 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Regulatory Compliance, Governance and Security &#187; payment card industry data security standards (PCI DSS)</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/compliance-governance/tag/payment-card-industry-data-security-standards-pci-dss/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/compliance-governance</link>
	<description></description>
	<lastBuildDate>Thu, 10 Mar 2011 15:04:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>SAS 70 Audits and PCI DSS Assessments &#124; Expert Advice from an Auditor</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-and-pci-dss-assessments-expert-advice-from-an-auditor/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-and-pci-dss-assessments-expert-advice-from-an-auditor/#comments</comments>
		<pubDate>Wed, 25 Nov 2009 20:20:58 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[payment card industry data security standards (PCI DSS)]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[pci dss assessments]]></category>
		<category><![CDATA[SAS 70]]></category>
		<category><![CDATA[type II]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-and-pci-dss-assessments-expert-advice-from-an-auditor/</guid>
		<description><![CDATA[SAS 70 audits and PCI DSS assessments are truly starting to dominate the regulatory compliance landscape. For a large number of our firm&#8217;s clients, we actively assess them for yearly SAS 70 and PCI DSS compliance. The chatter of late is surrounding what efficiencies of scale, if any, can be had by conducting both a [...]]]></description>
				<content:encoded><![CDATA[<p>SAS 70 audits and PCI DSS assessments are truly starting to dominate the regulatory compliance landscape.  For a large number of our firm&#8217;s clients, we actively assess them for yearly SAS 70 and PCI DSS compliance.  The chatter of late is surrounding what efficiencies of scale, if any, can be had by conducting both a SAS 70 audit and a PCI DSS assessment for an organization that needs both.</p>
<p>I urge you to read a very compelling article I wrote regarding both of these major compliance initiatives.<br />
Titled &#8220;<strong><a href="http://www.sas70.us.com/industries/organizationsthatneed.php">SAS 70 Audits and PCI DSS | a Technical White Paper</a></strong>&#8221; it discusses these very issues and brings to light some extremely important points for both SAS 70 and PCI DSS compliance.</p>
<p>In summary, tread cautiously when thinking that doing both is simply a &#8220;two for one&#8221;, meaning you can conduct both a SAS 70 audit and a PCI DSS assessment at the same time.</p>
<p>If you want to learn more about SAS 70 audits, visit the official <a href="http://www.sas70.us.com">SAS 70 Resource Guide</a> and if you want to learn more about PCI DSS assessments, visit the official <a href="http://www.pciassessment.org">PCI DSS Resource Guide</a>.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/sas-70-audits-and-pci-dss-assessments-expert-advice-from-an-auditor/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI DSS and Service Providers &#124; Common Examples of these Entities</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-and-service-providers-common-examples-of-these-entities/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-and-service-providers-common-examples-of-these-entities/#comments</comments>
		<pubDate>Wed, 18 Nov 2009 15:44:12 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[merchants]]></category>
		<category><![CDATA[payment card industry data security standards (PCI DSS)]]></category>
		<category><![CDATA[pci dss compliant]]></category>
		<category><![CDATA[pciassessment.org]]></category>
		<category><![CDATA[service providers]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-and-service-providers-common-examples-of-these-entities/</guid>
		<description><![CDATA[The Payment Card Industry Data Security Standards (PCI DSS) provisions call for both merchants and service providers to become PCI DSS compliant. Though the term &#8220;merchant&#8221; is easily understood, the term &#8220;service provider&#8221; has created some confusion as to who these entities really are. With that said, here is a list of common service providers [...]]]></description>
				<content:encoded><![CDATA[<p>The <strong><a href="http://www.pciassessment.org">Payment Card Industry Data Security Standards</a> </strong>(PCI DSS) provisions call for both merchants and service providers to become PCI DSS compliant. Though the term &#8220;merchant&#8221; is easily understood, the term &#8220;service provider&#8221; has created some confusion as to who these entities really are. With that said, here is a list of common service providers that are being required to become PCI DSS compliant:</p>
<p><strong>Transaction Processors<br />
Payment Gateways<br />
Independent Sales Organizations (ISO)<br />
External Sales Agents (ESA)<br />
Call Centers and Customer Service Entities<br />
Plastic Card Embossing Companies<br />
Remittance Processing Companies<br />
Managed Service Providers<br />
Data Centers<br />
Co-location Entities<br />
Web Hosting Providers<br />
Email (Microsoft Exchange) Providers</strong></p>
<p>In short, any entity other than a merchant that is directly involved in the processing, storage, or transmission of cardholder data will need to become Payment Card Industry Data Security Standards (PCI DSS) compliant.</p>
<p>To learn more about PCI compliance, <strong><a href="http://www.pciassessment.org">visit the official PCI DSS Resource Guide</a>.</strong></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-and-service-providers-common-examples-of-these-entities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI DSS Roadmap to Compliance &#124; Phase I</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-roadmap-to-compliance-phase-i/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-roadmap-to-compliance-phase-i/#comments</comments>
		<pubDate>Mon, 09 Nov 2009 12:58:43 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[Add new tag]]></category>
		<category><![CDATA[merchants]]></category>
		<category><![CDATA[payment card industry data security standards (PCI DSS)]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[service providers]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-roadmap-to-compliance-phase-i/</guid>
		<description><![CDATA[Merchants and service providers seeking to become Payment Card Industry Data Security Standards (PCI DSS) compliant, will need to embark on a structured &#8220;PCI DSS Roadmap to Compliance&#8221; for ensuring a seamless and transparent process. So what does this really mean and entail? It essentially requires all organizations to follow a path for PCI DSS [...]]]></description>
				<content:encoded><![CDATA[<p>Merchants and service providers seeking to become Payment Card Industry Data Security Standards (PCI DSS) compliant, will need to embark on a structured &#8220;PCI DSS Roadmap to Compliance&#8221; for ensuring a seamless and transparent process. So what does this really mean and entail? It essentially requires all organizations to follow a path for PCI DSS compliance that is scalable, efficient, and gets you the results you need. </p>
<p>With that said, the first phase to undertake for any PCI DSS assessment is essentially a Readiness Assessment. This is a vital process that must always be the first step to undertake. In this phase, your organization will essentially identify the &#8220;who, what, where, and why&#8221; of the PCI DSS cardholder data environment. You will come to understand what the essential scope of the overall PCI DSS assessment will be, what &#8220;system components&#8221; are included in the scope of the assessment, and most importantly, what gaps or remediation activities have been found that will need to be corrected. To learn more about PCI DSS compliance, visit the official <strong><a href="http://www.pciassessment.org">PCI DSS resource guide</a></strong>.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-roadmap-to-compliance-phase-i/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI DSS Compliance &#124; Why You Need a QSA for Level 1 Compliance</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-why-you-need-a-qsa-for-level-1-compliance/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-why-you-need-a-qsa-for-level-1-compliance/#comments</comments>
		<pubDate>Fri, 24 Jul 2009 20:00:58 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[dss]]></category>
		<category><![CDATA[level 1]]></category>
		<category><![CDATA[merchant]]></category>
		<category><![CDATA[payment card industry data security standards (PCI DSS)]]></category>
		<category><![CDATA[payment card industry security standards council]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[pci ssc]]></category>
		<category><![CDATA[qsa]]></category>
		<category><![CDATA[qualified security assessor (QSA)]]></category>
		<category><![CDATA[service provider]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-why-you-need-a-qsa-for-level-1-compliance/</guid>
		<description><![CDATA[PCI DSS Compliance for Level 1 Merchants and Service Providers is mandatory. In short, if you are a Merchant or Service Provider and have been called upon to become Payment Card Industry Data Security Standards (PCI DSS) compliant, then an on-site assessment by a Qualified Security Assessor (QSA) is what you will need. A QSA [...]]]></description>
				<content:encoded><![CDATA[<p>PCI DSS Compliance for Level 1 Merchants and Service Providers is mandatory. In short, if you are a Merchant or Service Provider and have been called upon to become Payment Card Industry Data Security Standards (PCI DSS) compliant, then an on-site assessment by a Qualified Security Assessor (QSA) is what you will need.</p>
