[1] Payment Card Industry - Data Security Standards (PCI-DSS)Source references for establishing PCI DSS compliance in shopping carts using external payment options eg Paypal. |
|||
| SOURCE: | ABSTRACTS | ||
PAYPAL |
What is PCI DSS and who needs to comply? PCI compliance shows you have secure procedures in place that keeps their payment information safe and secure. The PCI Security Standards require all merchants, regardless of size or number of transactions, who accept, store, transmit or process any cardholder data to comply with PCI DSS. |
||
As a merchant accepting card payments you are required to comply with PCI DSS. |
|||
PCI compliance handled by PayPal |
PCI compliance handled by you |
||
With Website Payments Standard, Online Invoicing, Express Checkout and Website Payments Pro Hosted, PayPal handles the payment card information on your behalf and so greatly eases the burden of PCI compliance. |
If you use Website Payments Pro it means that you handle card data directly and will need to ensure you are PCI compliant. You can use one of our PCI compliant partners or register with Trustwave to help you become compliant. If you use Virtual Terminal, we strongly recommend you become compliant as part of your security best practice. |
||
|
MTI holds the Queen’s Royal Warrant for Data Security Products & Services Link for info. |
* What are the twelve major requirements of the PCI DSS Compliance?...the PCI DSS only applies to network and application infrastructure that transmit or store credit card data elements...
Build and Maintain a Secure Network More information is available at: https://www.pcisecuritystandards.org |
||
| Author's CONCLUSION | The PCI require that websites, which at any time result in cardholder data being held by the owner, must be PCI compliant. |
||
BACKGROUND |
|||
| WIKIPEDIA | The Payment Card Industry Data Security Standard (PCI DSS) is a proprietary information security standard for organizations that handle branded credit cards from the major card schemes including Visa, MasterCard, American Express, Discover, and JCB. Private label cards – those which aren't part of a major card scheme – are not included in the scope of the PCI DSS. |
||
PAYPAL |
Ten Common Myths of PCI DSS (pdf)Myth 2 – "Outsourcing card processing makes us compliant." Outsourcing simplifies payment card processing but does not provide automatic compliance. |
||
PCI SELF ASSESSMENTSAQ A
|
Payment Card Industry (PCI)
Data Security Standard SAQ A has been developed to address requirements applicable to merchants whose cardholder data functions are completely outsourced to validated third parties, where the merchant retains only paper reports or receipts with cardholder data. |
||
| SAQ A EP | Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A EP and Attestation of Compliance Card-not-present Merchants, SAQ A-EP merchants confirm that, for this payment channel: ......... § Your company has confirmed that all third party(s) handling storage, processing, and/or transmission of cardholder data are PCI DSS compliant; and § Your company retains only paper reports or receipts with cardholder data, and these documents are not received electronically. |
||
ZEN CART |
PCI PA-DSS Certification Approved for Zen Cart v1.5.4PA-DSS Admin Session Timeout Enforced? v1.54 Time Out |
||
'CARDHOLDER DATA' |
Glossary, Abbreviations and Acronyms CARDHOLDER DATA At a minimum, cardholder data consists of the full PAN. Cardholder data may also appear in the form of the full PAN plus any of the following: cardholder name, PAN
|
21/6/15 | |