<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>2Checkout.com &#187; PCI</title>
	<atom:link href="http://www.2checkout.com/community/blog/tag/pci/feed" rel="self" type="application/rss+xml" />
	<link>http://www.2checkout.com/community</link>
	<description>merchant account / credit card processing alternative</description>
	<lastBuildDate>Tue, 16 Mar 2010 13:29:45 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Clearing the Mystery of PCI Compliance &#8211; Final Thoughts</title>
		<link>http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-final-thoughts</link>
		<comments>http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-final-thoughts#comments</comments>
		<pubDate>Fri, 08 Jan 2010 14:30:05 +0000</pubDate>
		<dc:creator>bion</dc:creator>
				<category><![CDATA[2Checkout Blog]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[E-Commerce]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.2checkout.com/community/?p=2832</guid>
		<description><![CDATA[In previous weeks we have been looking at how to become PCI compliant. I will confess, that starting on this article series I knew next to nothing about PCI DSS. Research for this series was, for me, very educational. The first thing I realized was how involved and complicated compliance can be. The next, and [...]]]></description>
			<content:encoded><![CDATA[<p>In previous weeks we have been looking at how to become PCI compliant. I will confess, that starting on this article series I knew next to nothing about <a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml">PCI DSS</a>. Research for this series was, for me, very educational. The first thing I realized was how involved and complicated compliance can be. The next, and more important realization is that compliance is a process, and never actually ends. From <a href="http://searchsecurity.techtarget.com/expert/KnowledgebaseAnswer/0,289625,sid14_gci1285601,00.html">SearchSecurity.com</a> :</p>
<blockquote><p>&#8220;Compliance is not something that&#8217;s bought; it&#8217;s a process. It never ends, and it needs to stay in lock step with the changes happening in a dynamic business. Understanding direct costs will probably require additional headcount to pull proper reports and document the program. It also may require investment in some software tools to mine through all the data that is generated by systems, networks and applications.&#8221;</p></blockquote>
<p><span id="more-2832"></span>One goal of this article series was to provide a reliable &#8220;bottom line&#8221; financial investment in becoming and maintaining PCI compliance. The more I learned about the industry that specializes in compliance the more difficult it was to find solid, or even estimated, pricing. What I found easliy matched the research that was released by <a href="http://www.gartner.com/technology/home.jsp">Gartner</a> and reported in the <a href="http://blog.elementps.com/element_payment_solutions/2009/02/pci-compliance-costs.html">PCI DSS Compliance Blog</a>.</p>
<blockquote><p>&#8220;Level 3 merchants, those processing between 20,000 and one million transactions per year, spent an average of $155,000, excluding security assessment.&#8221;</p></blockquote>
<p>In doing this article series, I gained a better understanding for both our internal security procedures (electronic keyed entry, guests signed in, frequent password changes, etc.) as well as the job that <a href="http://www.2checkout.com/community/blog/2checkout-blog/small-ecommerce-sites-facing-fines-if-compromised">Warner</a> and his team does to make sure that every transaction that passes through our network is as secure as current technology allows. Warner was an amazing resource for this series. When I came to the point where the PCI regulations seems beyond comprehension, or a solution was difficult to find, they were able to clarify the instructions or give direction to products or services that would help. I likely would have given up the series at the 3rd article if I didn&#8217;t have access to a group that manages these details daily.</p>
<p>Even though I am finished with this series, and will not have to actually become PCI compliant personally, PCI compliance doesn&#8217;t actually ever end. If we were really starting a business with a traditional merchant account, we would just be getting started at this point. As the PCI DSS Compliance Blog <a href="http://blog.elementps.com/element_payment_solutions/2009/10/pci-compliance-a-moment-in-time.html">perfectly states</a> :</p>
<blockquote><p>&#8220;PCI compliance is dynamic, requiring ongoing adaptation.  PCI compliance starts with a set of 12 basic requirements, it continues with vigilance and adaptation, and it ends with….well, it doesn’t end.&#8221;</p></blockquote>
<p><strong>Further Reading:</strong></p>
<p><a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-1">Clearing the Mystery of PCI Compliance (Part 1)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/e-commerce/clearing-the-mystery-of-pci-compliance-part-2">Clearing the Mystery of PCI Compliance (Part 2)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-3">Clearing the Mystery of PCI Compliance (Part 3)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-4">Clearing the Mystery of PCI Compliance (Part 4)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part5">Clearing the Mystery of PCI Compliance (Part 5)</a><a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part6"></a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part6">Clearing the Mystery of PCI Compliance (Part 6)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part7">Clearing the Mystery of PCI Compliance (Part 7)</a></p>
<div><a href="http://www.addthis.com/bookmark.php" onclick="window.open('http://www.addthis.com/bookmark.php?pub=&amp;url=http%3A%2F%2Fwww.2checkout.com%2Fcommunity%2Fblog%2F2checkout-blog%2Fclearing-the-mystery-of-pci-compliance-final-thoughts&amp;title=Clearing+the+Mystery+of+PCI+Compliance+%26%238211%3B+Final+Thoughts', 'addthis', 'scrollbars=yes,menubar=no,width=620,height=520,resizable=yes,toolbar=no,location=no,status=no'); return false;" title="Bookmark using any bookmark manager!" target="_blank"><img src="https://secure.addthis.com/button1-bm.gif" width="125" height="16" border="0" /></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-final-thoughts/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clearing the Mystery of PCI Compliance (Part7)</title>
		<link>http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part7</link>
		<comments>http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part7#comments</comments>
		<pubDate>Fri, 18 Dec 2009 13:59:31 +0000</pubDate>
		<dc:creator>bion</dc:creator>
				<category><![CDATA[2Checkout Blog]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.2checkout.com/community/?p=2751</guid>
		<description><![CDATA[This is it. We have reached the end of the tunnel and find ourselves at the last step in becoming PCI compliant. So let&#8217;s take a look at what we need to meet the final PCI DSS standard&#8230;
Requirement 12: Maintain a policy that addresses information security
This part of the standard lists more policies we have [...]]]></description>
			<content:encoded><![CDATA[<p>This is it. We have reached the end of the tunnel and find ourselves at the last step in becoming PCI compliant. So let&#8217;s take a look at what we need to meet the final <a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml">PCI DSS</a> standard&#8230;</p>
<p><strong>Requirement 12: Maintain a policy that addresses information security</strong></p>
<p>This part of the standard lists more policies we have to implement and more procedural documentation to write. A complete list of specific policies and documentation we need is <a href="http://pcidssfaq.org/forum/forumdisplay.php?f=13">here</a>. Given the scope of this requirement, I can give some general information about complying with this standard, but I cannot cover every portion of the requirements. Some examples of policies that require documentation are:</p>
<ul>
<li>Formal Risk Assessment and Risk Management Program</li>
<li>Security Awareness Program</li>
<li>Usage Policies for all end-user technologies and company resources</li>
<li>Incident Response Plan</li>
</ul>
<p><span id="more-2751"></span>This standard, more than any other forces us to think about what we will do in the event of an attack on our network, or when our security is compromised either externally or internally. We need to know what to do in the event an attack is identified. How do we respond? Who is in charge of our response? What response capabilities do we have internally? Do we need to involve outside experts?</p>
<p>This also includes company directives such as the establishment of a security team, security education for all employees, and pre-employment screening. At this point in our small company of one, we still need to have these policies and procedeures in place and documented. As we grow we can spend more time revising them in the future(since we already have to review and update our policies regularly).</p>
<p>Reading the PCI DSS requirements, we see many areas calling for documentation for various systems and procedures relating to the use and storage of our customers&#8217; information.  Among the requirements are the following:</p>
<ul>
<li>Data Retention and Disposal Policy</li>
<li>Anti-Virus Policies and Procedures</li>
<li>Password Management rules</li>
<li>Firewall Policies and Procedures</li>
<li>Change Management Guidelines</li>
</ul>
<p>The documentation directly above will be useful in complying with this final PCI requirement, but they do not replace it. This is, in essence, the culmination of the previous eleven standards. Requirement 12 establishes how all of the above work together to create our over-arching security policy. In addition to formalizing established policies and their interaction, we need to establish daily, quarterly and annual audits of our users, our system updates, and a formal risk assessment. For example, checking our logs for potential employee security violations and purging users/employees who no longer require access.</p>
<p>In a few weeks I will recap what I learned during this exercise in meeting PCI DSS compliance. I will be extending this article series to provide more details on just how much time is involved in meeting the PCI standards. While there are significant hardware and software investments in meeting the requirements, time, I found, was my greatest investment.</p>
<p><strong>Further Reading:</strong></p>
<p><a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-1">Clearing the Mystery of PCI Compliance (Part 1)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/e-commerce/clearing-the-mystery-of-pci-compliance-part-2">Clearing the Mystery of PCI Compliance (Part 2)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-3">Clearing the Mystery of PCI Compliance (Part 3)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-4">Clearing the Mystery of PCI Compliance (Part 4)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part5">Clearing the Mystery of PCI Compliance (Part 5)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part6">Clearing the Mystery of PCI Compliance (Part 6)</a></p>
<div><a href="http://www.addthis.com/bookmark.php" onclick="window.open('http://www.addthis.com/bookmark.php?pub=&amp;url=http%3A%2F%2Fwww.2checkout.com%2Fcommunity%2Fblog%2F2checkout-blog%2Fclearing-the-mystery-of-pci-compliance-part7&amp;title=Clearing+the+Mystery+of+PCI+Compliance+%28Part7%29', 'addthis', 'scrollbars=yes,menubar=no,width=620,height=520,resizable=yes,toolbar=no,location=no,status=no'); return false;" title="Bookmark using any bookmark manager!" target="_blank"><img src="https://secure.addthis.com/button1-bm.gif" width="125" height="16" border="0" /></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part7/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clearing the Mystery of PCI Compliance (Part6)</title>
		<link>http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part6</link>
		<comments>http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part6#comments</comments>
		<pubDate>Fri, 11 Dec 2009 14:27:22 +0000</pubDate>
		<dc:creator>bion</dc:creator>
				<category><![CDATA[2Checkout Blog]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.2checkout.com/community/?p=2715</guid>
		<description><![CDATA[This week, we move on from creating our secure network and start to develop a system to monitor the network, alert us if there is any suspicious activity, and regularly test our security procedures. We have moved on to two parts of PCI compliance that need to continue through the life of our company. These [...]]]></description>
			<content:encoded><![CDATA[<p>This week, we move on from creating our secure network and start to develop a system to monitor the network, alert us if there is any suspicious activity, and regularly test our security procedures. We have moved on to two parts of PCI compliance that need to continue through the life of our company. These categories are more involved both technically and administratively than requirements that we looked at in past weeks. These requirements address the fact that as new applications, operating systems, and technology develops, new ways around existing security measures will also develop.</p>
<p><em><strong>Requirement 10: Track and monitor all access to network resources and cardholder data<br />
Requirement 11: Regularly test security systems and processes </strong></em></p>
<p><span id="more-2715"></span>The reason we need to have individual logins mentioned in last week&#8217;s article is so that we can limit, monitor, and track access to network resources and cardholder data. In the event of a security breach, these records allow us to find whose account was used to compromise the data and mitigate the damage done to our customers. We need to audit all accesses to customer data, review audit logs each day, and be able to reconstruct events that touch cardholder information. We also need to be able to provide detailed audit trails for all administrative events. An attempt to change system configuration for malicious purposes will be captured and can be traced back to the user. A <a href="http://howto.techworld.com/applications/843/how-to-implement-central-logging/">central logging solution</a> along with the <a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part5">policies we developed previously</a> will allow us to track internal access to our network and record actions that take place.</p>
<p>Auditing of network access attempts and tracking of access logs is a critical aspect of this requirement. Most operating systems have very basic utilities that monitor and record events. For the most part, the event browsing and filtering capabilities provided by these utilities are restricted and will not meet PCI standards. For instance, unauthorized access to a customer&#8217;s information will not, by default, alert anyone that the event has been logged, it will only be discovered later when someone does an audit. Because of these limitations, we will need to look for some companies to provide us with some assistance.</p>
<p>Thankfully, we can find a number of <a href="http://www.webopedia.com/TERM/s/security_information_management.html">Security Information Management</a> (SIM) products that maintain comprehensive log management. These tools can automate collecting data, issue needed alerts, and give very detailed reports. SIMs will will also help give us a baseline of normal network activity. We can use this information to establish rules to categorise events. When an event happens that falls outside of these rules a SIM can trigger an alert letting us know of potential security violations. Many security information management products also provide default rule sets that classify events according to PCI requirements.</p>
<p>Now we need to plan to test our network and security measures at least once each year. It is important to note that we cannot use actual customer data for these tests. While your computer may be safe now, new ways to compromise your computer and <a href="http://cve.mitre.org/cve/index.html">new vulnerabilities</a> are constantly being developed or discovered. It is important to test your systems and your network to make sure your customers&#8217; information is as safe as it can be. This is not the same as testing new applications as <a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-4">discussed previously</a>.</p>
<p>When it comes to scanning our systems for vulnerabilities, we need to use the right tools and techniques to expose vulnerabilities in devices on both wired and wireless networks. There are a number of <a href="http://www.itgi.org/Template.cfm?Section=Home&amp;CONTENTID=19745&amp;TEMPLATE=/ContentManagement/ContentDisplay.cfm">security risks linked to wireless devices</a>, weak encryption methods, and the lack of employee security awareness. Therefore, we need to test everything that touches customer information &#8211; from how easily our network can be compromised to how we access the data. The Payment Card Industry requires that we have a &#8220;PCI approved&#8221; company perform an external scan of our system to determine our general safety.</p>