<p>A QSA is simply an individual who has gone through the licensing to become an expert in PCI DSS compliance. This is somebody who has been awarded the designation by the Payment Card Industry Security Standards Council, known as the PCI SSC.</p>
<p>For more information about PCI DSS compliance and in hiring a QSA for all your Level 1 needs, visit the official <strong><a href="http://www.pciassessment.org">PCI DSS Resource Guide</a></strong>.</p>
<p>And lastly, MasterCard has now strengthened their requirements to make Level 2 merchants also undertake an on-site PCI DSS assessment.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-why-you-need-a-qsa-for-level-1-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI COMPLIANCE</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-compliance/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-compliance/#comments</comments>
		<pubDate>Sat, 20 Jun 2009 03:31:41 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[level 1]]></category>
		<category><![CDATA[merchants]]></category>
		<category><![CDATA[payment card industry data security standards (PCI DSS)]]></category>
		<category><![CDATA[payment card industry security standards council]]></category>
		<category><![CDATA[pci compliance]]></category>
		<category><![CDATA[PCI DSS]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/pci-compliance/</guid>
		<description><![CDATA[Payment Card Industry Data Security Standards (PCI DSS) compliance means many different things to many people. And after all, it should, based on the complexities of truly understanding what the phrase &#8220;PCI Compliance&#8221; or being &#8220;PCI compliant&#8221; really means. For an ounce of clarity, remember this. All merchants that fall into Level 1 of the [...]]]></description>
				<content:encoded><![CDATA[<p>Payment Card Industry Data Security Standards (PCI DSS) compliance means many different things to many people. And after all, it should, based on the complexities of truly understanding what the phrase &#8220;PCI Compliance&#8221; or being &#8220;PCI compliant&#8221; really means. </p>
<p>For an ounce of clarity, remember this. All merchants that fall into Level 1 of the transaction volume parameters for PCI will have to undertake an on-site PCI DSS assessment by a <strong><a href="http://www.pciassessment.org">Qualified Security Assessor</a>;</strong> somebody who has gone through the training and certification process by the Payment Card Industry Security Standards Council (PCI SSC).  </p>
<p>&#8220;Most&#8221; other levels (and i stress most, because there are exceptions) can conduct their own self-assessment for PCI compliance. The world &#8220;self&#8221; is misleading because most organizations trying to comply will need assistance from a PCI QSA.</p>
<p>To learn more about PCI DSS, visit <strong><a href="http://www.pciassessment.org">pciassessment.org</a>.</strong></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI DSS Requirements for Service Providers &#124; Expert Advice from a QSA</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-requirements-for-service-providers-expert-advice-froma-qsa/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-requirements-for-service-providers-expert-advice-froma-qsa/#comments</comments>
		<pubDate>Tue, 16 Jun 2009 11:40:01 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[amex]]></category>
		<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[data centers]]></category>
		<category><![CDATA[Discover Card]]></category>
		<category><![CDATA[ISO]]></category>
		<category><![CDATA[jcb]]></category>
		<category><![CDATA[managed service providers]]></category>
		<category><![CDATA[mastercard]]></category>
		<category><![CDATA[payment card industry data security standards (PCI DSS)]]></category>
		<category><![CDATA[payment gateways]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[pci dss compliance]]></category>
		<category><![CDATA[pci qsa]]></category>
		<category><![CDATA[qualified security assessor]]></category>
		<category><![CDATA[service providers payment card compliance]]></category>
		<category><![CDATA[transaction processors]]></category>
		<category><![CDATA[visa]]></category>
		<category><![CDATA[web hosting providers]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-requirements-for-service-providers-expert-advice-froma-qsa/</guid>
		<description><![CDATA[PCI DSS compliance is becoming a requirement for many service providers involved in the processing, storage, transmission, and switching of transaction data and cardholder data. In short, a service provider, for purposes of Payment Card Industry Data Security Standards (PCI DSS) compliance includes companies that provide services to merchants, to other &#8220;service providers&#8221; or are [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://www.pciassessment.org">PCI DSS compliance</a> is becoming a requirement for many service providers involved in the processing, storage, transmission, and switching of transaction data and cardholder data.</p>
