|
The credit card industry began to realize that the current level of security provided
for personal and financial cardholder information could have a significant impact
on their business. Organized crime and theives have begun to notice that the databases
of cardholder information as lucrative targets; the incidence of Identity theft
is growing and becoming more public. A report in 2005 from the FBI indicated that the
majority of the $315M fraud loss in the US was due to credit card fraud. All payment
card network members, including traditional and Internet organizations, banks and
payment processors, are required to comply with the Payment Card Industry (PCI)
Data Security Standard, introduced in 2004 by five leading credit card companies
and later updated in 2007. In order to ensure compliance with the PCI Data Security
Standard, all entities that accept credit cards as a form of payment must address
the 12 requirements of the PCI standard as well as complete quarterly network scans
of their payment network.
SourceSentry PCI Compliance solution consits of two specific software service solutions.
Our first solution with our OneComply product provides an integrated PCI Security
Audit Management solution based on the PCI DSS 1.1 Security Audit Producedures.
This complements our PCI Policy online software solution called
PCI Policy.com
What our PCI Compliance solution provides
1. PCI Compliant IT Security Policy
-
Addresses the Requirement 12 of the PCI DSS 1.1 Standards that mandates organziations to have an IT security Policy that contains acceptable usage procedures/policies
-
Custom generated security policy document that must be in place in order to comply
-
Specific provisions for employees to sign-off for future record keeping
-
Enables the awareness for protecting credit card data for all employees or contractors
-
Software as a Service model that is atttractive for Level 3 or Level 4 Merchants
Please visit Security Policy Service
for more information about this unique solution.
2. Security Audit Management
-
Enables an organization to verify using the Security Audit Procedures detailed by
the PCI DSS standards organziation
-
Allows detailed checking on every requirement before assessors can perform onsite
reviews
-
Pinpoints controls gap across all areas of the organization affected by PCI
-
Provides tracking metrics and dashboards for managers to understand bottlenecks
-
Audit ready reports enable external QSA's to review and complete assessments quickly
Regulations supported out-of-the-box
- PCI - Payment Card Industry Data Security Standard
- Various state regulations(Texas, Minnesota) that have mandated PCI Compliance
Want to know more? Please contact our Sales department.
|