<p>It is important that our software and hardware gets regularly patched with the latest security updates. In addition to the regular patching process, our network and applications can be protected from security threats by the consistent use of <a href="http://en.wikipedia.org/wiki/Vulnerability_scanner">vulnerability scanners</a> that can see all of the applications and devices on the network, identify vulnerabilities, and supply information to resolve these vulnerabilities. However, scanning our network will not reveal every potential vulnerability. To be aware of our ability to detect and counter any unwanted access to our systems, we need to perform a <a href="http://www.penetration-testing.com/">penetration test</a> that measures how well we can respond to and withstand an attack. This test exploits vulnerabilities so we can determine the actual risk to our specific system of any particular vulnerabilities. PCI requires an annual external penetration test. This test is in addition our regular scanning and audits of our security logs.</p>
<p>To comply with these particular PCI requirements, we will need to provide some financial investment in a Security Management System and a vulnerability scanner. We will also need to invest time finding a specialist to perform a penetration test correctly. Thankfully, we decided to  have our firewall and software applications automatically update with security fixes. This lets us be sure that what we are testing is the most up-to-date security for our particular system.</p>
<p><strong>Costs:</strong></p>
<p>Central Logging Solution &#8211; Starts $5,000<br />
Security Information Management &#8211; I found many companies willing to offer quotes, but no baseline costs.<br />
Quarterly external scan &#8211; As above, due to the complexity and variety of networks, pricing will be highly varied<br />
Vulnerability Scanner &#8211; Roughly $1,200 per year<br />
External penetration tests minimum $10,000 per year, likely much more than that</p>
<p><strong>Further Reading:</strong></p>
<p><a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-1">Clearing the Mystery of PCI Compliance (Part 1)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/e-commerce/clearing-the-mystery-of-pci-compliance-part-2">Clearing the Mystery of PCI Compliance (Part 2)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-3">Clearing the Mystery of PCI Compliance (Part 3)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-4">Clearing the Mystery of PCI Compliance (Part 4)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part5">Clearing the Mystery of PCI Compliance (Part 5)</a><br />
Clearing the Mystery of PCI Compliance (Part 7) <em>Coming Soon</em></p>
<div><a href="http://www.addthis.com/bookmark.php" onclick="window.open('http://www.addthis.com/bookmark.php?pub=&amp;url=http%3A%2F%2Fwww.2checkout.com%2Fcommunity%2Fblog%2F2checkout-blog%2Fclearing-the-mystery-of-pci-compliance-part6&amp;title=Clearing+the+Mystery+of+PCI+Compliance+%28Part6%29', 'addthis', 'scrollbars=yes,menubar=no,width=620,height=520,resizable=yes,toolbar=no,location=no,status=no'); return false;" title="Bookmark using any bookmark manager!" target="_blank"><img src="https://secure.addthis.com/button1-bm.gif" width="125" height="16" border="0" /></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part6/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clearing the Mystery of PCI Compliance (Part5)</title>
		<link>http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part5</link>
		<comments>http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part5#comments</comments>
		<pubDate>Fri, 04 Dec 2009 14:14:55 +0000</pubDate>
		<dc:creator>bion</dc:creator>
				<category><![CDATA[2Checkout Blog]]></category>
		<category><![CDATA[credit card]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.2checkout.com/community/?p=2661</guid>
		<description><![CDATA[Over the past four weeks we have been taking a look at becoming PCI compliant. We have set up our network, we are encrypting customer&#8217;s data, Our anti-virus program is installed and updated, and we are taking steps to make sure our network and software is secure. I feel good about this, and I think [...]]]></description>
			<content:encoded><![CDATA[<p>Over the past four weeks we have been taking a look at becoming <a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml">PCI compliant</a>. We have set up our <a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-1">network</a>, we are <a href="http://www.2checkout.com/community/blog/2checkout-blog/e-commerce/clearing-the-mystery-of-pci-compliance-part-2">encrypting customer&#8217;s data</a>, Our anti-virus program is <a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-3">installed and updated</a>, and we are taking steps to make sure our <a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-4">network and software is secure</a>. I feel good about this, and I think we have learned some useful information. Now, we will <a href="http://www.pci-portal.com/knowledge-centre/pci-control-objectives/access-control-measures/">Implement Strong Access Control Measures</a>:</p>
<ol>
<li><strong>Requirement 7: Restrict access to cardholder data by business need-to-know</strong></li>
<li><strong>Requirement 8: Assign a unique ID to each person with computer access</strong></li>
<li><strong>Requirement 9: Restrict physical access to cardholder data</strong></li>
</ol>
<p>Here we look over who has access to customer&#8217;s information and the computers that store this information. Like many people starting an Internet business, our business computer is also used for recreation. This can pose a problem if friends or family also use our computer. The safest measure is to have a dedicated system used for processing and storing cardholder information. Let&#8217;s look at using our existing computer and how we can make this compliant.</p>
<p><span id="more-2661"></span>We need to investigate who needs access to customer information. In our example, I will be the only one who needs to access customer information, so it will be simple. In some cases we may have a business partner or, if we expand as I hope, an employee or two. These people will probably need some access to customer information, so we need to figure out who needs what data to perform their job. The person answering customer service questions may need to know our customer&#8217;s name and address, but do they need to know any part of the credit card number? What information will be needed for accounting or systems administration? This is the time to decide who has access to what information. We need to record these policies and keep written authorization for individual access to specific data.</p>
<p>While we have reason to be aware of external threats, we need to be just as secure internally. We need a system of <a href="http://www.intranetjournal.com/articles/200311/ij_11_10_03a.html">access control</a> that identifies which users have access to information, systems, resources, and which identifies the user who accessed or changed the information. This allows us to protect our customers&#8217; data from internal security leaks. Employee theft and fraud are very real crimes and Internet businesses are certainly not immune.</p>
<p>In order to be able to track who is accessing our resources, we need to assign unique logins for everyone who will use our computer. Using the access control we implemented above, these logins will allow different access to stored data. In our case, I have full access while other logins have no access (until I get a partner or employee). We can&#8217;t have any group or general logins. My initial idea of having a &#8220;Me&#8221; login with full access and a &#8220;You&#8221; login with no access will not work. Strict compliance means that each person who uses the computer needs to have a distinct username and password.</p>
<p>Speaking of passwords, we need to change the passwords every three months, a password cannot be reused for a year, the password needs to be at least seven characters long, and needs to a combination of numbers and letters (special characters increase the security of a password). Our passwords also need encrypted and we need to limit the number of user login attempts. Let&#8217;s set this to 5 attempted logins. If a login is failed 5 times we need to lock the username for at least 30 minutes, or administrator reset.</p>