<p>In short, a service provider, for purposes of Payment Card Industry Data Security Standards (PCI DSS) compliance includes companies that provide services to merchants, to other &#8220;service providers&#8221; or are other entities that control OR could impact the security of cardholder data.</p>
<p>So, here are some common examples of service providers:</p>
<p>Transaction Processors<br />
Payment Gateways<br />
Customer Service Entities, such as Call Centers<br />
Managed Service Providers<br />
Web Hosting Providers<br />
Data Centers<br />
Independent Sales Organizations (ISO&#8217;s)</p>
<p>And you may also want to know that the major payment brands (VISA, MasterCard, AMEX, Discover Card, and JCB) have different &#8220;terms&#8221; for service providers.</p>
<p>AMEX-They are called a &#8220;Third Party Processor&#8221;<br />
Discover-They are called a &#8220;Third Party Processor&#8221; and a &#8220;Payment Service Provider&#8221;<br />
Mastercard-They are called &#8220;Third Party Processors&#8221; and a &#8220;Data Storage Entity&#8221;<br />
VISA-They can be called a &#8220;VisaNet Processor&#8221;, which is considered everybody that connects to VISA.</p>
<p>And generally speaking (with a noted exception), all Service Providers <a href="http://www.pciassessment.org/service-providers.php">will need an annual on-site Review</a> done by a <a href="http://www.pciassessment.org">Qualified Security Assessor</a>.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-requirements-for-service-providers-expert-advice-froma-qsa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI DSS Compliance &#124; Understanding Requirement 1</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-understanding-requirement-1/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-understanding-requirement-1/#comments</comments>
		<pubDate>Sun, 17 May 2009 21:36:08 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[CIS]]></category>
		<category><![CDATA[e-commerce]]></category>
		<category><![CDATA[firewalls]]></category>
		<category><![CDATA[internet access]]></category>
		<category><![CDATA[Network Diagrams]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[payment card industry data security standards (PCI DSS)]]></category>
		<category><![CDATA[Requirement 1: Install and maintain a firewall configuration to protect cardholder data]]></category>
		<category><![CDATA[routers]]></category>
		<category><![CDATA[rule sets]]></category>
		<category><![CDATA[SANS]]></category>
		<category><![CDATA[untrusted networks]]></category>
		<category><![CDATA[wireless networks]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-understanding-requirement-1/</guid>
		<description><![CDATA[PCI DSS Compliance is growing at an astonishing rate for merchants and service providers throughout the country and the globe. Let&#8217;s take some time to distill each of the twelve (12) core Payment Card Industry Data Security Standards (PCI DSS) Requirements. This will be the first in a 12 part series of giving you a [...]]]></description>
				<content:encoded><![CDATA[<p>PCI DSS Compliance is growing at an astonishing rate for merchants and service providers throughout the country and the globe.</p>
<p>Let&#8217;s take some time to distill each of the <strong><a href="http://www.pciassessment.org/12-pci-dss-requirements.php">twelve (12) core Payment Card Industry Data Security Standards</a></strong> (PCI DSS) Requirements. This will be the first in a 12 part series of giving you a better understanding of each of the requirements and the sub-requirements for each. </p>
<p>Build and Maintain a Secure Network<br />
Requirement 1: Install and maintain a firewall configuration to protect cardholder data</p>
<p>As stated by the Payment Card Industry Data Security Standards Requirements: All systems must be protected from unauthorized access from untrusted networks, whether entering the system via the Internet as e-commerce, employees’ Internet access through desktop browsers, employees’ e-mail access, dedicated connection such as business to business connections, via wireless networks, or via other sources. Often, seemingly insignificant paths to and from untrusted networks can provide<br />
unprotected pathways into key systems. Firewalls are a key protection mechanism for any computer network.&#8221;</p>
<p>Okay, fair enough and with that said, as a <strong><a href="http://www.pciassessment.org">Payment Card Industry Qualified Security Assessor</a> </strong>(PCI QSA), here&#8217;s what you need to be aware of for Requirement 1:</p>
