Sirius Computer Solutions
|
|
|
800.460.1237
|
PCI DSS Compliance: The Deadline that Merchants Can’t Afford to Miss Print
» Register for What is PCI, and How to Be Compliant: A Special Web Event
Sirius and IBM Can Help You Become Compliant

Every company that accepts credit cards must be compliant by December 31, 2008
The Payment Card Industry Data Security Standard (PCI DSS) was the first set of requirements developed by the PCI Security Standards Council to enhance payment account data security. PCI DSS is a security standard that includes requirements for security management, policies, procedures, network architecture, software design and other critical protective measures.

Level 1 Merchants (companies with more than six million transactions per year) and Level 2 Merchants (companies with more than one million and less than six million transactions per year) were required to be PCI DSS compliant by December 31, 2007, but Level 3 Merchants (with 250,000 to one million transactions per year) have until December 31st, 2008 to become compliant. The fines for non-compliance by this date could be $5,000 to $25,000 per month, and the PCI industry might also increase the transaction fee.
Why Sirius for PCI?
Since 2006, Sirius has been an Approved Scanning Vendor (ASV), authorized by the PCI Security Standards Council to verify corporations as PCI compliant [Certificate #4119-01-03]. The PCI Security Standards Council defines the qualifications for ASVs and requires us to recertify every year. Sirius is the only national IBM Business Partner who is a Certified PCI Compliance Vendor and an IBM ISS Tier 1 Partner (ISS is Internet Security Systems™, acquired by IBM). In addition, we are a Cisco® Premier Partner with Advanced Security Specializations, Advanced Voice over IP Specializations, and Advanced Data Center Storage Networking capabilities. Only a handful of Cisco partners have these unique skills. These credentials allow Sirius to offer increased security solutions to clients of all sizes. With the December 31, 2008 deadline coming fast, the time to act is now, so we can help you obtain PCI Authorization before year-end.

PCI DSS requirements:

    Build and Maintain a Secure Network
  • Requirement 1: Install and maintain a firewall configuration to protect cardholder data
  • Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters Protect Cardholder Data
  • Requirement 3: Protect stored cardholder data
  • Requirement 4: Encrypt transmission of cardholder data across open, public networks


  • Maintain a Vulnerability Management Program
  • Requirement 5: Use and regularly update anti-virus software
  • Requirement 6: Develop and maintain secure systems and applications Implement Strong Access Control Measures
  • Requirement 7: Restrict access to cardholder data by business need-to-know
  • Requirement 8: Assign a unique ID to each person with computer access
  • Requirement 9: Restrict physical access to cardholder data


  • Regularly Monitor and Test Networks
  • Requirement 10: Track and monitor all access to network resources and cardholder data
  • Requirement 11: Regularly test security systems and processes


  • Maintain an Information Security Policy
  • Requirement 12: Maintain a policy that addresses information security

   



 

» Your Privacy | » Legal | » Site Map | » Contact Us | » Community | » Unsubscribe | » Employee Login/Logout


Sirius Computer Solutions