Do you take credit cards?

Do you take credit cards?

image-credit-card-lockWe are not posing that question as a customer; we are posing the question as your IT and Security consultant.  We ask because a “YES” answer means that your organization is required by law to put in place certain IT and security practices.

If you handle any type of credit cards or banking information, make sure your organization is in line with PCI DSS (Payment Card Industry Data Security Standard) compliance.  PCI DSS is a set of security standards put in place to ensure that all organizations that accept, process, store or transmit credit card or banking information maintain a secure network environment.  This standard is administered by the Payment Card Industry Security Standards Council and its standards apply to any organization, regardless of size or number of transactions.  Failure to meet the requirements can result in fines and/or termination of credit card processing privileges.

The PCI DSS 12 requirements are:

  1. Install and maintain a firewall configuration to protect cardholder data.
  2. Do not use vendor-supplied defaults for system passwords and other security parameters.
  3. Protect stored cardholder data.
  4. Encrypt transmission of cardholder data across open, public networks
  5. Use and regularly update antivirus software.
  6. Develop and maintain secure systems and applications. (Note:  This includes ensuring the machine that you are entering the data on is secure.)
  7. Restrict access to cardholder data by business need-to-know.
  8. Assign a unique ID to each person with computer access.
  9. Restrict physical access to cardholder data.
  10. Track and monitor all access to network resources and cardholder data.
  11. Regularly test security systems and processes.
  12. Maintain a policy that addresses information security.

At IT Radix, we help our clients with being compliant with all 12 of the requirements listed and would be happy to help your organization anytime.  Give us a call today to review your network to ensure it meets with PCI DSS standards.