 |
PCI DSS stands for Payment Card Industry Data Security Standards. Commonly referred to as "PCI",
the standards are assembled by the Payment Card Industry Security Standards Council (PCI SSC).
The PCI security standards are a collection of technical and operational requirements, management
practices, and guidelines developed to help prevent credit card fraud. Hacking, phishing, and
SQL Injection are just some of the types of attacks used against web sites in an attempt to gain
access to credit card information.
Any company or organization transmitting, storing, or processing credit cards is required to
be PCI compliant. PCI compliance is more than just keeping your systems up to date and behind
firewalls, though. There are three levels of PCI compliance, I, II, and III. The level each
company falls under depends on the number of credit card transactions processed each month. Level
I and II organizations must have an annual on site audit of systems, policies and procedures performed
by a Qualified Security Assessor, while level III organizations can perform a self-audit.
The PCI DSS standards contain a variety of requirements for management practices, procedures
and policies. More general information on PCI requirements and specific PCI documents
is available from the web sites below.
|