Have an online store? What you need to do by July 1.
sinard.com
sinard.com
Outsource and be done with it, unless your turnover is so large that the accumulated fees for having some third party take care of it outweigh the costs of doing it yourself.
Get more information on PCI-DSS here: https://www.pcisecuritystandards.org
http://usa.visa.com/merchants/risk_management/cisp_merchants...
Level 3 merchants (up to a million transactions a year) need to complete a self-assessed questionnaire annually, fill out a form and have an automated external test run. All are very minor hurdles and if you're running that many transactions should be an extraordinarily small amount of expense as a percentage of revenue. If you're doing 20,000 transactions there is even less to do.
tl;dr FUD
Having said that, merchants at the level 2-3 size often won't have renegotiated rates agreed with their acquirer back when the merchant was smaller - doing so can soften the impact of outsourcing capture/storage considerably (perhaps even pay for it completely).
Agree that merchants should read PCI-DSS, but smaller shops may not have the expertise/time to realise/handle the implications (do you record telephone calls from customers, for instance?). For any size of merchant, to be able to say "we're unlikely to be breached as we don't store card numbers" is a good thing indeed.
The PCI specification seems to have been written to protect the payment card industry, not the merchants.
That goes for almost anything in the credit card world. Witness the way chargebacks due to failed approval policies on the part of the credit card companies are taken out on the merchants, lending policies that are totally irresponsible get taken out on the general public and so on.
Credit card companies are amongst the biggest scum on the planet, unfortunately they are so entrenched now that you can hardly move without them.
Try renting a car or booking an airplane ticket without a credit card.
I've outsourced each and every bit of the handling and processing to third parties, we still get hit with the chargeback penalty.
I guess we're all going to find out how a privatized monetary system works, at least on the consumer level.
That doesn't make sense. First, general credit cards has been around for 50 years, more limited predecessors for closer to 100 years.
Second, credit cards are decoupled from the monetary system, they are merely vessels for transferring money.
Ignoring the flaws in most current implementations, isn't this the kind of thing 3D-Secure (VBV, SecureCode, etc.) is supposed to reduce?
I helped a friend that runs an IPSP implement it, the spec is so large and convoluted that there's bound to be holes, so the flaws in the implementations are a problem but flaws in the spec are likely to crop up as well.
If that's the case then, holes aside, it makes sense for a merchant to integrate 3DS to reduce chargebacks (not to mention some acquirers charge lower rates for VBV payments, which can help offset PSP fees). But your earlier comment suggested that you were still being stung for chargebacks - I'd be interested to know why.
(and yes, it's a lot of spec for what's essentially 3 XML request/response pairs, but that's the payments industry for you - you'll know what I mean if you've had the joy of ploughing through APACS-70 or its predecessors...)
I was peripherally involved in some of the PCI compliance efforts at my workplace (big, household name international company).. Frankly I was incredibly frightened and embarrassed at some of the incredibly dumb, sloppy ways my employer were treating customer credit cards. Now don't get me wrong, we still do a lot of dumb shit, but at least some effort is taken to secure customer CC numbers now.
Just to note, I have clients who get emails scaring them into "pci scans" even when they don't handle credit card information.
Simply put, there are 12 areas that you need to pay close attention to, and I've pasted them below.
Build and Maintain a Secure Network
Requirement 1: Install and maintain a firewall configuration to protect cardholder data Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters
Protect Cardholder Data
Requirement 3: Protect stored cardholder data Requirement 4: Encrypt transmission of cardholder data across open, public networks
Maintain a Vulnerability Management Program
Requirement 5: Use and regularly update anti-virus software Requirement 6: Develop and maintain secure systems and applications
Implement Strong Access Control Measures
Requirement 7: Restrict access to cardholder data by business need-to-know Requirement 8: Assign a unique ID to each person with computer access Requirement 9: Restrict physical access to cardholder data
Regularly Monitor and Test Networks
Requirement 10: Track and monitor all access to network resources and cardholder data Requirement 11: Regularly test security systems and processes
Maintain an Information Security Policy
Requirement 12: Maintain a policy that addresses information security
For more information on PCI-DSS, go to https://www.pcisecuritystandards.org. Also, consider downloading the PCI-DSS, its a 60-70 page PDF with all of the information that you need on the PCI-DSS. It also contains a Self-Assessment Questionnaire that you can use to review your site or app.
As I work with ecommerce sites daily, I can assure you, PCI is not something that you want to ignore. At the same time, its not terribly difficult to adhere to the rules.
As a quick reminder, any site that is found to be non-compliant at the time of a breach could face fines into the hundreds of thousands of dollars ($ USD)
If your gateway doesn't intend to supply a PCI compatible solution of their own you should probably get another implemented instead. (I have one or two customer that went through PCI certification, it's a pointless hassle and they have to get reassessed once a year)
For smaller sites the conversion rate has tended to increase slightly (in sweden, so ymmv..) when using a reputable vendor.
Should we have every single project certified? How do you even go about that?
Just before July 1 so we're scrambling to get code out to we can continue to make money?
Or after the giant business murdering fine arrived?
And we are with one of the really BIG ones . . .
I am marking this one as link bait and moving on, annoyed at the waste of a couple of hours.
http://usa.visa.com/merchants/risk_management/cisp_payment_a...
While the use of PA-DSS validated payment applications is recommended, a payment application need not be included on Visa’s list of PABP validated payment applications or PCI SSC’s list of PA-DSS validated payment applications in order to comply with Phase 2, Phase 3 and Phase 5 requirements for use of PA-DSS compliant applications. Acquirers may determine the PA-DSS compliancy of a payment application through alternate validation processes, which should confirm that payment applications meet PA-DSS requirements and should facilitate compliance with the PCI DSS.
I was unable to find the corresponding clause for MasterCard, American Express, or Discover, and various forum posts I came across seemed to indicate it was a Visa-only mandate currently.