- The Payment Card Industry created the Data Security Standard to give merchants a framework for preventing data loss. Its implementation is important because most data loss happens at different points in the payment process, after banks have been separated from card holder information. Its purpose is to give merchants direction in how to assess security threats, fix security breaches, and report credit card security problems.
- Merchants are required to transfer card data over networks that are secured with firewalls that deny traffic from untrusted sources. Anti-virus software is to be updated regularly and if a wireless network is used to transmit payment information it must be an IEEE 802.11 network. All information must be encrypted. Passwords and system defaults should not be left at factory settings and employee access to computers should be evaluated every six months.
- Cardholder data should only be stored long enough to ensure legal compliance. Merchants need to implement a data disposal program that discards data at least every quarter. Sensitive customer information should not be stored after authorization. PIN codes should never be stored, and strong cryptographic keys should be used and changed every quarter. If encryption keys are stored after they are used, merchants need to ensure they are no longer used for encryption operations.
- Merchants need to regularly assess their business operations for potential security breaches. If employees are granted access to sensitive customer information, their IDs need to be regularly updated. Management practices pertaining to data storage should be given out on a business need-to-know basis. All business software should be configured to automatically update itself. Password changes to business networks should be approved by someone other than the person who originated the change and random audits should be performed to ensure password access is consistent with what management has stored on file.
Data Security
Secure Network
Cardholder Data
Vulnerability Management
SHARE