[1] Payment Card Industry - Data Security Standards (PCI-DSS)

Source references for establishing PCI DSS compliance in shopping carts using external payment options eg Paypal.

 
SOURCE: ABSTRACTS  
PAYPAL
pal

What is PCI DSS and who needs to comply?

PCI compliance shows you have secure procedures in place that keeps their payment information safe and secure.
PCI DSS is a set of 12 requirements* that all businesses who handle credit or debit card payments must comply with.
It provides business best practice guidelines to establish a "minimum security standard".

The PCI Security Standards require all merchants, regardless of size or number of transactions, who accept, store, transmit or process any cardholder data to comply with PCI DSS.
The requirements, for the majority of merchants, are an Annual PCI Self Assessment Questionnaire and a Quarterly Network Scan.

 
 
 
 
 

As a merchant accepting card payments you are required to comply with PCI DSS.
As a service provider, PayPal is also required to comply with PCI DSS. The majority of our products can form part of your PCI DSS compliance solution by easing the burden of PCI compliance for you, however, for some of our products you are responsible for ensuring you are compliant.

 
 

PCI compliance handled by PayPal

PCI compliance handled by you

 
 

With Website Payments Standard, Online Invoicing, Express Checkout and Website Payments Pro Hosted, PayPal handles the payment card information on your behalf and so greatly eases the burden of PCI compliance.

If you use Website Payments Pro it means that you handle card data directly and will need to ensure you are PCI compliant. You can use one of our PCI compliant partners or register with Trustwave to help you become compliant. If you use Virtual Terminal, we strongly recommend you become compliant as part of your security best practice.

 
 
 

MTI
mti

MTI holds the Queen’s Royal Warrant for Data Security Products & Services

Link for info.
No endorsement of service intended

* What are the twelve major requirements of the PCI DSS Compliance?

...the PCI DSS only applies to network and application infrastructure that transmit or store credit card data elements...


The standard comprises twelve major requirements, which are further grouped under six related 'control objectives' as shown below:

Build and Maintain a Secure Network
Requirement 1: Install and maintain a firewall configuration to protect cardholder data
Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters
Protect Cardholder Data
Requirement 3: Protect stored cardholder data
Requirement 4: Encrypt transmission of cardholder data across open, public networkss
Maintain a Vulnerability Management Program
Requirement 5: Use and regularly update anti-virus software
Requirement 6: Develop and maintain secure systems and applications
Implement Strong Access Control Measures
Requirement 7: Restrict access to cardholder data by business need-to-know
Requirement 8: Assign a unique ID to each person with computer access
Requirement 9: Restrict physical access to cardholder data
Regularly Monitor and Test Networks
Requirement 10: Track and monitor all access to network resources and cardholder data
Requirement 11: Regularly test security systems and processes
Maintain an Information Security Policy
Requirement 12: Maintain a policy that addresses information security

More information is available at: https://www.pcisecuritystandards.org

 
Author's CONCLUSION

The PCI require that websites, which at any time result in cardholder data being held by the owner, must be PCI compliant.
A website out sourcing to PayPal, using Website Payments Standard, Online Invoicing, Express Checkout and Website Payments Pro Hosted is never privy to cardholder data and under current (June2015) regulations, does not need PCI compliance.

 

BACKGROUND

 
WIKIPEDIA

The Payment Card Industry Data Security Standard (PCI DSS) is a proprietary information security standard for organizations that handle branded credit cards from the major card schemes including Visa, MasterCard, American Express, Discover, and JCB. Private label cards – those which aren't part of a major card scheme – are not included in the scope of the PCI DSS.
The PCI Standard is mandated by the card brands and administered by the Payment Card Industry Security Standards Council. The standard was created to increase controls around cardholder data to reduce credit card fraud via its exposure. Validation of compliance is performed annually, either by an external Qualified Security Assessor (QSA) that creates a Report on Compliance (ROC) for organizations handling large volumes of transactions, or by Self-Assessment Questionnaire (SAQ) for companies handling smaller volumes.

 

PAYPAL

Ten Common Myths of PCI DSS (pdf)

Myth 2 – "Outsourcing card processing makes us compliant."

Outsourcing simplifies payment card processing but does not provide automatic compliance.
Don’t forget to address policies and procedures for cardholder transactions and data processing.
Your business must protect cardholder data when you receive it, and process charge backs and refunds.

 

PCI SELF ASSESSMENT

SAQ A

 

Payment Card Industry (PCI) Data Security Standard
Self-Assessment Questionnaire A and Attestation of Compliance

SAQ A has been developed to address requirements applicable to merchants whose cardholder data functions are completely outsourced to validated third parties, where the merchant retains only paper reports or receipts with cardholder data.

 
SAQ A EP

Payment Card Industry (PCI) Data Security Standard

Self-Assessment Questionnaire A EP and Attestation of Compliance

Card-not-present Merchants,
All Cardholder Data Functions Fully Outsourced  

SAQ A-EP merchants confirm that, for this payment channel:

.........

§       Your company has confirmed that all third party(s) handling storage, processing, and/or transmission of cardholder data are PCI DSS compliant; and

§       Your company retains only paper reports or receipts with cardholder data, and these documents are not received electronically.

 

ZEN CART
FORUM THREADS

PCI PA-DSS Certification Approved for Zen Cart v1.5.4

PA-DSS Admin Session Timeout Enforced?

v1.54 Time Out

 
     

'CARDHOLDER DATA'
PCI Glossary

Glossary, Abbreviations and Acronyms

CARDHOLDER DATA

At a minimum, cardholder data consists of the full PAN. Cardholder data may also appear in the form of the full PAN plus any of the following: cardholder name,
expiration date
and/or service code
See Sensitive Authentication Data for additional data elements that may be transmitted or processed (but not stored) as part of a payment transaction.

PAN


Acronym for “primary account number” and also referred to as “account number.” Unique payment card number (typically for credit or debit cards) that identifies the issuer and the particular cardholder account.

21/6/15
TOP