Complying with the PCI DSS Standard
摘要
It is hard to be in business without making money, so one of the first standards that must be adhered to internationally, is the Payment Card Industry Data Security Standard (PCI DSS). Any organization that accepts payment cards must adhere to the PCI DSS, as mandated by credit card companies. This is an international standard, not a national regulation. Fortunately, this standard is comprehensive, technical, detailed, and wide-reaching; thus it is a great start for a security implementation. Obviously, nations have passed security regulation, addressing more than payment card information, such as protecting financial, health and other personal information. This chapter outlines the requirements of this Data Security Standard, as well as some associated threats to payment cards and required merchant procedures.