AllBusiness.com
    • Starting a Business
    • Career
    • Sales & Marketing
    • AI
    • Finance & Fundraising
    • M & A
    • Tech
    • Business Resources
    • Business Directory
    1. Home»
    2. Legacy»
    3. Requirements for Secure Credit Card Transactions»

    Requirements for Secure Credit Card Transactions

    Chandler Harris
    LegacyFinancing & Credit

    If your business processes credit card payments, you must comply with federal security standards to prevent fraud, hacking, and various other security vulnerabilities and threats, or risk losing this ability and being audited or fined.

    Any company or government agency that processes, stores, or transmits payment card data must comply with the Payment Card Industry Data Security Standard, a set of requirements to enhance data security. Some of the PCI standards are common sense, such as building and maintaining a secure network through common practices and not using vendor-supplied defaults for system passwords.

    In 2007, TJX Companies, a discount retailer of apparel and home products with stores such as TJMaxx and Marshalls, reported one of the largest data breaches ever, with an estimated 45.6 million credit and debit card numbers stolen from one of its systems. The cost was severe for the retail giant, whose settlement required it to pay an estimated $65 million to MasterCard and Visa card users. The settlement with the Federal Trade Commission also requires the company to retain independent auditors to asses its security every other year for 20 years.

    The TJX breach reveals what can happen to a company that fails to comply with the PCI DSS. Data security analysts criticized TJX for collecting too much personal information, keeping it too long, and relying on weak encryption technology to protect it.

    The following 12 security guidelines are mandatory for any organization that processes credit cards:

    1. Install and maintain a firewall configuration to protect cardholder data.
    2. Do not use vendor-supplied defaults for system passwords and other security parameters.
    3. Protect stored cardholder data.
    4. Encrypt transmission of cardholder data across open, public networks.
    5. Use and regularly update antivirus software or programs.
    6. Develop and maintain secure systems and applications.
    7. Restrict access to cardholder data by a need-to-know basis.
    8. Assign a unique ID to each person with computer access.
    9. Restrict physical access to cardholder data.
    10. Track and monitor all access to network resources and cardholder data.
    11. Regularly test security systems and processes.
    12. Maintain a policy that addresses information security for employees and contractors.

    Hot Stories

    A small business owner looking at her personal credit

    New Development Could Improve Small Business Owners’ Credit

    Small business owner reviewing daily finances on a tablet

    How Suppliers and Vendors Can Help Small Businesses Access Financing

    Profile: Chandler Harris

    BizBuySell
    logo
    AllBusiness.com is a premier business website dedicated to providing entrepreneurs, business owners, and business professionals with articles, insights, actionable advice,
    and cutting-edge guides and resources. Covering a wide range of topics, from starting a business, fundraising, sales and marketing, and leadership, to emerging AI
    technologies and industry trends, AllBusiness.com empowers professionals with the knowledge they need to succeed.
    About UsContact UsExpert AuthorsGuest PostEmail NewsletterAdvertiseCookiesIntellectual PropertyTerms of UsePrivacy Policy
    Copyright © AliBusiness.com All Rights Reserved.
    logo
    • Experts
      • Latest Expert Articles
      • Expert Bios
      • Become an Expert
      • Become a Contributor
    • Starting a Business
      • Home-Based Business
      • Online Business
      • Franchising
      • Buying a Business
      • Selling a Business
      • Starting a Business
    • AI
    • Sales & Marketing
      • Advertising, Marketing & PR
      • Customer Service
      • E-Commerce
      • Pricing and Merchandising
      • Sales
      • Content Marketing
      • Search Engine Marketing
      • Search Engine Optimization
      • Social Media
    • Finance & Fundraising
      • Angel and Venture Funding
      • Accounting and Budgeting
      • Business Planning
      • Financing & Credit
      • Insurance & Risk Management
      • Legal
      • Taxes
      • Personal Finance
    • Technology
      • Apps
      • Cloud Computing
      • Hardware
      • Internet
      • Mobile
      • Security
      • Software
      • SOHO & Home Businesses
      • Office Technology
    • Career
      • Company Culture
      • Compensation & Benefits
      • Employee Evaluations
      • Health & Safety
      • Hiring & Firing
      • Women in Business
      • Outsourcing
      • Your Career
      • Operations
      • Mergers and Acquisitions
    • Operations
    • Mergers & Acquisitions
    • Business Resources
      • AI Dictionary
      • Forms and Agreements
      • Guides
      • Company Profiles
        • Business Directory
        • Create a Profile
        • Sample Profile
      • Business Terms Dictionary
      • Personal Finance Dictionary
      • Slideshows
      • Entrepreneur Profiles
      • Product Reviews
      • Video
    • About Us
      • Create Company Profile
      • Advertise
      • Email Newsletter
      • Contact Us
      • About Us
      • Terms of Use
      • Contribute Content
      • Intellectual Property
      • Privacy
      • Cookies