Wednesday, May 26, 2010

If Your Business Takes Credit Cards, You Must Be PCI Compliant!


I've been getting a lot of requests to help companies become PCI compliant these days. PCI (Payment Card Industry) is the infrastructure, tools and processes that allow merchants to accept credit card payments for goods and service they provide. If your company takes credit cards and especially if your company stores credit card information for reoccuring transations, there are certain information protection guidelines and practices that you must meet to insure that internet harckers or scammers do not steal this information. These guidelines are described in the PCI DSS standards documents.

Here is a clip that was aired on ABC News 7 a few weeks back. I think it paints a very clear picture of the risks, the threats and the consequences of a security breach in your computer networks and systems that makes your customer's credit card information vunerable to theft.

Berkeley Restaurant Falls Victim To Credit Card Scam

You can not be too careful. The World Wide Web is a rough and tumble place and there are many orgnized crime rings that prey on people and companies who do not take the necessary precations to protect their systems, their networks and their valuable information. Even Wells Fargo has had security breaches of their network and banking systems that have exposed their clients personal financial information. The problems that presents for their brand is enormous. Do you want to take similar risks with your business and your brand?

What are the deadlines for Complying with PCI DSS?
Compliance is mandated by the payment card brands and not by the PCI Security Standards Council. However, for most merchants, the deadlines for validating compliance with the PCI DSS have already passed. All entities that transmit, process or store payment card data must be compliant with PCI DSS.

What are the consequences of non-compliance with PCI DSS?The PCI Security Standards Council encourages all businesses that store payment account data to comply with the PCI DSS. Failure to do so subjects your business to brand risks and financial liabilities associated with account payment data compromises. Merchant service providers can impose their own financial and operational sanctions for non-compliance.

For more information about PCI Compliance you can visit the PCI Secuity Standards Council website at http://www.pcisecuritystandards.org/

If your company is faced with a PCI Compliance audit or wants to take the necessary steps to become PCI compliant, give us a call at 650-204-3151. TeamLogicIT can help you achieve the peace of mind that your computer and networking systems are secure. We are your Bay Area experts in data security.


1 comment:

  1. Thank you for the information and the link. Very helpful.

    ReplyDelete