• Schedule
  • Videos
  • About
  • Sponsors
  • News
  • Drupalchix
  • Attendees
  • Forums
  • FAQ
  • Contact Us
DrupalCamp LA 2010

E-Commerce 2010: PCI (DSS) Compliance BoF

Note: this is an archived site. Visit us at http://ladrupal.org.
40
Sign In
  • commerce
  • compliance
  • pci
  • Security
  • Advanced
  • Beginner
  • BoF (Birds of a Feather)
  • Business Side
  • Code & Development
  • Intermediate
  • Site Building
Logistics
Day: 
Sunday
Time: 
1:30p
Room: 
EH 1150
Duration: 
One hour
Link: 
https://www.pcisecuritystandards.org
Link: 
PCI DSS - PCI Security Standards Council
Link: 
screencast

This October/December new regulations will take effect for businesses who accept credit cards online and off! Various new technical requirements for web servers and company computers to be PCI compliant.

I have done some research and am helping a client get PCI compliant so I canshare what I know, especially where to go, how much things have been costing in time and money.

This is a roundtable knowledge share and if others with experience can come to share more about this would be great.

Some highlights:

– Servers need to be audited every quarter.
– Anti-virus must be installed on servers & company computers.
– Password protected screens must auto-trigger on any company computer that stores financial/ordering/creditcard info. So the mail guy can’t steal someone’s credit card number while you’re in the bathroom.
– Changes in Apache (ETAGS, ServerSignature Off, etc.)
– and more.

  • Login to post comments

Comments

Links from this BoF session

Submitted by Chris Charlton on Sun, 2010-08-08 13:22.

http://www.PCIsecuritystandards.org

http://www.PCIsecuritystandards.org/saq/

http://www.neospire.net/business.solutions/pci.dss.misconceptions.php

http://www.instacarma.com/blog/technical/pci-compliance

http://www.authorize.net/pcidss

http://www.paypal.com/pcicompliance

http://www.nessus.org (security scan tool)

  • Login to post comments

Dave said...

Submitted by Chris Charlton on Tue, 2010-08-10 08:20.

The sentence from www.pcicomplianceguide.org is

“ALL PCI Level 4 merchants (new and existing) using third-party software must use validated applications. July 1, 2010”

  • Login to post comments

About Chris Charlton

Full Name Chris Charlton

Company XTND.US

Link to web site http://xtnd.us

Interest Drupal Service Provider

View full user profile

Attendees

Filter Sessions

  • All Sessions
  • Your Picks
  • Business Side
  • Code & Development
  • Design & Usability
  • Drupalchix
  • Performance and Scalability
  • Showcase & Strategy
  • Site Building
  • Presenters (must read!)

Get our exclusive T-shirts at the camp for only $10 — or for $20 after the camp.

Get our DrupalCamp LA T-shirtGet our DrupalCamp LA T-shirt

T-shirts by Monstrositee with design by This by Them

Become a Sponsor

Attendees

View All

Drupalchix Information

View all Sponsors

  • News
  • FAQ
  • About LA Drupal
  • Become a Sponsor
  • Twitter
Designed and built by This By Them and the members of LA Drupal
Powered by Drupal | Copyright © 2009-2022
Graciously hosted by SoftLayer
LA Drupal on Facebook LA Drupal on LinkedIn LA Drupal on Twitter