 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Regulatory Compliance, Governance and Security &#187; compliance with pci dss</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/compliance-governance/tag/compliance-with-pci-dss/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/compliance-governance</link>
	<description></description>
	<lastBuildDate>Thu, 10 Mar 2011 15:04:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Compliance with PCI DSS &#124; Expert Advice from a PCI QSA</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/compliance-with-pci-dss-expert-advice-from-a-pci-qsa/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/compliance-with-pci-dss-expert-advice-from-a-pci-qsa/#comments</comments>
		<pubDate>Thu, 26 Mar 2009 13:34:43 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[compliance with pci dss]]></category>
		<category><![CDATA[merchants]]></category>
		<category><![CDATA[payment card industry]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[pci dss self assessment]]></category>
		<category><![CDATA[qsa]]></category>
		<category><![CDATA[qualified security assessor]]></category>
		<category><![CDATA[service providers]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/compliance-with-pci-dss-expert-advice-from-a-pci-qsa/</guid>
		<description><![CDATA[Compliance with PCI DSS can be daunting and a challenge indeed. However, simply breaking down the PCI DSS requirements and looking at it in a thought manner will help alleviate your concerns. As a Payment Card Industry Qualified Security Assessor (PCI QSA), i&#8217;m often asked the who, what, when, where, and why of compliance with [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://www.pciassessment.org">Compliance with PCI DSS</a> can be daunting and a challenge indeed. However, simply breaking down the PCI DSS requirements and looking at it in a thought manner will help alleviate your concerns. As a Payment Card Industry Qualified Security Assessor (PCI QSA), i&#8217;m often asked the who, what, when, where, and why of compliance with PCI DSS.</p>
<p>So, with that said, here is some important advice in truly understanding compliance.</p>
<p>1. You need to find out if you are identified as a merchant or a service providers in the eyes of PCI compliance. <a href="http://www.pciassessment.org/contact.php">Contact a PCI QSA</a> for advice on this issue if you are not sure of  your answer.</p>
<p>2. Once you have accomplished this, you need to identify what &#8220;Level&#8221; of compliance is mandated for your organization. This can be done by calculating the total number of transactions your organization undertook or will undertake in a full year&#8217;s time. Take note, that for <a href="http://www.pciassessment.org/merchants.php">merchants</a>, most organizations will fall into Levels 2,3, and 4, which can allow you to conduct a PCI DSS self-assessment (with oversight and guidance from a PCI-QSA is what i highly recommend). Level 1 merchants will have to undergo an actual on-site PCI DSS assessment by a QSA. As for <a href="http://www.pciassessment.org/service-providers.php">service providers</a>, most of you will also have to undergo an on-site PCI DSS assessment. Again, find your level based on your transaction volume.</p>
<p>3. If you can self-assess, then visit <a href="http://www.pcisecuritystandards.org">pcisecuritystandards.org</a> and obtain the self assessment questionnaires. There are five (5) of them, so read carefully as to which one is for you. If you have to have an actual on-site PCI DSS assessment done, then contact a firm who can conduct this for you.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/compliance-with-pci-dss-expert-advice-from-a-pci-qsa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
