I have just been reading about the AIS (Account Information Security) program between VISA, Mastercard and the other big credit card companies.
See BBC website: http://news.bbc.co.uk/1/hi/technology/4449759.stm
And Visa website: http://www.visaeurope.com/acceptingv...programme.html
for more information.
There are a dozen requirements which are listed below:
Build and Maintain a Secure Network
Requirement 1: Install and maintain a firewall configuration to protect data.
Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters.
Protect Cardholder Data
Requirement 3: Protect stored data.
Requirement 4: Encrypt transmission of cardholder data and sensitive information across public networks.
Maintain a Vulnerability Management Program
Requirement 5: Use and regularly update anti-virus software.
Requirement 6: Develop and maintain secure systems and applications.
Implement Strong Access Control Measures
Requirement 7: Restrict access to data by business need-to-know.
Requirement 8: Assign a unique ID to each person with computer access.
Requirement 9: Restrict physical access to cardholder data.
Regularly Monitor and Test Networks
Requirement 10: Track and monitor all access to network resources and cardholder data.
Requirement 11: Regularly test security systems and processes.
Maintain an Information Security Policy
Requirement 12: Maintain a policy that addresses information security.
How will this affect Actinic and will there be any upgrades with regard to this
They are suggesting all webshops will be audited quarterly and certified annually with those failing being banned from accepting credit card payments!
I look forward to some feedback on this
Thanks
Jane
See BBC website: http://news.bbc.co.uk/1/hi/technology/4449759.stm
And Visa website: http://www.visaeurope.com/acceptingv...programme.html
for more information.
There are a dozen requirements which are listed below:
Build and Maintain a Secure Network
Requirement 1: Install and maintain a firewall configuration to protect data.
Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters.
Protect Cardholder Data
Requirement 3: Protect stored data.
Requirement 4: Encrypt transmission of cardholder data and sensitive information across public networks.
Maintain a Vulnerability Management Program
Requirement 5: Use and regularly update anti-virus software.
Requirement 6: Develop and maintain secure systems and applications.
Implement Strong Access Control Measures
Requirement 7: Restrict access to data by business need-to-know.
Requirement 8: Assign a unique ID to each person with computer access.
Requirement 9: Restrict physical access to cardholder data.
Regularly Monitor and Test Networks
Requirement 10: Track and monitor all access to network resources and cardholder data.
Requirement 11: Regularly test security systems and processes.
Maintain an Information Security Policy
Requirement 12: Maintain a policy that addresses information security.
How will this affect Actinic and will there be any upgrades with regard to this
They are suggesting all webshops will be audited quarterly and certified annually with those failing being banned from accepting credit card payments!
I look forward to some feedback on this
Thanks
Jane
Comment