<p>1. Have in place an excellent network topology diagram.<br />
2. Make sure you develop the documented policies and procedures that are being called for in Requirement 1<br />
3. When deploying and hardening network devices, (routers, firewalls,etc.), please keep in mind that you need to be documenting this process along with utilizing industry accepted configuration guidelines , such as SANS, NIST, CIS.</p>
<p>This is just a start and by no means all the items for Requirement 1, but being aware of these issues will greatly help you meet the guidelines for PCI DSS Requirement 1.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-understanding-requirement-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI DSS Transaction Levels &#124; VISA Requirements for Merchants</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-transaction-levels-visa-requirements-for-merchants/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-transaction-levels-visa-requirements-for-merchants/#comments</comments>
		<pubDate>Fri, 27 Mar 2009 22:15:16 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[payment card industry data security standards (PCI DSS)]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[pci dss transaction levels]]></category>
		<category><![CDATA[pci qsa]]></category>
		<category><![CDATA[qualified security assessor (QSA)]]></category>
		<category><![CDATA[visa]]></category>
		<category><![CDATA[visa level 1]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-transaction-levels-visa-requirements-for-merchants/</guid>
		<description><![CDATA[PCI DSS transaction levels for merchants are used to identify what &#8220;Level&#8221; an organization would fall into for PCI DSS compliance. Level 1: Any merchant-regardless of acceptance channel-processing over 6,000,000 Visa transactions per year OR Any merchant that Visa, at its sole discretion, determines should meet the Level 1 merchant requirements to minimize risk to [...]]]></description>
				<content:encoded><![CDATA[<p>PCI DSS transaction levels for <strong><a href="http://www.pciassessment.org/merchants.php#bookmark-1">merchants </a></strong>are used to identify what &#8220;Level&#8221; an organization would fall into for PCI DSS compliance.  </p>
<p><strong>Level 1:</strong> Any merchant-regardless of acceptance channel-processing over 6,000,000 Visa transactions per year OR Any merchant that Visa, at its sole discretion, determines should meet the Level 1 merchant requirements to minimize risk to the Visa system.</p>
<p><strong>Level 2:</strong> Any merchant-regardless of acceptance channel-processing 1,000,000 to 6,000,000 Visa transactions per year.</p>
<p><strong>Level 3: </strong>Any merchant processing 20,000 to 1,000,000 Visa e-commerce transactions per year.</p>
<p><strong>Level 4:</strong> Any merchant processing fewer than 20,000 Visa e-commerce transactions per year, and all other merchants-regardless of acceptance channel-processing up to 1,000,000 Visa transactions per year.</p>
<p>Regarding PCI DSS compliance for VISA, most merchants will fall into Levels 2, 3, and 4, which allows a merchant to conduct a payment card industry Data Security Standards (PCI DSS) self assessment. However, a self-assessment is easier said than done, as it is best to still <strong><a href="http://www.pciassessment.org">utilize a Qualified Security Assessor (PCI QSA</a>)</strong> to assist in self-assessment matters. </p>
<p>Level 1 compliance for merchants requires an actual on-site PCI DSS assessment by a PCI-QSA.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-transaction-levels-visa-requirements-for-merchants/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Credit Card Security Compliance &#124; Learn about PCI DSS</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/credit-card-security-compliance-learn-about-pci-dss/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/credit-card-security-compliance-learn-about-pci-dss/#comments</comments>
		<pubDate>Thu, 26 Mar 2009 01:09:17 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[american express]]></category>
		<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[credit card security compliance]]></category>
		<category><![CDATA[Discover Card]]></category>
		<category><![CDATA[jcb]]></category>
		<category><![CDATA[mastercard]]></category>
		<category><![CDATA[payment card industry data security standards (PCI DSS)]]></category>
		<category><![CDATA[pci dss self assessment]]></category>
		<category><![CDATA[qualified security assessor (QSA)]]></category>
		<category><![CDATA[visa]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/credit-card-security-compliance-learn-about-pci-dss/</guid>
		<description><![CDATA[Credit card security compliance is more technically known as the Payment Card Industry Data Security Standards, simply known as PCI DSS. PCI DSS is a framework established and agreed upon by the major payment brands (Visa, MasterCard, American Express, Discover Card, and JCB). The oversight, training and assessment guidelines for PCI DSS is conducted by [...]]]></description>
