{"id":161,"date":"2006-08-04T06:10:11","date_gmt":"2006-08-04T13:10:11","guid":{"rendered":"http:\/\/www.merchantaccountblog.com\/archives\/161"},"modified":"2012-03-22T14:55:02","modified_gmt":"2012-03-22T19:55:02","slug":"requirements-for-securing-cardholder-information","status":"publish","type":"post","link":"https:\/\/www.merchantequip.com\/merchant-account-blog\/161\/requirements-for-securing-cardholder-information","title":{"rendered":"Requirements for Securing Cardholder Information"},"content":{"rendered":"<p>A joint news release was issued just a few days ago from Visa, Mastercard, American Express, Diners Club, JCB and Discover outlining what businesses need to do to secure cardholder data. This brief article is applicable for all businesses and is a very easy to follow, guide to protecting cardholder information.<\/p>\n<p>What makes this short guide very good, is that any one can understand it.<\/p>\n<div style=\"border: 1px dotted #000; margin: 5px; padding: 5px;\">\n<p><strong>TO: <\/strong>All Merchants<br \/>\n<strong>FROM: <\/strong>American Express\u00ae, Diners Club\u00ae, Discover\u00ae Card, JCB\u00ae, MasterCard International\u00ae, Visa\u00ae U.S.A.<br \/>\n<strong>RE: <\/strong>Merchant Requirements for Securing Cardholder Information<\/p>\n<p>The rising incidence of stolen cardholder account data is a major concern for all participants in the payment industry. As a result of these thefts, merchants and financial institutions suffer fraud losses and unanticipated operational expenses, and consumers are inconvenienced significantly. To protect your business, your customers (cardholders), and the integrity of the payment system, each of the card companies has in place a set of requirements governing the safekeeping of account information. This document gives a brief overview of the most critical aspects of those requirements.<\/p>\n<table style=\"border: 1px solid #000;\" width=\"100%\" border=\"0\" cellspacing=\"0\" cellpadding=\"5\">\n<tbody>\n<tr>\n<td style=\"border-bottom: 1px solid #000;\" width=\"200\"><strong>Storage of Cardholder Information<\/strong><\/td>\n<td style=\"border-bottom: 1px solid #000;\">\u2022 Do not store the following under any circumstance:<br \/>\n&#8211; Full contents of any track from the magnetic stripe on the back of the card.<br \/>\n&#8211; Card-validation code<br \/>\n&#8211; the three-digit value printed on the signature panel of a MasterCard\u00ae, Visa\u00ae, Discover\u00aeCard, JCB\u00ae, or Diners Club\u00ae card, and four<br \/>\n&#8211; digit code printed on the front of an American Express\u00ae card.<br \/>\n\u2022 Store only that portion of the customer&#8217;s account information that is essential to your business<br \/>\n&#8211; i.e. name, account number or expiration date.<br \/>\n\u2022 Store all material containing this information (e.g., authorization logs, transaction reports, transaction receipts, car rental agreements, and carbons) in a secure area limited to authorized personnel.<\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: 1px solid #000;\"><strong>Destruction of Cardholder Information<\/strong><\/td>\n<td style=\"border-bottom: 1px solid #000;\">\u2022 Destroy or purge all media containing obsolete transaction data with cardholder information.<\/td>\n<\/tr>\n<tr>\n<td style=\"border-bottom: 1px solid #000;\"><strong>Use of Agents or Third Parties (Vendors, Processors, Software Providers, Payment Gateways, or Other Service Providers)<br \/>\n<\/strong><\/td>\n<td style=\"border-bottom: 1px solid #000;\">\u2022 Advise each merchant bank or processing contact (representing each of your card brands) of any agents that engage in, or propose to engage in, the processing or storage of transaction data on your behalf-regardless of the manner or duration of such activities.<br \/>\n\u2022 Make sure these agents adhere to all rules and regulations governing cardholder information security. Any violation by your agent may result in unnecessary financial exposure and inconvenience to your business.<\/td>\n<\/tr>\n<tr>\n<td><strong>Reporting a Security Incident<\/strong><\/td>\n<td>\u2022 In the event that transaction data is accessed or retrieved by any unauthorized entity, notify the merchant bank or processing contact for each card brand immediately.<br \/>\n\u2022 This report will not only minimize risk to the payment system, but protect your customers in the most responsible manner. Systems and procedures are in place to immediately stop the unauthorized use of compromised data, but are effective only when you do your part to promptly report a security incident.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>We continue to work on your behalf to reduce payment card fraud, and offer this communication to enhance your awareness, minimize risk, and protect your customers. If you have any questions or would like to have more information, please visit our web sites or contact your representatives for any of the card brands sponsoring this correspondence.<\/p>\n<\/div>\n<p>The actual PDF is available on the <a href=\"\/downloads\/\">download page<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A joint news release was issued just a few days ago from Visa, Mastercard, American Express, Diners Club, JCB and Discover outlining what businesses need to do to secure cardholder data. This brief article is applicable for all businesses and is a very easy to follow, guide to protecting cardholder information. What makes this short [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[22,7,1],"tags":[],"class_list":["post-161","post","type-post","status-publish","format-standard","hentry","category-ecommerce","category-guides","category-merchantaccounts"],"_links":{"self":[{"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/posts\/161","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/comments?post=161"}],"version-history":[{"count":3,"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/posts\/161\/revisions"}],"predecessor-version":[{"id":1652,"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/posts\/161\/revisions\/1652"}],"wp:attachment":[{"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/media?parent=161"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/categories?post=161"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/tags?post=161"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}