnerabilities.”
 
The PCI DSS E-commerce Guidelines Information Supplement provides an introduction to e-commerce security and guidance around the following primary areas and objectives:
 
E-commerce Overview – provides merchants and third parties with explanation of typical e-commerce components and common implementations and outlines high-level PCI DSS scoping guidance to be considered for each.
 
Common Vulnerabilities in E-commerce Environments – educates merchants on vulnerabilities often found in web applications (such as e-commerce shopping carts) so they can emphasize security when developing or choosing e-commerce software and services.
 
Recommendations - provides merchants with best practices to secure their e-commerce environments, as well as list of recommended industry and PCI SSC resources to leverage in e-commerce security efforts.
 
The document also includes two appendices to address specific PCI DSS requirements and implementation scenarios:
 
PCI DSS Guidance for E-commerce Environments – provides high-level e-commerce guidance that corresponds to the main categories of PCI DSS requirements; includes chart to help organizations identify and document which PCI DSS responsibilities are those of the merchant and which are the responsibility of any e-commerce payment processor.
 
Merchant and Third-Party PCI DSS Responsibilities – for outsourced or “hybrid” e-commerce environments, includes sample checklist that merchants can use to identify which party is responsible for compliance and specify the details on the evidence of compliance.
 
The information supplement can be downloaded from the documents library on the PCI SSC website at www.pcisecuritystandards.org/security_standards/documents.php.
 
 

Rate this Content (5 Being the Best)
12345
Current rating: 0 (0 ratings)
 


Profiling the Restaurant of the Future Profiling the Restaurant of the Future
4/24/2013
The restaurant industry is rapidly changing as consumers have unprecedented abilities to drive their engagement with quick service and casual restaurants. Find out what technologies will give restaurants a competitive advantage in this future-looking whitepaper.



Download Now

4th Annual Shopper Experience Study: Rise of the Individual Shopper 4th Annual Shopper Experience Study: Rise of the Individual Shopper
6/10/2013
This annual survey of 2,500 consumers provides key insights on shopper preferences. Download the 4th Annual RIS/Cognizant Shopper Experience Study to learn how the retailing paradigm has shifted from serving many customers to serving each individual shopper.
Download Now

Building Flexible and Functional Kitchens: Technology to Drive Quality, Labor, Speed
10/23/2012 2:00:00 PM (EST)
Moderator:
>>Dorothy Creamer,Managing Editor, Hospitality Technology

Panelist:
>>Alex Birnbaum, Vice President of Information Technologies, CraftWorks
>>Michael Lukianoff, Principal Founder, Czar Metrics
>>Brian Wayne, Product Manager, QSR,
View On Demand


MEDIA KIT | EDITORIAL CALENDAR | PRIVACY STATEMENT | TERMS & CONDITIONS | CONTACT US
All materials on this site Copyright Edgell Communications. All rights reserved.