PCI DSS Compliance & Certification

Share

Maintaining payment security is required for all entities that store, process, or transmit cardholder data. Guidance for maintaining payment security is provided in PCI security standards. These set the technical and operational requirements for organizations accepting or processing payment transactions, and for software developers and manufacturers of applications and devices used in those transactions.


The PCI Standards Council (SSC) is responsible for the development of the standards for PCI compliance. Its purpose is to help secure and protect the entire payment card ecosystem. These standards apply for merchants, service providers processing credit/debit card payment transactions.

There are currently 12 requirements for PCI DSS that are set forth by the PCI SSC which are both operational, technical, and the core focus of these rules is always to protect cardholder data.

The 12 requirements of PCI DSS are:

1.Install and maintain a firewall configuration to protect cardholder data

2. Do not use vendor-supplied defaults for system passwords and other security parameters

3. Protect stored cardholder data

4. Encrypt transmission of cardholder data across open, public networks

5. Use and regularly update anti-virus software or programs

6. Develop and maintain secure systems and applications

7. Restrict access to cardholder data by business need to know

8. Assign a unique ID to each person with computer access

9. Restrict physical access to cardholder data

10. Track and monitor all access to network resources and cardholder data

11. Regularly test security systems and processes

12. Maintain a policy that addresses information security for all personnel


THZ is a Self-Assessed PCI DSS Compliant business.
THZ can also assist your business in becoming PCI DSS Compliant, helping you through the process, performing ongoing technical requirements such as Pen Testing, Vulnerability Scans, Credit Card Scans etc.

Speak to one of our security consultants today, and we can discuss your PCI DSS needs.