<p>Physical access to credit card information needs to also be restricted and monitored. We need to have cameras recording any area that hold sensitive data, like our office. These recording need to be kept for a minimum of 3 months. Physical access to the office will need to be restricted. In our situation, we can use a locked door and a key. Access to the key will need to closely monitored and logged. Physical documentation of card holder data needs to be secured. This is independent of other security, so a safe or locked file cabinet. When the information is not needed for business purposes, it must be destroyed. Paper shredders are probably the most common and safest method of destroying the documents, but burning and pulping the data is compliant. Electronic data will need to be purged from our systems as well.</p>
<p>As we work on this portion of PCI DSS compliance, I found that we are making a number of small purchases to meet the requirements. There are a number of companies that sell computer access control programs for a reasonable amount of money for one or two computers. The larger expenses are going to be a new key less lock for the office door, a closed circuit camera set, a file cabinet. I guess I&#8217;m off to the local office supply store.</p>
<p><em><strong>Bottom Line for Step 5:</strong></em></p>
<p><strong>Cost:</strong></p>
<ul>
<li>Key less locks $200-$350</li>
<li>Locking file cabinets $200-$500</li>
<li>Camera system with 3 month storage $300-$600</li>
<li>Security software $50-$75 per computer renewed each year.</li>
</ul>
<p><strong><br />
</strong></p>
<p><strong>Further Reading:</strong></p>
<p><a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-1">Clearing the Mystery of PCI Compliance (Part 1)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/e-commerce/clearing-the-mystery-of-pci-compliance-part-2">Clearing the Mystery of PCI Compliance (Part 2)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-3">Clearing the Mystery of PCI Compliance (Part 3)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-4">Clearing the Mystery of PCI Compliance (Part 4)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part6">Clearing the Mystery of PCI Compliance (Part 6)</a><br />
Clearing the Mystery of PCI Compliance (Part 7) <em>Coming Soon</em></p>
<div><a href="http://www.addthis.com/bookmark.php" onclick="window.open('http://www.addthis.com/bookmark.php?pub=&amp;url=http%3A%2F%2Fwww.2checkout.com%2Fcommunity%2Fblog%2F2checkout-blog%2Fclearing-the-mystery-of-pci-compliance-part5&amp;title=Clearing+the+Mystery+of+PCI+Compliance+%28Part5%29', 'addthis', 'scrollbars=yes,menubar=no,width=620,height=520,resizable=yes,toolbar=no,location=no,status=no'); return false;" title="Bookmark using any bookmark manager!" target="_blank"><img src="https://secure.addthis.com/button1-bm.gif" width="125" height="16" border="0" /></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part5/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clearing the Mystery of PCI Compliance (Part 4)</title>
		<link>http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-4</link>
		<comments>http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-4#comments</comments>
		<pubDate>Thu, 26 Nov 2009 21:29:42 +0000</pubDate>
		<dc:creator>bion</dc:creator>
				<category><![CDATA[2Checkout Blog]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.2checkout.com/community/?p=2603</guid>
		<description><![CDATA[Last week we looked at Anti-Virus(AV) software. This provides us with a reasonable level of protection so that we can protect our customers’ information. However, new threats are always being released and we need to make sure we keep updated on the latest virus or new security threat. We also need to have a place [...]]]></description>
			<content:encoded><![CDATA[<p>Last week we looked at Anti-Virus(AV) software. This provides us with a reasonable level of protection so that we can protect our customers’ information. However, new threats are always being released and we need to make sure we keep updated on the latest virus or new security threat. We also need to have a place to test out software and hardware updates, as well as a place to try new shopping carts, or new pieces of code that will make our business more efficient, profitable, or just easier. Let&#8217;s take a look at the <a href="https://www.pcisecuritystandards.org/">PCI Requirements</a> on how to develop and maintain secure systems and applications.</p>
<p><span id="more-2603"></span>First, we need to make sure that our computers, firewall, and any other devices we have are all updated with vendor-supplied security patches. We also need to make sure that we install any future updates within one month of release. In our example, we have agreed to a contract with our firewall  and anti-virus manufacturers for a years worth of free updates. Our web browser and operating systems will also provide us with security updates. So this is already covered. Good thing we think ahead! It is our responsibility to make sure we are aware of new security threats and take steps to counter them. It isn&#8217;t a good idea to rely on one source of information, one example of a free threat alert is from <a href="http://www.securityfocus.com/">Bugtraq</a>. Your anti-virus vendor should also provide you with updated threat reports. There are others, and I recommend checking at least two alerts every day.</p>
<p>Now, we need to make sure that our new updates, or any other new applications for that matter, will work on our network. Unless you are comfortable working on your network alone, you will need to hire a system admin for this. We need to have a completely separate environment to develop and test all security patches and system and software configuration changes before deployment. We need this separation because we cannot use or endanger our customers&#8217; information. If a new piece of code for our shopping cart ends up being a security risk, it&#8217;s best to find that out before our customers use it. So, separate environments for all development, new programs, everything except processing the live sales.</p>
<p>After <a href="http://pcidssfaq.org/forum/forumdisplay.php?f=7">testing the updates, creating a back out plan and verification process</a> (assuming they all work with no security risks) we are ready to move them over into the &#8220;live&#8221; environment. While you have your network admin available you will want to establish a variety of procedures for when you need to make changes using your new development environment. Essentially, you need documentation stating what is being developed/tested, who recommended the development, and what testing is being done to make sure it&#8217;s safe.</p>
<p>If we develop or use web software and applications we need to make sure they are based on secure coding guidelines such as the <a href="http://www.owasp.org/index.php/Category:OWASP_Project">Open Web Application Security Project</a> guidelines. We have to review custom application code to identify coding vulnerabilities for each new piece of code or application we use/update. This requirement also covers the prevention of common coding vulnerabilities in software development such as buffer overflows, improper error handling, insecure storage, and the dread denial of service. This is by no means a <a href="http://www.pciforum.us/pci/Requirement6/tabid/91/Default.aspx">complete lis</a>t of what we need to cover, but it gives a good place to start.</p>
<p>I have already established my limited knowledge regarding networking, so I looked for estimates on how long it will take for a network admin to complete this project. Unfortunately, different networks and needs make estimating this job particularly difficult. The minimum estimation I have is roughly 60 hours, but they can easily go as high as 300 &#8211; 500 hours.</p>
<p>Now that we have our network protected with AV software and a testing/development environment to make sure that everything is secure for our customers, we should be just about finished meeting the PCI standards. Well, we are half way through &#8211; the end is in sight.</p>
<p><strong>Bottom Line for Steps 5 and 6:</strong></p>
<p><strong>Time:</strong><br />
Networking &#8211; 100 &#8211; 500 hours</p>
<p><strong>Cost:</strong><br />
