Securing Payments: The PCI DSS Essential Guide
If your business accepts, processes, stores, or transmits credit card information, you are subject to PCI DSS. It's the global standard designed to prevent fraud and data theft.
The 6 Goals and 12 Requirements
PCI DSS is structured around huge goals that break down into 12 specific requirements:
- Build and Maintain a Secure Network: Install firewalls and change default passwords.
- Protect Cardholder Data: Encrypt transmission and protect stored data.
- Maintain a Vulnerability Management Program: Use anti-virus and develop secure systems.
- Implement Strong Access Control Measures: Restrict access to data on a need-to-know basis and use unique IDs.
- Regularly Monitor and Test Networks: Track all access and test security systems regularly.
- Maintain an Information Security Policy: Address information security for all personnel.
Levels of Compliance
Your validation requirements depend on your transaction volume. Level 1 merchants (over 6M transactions) require an onsite audit by a QSA. Level 2-4 merchants may self-assess using an SAQ.
Preparing for PCI DSS 4.0
The new 4.0 standard introduces flexibility ("Customized Approach") and stricter requirements for authentication and phishing protections. Start your gap analysis now.