What is PCI DSS Compliance?
The Payment Card Industry (PCI) Security Standards Council (SSC) is an industry forum for the ongoing management of security standards for account data protection. The PCI Data Security Standard (DSS) provides an actionable framework for developing a robust payment card security process – including prevention, detection and appropriate reaction to security incidents.
Ensuring PCI DSS compliance for your organization
Organizations handling credit card account data – including merchants and processors – are required to be compliant with PCI DSS. Some organizations are additionally required to validate compliance through a third-party audit of the following requirements:
- Build and Maintain a Secure Network
- Requirement 1: Install and maintain a firewall configuration to protect cardholder data
- Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters
- Protect Cardholder Data
- Requirement 3: Protect stored cardholder data
- Requirement 4: Encrypt transmission of cardholder data across open, public networks
- Maintain a Vulnerability Management Program
- Requirement 5: Use and regularly update anti-virus software
- Requirement 6: Develop and maintain secure systems and applications
- Implement Strong Access Control Measures
- Requirement 7: Restrict access to cardholder data by business need-to-know
- Requirement 8: Assign a unique ID to each person with computer access
- Requirement 9: Restrict physical access to cardholder data
- Regularly Monitor and Test Networks
- Requirement 10: Track and monitor all access to network resources and cardholder data
- Requirement 11: Regularly test security systems and processes
- Maintain an Information Security Policy
- Requirement 12: Maintain a policy that addresses information security
Expedient is your managed services data center provider for PCI DSS compliance.
In addition to a wide range of complementary managed data center services, Expedient can assist with the PCI DSS compliance process by providing the following documentation offering written assurances:
- Service Organization Control (SOC) 1 Report (aka SSAE-16)
- Service Organization Control (SOC) 2 Report (security, availability and confidentiality)
- Attestation of Compliance (AOC) for Report on Compliance (ROC)
- Visa Global Registry of PCI DSS Compliant Service Providers Listing
Hosting with Expedient doesn’t exclusively make an organization compliant with PCI, however, it does reduce the time and expense associated with many of the requirements.
More information about PCI DSS is available from the SSC.