Business level Anti-Virus Software: $500-$700 (Includes one year&#8217;s worth of updates)<br />
Network Admin $1,000 &#8211; $5,000 minimum. People who specialize in PCI Compliance often charge $250+ each hour of work.</p>
<p><strong>Further Reading:</strong></p>
<p><a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-1">Clearing the Mystery of PCI Compliance (Part 1)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/e-commerce/clearing-the-mystery-of-pci-compliance-part-2">Clearing the Mystery of PCI Compliance (Part 2)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-3">Clearing the Mystery of PCI Compliance (Part 3)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part5">Clearing the Mystery of PCI Compliance (Part 5)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part6">Clearing the Mystery of PCI Compliance (Part 6)</a><br />
Clearing the Mystery of PCI Compliance (Part 7) <em>Coming Soon</em></p>
<div><a href="http://www.addthis.com/bookmark.php" onclick="window.open('http://www.addthis.com/bookmark.php?pub=&amp;url=http%3A%2F%2Fwww.2checkout.com%2Fcommunity%2Fblog%2F2checkout-blog%2Fclearing-the-mystery-of-pci-compliance-part-4&amp;title=Clearing+the+Mystery+of+PCI+Compliance+%28Part+4%29', 'addthis', 'scrollbars=yes,menubar=no,width=620,height=520,resizable=yes,toolbar=no,location=no,status=no'); return false;" title="Bookmark using any bookmark manager!" target="_blank"><img src="https://secure.addthis.com/button1-bm.gif" width="125" height="16" border="0" /></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-4/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clearing the Mystery of PCI Compliance (Part 3)</title>
		<link>http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-3</link>
		<comments>http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-3#comments</comments>
		<pubDate>Fri, 20 Nov 2009 14:14:45 +0000</pubDate>
		<dc:creator>bion</dc:creator>
				<category><![CDATA[2Checkout Blog]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[credit card]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[policy]]></category>

		<guid isPermaLink="false">http://www.2checkout.com/community/?p=2556</guid>
		<description><![CDATA[We are at the half-way mark in becoming PCI Compliant. We took a little break for Fraud Awareness Week and now we are ready to &#8220;Maintain a Vulnerability Management System&#8221;. Our previous efforts have been focused on Building and Maintaining a Secure Network and Protecting Cardholder Data. We now have a firewall, clear policies regarding [...]]]></description>
			<content:encoded><![CDATA[<p>We are at the half-way mark in becoming <a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml">PCI Compliant</a>. We took a little break for <a href="http://www.2checkout.com/community/blog/knowledge-base/suppliers/fraud-bank-assisted-disputes-chargebacks/international-fraud-awareness-week-november-8-14-2009">Fraud Awareness Week</a> and now we are ready to &#8220;Maintain a Vulnerability Management System&#8221;. Our previous efforts have been focused on <a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-1">Building and Maintaining a Secure Network</a> and <a href="http://www.2checkout.com/community/blog/2checkout-blog/e-commerce/clearing-the-mystery-of-pci-compliance-part-2">Protecting Cardholder Data</a>. We now have a firewall, clear policies regarding the type of information we will store, and the length of time we will store it. We even have encryption software and an <a href="http://www.webopedia.com/TERM/S/SSL.html">SSL</a> certificate. Congratulations!</p>
<p>Now, we need to Maintain a Vulnerability Management Program. This comes in two parts. First, we need to use and regularly update anti-virus software. Then, we have to develop and maintain secure systems and applications. I know what anti-virus software is, so let&#8217;s start there.</p>
<p><a href="http://www.pcworld.com/businesscenter/article/172438/pci_survey_finds_some_merchants_dont_use_antivirus_software.html"><span id="more-2556"></span>Before we look into AV software</a>, I want to give one bit of basic Internet advice. If you don&#8217;t know/trust a person or site &#8211; don&#8217;t download ANYTHING they send you if you don&#8217;t have AV protection. <a href="http://www.pc1news.com/news/0544/how-you-catch-a-computer-virus.html">The most common method of catching a computer virus is still from opened email attachments</a>. Most people have some anti-virus (AV) protection for their computers, but to be PCI compliant, we need to look into software that will protect every computer and device connected to the Internet through our network.</p>
<p>There are a number of companies that make anti-virus software, compile virus databases, and offer frequent updates. Most of these companies have PCI compliant versions of their software. The standard single-PC software will cost $50 &#8211; $75 for a year&#8217;s worth of automatic updates. Unfortunately, this level of protection, while typically excellent for home users, will not meet PCI compliance. Part of the reason for this is that PCI compliance requires that your AV software be able to monitor and generate reports detailing what viruses it has caught/contained. We need to look at the more robust offerings for business networks. The range of prices in this field is vast from $350 &#8211; nearly $3,000 yearly. The top end software is really more of an anti-virus &#8220;system&#8221; that protects mainframes and large networks, so we can breathe a sigh of relief and look a little lower on the price points. For covering a network with a few devices for one year, including unlimited updates, and support, the average cost settles in at about $500-$700.</p>
<p>The next standard, &#8220;Develop and Maintain Secure Systems and Applications&#8221;, requires a little more than picking anti-virus software that will meet your needs. Looking at the <a href="http://www.pciforum.us/pci/Requirement6/tabid/91/Default.aspx">requirements</a> to meet this standard, it becomes obvious that we either need to know our way around a network, or we need to get our networking expert back to test our network after each update, make sure that we have a separate part of the network used only for testing applications, and system monitors that watch our network. Because of the scope of this requirement, the next article will be devoted to addressing the various aspects of maintaining the security of our systems and applications.</p>
<p><strong>Further Reading:</strong></p>
<p><a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-1">Clearing the Mystery of PCI Compliance (Part 1)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/e-commerce/clearing-the-mystery-of-pci-compliance-part-2">Clearing the Mystery of PCI Compliance (Part 2)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-4">Clearing the Mystery of PCI Compliance (Part 4)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part5">Clearing the Mystery of PCI Compliance (Part 5)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part6">Clearing the Mystery of PCI Compliance (Part 6)</a><br />
Clearing the Mystery of PCI Compliance (Part 7) <em>Coming Soon</em></p>
<div><a href="http://www.addthis.com/bookmark.php" onclick="window.open('http://www.addthis.com/bookmark.php?pub=&amp;url=http%3A%2F%2Fwww.2checkout.com%2Fcommunity%2Fblog%2F2checkout-blog%2Fclearing-the-mystery-of-pci-compliance-part-3&amp;title=Clearing+the+Mystery+of+PCI+Compliance+%28Part+3%29', 'addthis', 'scrollbars=yes,menubar=no,width=620,height=520,resizable=yes,toolbar=no,location=no,status=no'); return false;" title="Bookmark using any bookmark manager!" target="_blank"><img src="https://secure.addthis.com/button1-bm.gif" width="125" height="16" border="0" /></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-3/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clearing the Mystery of PCI Compliance (Part 2)</title>
		<link>http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-2</link>
		<comments>http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-2#comments</comments>
		<pubDate>Fri, 30 Oct 2009 16:42:12 +0000</pubDate>
		<dc:creator>bion</dc:creator>
				<category><![CDATA[2Checkout Blog]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.2checkout.com/community/?p=2305</guid>
		<description><![CDATA[Last week I wrote an article detailing how to comply with the first two PCI DSS Standards. In this article, I will show what is involved in complying with the two requirements in the &#8220;Protect Cardholder Data&#8221; standard.
