The Payment Card Industry – Data Security Standard (PCI-DSS) is run by the PCI Security Standards Council (American Express, Discover Financial Services, JCB, MasterCard and Visa) and represents an effort by the industry to tackle identity theft and on-line fraud.
Representing a common set of industry tools and measurements to help ensure safe handling of sensitive information, the Standard provides a framework for developing a robust data security process.
This includes the prevention, detection and reaction to security incidents.
Do I need to comply with PCI DSS?
If you are an organisation that stores, processes or transmits payment card data, then you will need to comply with the Standard.
This includes a number of organisations which includes resellers, web hosting providers, card processing bureaux, data storage entities and payment service providers.
To see if you need to comply and to what level, please check on our PCI compliance grid or complete and submit the enquiry form
What does the standard cover?
The PCI DSS is a multifaceted security standard that includes requirements for security management, policies, procedures, network architecture, software design and other critical protective measures. It comprises 12 general requirements designed to:
- build and maintain a secure network
- protect cardholder data
- ensure the maintenance of vulnerability management programs
- implement strong access control measures
- regularly monitor and test networks
- ensure the maintenance of information security policies
Your next step
LRQA can help you to easily achieve compliance to PCI requirements.
You might like to download and read our special Q&A article on PCI DSS here (requires PDF reader) which answers some of the more common questions that we get asked about this new standard.
Simply call one of our business advisors on 0800 783 2179 or complete and submit the enquiry form, after which we will arrange for our PCI partners to contact you to discuss your options.
They will advise on and can even manage the whole process for you if required, liasing with us throughout the process to ensure easy and hassle free compliance.
A member of the Lloyd's Register Group ©LRQA
2010
Page last modified on 08 December 2009 |


