What is PCI DSS?
The Payment Card Industry Data Security Standard (PCI DSS) is a security standard that applies to anyone who stores, processes or transmits cardholder data. The purpose of the security standard is to enhance payment account data security and protect cardholders against misuse of their personal information. In simple terms it is a set of requirements that are designed to reduce the likelihood of a data breach occurring.
The standard contains twelve requirements that are grouped into six principles:
- Build and Maintain a Secure Network
- Protect Cardholder Data
- Maintain a Vulnerbility Management Program
- Implement Strong Access Control Measures
- Regularly Monitor and Test Networks
- Maintain an Information Security Policy
The PCI DSS defines the elements of cardholder information such as the PAN and then indicates if storage of each data element is permitted or prohibited and whether each data element must be protected.
What is the PCI SSC?
The Payment Card Industry Security Standards Council (PCI-SSC) is the group responsible for maintaining the PCI DSS along with a number of other standards such as the Payment Application DSS (PS-DSS) and the PIN Entry Device (PED) standard. The PCI-SSC is lead by an Executive Committee, composed on representatives from the founding payment brands - Visa, MasterCard, American Express, Discover and JCB. The Executive Committee is responsible for policy setting with the PCI-SSC. Operational decisions are made by a Management Committee, which is also composed of representatives from the payment brands. There is an Advisory Board, drawn from participating organsations. This advisory group provides input and feedback to the PCI-SSC.
How did it come about?
Before the formation of the PCI-SSC there were five different programs operated by the five card brands - Visa, MasterCard, American Express, Discover and JCB.
- Visa Card Information Security Program
- MasterCard Site Data Protection
- American Express Data Security Operating Policy
- Discover Information and Compliance
- JCB Data Security Program
Each of these five programs where very similar and each program had the same goal - to ensure organsations that stored, processed or transmitted cardholder data protected this data from misuse. This was achieved by forcing the organisation to comply with a minimum set of security requirements. They decided to combine their programs and controls to produce one industry standard.
|