				<content:encoded><![CDATA[<p>Credit card security compliance is more technically known as the Payment Card Industry Data Security Standards, simply known as PCI DSS. PCI DSS is a framework established and agreed upon by the major payment brands (Visa, MasterCard, American Express, Discover Card, and JCB). The oversight, training and assessment guidelines for PCI DSS is conducted by the Payment Card Industry Security Standards Council, known as the PCI SSC. </p>
<p>Payment card industry compliance is a very general and broad term, thus you need to fully understand what your compliance needs are and how to go about undertaking the requirements for meeting these very needs. Most organizations requiring PCI DSS compliance are either <a href="http://www.pciassessment.org/merchants.php">merchants</a> or <a href="http://www.pciassessment.org/service-providers.php">service providers</a>, and they have to comply based on what level they fall into for PCI DSS.</p>
<p>Add to this is the ability to either conduct a PCI DSS self assessment or to undertake an actual on-site PCI DSS assessment by a qualified security assessor, known as PCI-QSA. Get the facts about compliance and start making inroads sooner rather than later for all your credit card security compliance needs (again, more technically known as PCI DSS <img src='http://itknowledgeexchange.techtarget.com/compliance-governance/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/credit-card-security-compliance-learn-about-pci-dss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>12 PCI DSS Requirements &#124; Lessons Learned from a PCI QSA</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/12-pci-dss-requirements-lessons-learned-from-a-pci-qsa/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/12-pci-dss-requirements-lessons-learned-from-a-pci-qsa/#comments</comments>
		<pubDate>Tue, 24 Mar 2009 23:39:00 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[12 PCI DSS requirements]]></category>
		<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[payment card industry dat]]></category>
		<category><![CDATA[payment card industry data security standards (PCI DSS)]]></category>
		<category><![CDATA[pci dss policies and procedures]]></category>
		<category><![CDATA[pci readiness assessment]]></category>
		<category><![CDATA[qualified security assessor (QSA)]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/12-pci-dss-requirements-lessons-learned-from-a-pci-qsa/</guid>
		<description><![CDATA[The 12 PCI DSS Requirements are lengthy and technical indeed. However, organizations need to truly understand the scope of the PCI assessment for gaining greater insight into the efficiencies that can be had for undertaking a Payment Card Industry Data Security Standards (PCI DSS) Assessment. So, what are my lessons learned as a Qualified Security [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://www.pciassessment.org/12-pci-dss-requirements.php">The 12 PCI DSS Requirements</a> are lengthy and technical indeed. However, organizations need to truly understand the scope of the PCI assessment for gaining greater insight into the efficiencies that can be had for undertaking a Payment Card Industry Data Security Standards (PCI DSS) Assessment.</p>
<p>So, what are my lessons learned as a Qualified Security Assessor (QSA) who conducts PCI assessments?</p>
<p>First and foremost, the assessment is NOT always about technology. Sure there is a host of requirements  surrounding the &#8220;system components&#8221; of the &#8220;cardholder environment&#8221;, but look closer and you will find that developing documented policies and procedures is one of the most time-consuming and arduous processes of the entire assessment? Your kidding, you might say? Not at all, it&#8217;s amazing how much time and effort is needed for developing these documents for ensuring PCI compliance. </p>
<p>Add to the fact that you need to properly &#8220;scope&#8221; the assessment for a number of parameters and I would highly advice a PCI Readiness Assessment for any entity going through a Level 1 PCI engagement. </p>
<p>Properly scope the assessment for what is and is not included in the &#8220;cardholder environment&#8221;, conduct a <a href="http://www.pciassessment.org/pci-dss-readiness-assessment.php">PCI Readiness Assessment</a> and be mindful of the documented policies and procedures that must be in place for compliance. </p>
<p>To learn more about PCI, visit <a href="http://www.pciassessment.org">pciassessment.org</a></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/12-pci-dss-requirements-lessons-learned-from-a-pci-qsa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
