E-Commerce 2010: PCI (DSS) Compliance BoF
This October/December new regulations will take effect for businesses who accept credit cards online and off! Various new technical requirements for web servers and company computers to be PCI compliant.
I have done some research and am helping a client get PCI compliant so I canshare what I know, especially where to go, how much things have been costing in time and money.
This is a roundtable knowledge share and if others with experience can come to share more about this would be great.
Some highlights:
– Servers need to be audited every quarter.
– Anti-virus must be installed on servers & company computers.
– Password protected screens must auto-trigger on any company computer that stores financial/ordering/creditcard info. So the mail guy can’t steal someone’s credit card number while you’re in the bathroom.
– Changes in Apache (ETAGS, ServerSignature Off, etc.)
– and more.
- Login to post comments
Comments
Links from this BoF session
http://www.PCIsecuritystandards.org
http://www.PCIsecuritystandards.org/saq/
http://www.neospire.net/business.solutions/pci.dss.misconceptions.php
http://www.instacarma.com/blog/technical/pci-compliance
http://www.authorize.net/pcidss
http://www.paypal.com/pcicompliance
http://www.nessus.org (security scan tool)
Dave said...
The sentence from www.pcicomplianceguide.org is
“ALL PCI Level 4 merchants (new and existing) using third-party software must use validated applications. July 1, 2010”