Credit card safety
Mon, 1st Nov 2010
FYI, this story is more than a year old
S
STAFF WRITER
Well, as we hinted, it is a baseline security standard designed to reduce the risk of credit card data theft. There are 12 requirements comprising over 240 individual controls. As we stated, you can't be mostly compliant. It's an all-or-nothing standard developed and maintained by the PCI Security Standards Council (www.pcisecuritystandards.org/index.shtml). The 12 requirements of the standard are:
- Install and maintain a firewall configuration to protect cardholder data
- Do not use vendor-supplied defaults for system passwords and other security parameters
- Protect stored cardholder data
- Encrypt transmission of cardholder data across open, public networks
- Use and regularly update anti-virus software or programs
- Develop and maintain secure systems and applications
- Restrict access to cardholder data by business need to know
- Assign a unique ID to each person with computer access
- Restrict physical access to cardholder data
- Track and monitor all access to network resources and cardholder data
- Regularly test security systems and processes
- Maintain a policy that addresses information security for employees and contractors.
- Prevent inappropriate disclosure of cardholder data
- Detect when inappropriate disclosure occurs, allowing quick remediation.
Related stories
Yubico well-prepared for post-quantum computing threats
Ant International upgrades Alipay+ with privacy tech
Cloudflare, WatchGuard warn cloud security assumptions fail
Why data infrastructure will decide which AI strategies succeed in 2026
Retailers hit by ransomware face higher USD $2 million demands