WHAT IS PCI DSS
PCI DSS stand for the Payment Card Industry Data Security Standard and was adopted by the payment card brands for the protection of cardholder data being processed, stored, and/or transmitted. The standard encompasses numerous controls in support of the following 12 primary control objectives:
|GOALS||PCI DSS Control Objectives|
|Build & Maintain a Secure Network||1. Install and maintain a firewall configuration to protect cardholder data|
|2. Do not use vendor-supplied defaults for system passwords and other security parameters|
|Protect Cardholderdata||3. Protect stored cardholder data|
|4. Encrypt transmission of cardholder data across open, public networks|
|Maintain a Vulnerability Management Program||5. Use and regularly update anti-virus software or programs|
|6. Develop and maintain secure systems and applications|
|Implement Strong Access Control Measures||7. Restrict access to cardholder data by business need to know|
|8. Assign a unique ID to each person with computer access|
|9. Restrict physical access to cardholder data|
|Regularly Monitor and Test Networks||10. Track and monitor all access to network resources and cardholder data|
|11. Regularly test security systems and processes|
|Maintain an Information Security Policy||12. Maintain a policy that addresses information security for all personnel|
DO I NEED A QSA TO PERFORM MY PCI DSS ASSESSMENT?
Qualified Security Assessors (QSA) are certified by the PCI Security Standards Council to perform assessments to determine compliance with PCI DSS. Each payment card brand (i.e., Visa, MasterCard, American Express, and Discover) has their own program for PCI DSS compliance, validation requirements, and overall enforcement. The quantity of annual payment card transactions is the primary driver for determining whether a certified QSA is required to perform your assessment. All entities processing card payments will fall under 1 of 4 categories. The following are the current gross transaction levels for Merchant Levels 1-4.
(greater than or equal to:)
|Level 2||1,000,000 to 5,999,999||1,000,000 to 5,999,999||50,000 to 2,499,999||1,000,000 to 5,999,999|
|Level 3||20,000 to 999,999||20,000 to 999,999||Less than 50,000||All other merchants|
|Level 4||Less than 20,000||Less than 20,000||N/A||N/A|
Merchants falling under the Merchant Level 1 category are required to engage a QSA to perform the PCI DSS assessment and submit a Report on Compliance (ROC).