PCI - Frequently Asked Questions



What is PCI DSS and why do I need it?

Well, first things first…

In the beginning, all big five payment card brands had their own security programs. The five brands are: Visa, MasterCard, American Express, Discover and JCB. They all wanted to accomplish the same thing, which was to create an additional layer of defense for their customers and to limit their liability for credit card data theft.

Read more...
 
Who can help me with PCI?

You can hire any consultant or professional you want to help you with the preparations for PCI DSS.

There are many domestic and international companies that offer their services in gap analysis, PCI preparation, audit preparation, firewall compliancy, policy compliancy and more.

Read more...
 
What is the difference between PCI DSS and PA DSS?

PCI DSS is the standard that credit card companies established for providing overall guidelines for organizations on creating a more secure environment with the goal of protecting customers’ data.

Read more...
 
What are merchant levels?

Merchant levels are the categories as defined by the payment brands to include all businesses dealing with credit cards. There are four merchant levels as defined below:

Read more...
 
What is required from each merchant?

The following is required by merchants by the payment card brands:

Merchant Level 1:

  • Annual on-site security audit conducted by a qualified security assessor (QSA).
    • Alternatively, an internal audit is acceptable if signed by an officer of the company.
Read more...
 
Which self assessment questionnaire do I need to fill?

There are five self assessment questionnaire categories, as illustrated in the table below.

Read more...
 
Which attestation of compliance do I need to fill?

First, you need to determine which merchant level you are. If you do not know this yet, go here.

Read more...
 
PCI DSS 1.2 is now in stage 1 - what does that mean?

The PCI DSS standard is published and maintained by the PCI Security Standards Council (SSC). Changes to the standard follow a 24-month lifecycle with five stages.

Read more...