Requirement 3: Protect stored cardholder data
Requirement 4: Encrypt transmission of cardholder data across open, public networks
We have provided [...]]]></description>
			<content:encoded><![CDATA[<p>Last week I wrote an <a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-1">article</a> detailing how to comply with the first two <a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml">PCI DSS Standards</a>. In this article, I will show what is involved in complying with the two requirements in the &#8220;Protect Cardholder Data&#8221; standard.</p>
<p><strong>Requirement 3: Protect stored cardholder data<br />
Requirement 4: Encrypt transmission of cardholder data across open, public networks</strong></p>
<p>We have provided a secure network to collect and store our customer&#8217;s information. Now, we need to turn our attention to the data itself. To fulfill requirement 3, we need to come up with a policy detailing how we will store card holder data. This sounds easy enough, just make a few decisions and stick with them. However, this is actually a bit more complicated as the <a href="http://pcidssfaq.org/forum/forumdisplay.php?f=4">PCI-DSS FAQ</a> explains. There are 20 different criteria to meet. While I suggest reading the linked FAQ some highlights are:</p>
<ul>
<li>3.1 Keep cardholder data storage to a minimum.</li>
<li>3.2 Do not store sensitive authentication data after authorization (even if encrypted).</li>
<li>3.2.3 Do not store the personal identification number (PIN) or the encrypted PIN block.</li>
<li>3.3 Mask PAN (Personal Account Number) when displayed (the first six and last four digits are the maximum number of digits to be displayed).</li>
</ul>
<p><span id="more-2305"></span>I have to admit, after reading what is involved with this portion of PCI compliance, I nearly gave up. This part of PCI compliance doesn&#8217;t really have a cost that can easily be measured in money. The cost is in time &#8211; hours and hours of time spent looking over what information is stored, where it is stored, how long it should be stored, what systems are used to backup that data, etc. it gets exhausting.</p>
<p>As you become familiar with the standard, you will need to figure out what data you must keep on hand and how long would be a reasonable amount of time to keep that data. The longer you keep the data, the more risky and potentially costly it becomes in the unfortunate event the data becomes compromised. Generally, to comply with requirement 3, you need to understand that all information you collect from your customers must be protected. This means that you can only store a limited amount of the data, and the data you do store must be encrypted (see below).  A simple overview of the requirements for card data storage encryption can be found <a href="http://pcianswers.com/2007/05/01/encryption-for-pci-compliance/">here</a>.</p>
<p>Requirement 4 is a little more straightforward. While most people recognize the need to encrypt sensitive information during transmission over networks that are easily accessed by malicious individuals, few recognize the importance of encrypting information sent between back-end systems. This also means that stored information needs to also be encrypted.</p>
<p><a href="http://www.webopedia.com/term/e/encryption.html">Encryption</a> is the most effective way to achieve data security by translating data into a secret code. Essentially, both stored and transmitted data must be made unreadable. The most common method used by credit card processors to protect high speed transactions is a network security protocol called <a href="http://www.webopedia.com/TERM/S/SSL.html">Secure Socket Layer(SSL)</a>.</p>
<p>To get an SSL certificate you will first need to choose a certificate that matches your specific needs. Then you need to generate a Certificate Signing Request (CSR) for the site. For example, I found a <a href="http://www.ssl247.com/ssl-certificate-signing-solutions/ssl-certificates/extended-validation.php">site selling </a>a certificate for a single domain for $600.00/year. This is on the low end for SSL pricing considering that it comes with a warranty, re-issuance, and provides features I like (priority phone support and regular security audits). I should also note this is a <a href="http://www.2checkout.com/community/blog/2checkout-blog/2checkout-turns-to-loyal-customer-for-ssl-certification">2Checkout supplier</a>.</p>
<p>If someone were to access our network from the previous article, we want to have protections in place that both limit their access to our customer&#8217;s information and makes any information they may access unreadable. Complying with the second set of requirements provides another layer of security for our customers.</p>
<p><strong><em>Bottom Line for Step 2</em></strong></p>
<p><strong>Time:</strong><br />
Hours and hours &#8211; Literally HOURS and HOURS</p>
<p><strong>Cost:</strong><br />
SSL Certificate: $250-$700+/ year</p>
<p><strong>Further Reading:</strong></p>
<p><a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-1">Clearing the Mystery of PCI Compliance (Part 1)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-3">Clearing the Mystery of PCI Compliance (Part 3)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-4">Clearing the Mystery of PCI Compliance (Part 4)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part5">Clearing the Mystery of PCI Compliance (Part 5)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part6">Clearing the Mystery of PCI Compliance (Part 6)</a><br />
Clearing the Mystery of PCI Compliance (Part 7) <em>Coming Soon</em></p>
<div><a href="http://www.addthis.com/bookmark.php" onclick="window.open('http://www.addthis.com/bookmark.php?pub=&amp;url=http%3A%2F%2Fwww.2checkout.com%2Fcommunity%2Fblog%2F2checkout-blog%2Fclearing-the-mystery-of-pci-compliance-part-2&amp;title=Clearing+the+Mystery+of+PCI+Compliance+%28Part+2%29', 'addthis', 'scrollbars=yes,menubar=no,width=620,height=520,resizable=yes,toolbar=no,location=no,status=no'); return false;" title="Bookmark using any bookmark manager!" target="_blank"><img src="https://secure.addthis.com/button1-bm.gif" width="125" height="16" border="0" /></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-2/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clearing the Mystery of PCI Compliance (Part 1)</title>
		<link>http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-1</link>
		<comments>http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-1#comments</comments>
		<pubDate>Fri, 23 Oct 2009 22:20:38 +0000</pubDate>
		<dc:creator>bion</dc:creator>
				<category><![CDATA[2Checkout Blog]]></category>
		<category><![CDATA[credit card]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.2checkout.com/community/?p=2157</guid>
		<description><![CDATA[This is the first is a twelve-part series detailing what is involved with PCI compliance. Earlier, Warner gave a very good overview of PCI DSS compliance.
