Protecting Card Payments with PCI DSS
The Payment Card Industry Data Security Standard (PCI DSS) is an international information security standard that all companies and organisations that process, store or transmit payment card data need to comply with.
The purpose of PCI DSS is to protect card payments and prevent card fraud. PCI DSS was developed by Visa Inc., MasterCard, American Express, Discover and JCB, which also established the standard's governing body, the PCI Security Standards Council (PCI SSC). PCI SSC is responsible for maintaining PCI DSS over time.
PCI DSS comprises six main goals aimed at minimising the risk that card data — such as the card number (PAN), chip data, PIN and CVC — ends up in the wrong hands and is used for fraud.
It is important to comply with PCI DSS, both to avoid fraud that leads to negative publicity, and to avoid fines.
Goals and requirements in PCI DSS
PCI DSS comprises six main goals and 12 requirement areas. Each requirement area contains detailed requirements, totaling 250 requirements that must be met to comply with PCI DSS.
Each main goal and its associated requirement areas are described below.
Build and maintain a secure network
- Install and update one or more firewalls to protect card data.
- Do not use vendor-supplied default passwords and other security parameters in the systems. It must be easy for users to change credentials, passwords and PIN codes.
Protect cardholder data
- Protect stored card data and the cardholder's national identity number, address, phone number, etc.
- Encrypt the transmission of card data across open, public networks.
Maintain a vulnerability management program
- Use and regularly update anti-malware software.
- Build security in from the outset when developing new systems and applications. Maintain operating systems and applications through regular software updates and upgrades.
Implement strong access control measures
- Restrict access to card data to only those individuals who need it.
- Assign a unique user ID to each person with access to card data.
- Restrict physical access to card data, for example through access-controlled zones in data centres.
Regularly monitor and test networks
- Monitor and enable tracking of all access to network resources and card data.
- Regularly test security systems and processes.
Maintain an information security policy
- Establish a policy that addresses information security for employees and contractors.
Who is covered by PCI DSS?
Every company and organisation that handles card data in any way must comply with PCI DSS. This applies, for example, to payment processors, merchants, service providers and online retailers. Actors that handle physical infrastructure for payment cards are also affected by PCI DSS, such as providers of payment terminals.
Ensuring PCI DSS compliance is an ongoing process
A vulnerability scan must be carried out every quarter by a company approved by PCI SSC as an Approved Scanning Vendor (ASV). This requirement applies regardless of how many card transactions are processed annually.
In addition, the following requirements for verification apply:
- More than 6 million card transactions per year, an audit is carried out annually by an assessor accredited by PCI SSC, a Qualified Security Assessor (PCI QSA).
- 1 million to 6 million card transactions per year, a Self-Assessment Questionnaire (SAQ) must be completed annually.
- Fewer than 1 million card transactions per year, the acquiring bank decides on reporting requirements.
For e-commerce, the following also applies:
- 20,000 to 1 million card transactions per year in e-commerce, a Self-Assessment Questionnaire (SAQ) must be completed annually.
- Fewer than 20,000 card transactions per year in e-commerce, the acquiring bank decides on reporting requirements.