{"id":336,"date":"2008-05-06T11:58:20","date_gmt":"2008-05-06T16:58:20","guid":{"rendered":"http:\/\/www.merchantaccountblog.com\/?p=336"},"modified":"2008-05-12T11:05:23","modified_gmt":"2008-05-12T16:05:23","slug":"forcing-software-for-pci-compliance","status":"publish","type":"post","link":"https:\/\/www.merchantequip.com\/merchant-account-blog\/336\/forcing-software-for-pci-compliance","title":{"rendered":"Forcing Software for PCI Compliance"},"content":{"rendered":"<p>Lately I&#8217;ve been hearing reports of processors that are starting to charge their customers $19.95 per month for not being PCI compliant. To fix this problem, these processors are requiring their customers to install some PC based scanning software that is supposed to magically make the business PCI compliant, thereby allowing them to avoid the monthly charge.<\/p>\n<p>Let me start out by saying: <strong>This is a bunch of crap!<\/strong><\/p>\n<p>There is nothing that you can just put on your PC that will make your business PCI compliant. This is so far off course that it hardly can be related to PCI. PCI compliance is in reference to networks, computers, hardware and software that play a part in the processing, storage, or transfer of a credit card transaction.<\/p>\n<p>It is now required that every business be PCI compliant, but let me assure you that there is no simple computer program that will do this for any business. Even if only a single computer is used to enter card data, it is unlikely that it is the only piece of the puzzle, and even more unlikely that a single piece of software can guarantee PCI compliance.<\/p>\n<p><strong>Steps to get compliant:<\/strong><\/p>\n<ol>\n<li>Determine whether you need to be PCI compliant. <em>(If you accept credit cards, or play any part in the processing of a credit card, you need to be PCI compliant.)<\/em><\/li>\n<li>Determine which <a href=\"http:\/\/usa.visa.com\/merchants\/risk_management\/cisp_merchants.html?it=c|\/merchants\/risk_management\/cisp.html\">Level of compliance<\/a> is required for your business.\n<ul style=\"list-style:none;\">\n<li><strong>Level 1<\/strong>: Greater than 6 million credit card transactions per year or any business that has suffered a hack or data breach, or any business deemed Level 1 by card associations.<\/li>\n<li><strong>Level 2<\/strong>: 1 to 6 Million credit card transactions per year.<\/li>\n<li><strong>Level 3<\/strong>: 20K to 1 Million credit card transactions per year.<\/li>\n<li><strong>Level 4<\/strong>: Less than 20K ecommerce, or 1 Million total transactions per year.<\/li>\n<\/ul>\n<\/li>\n<li>Fill out the self assessment questionaire (SAQ).<\/li>\n<li>Fix every area that you answered &#8216;NO&#8217; to on the SAQ.<\/li>\n<li>Hire an <a href=\"https:\/\/www.pcisecuritystandards.org\/resources\/approved_scanning_vendors.htm\">approved scanning vendor<\/a> (ASV) to perform quarterly scans of any external networks. &#8211; All Levels<\/li>\n<li>Fix and maintain any failed area of the scan.<\/li>\n<li><em>Level 1 Only:<\/em> Complete an annual on-site audit by a <a href=\"https:\/\/www.pcisecuritystandards.org\/resources\/qualified_security_assessors.htm\">Qualified Security Assessor<\/a> (QSA).<\/li>\n<li>** Continue to maintain security of networks and card information! **<\/li>\n<\/ol>\n<p>Once you complete all of those requirements, and maintain a secure network and business environment, you are PCI compliant. Most of the details of PCI compliance can be found in the SAQ, and on the <a href=\"https:\/\/www.pcisecuritystandards.org\/\">PCI Security Standards website<\/a>.<\/p>\n<p><strong>If you&#8217;re trying to determine whether PCI compliance is worth it to you, consider this:<\/strong> A security breach will result in a business requiring Level 1 compliance. The cost for level 2, 3, and 4 compliance can be as low as a few hundred dollars per year. The cost of Level 1 compliance can easily reach into the 6 and 7 figures per year.<\/p>\n<p><strong>Some Good PCI Resources:<\/strong><br \/>\n<a href=\"http:\/\/pcianswers.com\/\">PCI Answers Blog<\/a><br \/>\n<a href=\"https:\/\/www.pcisecuritystandards.org\/\">PCI Security Standards website<\/a><br \/>\n<a href=\"http:\/\/usa.visa.com\/merchants\/risk_management\/cisp.html\">Visa Cardholder Information Security Program<\/a><br \/>\n<a href=\"http:\/\/www.mastercard.com\/us\/sdp\/index.html\">MasterCard SDP Program<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Lately I&#8217;ve been hearing reports of processors that are starting to charge their customers $19.95 per month for not being PCI compliant. To fix this problem, these processors are requiring their customers to install some PC based scanning software that is supposed to magically make the business PCI compliant, thereby allowing them to avoid the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8,1],"tags":[],"class_list":["post-336","post","type-post","status-publish","format-standard","hentry","category-fraud","category-merchantaccounts"],"_links":{"self":[{"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/posts\/336","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/comments?post=336"}],"version-history":[{"count":0,"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/posts\/336\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/media?parent=336"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/categories?post=336"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.merchantequip.com\/merchant-account-blog\/wp-json\/wp\/v2\/tags?post=336"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}