&#8220;PCI DSS (Payment Card Industry Data Security Standard) is a security standard that applies to companies handling credit card numbers. The PCI level of enforcement differs based on the volume [...]]]></description>
			<content:encoded><![CDATA[<p>This is the first is a twelve-part series detailing what is involved with PCI compliance. Earlier, Warner gave a <a href="http://www.2checkout.com/community/blog/2checkout-blog/small-ecommerce-sites-facing-fines-if-compromised">very good overview </a>of PCI DSS compliance.</p>
<blockquote><p>&#8220;PCI DSS (<a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml">Payment Card Industry Data Security Standard</a>) is a security standard that applies to companies handling credit card numbers. The <a href="http://usa.visa.com/merchants/risk_management/cisp_merchants.html">PCI level of enforcement</a> differs based on the volume of transactions that a company handles.&#8221;</p></blockquote>
<p>My purpose with this series is to provide the details involved in each requirement. I want to look at this from the point of view of a very small home-based business with a website selling tangible products.</p>
<p><span id="more-2157"></span>The first requirement for PCI DSS is to have a secure environment to hold credit card data:</p>
<p><strong>1) Install and maintain a firewall configuration to protect cardholder data<br />
2) Do not use vendor-supplied defaults for system passwords and other security parameters</strong></p>
<p>First, we need to make our connection to the Internet as safe and secure as we can. This involves using a  form of protection. The most common example of this is a <a href="http://www.techterms.com/definition/firewall">firewall</a>. A <a href="http://www.techterms.com/definition/router">router</a> is probably the most common device used. This will protect a network from unauthorized connections as well as keep a log of network activity.</p>
<p>A basic home use router can cost roughly $50-100+. However, as we will see in future articles in this series, these routers will not be able to provide the level of protection required to collect customer information. Based on my research, the cost of a compliant router starts at about $200 and can run into the thousands of dollars. There are significant differences between routers, and some of the more costly routers come with additional security packages from the manufacturer that includes network/technical support. Researching what router is going to work for your business is important. The firewall you choose will depend on a number of factors that only you can determine. It is important to note that laptops require a separate security device when used away from the home, and Internet cafe&#8217;s will not have nearly the security required for PCI DSS compliance.</p>
<p>Along with the router, we will need to have it connected to the network. Networking is a highly specialized, highly technical field. When was the last time you could remember terms like &#8220;internal IP address,&#8221; &#8220;network diagram,&#8221; and &#8220;network segmentation&#8221;  used in casual conversation? Since this is something that is critical to the ability to process credit cards, we want to be sure that the router (and the rest of the network) is as secure as it can be. This means we will have to pay someone who can create and manage the network. Thankfully, there are a number of people who are willing to do so. Alternately, at an additional cost, most router manufacturers will provide support and security update services. The cost for an independent networking freelancer will vary greatly from area to area (In my case, I would need to make sure I had $800-$1,000 to cover this expense).</p>
<p>Once we have the network all set up we will have to reset the username and password of the firewall. During the initial setup and testing, the device will have a preset password and username. This allows for easy troubleshooting for the manufacturer&#8217;s technical support. Since all of the devices by one manufacturer will have the same defaults, it is very important that this is changed before credit cards are accepted.</p>
<p><em><strong>Bottom Line for Step 1:</strong></em></p>
<p><strong>Time:</strong></p>
<ul>
<li> Research on the best firewall for your individual needs.</li>
<li> Research on availability of either manufacturer-provided or independent networking assistance</li>
</ul>
<p><strong>Costs:</strong></p>
<ul>
<li> Router: $200 &#8211; $3000 for the router. ($500-$800 is the average for the device alone)</li>
<li> Support: Additional security features/support (varies from company to company, $200 seems average)</li>
<li> Networking: Free if you already know how to do this.</li>
<li> $1,000 &#8211; $149 basic charge with $100/hour fee for additional support  (Varies from place to place, but $100 looks to be the low end of average) assuming a full day&#8217;s work minimum.</li>
</ul>
<p>We have just bought a router, hired someone to make sure our network is secure and spent roughly $1,000-$2,000. Now we have 10 more standards to meet before we are PCI compliant. Over the next few weeks we will explore topics ranging from data encryption to network monitoring, as well as realistically detail the costs associated with meeting all twelve PCI standards.</p>
<p><strong>Further Reading:</strong></p>
<p><a href="http://www.2checkout.com/community/blog/2checkout-blog/e-commerce/clearing-the-mystery-of-pci-compliance-part-2">Clearing the Mystery of PCI Compliance (Part 2)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-3">Clearing the Mystery of PCI Compliance (Part 3)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-4">Clearing the Mystery of PCI Compliance (Part 4)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part5">Clearing the Mystery of PCI Compliance (Part 5)</a><br />
<a href="http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part6">Clearing the Mystery of PCI Compliance (Part 6)</a><br />
Clearing the Mystery of PCI Compliance (Part 7) <em>Coming Soon</em></p>
<div><a href="http://www.addthis.com/bookmark.php" onclick="window.open('http://www.addthis.com/bookmark.php?pub=&amp;url=http%3A%2F%2Fwww.2checkout.com%2Fcommunity%2Fblog%2F2checkout-blog%2Fclearing-the-mystery-of-pci-compliance-part-1&amp;title=Clearing+the+Mystery+of+PCI+Compliance+%28Part+1%29', 'addthis', 'scrollbars=yes,menubar=no,width=620,height=520,resizable=yes,toolbar=no,location=no,status=no'); return false;" title="Bookmark using any bookmark manager!" target="_blank"><img src="https://secure.addthis.com/button1-bm.gif" width="125" height="16" border="0" /></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.2checkout.com/community/blog/2checkout-blog/clearing-the-mystery-of-pci-compliance-part-1/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Small eCommerce Sites Facing Fines if Compromised</title>
		<link>http://www.2checkout.com/community/blog/2checkout-blog/small-ecommerce-sites-facing-fines-if-compromised</link>
		<comments>http://www.2checkout.com/community/blog/2checkout-blog/small-ecommerce-sites-facing-fines-if-compromised#comments</comments>
		<pubDate>Wed, 09 Sep 2009 15:25:45 +0000</pubDate>
		<dc:creator>warner</dc:creator>
				<category><![CDATA[2Checkout Blog]]></category>
		<category><![CDATA[E-Commerce]]></category>
		<category><![CDATA[business]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[ecommerce]]></category>
		<category><![CDATA[fines]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.2checkout.com/community/?p=1937</guid>
		<description><![CDATA[PCI DSS (Payment Card Industry Data Security Standard) is a security standard that applies to companies handling credit card numbers.  The PCI level of enforcement differs based on the volume of transactions that a company handles.  The lowest level is level 4, which applies to eCommerce sites processing less than 20,000 transactions annually. [...]]]></description>
