Saturday 11 August 2012

PCI Compliance Security Standards

By Karen Carter


PCI stands for Payment Card Industry, and DSS stands for Data Security Standard. Why does it make sense to follow PCI Security Standards Council for PCI compliance? Many small and medium size business owners have complained about the complicated nature of the PCI data security standard, and stated that it adds to the administrative burden, regardless of whether they already have excellent security procedures in place in their enterprise. Regardless of such complaints, there are reasons of import as for why it makes sense to comply with the PCI DSS standards. The three main reasons are: Payment Card Industry has years of experience, Compliance with PCI security standard will give you ideas on how to protect your own data, and last but not least, You may not have a choice. Let's see all these reasons in detail.

The cards can actually be issued by one of these companies or by a bank that has a contract with one of these companies. Now the companies will also make deals with some merchants and even some online merchants in order to make sure that they accept their card and their logo. Keep in mind that there is always going to be a PCI compliance deadline to consider. As a merchant when you accept credit cards then you are required to operate under certain PCI compliance requirements. All of these will be outlines in your merchant agreement that you signed when you started accepting credit cards.

There is really no cost of PCI compliance unless you are not compliant and then you can be fined. The thing is that if you are not compliant you can get fined very heavily from the bank. This is because the bank is actually being fined by the credit card processing companies and then they are passing on the fine to you as the consumer who was under them and consequently had broken their contract. So it is essential not to have the cost of the compliance that you actually focus on the agreement and understand what is required of you.

This might include a deadline in which certain things might have to be completed in a specific time frame. The things that they PCI compliance is asking for are not anything that should not already be done anyways. They maintain that you have to have a secure connection and that there are appropriate firewalls preventing someone from being able to hack into the system by the compliance deadline.

So by maintaining proper security standards there is not going to be a cost of PCI compliance. The problem is that the fines are rather heavy if you are not in compliance. Now if you have to change some things and this ends up costing you some money you can always consider the cost of the fines and the reputation of your business if you had chosen to not follow through with this important compliance. In the end you will easily see how this is a much cheaper option then taking your chances on being fined.




About the Author:



No comments:

Post a Comment