вторник, 21 мая 2019 г.
PCI DSS stands for Payment Card Industry Essay
The senior counselling has been advised by the legal department that the organization leave alone need to become PCI DSS compliant before using online applications that accept credit cards and customer personal information. The management isnt familiar with PCI DSS compliance therefore, the management asked you to prepare a recommendation explaining PCI DSS compliance, how the organization can move through the compliance process, and the consequences of noncompliance.PCI DSS stands for Payment Card Industry Data Security Standard. PCI DSS originally began as five different programs Visa, MasterCard, American Express, Discover and JCB data security programs. Each company creates an additional level of protection for card issuers by ensuring that merchants meet token(prenominal) levels of security when they store, process and transmit cardholder data. PCI DSS specifies 12 requirements for compliance, organized into six logically related groups called control objectives. Each version of PCI DSS has divided these 12 requirements into a human action of sub-requirements differently, but the 12 high level requirements have not changed since the inception standard.The control objectives are Build and entertain a secure network, protect cardholder data, swan a vulnerability management program, implement strong opening control measures, regularly monitor and test networks and maintain an information security policy. The requirements for compliance are, institute and maintain a firewall configuration to protect card holder data, do not use vendor-supplied defaults for system passwords and other security parameters, protect stored cardholder data, encrypt transmitting of cardholder data across open public networks, use and regularly update anti-virus software on all systems commonly affected by malware, develop and maintain secure systems and applications, restrict access to cardholder data by business need-to-know, assign a unique ID to each person with computer access, restrict physical access to card holder data, track and monitor all access to network resources and cardholder data, regularly test security systems and processes and maintain a policy that addresses information security. fit in to Visa, no compromised entity has yet been found to be in compliance with PCI DSS at the time of a breach. Assessments examine the compliance of merchants and services providers with the PCI DSS at a circumstantial point intime and frequently utilize a sampling methodology to allow compliance to be demonstrated through representative systems and processes. It is the office of the merchant and service provider to achieve, demonstrate, and maintain their compliance at all times both throughout the annual validation/assessment cycle and across all system and processes in their entirely.
Подписаться на:
Комментарии к сообщению (Atom)
Комментариев нет:
Отправить комментарий