Online Payments Blog

Industry News and discussions relating to Online Payments and Application Security.

Feb 07
2010

An Introduction to PCI DSS for Merchants

Posted by: Dave

pci dssPCI DSS is a security standard that applies to anyone who stores, processes or transmits cardholder data. This includes Payment Service Providers and merchants. I know most of the readers of this blog fall into the latter category. Merchants can approach PCI DSS in a number of different ways such as using in-house expertise, outsourcing PCI Compliance to an external party (more of a checkbox approach in my opinion) or using a PCS DSS solution from a third party.

If you are a small merchant you may not be able to afford any of these options but you still need to be compliant. In that case the best option is to limit the risk and thus reduce the scope for PCI DSS. To begin with you should not store cardholder information under any circumstances. If the storage of cardholder information is a requirement for your business then we recommend you find a Payment Service Provider who can do this for you. The RealEFT service from Realex Payments and the SecureCard service from WorldNet TPS are two services that are designed specifically to meet this requirement.
 
If you want to reduce your risk even further then you can use a hosted payments page integration option so you ensure that cardholder information never comes in contact with your website or server. The customer will enter their card details on the secure hosted payment page provided by your payment service provider. With this option the sensitive cardholder information does not come in contact with your website or server. For more information on PCI DSS you can read our PCI DSS Guide, look at the PCI Councils website or ask a question on our PCI DSS forum.

Dave

--

If you liked this article then you can:


Related Blog Posts:


Related Articles:

Comments (0)add comment

Write comment
smaller | bigger
 

busy
Tag Cloud