			<content:encoded><![CDATA[<p>PCI DSS (<a href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml">Payment Card Industry Data Security Standard</a>) is a security standard that applies to companies handling credit card numbers.  The <a href="http://usa.visa.com/merchants/risk_management/cisp_merchants.html">PCI level of enforcement</a> differs based on the volume of transactions that a company handles.  The lowest level is level 4, which applies to eCommerce sites processing less than 20,000 transactions annually.  The highest and most stringent is PCI level 1, which applies to merchants processing over 6 million transactions a year.  Ultimately, the goal is to increase security for all Web sites accepting payment via credit card.  2Checkout completes an annual audit for PCI compliance, which we take pride in maintaining consistently.</p>
<p>Level 4 merchants are typically subject to completing an annual self-assessment questionaire, which contains approximately 220 questions.  Furthermore, annual external quarterly scans are a common requirement.  The exact requirements are typically set by the merchants’ bank.</p>
<p>Smaller eCommerce sites that have credit cards compromised can be fined between $20 and $30 dollars per each stolen credit card up to $500,000 dollars.  Additionally, depending on the size of the breach, the site could be required to hiring an external forensic investigator.  The cost of an external audit typically begins around $10,000.</p>
<p>A <a href="http://www.ecommerce-guide.com/article.php/3837101">report</a> published recently by ECommerce-Guide.com identifies increased scrutiny that PCI Level 4 eCommerce sites are being subjected to.  </p>
<p>The cost of becoming PCI compliant can be substantial.  Especially if your Web site was not initially designed with security being a focus.  The requirements cover all aspects of business: technology utilized and how it is implemented as well as business processes and workflow.</p>
<p>Becoming a 2Checkout supplier can quickly enable PCI compliance for your eCommerce site, while keeping the cost of doing business lower in the long term.  A 2Checkout supplier will not be required to complete any PCI compliance forms.  No changes to your servers or business processes will be required!  This is one of the many areas where 2Checkout provides more value to you, our customers and suppliers.</p>
<p><em>Article was updated on 9/21/2009 clarifying requirements for “PCI Questionnaire A.”</em></p>
<p><em>Article was updated on 11/9/2009 to eliminate possible ambiguity in supplier obligations.</em></p>
<div><a href="http://www.addthis.com/bookmark.php" onclick="window.open('http://www.addthis.com/bookmark.php?pub=&amp;url=http%3A%2F%2Fwww.2checkout.com%2Fcommunity%2Fblog%2F2checkout-blog%2Fsmall-ecommerce-sites-facing-fines-if-compromised&amp;title=Small+eCommerce+Sites+Facing+Fines+if+Compromised', 'addthis', 'scrollbars=yes,menubar=no,width=620,height=520,resizable=yes,toolbar=no,location=no,status=no'); return false;" title="Bookmark using any bookmark manager!" target="_blank"><img src="https://secure.addthis.com/button1-bm.gif" width="125" height="16" border="0" /></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.2checkout.com/community/blog/2checkout-blog/small-ecommerce-sites-facing-fines-if-compromised/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Revisiting 2CO’s #1 Value Proposition:  Software-On-Demand</title>
		<link>http://www.2checkout.com/community/blog/2checkout-blog/revisiting-2checkout%e2%80%99s-1-value-proposition-software-on-demand</link>
		<comments>http://www.2checkout.com/community/blog/2checkout-blog/revisiting-2checkout%e2%80%99s-1-value-proposition-software-on-demand#comments</comments>
		<pubDate>Mon, 23 Mar 2009 16:57:58 +0000</pubDate>
		<dc:creator>vcleary</dc:creator>
				<category><![CDATA[2Checkout Blog]]></category>
		<category><![CDATA[E-Commerce]]></category>
		<category><![CDATA[PCI]]></category>

		<guid isPermaLink="false">http://www.2checkout.com/community/blog/2checkout-blog/revisiting-2checkout%e2%80%99s-1-value-proposition-software-on-demand/</guid>
		<description><![CDATA[Sometimes you luck out when a third party reminds the world of your company’s true value proposition.  This time the thanks goes to Internet Retailer.
According to a recent article on the rising popularity of software-on-demand products, “despite the economic downturn, providers of on-demand e-commerce technology platforms say they’re experiencing strong demand from retailers looking [...]]]></description>
			<content:encoded><![CDATA[<p>Sometimes you luck out when a third party reminds the world of your company’s true value proposition.  This time the thanks goes to Internet Retailer.</p>
<p>According to a <a href="http://www.internetretailer.com/dailyNews.asp?id=29562">recent article</a> on the rising popularity of software-on-demand products, “despite the economic downturn, providers of on-demand e-commerce technology platforms say they’re experiencing strong demand from retailers looking for a relatively quick and economical way to launch web sites&#8230;”   In other words, with the help of software-on-demand, many businesses that have excellent products, but lack the time and technical expertise to manage backend e-commerce technology, are turning to fast, automated solutions that will help them establish a web presence quickly and start selling.</p>
<p>In a nutshell, this is 2Checkout’s value proposition.  2CO’s e-commerce software-on-demand helps thousands of full-time and part-time business owners live their entrepreneurial dreams, by providing turnkey automation in the areas that matter most but are oftentimes the most difficult to manage.</p>
<p>Take PCI DSS as the perfect example.  <span id="more-730"></span>PCI DSS stands for <a href="https://www.pcisecuritystandards.org/">Payment Card Industry Data Security Standard</a>… a rather intimidating acronym.  Very few online retailers researching payment solutions for the first time realize that merchant account providers will require them to setup, run and maintain a separate, secure server to safely store customer data.  As a small business owner, when will you honestly have time to manage this?  2Checkout manages it for you &#8212; hence software-on-demand.</p>
<p>Look at fraud and chargebacks.  2Checkout’s sophisticated fraud mitigation service is dynamically designed and networked to stop criminals all over the world while allowing your honest customers quick passage through the examination process.  Private merchant accounts and some other web-based e-commerce services lack sophisticated fraud mitigation as part of their software-on-demand suite of features, placing the risk and responsibility solely on you.  Do you truthfully have time to examine each order?  2CO manages this for you!</p>
<p>These additional backend services, coupled with live and professional 24 hour customer care, and a selection of the most popular payment methods – Visa, MasterCard, Discover, Amex, PayPal, JCB, Diners Club, and E-Check are valued commodities to business owners.</p>
<p>So, if you lack the time to compare shopping carts, manage the fees and administrative affairs of a private credit card merchant account, and lack the technical knowledge to setup sophisticated systems that will block fraudulent charges and keep your customers’ personal information out of the hands of criminals, then 2Checkout is your answer.  2CO’s software-on-demand, e-commerce solution offers all of the most widely used payment methods while simplifying fees, setup, and everyday account maintenance to free you for more important tasks.  Now that’s on-demand!</p>
<div><a href="http://www.addthis.com/bookmark.php" onclick="window.open('http://www.addthis.com/bookmark.php?pub=&amp;url=http%3A%2F%2Fwww.2checkout.com%2Fcommunity%2Fblog%2F2checkout-blog%2Frevisiting-2checkout%25e2%2580%2599s-1-value-proposition-software-on-demand&amp;title=Revisiting+2CO%E2%80%99s+%231+Value+Proposition%3A++Software-On-Demand', 'addthis', 'scrollbars=yes,menubar=no,width=620,height=520,resizable=yes,toolbar=no,location=no,status=no'); return false;" title="Bookmark using any bookmark manager!" target="_blank"><img src="https://secure.addthis.com/button1-bm.gif" width="125" height="16" border="0" /></a></div>]]></content:encoded>
			<wfw:commentRss>http://www.2checkout.com/community/blog/2checkout-blog/revisiting-2checkout%e2%80%99s-1-value-proposition-software-on-demand/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
