|
<< Click to Display Table of Contents >> Navigation: Appendix C Processing Credit Cards Securely > Introduction |
The Payment Card Industry Data Security Standard (PCI-DSS) requires that merchants that process credit and/or debit cards meet minimum security standards to protect sensitive customer cardholder data.
As stated in following PCI-DSS excerpts, the security requirements apply to all parts of your credit card processing environment.
These security requirements apply to all “system components.” System components are defined as any network component, server, or application that is included in or connected to the cardholder data environment. The cardholder data environment is that part of the network that possesses cardholder data or sensitive authentication data.
Network components include but are not limited to firewalls, switches, routers, wireless access points, network appliances, and other security appliances. Server types include but are not limited to the following: web, database, authentication, mail, proxy, network time protocol (NTP), and domain name server (DNS). Applications include all purchased and custom applications, including internal and external (Internet) applications.
If you are using the RetailEdge CC Module or RetailEdge to process credit cards as part of your RetailEdge software package, then you are required by the PCI to install, maintain, and use the software in accordance with PCI-DSS requirements.
This RE CC Module Implementation Guide will help you install and configure RetailEdge and RetailEdge CC Module into a secure PCI-DSS compliant environment. The Guide will review the PCI-DSS requirements and explain how each requirement applies to RetailEdge and RetailEdge CC Module and outline the steps you will need to take to make sure your operation is protecting cardholder data.
If you do not use RetailEdge CC Module to process credit cards, then this manual does not apply. However, many of the security concepts in this document and in the PCI-DSS are good general recommendations and should be reviewed for applicability to your computer and/or network environment.
The PCI-DSS standard is comprised of the following core requirements:
Build and Maintain a Secure Network:
Requirement 1: Install and maintain a firewall configuration to protect cardholder data.
Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters.
Protect Cardholder Data:
Requirement 3: Protect stored cardholder data.
Requirement 4: Encrypt transmission of cardholder data across open, public networks.
Maintain a Vulnerability Management Program:
Requirement 5: Use and regularly update anti-virus software.
Requirement 6: Develop and maintain secure systems and applications.
Implement Strong Access Control Measures:
Requirement 7: Restrict access to cardholder data by business need-to-know.
Requirement 8: Assign a unique ID to each person with computer access.
Requirement 9: Restrict physical access to cardholder data.
Regularly Monitor and Test Networks:
Requirement 10: Track and monitor all access to network resources and cardholder data.
Requirement 11: Regularly test security systems and processes.
Maintain an Information Security Policy:
Requirement 12: Maintain a policy that addresses information security.
Additional and updated information about the PCI Security Standards Council and the PCI-DSS can be found at the following web sites:
https://www.pcisecuritystandards.org/
https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml