 |
CISP - PCI DSS |
 |
|
|
|
|
|
CISP - PCI DSS Compliance for Small Business
Retailers

Article, Comment and Opinion - PCI DSS Compliance
November 28, 2006
by: James Childers - CEO ASG
james@iqbio.net
DISCLAIMER
Congratulations
and welcome to the world of small business eCommerce. The
Internet has greatly expanded the opportunities for small
businesses to thrive in the new economy and more entrepreneurs
are joining the ranks of the small business eCommerce community
every day. It is likely that a significant portion of your
revenue stream will result in credit card processing through the
telephone, fax or over your ecommerce enabled website.
There is substantial contingent liability if you do not comply
with the requirements for privacy of customers data.
If you accept credit cards in your business, you are
responsible for the integrity of the systems that collect,
record, maintain and distribute your customers private
information. Visa implemented a program called the
Cardholder Information Security Program (CISP) in June 2001,
CISP was intended to protect Visa cardholder data–wherever it
resides–ensuring that members, merchants, and service providers
maintain the highest information security standard.
In 2004, the entire credit card industry combined their
standards into what is now known as the Payment Card Industry (PCI)
Data Security Standard (DSS). Effective September 7, 2006,
this standard is having a dramatic impact on how small
businesses conduce face-to-face and ecommerce transactions, the
storage of private cardholder data and the integrity of their
networks.
"WAKEFIELD, Mass. Sept. 7, 2006 - American Express,
Discover Financial Services, JCB, MasterCard Worldwide and
Visa International today jointly announced the formation of
an independent council designed to manage the ongoing
evolution of the Payment Card Industry (PCI) Data Security
Standard, which focuses on improving payment account
security throughout the transaction process." -
PCI Press Release
Biometric and PKI (Token) security technology is specifically
mentioned as enabling compliance with the PCI-DSS 1.1 standard (PCI
DSS Requirement 8 Section 8.2). Our PCI-DSS Compliance
Enabled Solution involves the implementation and proper
maintenance of the following systems and components for most
small businesses that accept credit cards through face-to-face
or ecommerce transactions:
Recommended PCI-DSS Security Solution
PCI-DSS
Compliance Enabled Network Software - VeriSoft SSO Single Sign On
PCI-DSS Compliance Enabled Desktop Software - BioCert
Intelligent Identity Manager
PCI-DSS
Compliance Enabled PC Peripherals - Precise Biometrics and
BioCert PC Peripherals
PCI-DSS Compliance
Active Sonar Proximity Scanner - Session Locker - TF2000
PCI-DSS Compliance
Enabled Drug Samples Storage - BioSaf GunLokR with Storage
Shelf Unit and Wall Mount
NOTE - "COMPLIANCE ENABLED" SHALL
NOT INFER OR BE CONSTRUED TO MEAN THAT A BUSINESS IS COMPLIANT.
WE CAN PROVIDE THE TOOLS WITH WHICH YOUR ORGANIZATION
MAY COMPLY WITH THE ASSOCIATED SECURITY STANDARDS AND
DIRECTIVES, BUT WE DO NOT UNDER ANY
CIRCUMSTANCES GUARANTEE THAT YOUR PARTICULAR IMPLEMENTATION IS
COMPLIANT, NOR WILL ARTEMIS SOLUTIONS GROUP, IQBIO,
INC. OR ANY OF OUR AFFILIATED COMPANIES BE LIABLE FOR YOUR
ORGANIZATIONS MISUNDERSTANDING, IMPLEMENTATION, CONFIGURATION,
INCORRECT ASSUMPTIONS OR ABILITIES TO IMPLEMENT THE RULES
REGARDING THE DIRECTIVE. THE ARTICLES AND OPINIONS
EXPRESSED HEREIN ARE THE OPINION OF THE AUTHORS AND MAY CONTAIN
FACTUAL MISREPRESENTATIONS, INCORRECT ASSUMPTIONS, MISSTATEMENTS
OF FACT OR THEORY AND YOUR RELIANCE UPON THIS INFORMATION IS AT
YOUR OWN PERIL, RISK AND LIABILITY. WE ADVISE YOU TO SEEK
COMPETENT COUNSEL REGARDING YOUR IMPLEMENTATION OF YOUR PC,
NETWORK OR PORTABLE DATA SECURITY SOLUTION. THE PCI DSS
STANDARDS AND ALL ASSOCIATED MATERIALS ARE ©2006
PCI SECURITY STANDARDS COUNCIL, LLC AND/OR ANY
REFERENCE TO THE STANDARDS WITHIN THESE DOCUMENTS IS FOR THE
RESEARCH, REPORTING, TEACHING AND COMMENTARY PURPOSES ONLY BASED
UPON THE "FAIR USE DOCTRINE" AS OUTLINED IN
17 U.S.C. §107. ALL OTHER RIGHTS ARE HEREBY RESERVED
FOR THE ORIGINAL AUTHORS PURSUANT TO
17 U.S.C. §106, AND
17 U.S.C. §106A. |