subject: Why You Should Comply With PCI [print this page] Why You Should Comply With PCI Why You Should Comply With PCI
It's extremely important to make sure that your server is secure, but that's only half the puzzle. It's all well and good if your server is secure, but if it is not PCI compliant, and your server is compromised, you could face massive fines and quite possibly the loss of your business.Payment Card Industry compliance is making sure that your servers meet the standards set forth for testing, and you must undergo regular testing to ensure that your compliance is ongoing. This will show your consumers that your server is not only secure, but that your business is compliant, meaning that the chances of their information being compromised is reduced.It's important to note that even if a site is PCI compliant, it's not a guarantee that their servers won't be breached. After all, TJ Maxx, Wyndham Worldwide, and Heartland Payment Systems were PCI complaint, but all of those sites were breached. Even so, PCI compliance is a must if your customer's credit card information even touches your server.Simply put, if you store, process, or transmit credit card data, you must be PCI compliant. If, for example, you only accept payment via PayPal, MoneyBooker, or other sites that are themselves PCI complaint, then you needn't worry, because although your customer may use those sites to pay you via credit card, that data is never stored on your server, nor does it even touch your server in those cases.However, if you accept credit card payments through your own merchant account, and that credit card data touches your server for even a moment, you must be compliant.So how does one become PCI compliant? It can be rather expensive and complicated for the small business website, but the fines that would be assessed in the event of a breach are much heavier.Here are just some of the many steps you must take to become PCI compliant: you must ensure that your server is secure, and that information such as e-mail communications are not transferred in plain text. You must also ensure that your passwords are strong, among many other requirements. You also need to install a firewall on your server to aid in protection against intrusions.Other necessary measures include the encryption of credit card data, and the installation of anti-virus programs. Access to customer information on your end must be restricted to those employees with a legitimate need to know, and each of those employees must have their own unique user ID and password. Also, physical access to the server storing the credit card information must likewise be restricted.Obviously, becoming PCI compliant can become rather involved. A smaller business may find the task to be daunting; a site hosted on a shared server, for example, would have no chance at being PCI compliant, especially since an SSL certificate (and with it, a dedicated IP) would be required. A site on a VPS may also find it challenging to become PCI compliant. Consequently, the best solution for PCI compliance is having dedicated servers, as the entire server is dedicated to that company, and is not being shared among other sites.Another condition of being PCI compliant is a quarterly scan by a vendor who is authorized to do such scans. You must also do a self-assessment questionnaire yearly.So what do you do if you want to become PCI complaint? Many vendors on the World Wide Web who will do PCI compliance scans. As part of that scan, they will advise you as to any issues that may arise that would prevent your certification. At that point, you'll want to fix the problems yourself, or if that is beyond your technical ability, engage the services of a company or person who is able to make the changes, as the list can be rather extensive and complicated.Even though the road to PCI compliance can be extensive for some, the reward is worth it: PCI compliance will not only increase consumer confidence, but it will prevent massive fines (up to 370 000) being assessed for non-compliance.