PCI DSS Compliance

creditcardsSecure and Protect Credit Card Information

In 2004, five major credit card companies joined forces to align their individual security policies and form a single set of mandatory requirements for all merchants and credit card payment processors. The result, known as the Payment Card Industry Data Security Standard (PCI DSS), was a cohesive policy designed to help merchants protect credit card account information and prevent credit card fraud.

Applicability

Security breaches and fraudulent credit card purchases have been rising dramatically over the past decade, and any business that processes, stores or transmits credit card information inherently runs the risk of mishandling or losing their customersÕ account data. PCI DSS affects any merchant that accepts MasterCard, Visa, American Express, Discover or JCB cards, and no matter how many credit card transactions a merchant makes, they must be in compliance with PCI DSS.

The Impact to Your Business

A survey conducted by Javelin Strategy & Research studying retailers and credit card security found that 78% of consumers would be unlikely to continue shopping at a store if they learned it had a breach that may have compromised their credit account information. On the other hand, 85% of customers would be likely to increase their shopping at a store if they knew it was a leader in devoting resources and technology to protecting its customersÕ personal credit and or debit card account information.

PCI DSS is a multifaceted security standard that includes 12 requirements for security management. Individual credit card brands enforce the regulations and have their own compliance consequences, which can include audits, fines of up to $500,000 per incident and losing the ability to process credit card payments. Retailers face increased financial liability for lost credit card information and find themselves in courtrooms arguing over lost data, meanwhile losing important business partners, customer confidence and loyalty. PCI DSS requirements force merchants to redefine their policies and procedures for:

ECM Enables PCI DSS Compliance

Enterprise Content Management (ECM) technology provides merchants and retailers with a secure information management system that can enhance PCI DSS compliance strategies and improve operational efficiency. PaperVision¨ Enterprise, the on-premise ECM system, and ImageSilo¨, the worldÕs most trusted on-demand ECM service, are affordable, easy-to-implement systems that can also help companies reduce information management costs. Many businesses with limited IT resources prefer to outsource their data storage with ImageSilo and rely on its ultra-secure network to address PCI DSS requirements.

Reliable Network Security

PCI DSS requires merchants to build a firewall configuration that denies all traffic from ÒuntrustedÓ networks and hosts. Additionally, retailers cannot use vendor-supplied defaults for system passwords and other security parameters. PaperVision Enterprise and ImageSilo provide comprehensive systems, features and settings to safeguard information and control application security.

Protected Credit Card Information

Key elements of PCI DSS compliance include data encryption, hidden account numbers, as well as secure information transmission and storage. FireproofÕs ECM products technology can enhance security and make credit card information unreadable anywhere it is stored.

Simple Vulnerability Management

PCI DSS was designed to protect against exploitation and forces businesses to detect and manage any network vulnerabilities. Specifically, retailers must track all access to cardholder data, have the most recently released software patches and regularly test security systems. PaperVision Enterprise and ImageSilo include tools that can track system activity and verify security. Plus, ImageSilo frees merchants from managing software updates.

DISCLAIMER: This document is for informational purposes only; Fireproof Records Center. is not liable for errors, omissions or inadequacies. Please consult an appropriate compliance expert to understand your needs. This information is subject to change without notice.