AccessMyLibrary provides FREE access to over 30 million articles from top publications available through your library.

It only takes one dealing with PCI-DSS.(Payment Card Industry Data Security Standard)

Business Credit

| February 01, 2009 | Barron, Jacob | COPYRIGHT 2009 National Association of Credit Management. This material is published under license from the publisher through the Gale Group, Farmington Hills, Michigan.  All inquiries regarding rights should be directed to the Gale Group. (Hide copyright information)Copyright

[ILLUSTRATION OMITTED]

With the advent of email and the Internet, the world of personal finance has taken a turn for the dramatic; whereas in prior eras, following the depression and the establishment of the Federal Deposit Insurance Corporation (FDIC), your money was yours, was kept in a bank and was safe from anything short of robbery coupled with governmental collapse. Now banks and their customers are beset on all sides by both active and passive security threats. Whether in the form of adolescent hackers, email scammers or merely a company's lax approach to IT security, the risks facing consumers and companies today are considerably greater than what they were even a decade ago, and a level of suspicion, as well as a judicious approach to spending, has become a necessity for sound financial management and planning.

But despite the increase in threats, the speed with which both consumer and B2B business is conducted shows no sign of slowing. Consumers continue to rely on credit cards and business vendors, despite the sometimes considerable, albeit manageable, interchange fees, continue to move toward accepting credit cards as a means of quick, assured payment. This being the case, the world of business and finance has had to come to terms with the seedy world of fraud, hacking and identity theft and find a way to better protect customer data and identifiable information.

The primary source of the data used and abused in breaches and hacks is from credit cards, which, as online transactions have increased, has become a bit easier to attain. Just a few years ago, as threats increased in frequency, notoriety and sophistication, regulations and measures were discussed and pored over in board rooms as much as living rooms, culminating in an agreement between all card brands to instate a set of standards to protect cardholder information. The result, established on September 7, 2006, was the Payment Card Industry Data Security Standard (PCI-DSS), a set of 12 standards that applies to all organizations, systems, networks and applications that process, store or transmit a cardholder number. This move, made with the blessing of Capitol Hill, requires companies that accept credit cards to never store any cardholder data beyond the name, number, expiration date and service code. Nothing has to be signed on the part of the merchant; if a company agrees to accept payment cards, it's implied that they will comply with these rules.

Compliance

Twelve more standards atop the already considerable compliance requirements levied on businesses seems like an overwhelming prospect for companies merely looking to accept other payment cards as a means to reduce days sales outstanding (DSO) and increase payment cycles, but PCI-DSS compliance shouldn't deter merchants from making the switch to credit card acceptance. "Nothing here is so major that we can't overcome it," said Robert Day, vice president of commercial interchange at Fifth Third Processing Solutions. "It's a very serious matter and you do need to be alarmed, but at the end of the day, it's pretty simple stuff." In a recent NACM-sponsored teleconference, Day outlined what's expected of card-accepting merchants and iterated the seriousness of compliance, but still reassured his audience that all compliance requires is a carefully considered approach that's appropriate for the accepting company in question.

Credit professionals and companies should understand the 12 PCI-DSS standards and base a compliance plan around those basic tenets. They are:

Related articles from newspapers, magazines, journals, and more
Payment Card Industry Data Security Standard - Does Your Company Store, Process...
News wire article from: Mondaq Business Briefing August 3, 2006 700+ words
...series of high profile data security breaches, credit...Payment Card Industry Data Security Standard (PCI DSS...processes or transmits cardholder data. The standard applies...network. Protect cardholder data. Maintain a vulnerability...
Leading Analyst Firm and Consul Present Complimentary Webinar on Payment Card...
Press release article from: Business Wire August 3, 2005 700+ words
...to the Payment Card Industry (PCI) Data Security Standard. Effective January 2005...of noncompliance; --The future of cardholder data protection and government mandates. What: "Data Security and Privacy - not an Entitlement...
ArcSight Joins the PCI Security Standards Council and PCI Security Vendor...
Press release article from: M2 Presswire January 24, 2008 700+ words
...perspective to data security standard that protects cardholder data(C)1994...including the PCI Data Security Standard...protecting cardholder data. The PCI...payment account data security by fostering...improving cardholder data protection...
Electronic Payment Exchange Launches Revolutionary Cardholder Data Security...
Press release article from: Business Wire October 22, 2007 700+ words
...transmits and stores cardholder data ensuring it never...hearing three major data security concerns from merchants...the first and only cardholder data protection system...expert insight on cardholder data security, visit www.DontBeTheNextHeadline...
Electronic Payment Exchange to Launch Revolutionary Cardholder Data Security...
Press release article from: Business Wire October 18, 2007 700+ words
...transmits or stores cardholder data, it is in no danger...has put in place Data Security Standards (DSS...the first and only cardholder data protection system...expert insight on cardholder data security, visit www.DontBeTheNextHeadline...
Visa launches first-ever free internet security assessment service: Visa has...
Magazine article from: Australian Banking & Finance September 30, 2005 700+ words
...for all parties handling Visa cardholder data. Visa will partner with ScanAlert...compliant with Visa's global data security standards. The result will be...have nearly doubled. Ensuring cardholder data is kept secure Visa's Account...
MasterCard Partners with Fraternal Order of Police to Help Merchants Keep...
Press release article from: Business Wire June 7, 2006 700+ words
...happens, protect cardholder data and deliver peace...collaboration on data security throughout the...merchants keep cardholder data safe and secure...with "Protecting Cardholder Data with the PCI Data Security Standard" on...
The Protegrity code: cardholder data must be encrypted.
Newspaper article from: Stamford Advocate (Stamford, CT) June 23, 2005 700+ words
...Stamford-based provider of data security encryption software, any stolen...company to benefit from a new data security standard the credit card industry...standards require encryption of cardholder data and transmissions across public...
For more facts and information, see all results
©2009 Gale, a part of Cengage Learning. All rights reserved.
About us | FAQs | Contact us | Privacy policy | Terms and conditions
Other Gale sites: Encyclopedia.com | HighBeam Research | Acquire Content | Books & Authors | Goliath | MovieRetriever | Smart QandA