 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Regulatory Compliance, Governance and Security &#187; pci ssc</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/compliance-governance/tag/pci-ssc/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/compliance-governance</link>
	<description></description>
	<lastBuildDate>Thu, 10 Mar 2011 15:04:50 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>PCI DSS Compliance &#124; Why You Need a QSA for Level 1 Compliance</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-why-you-need-a-qsa-for-level-1-compliance/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-why-you-need-a-qsa-for-level-1-compliance/#comments</comments>
		<pubDate>Fri, 24 Jul 2009 20:00:58 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[dss]]></category>
		<category><![CDATA[level 1]]></category>
		<category><![CDATA[merchant]]></category>
		<category><![CDATA[payment card industry data security standards (PCI DSS)]]></category>
		<category><![CDATA[payment card industry security standards council]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[pci ssc]]></category>
		<category><![CDATA[qsa]]></category>
		<category><![CDATA[qualified security assessor (QSA)]]></category>
		<category><![CDATA[service provider]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-why-you-need-a-qsa-for-level-1-compliance/</guid>
		<description><![CDATA[PCI DSS Compliance for Level 1 Merchants and Service Providers is mandatory. In short, if you are a Merchant or Service Provider and have been called upon to become Payment Card Industry Data Security Standards (PCI DSS) compliant, then an on-site assessment by a Qualified Security Assessor (QSA) is what you will need. A QSA [...]]]></description>
				<content:encoded><![CDATA[<p>PCI DSS Compliance for Level 1 Merchants and Service Providers is mandatory. In short, if you are a Merchant or Service Provider and have been called upon to become Payment Card Industry Data Security Standards (PCI DSS) compliant, then an on-site assessment by a Qualified Security Assessor (QSA) is what you will need.</p>
<p>A QSA is simply an individual who has gone through the licensing to become an expert in PCI DSS compliance. This is somebody who has been awarded the designation by the Payment Card Industry Security Standards Council, known as the PCI SSC.</p>
<p>For more information about PCI DSS compliance and in hiring a QSA for all your Level 1 needs, visit the official <strong><a href="http://www.pciassessment.org">PCI DSS Resource Guide</a></strong>.</p>
<p>And lastly, MasterCard has now strengthened their requirements to make Level 2 merchants also undertake an on-site PCI DSS assessment.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-compliance-why-you-need-a-qsa-for-level-1-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Payment Card Industry Data Security Standard &#124; Learn about PCI DSS</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-data-security-standard-learn-about-pci-dss/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-data-security-standard-learn-about-pci-dss/#comments</comments>
		<pubDate>Mon, 20 Apr 2009 13:03:14 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[american express]]></category>
		<category><![CDATA[amex]]></category>
		<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[discover]]></category>
		<category><![CDATA[jcb]]></category>
		<category><![CDATA[mastercard]]></category>
		<category><![CDATA[merchants]]></category>
		<category><![CDATA[Payment Card Industry Data Security Standard]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[pci dss self assessment]]></category>
		<category><![CDATA[pci ssc]]></category>
		<category><![CDATA[service providers]]></category>
		<category><![CDATA[visa]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-data-security-standard-learn-about-pci-dss/</guid>
		<description><![CDATA[The Payment Card Industry Data Security Standard, commonly known as PCI DSS, is a far reaching compliance initiative put forth in a collaborative fashion by the major payment brands (VISA, MasterCard, American Express, Discover, and JCB). These compliance initiatives are overseen and guided by the Payment Card Industry Security Standards Council (PCI SSC). Thus, if [...]]]></description>
				<content:encoded><![CDATA[<p>The Payment Card Industry Data Security Standard, commonly known as PCI DSS, is a far reaching compliance initiative put forth in a collaborative fashion by the major payment brands (VISA, MasterCard, American Express, Discover, and JCB). These compliance initiatives are overseen and guided by the Payment Card Industry Security Standards Council (PCI SSC).  </p>
<p>Thus, if you need to become PCI DSS compliant, there are a number of valuable resources to look at.  But first and foremost, you need to understand what Level you fall into for PCI DSS compliance. For merchants, you can be categorized anywhere from a Level 1 to a Level 4. Level 1 audit require an on site PCI DSS assessment, while other Levels you can conduct a PCI DSS Self Assessment. These are general rules, however. Compelling business requirements would require some Level 2, 3, and 4 providers to possibly have an on site audit conducted. Also, there are varying requirements depending on your transaction level between the major payment brands. <a href="http://www.pciassessment.org/merchants.php">Find out what your transaction level is</a>, first and foremost.</p>
<p>Additionally, there are also requirements for service providers, thus you will <a href="http://www.pciassessment.org/service-providers.php">need to identify your transaction level also.</a></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-data-security-standard-learn-about-pci-dss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI DSS Merchants Levels &#124; Learn Your Requirements for PCI DSS Compliance</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-merchants-levels-learn-your-requirements-for-pci-dss-compliance/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-merchants-levels-learn-your-requirements-for-pci-dss-compliance/#comments</comments>
		<pubDate>Mon, 23 Mar 2009 12:07:43 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[american express]]></category>
		<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[discover]]></category>
		<category><![CDATA[jcb]]></category>
		<category><![CDATA[mastercard]]></category>
		<category><![CDATA[pci dss merchant levels]]></category>
		<category><![CDATA[pci ssc]]></category>
		<category><![CDATA[qsa]]></category>
		<category><![CDATA[qualified security assessor (QSA)]]></category>
		<category><![CDATA[self assessment questionnaire]]></category>
		<category><![CDATA[visa]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-merchants-levels-learn-your-requirements-for-pci-dss-compliance/</guid>
		<description><![CDATA[Regarding PCI DSS merchant levels, it is paramount that these very merchants properly identify the level they fall under for compliance with PCI DSS. Most merchants will be able to undergo their own payment card industry data security standards (PCI DSS) self assessment questionnaire (SAQ). However, many will also be required to conduct and go [...]]]></description>
				<content:encoded><![CDATA[<p>Regarding PCI DSS merchant levels, it is paramount that these very merchants properly identify the level they fall under for compliance with PCI DSS. Most merchants will be able to undergo their own payment card industry data security standards (PCI DSS) self assessment questionnaire (SAQ). However, many will also be required to conduct and go through an annual on-site assessment by a Qualified Security Assessor (QSA).</p>
<p>Again, this all depends on the merchant levels and you have to understand that these PCI DSS merchant levels are different for each of the respective payment brands. So, let&#8217;s take a closer look at this.</p>
<p>Discover Card: They do not even use merchant level categories, rather, they use a risk based approach for assigning PCI DSS requirments.</p>
<p>VISA: Visa uses Levels 1 to 4 for classifying merchant levels. <a href="http://www.pciassessment.org/merchants.php#bookmark-2">Learn more about VISA Merchant requirments</a></p>
<p>American Express, JCB, MasterCard: These major payment brand heavyweights also have identify merchants from Levels 1 to 4, and again, this is based on transaction volume. <a href="http://www.pciassessment.org/merchants.php#bookmark-3">Learn more about their PCI DSS merchant levels.</a></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/pci-dss-merchants-levels-learn-your-requirements-for-pci-dss-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Payment Card Industry Compliance &#124; Its much more than just PCI DSS</title>
		<link>http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-compliance-its-much-more-than-just-pci-dss/</link>
		<comments>http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-compliance-its-much-more-than-just-pci-dss/#comments</comments>
		<pubDate>Mon, 23 Mar 2009 11:53:29 +0000</pubDate>
		<dc:creator>Charles Denyer</dc:creator>
				<category><![CDATA[charles denyer]]></category>
		<category><![CDATA[cvv2]]></category>
		<category><![CDATA[pa-dss]]></category>
		<category><![CDATA[payment application data security standard]]></category>
		<category><![CDATA[payment card industry compliance]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[pci ssc]]></category>
		<category><![CDATA[ped]]></category>
		<category><![CDATA[pin data]]></category>
		<category><![CDATA[pin entry devices]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-compliance-its-much-more-than-just-pci-dss/</guid>
		<description><![CDATA[When people think of payment card industry compliance, they naturally think of PCI DSS compliance. And to be fair, the vast majority of organizations undergoing PCI DSS compliance are merchants and service providers who have to either conduct their own self assessment or go through an on-site assessment with a Qualified Security Assessor (QSA). But [...]]]></description>
				<content:encoded><![CDATA[<p>When people think of payment card industry compliance, they naturally think of <a href="http://www.pciassessment.org">PCI DSS compliance</a>. And to be fair, the vast majority of organizations undergoing PCI DSS compliance are merchants and service providers who have to either conduct their own self assessment or go through an on-site assessment with a Qualified Security Assessor (QSA). </p>
<p>But here&#8217;s what else you need to know about payment card industry compliance and how it could affect you.<br />
<strong><br />
Payment Application Data Security Standard (PA-DSS)</strong><br />
The goal of PA-DSS is to help software vendors and others develop secure payment applications that do not store prohibited data, such as full magnetic stripe, CVV2 or PIN data, and ensure their payment applications support compliance with the PCI DSS.</p>
<p><strong>Pin Entry Devices (PED)</strong><br />
To gain approval by PCI Security Standards Council, PIN entry devices must comply with the requirements and guidelines specified by a number of documents listed on the PCI SSC website.</p>
<p>In summary, these are two additional compliance initiatives outside of the traditional PCI DSS assessments that many people are not familiar with. I&#8217;ll be covering these in a much more in-depth manner in subsequent blogs. </p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/compliance-governance/payment-card-industry-compliance-its-much-more-than-just-pci-dss/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
