COMPLIANCE Jobs, Jobs in COMPLIANCE - ComplianceCrossing.comJob Aggregators - ComplianceCrossing.com

     

Forgot Your Password?    Remember Me

TRY IT NOW!

Job Seekers  Employers
How We Help You  |  Why We're Not Free
The Most Compliance Jobs Anywhere — ComplianceCrossing
Search Thousands of Jobs in Our Database
What Where


Search in Job Title Only

Select Country:


+ Browse Jobs    + Advanced Search    + Search Tips
Compliance Career Feature

PCI DSS Compliance: An Overview
By Chakri Devarakonda and Durga Prasad Adusumalli, AppLabs
Introduction

The growth of online services to facilitate ease of use for customers to purchase goods has grown exponentially in recent years. In order to make the purchase process easier, customers generally pay for the services or goods by credit or debit card. However, improved efficiency and convenience for the consumer mean that crime has also become easier and more convenient.

Act Now! Activate a FREE three days trial to ComplianceCrossing.com, because you know how important it is to know about all the jobs.
Activate My Risk Free Trial
PCI DSS Compliance: An Overview
PCI DSS Compliance: An Overview
+ Enlarge
Chakri Devarakonda
Criminals have become more skillful, having discovered that there is a significant amount of money to be acquired with very little risk, and as such, credit card fraud and identity theft have become much more common in recent years. Network infrastructures that are utilized commercially necessitate absolute security due to the sensitive personal information which they contain.

Every company that accepts credit card payments, processes credit card transactions, stores credit card data, or in any other way touches personal or sensitive data associated with credit card payment processing is affected by PCI DSS.

What Is PCI DSS?

Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards that has been created by the major credit card companies (American Express, Discover Financial Services, JCB, MasterCard Worldwide, and Visa International) to protect their customers from increasing identity theft and security breaches.

Who Must Comply with PCI DSS?

Virtually all businesses, regardless of their size, need to understand the scope of PCI DSS and how to implement network security that is compliant with PCI DSS guidelines. In doing so, they will avoid penalties or the possibility of having their merchant status revoked and potentially being banned from accepting or processing credit cards.

Any company that stores, processes, or transmits cardholder data must comply with PCI DSS. Primarily, merchants and service providers should be compliant to this standard. Merchants are the companies that accept credit cards in exchange for goods or services. A service provider is any company that processes, stores, or transmits cardholder data, including companies that provide services to merchants or other service providers. To comply with this standard, a merchant or service provider has to satisfy the requirements listed below.

Overview of PCI DSS Requirements

PCI DSS version 1.1 comprises six control objectives which in turn contain one or more requirements covering the ambit of IT security with a mix of technical and security controls. According to PCI DSS 1.1, the scope includes the cardholder data environment only if adequate network segmentation is in place. In most cases, this implies the use of dedicated firewalls and non-routable virtual local area networks (VLANs). If you do not have such controls in place, the scope of PCI compliance validation will cover your entire network. The list below elucidates the 12 PCI requirements:
  • Requirement 1: Install and maintain a firewall configuration to protect cardholder data

  • Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters

  • Requirement 3: Protect stored cardholder data

  • Requirement 4: Encrypt transmission of cardholder data across open, public networks

  • Requirement 5: Use and regularly update anti-virus software

  • Requirement 6: Develop and maintain secure systems and applications

  • Requirement 7: Restrict access to cardholder data on a need-to-know basis

  • Requirement 8: Assign a unique ID to each person with computer access

  • Requirement 9: Restrict physical access to cardholder data

  • Requirement 10: Track and monitor all access to network resources and cardholder data

  • Requirement 11: Regularly test security systems and processes

  • Requirement 12: Maintain a policy that addresses information security
Compliance Process

Depending on the company’s merchant or service level provider, either an annual onsite PCI audit has to be conducted or a Self-Assessment Questionnaire (SAQ) has to be filled in to validate compliance. In addition to this, results of quarterly network perimeter scans (which have to be performed by an approved scanning vendor), evidence of internal vulnerability scans, and evidence of application and network penetration tests are to be shared with card brands
to prove to them that the company practices sound patch management and vulnerability management processes.

PCI classifies merchants and service providers based on the number of transactions that take place through their service. Tables I and II below classify different levels for merchants and service providers, respectively.

Level Selection Criteria Compliance
Level 1 More than six million VISA/Mastercard transactions annually across all channels, including e-commerce
  • Annual onsite PCI data security assessment
  • Quarterly network scans
Level 2 1,000,000-5,999,999 VISA/Mastercard transactions annually
  • Annual self-assessment
  • Quarterly network scans
Level 3 20,000-1,000,000 VISA/Mastercard e-commerce transactions annually
  • Annual self-assessment
  • Quarterly network scans
Level 4 Less than 20,000 e-commerce transactions annually and all merchants across channel up to 1,000,000 VISA transactions annually
  • Annual self-assessment
  • Quarterly network scans

Level Selection Criteria Compliance
Level 1 All VisaNet processors (member and nonmember) and all payment gateways
  • Annual onsite PCI data security assessment
  • Quarterly network scans
Level 2 Any service provider that is not in Level 1 and stores, processes, or transmits more than 1,000,000 VISA/ Mastercard accounts/transactions annually
  • Annual onsite PCI data security assessment
  • Quarterly network scans
Level 3 Any service provider that is not in Level 1 and stores, processes, or transmits fewer than 1,000,000 VISA/ Mastercard accounts/transactions annually
  • Annual self-assessment
  • Quarterly network scans

Achieving PCI DSS Compliance

It is recommended that a proactive means for merchants and service providers to meet PCI DSS compliance includes having their network perimeter scanned by an Approved Scanning Vendor (ASV) every quarter. An ASV, at the request of a merchant or service provider, will obtain the required information, run a scan, and submit a scan report clearly highlighting compliance status, network vulnerabilities, and vulnerable services classified as per the scoring pattern and severities prescribed by PCI DSS. The compliance scan follows the steps highlighted below:
  • The merchant or service provider engages with an ASV to perform the PCI DSS scanning service;

  • The merchant provides the ASV with information about their network perimeter. Any special requirements like exclusion or justification of specific services are taken into account as part of this step;

  • The ASV scans the merchant’s network perimeter from a remote site using non-intrusive tests;

  • The ASV determines compliance based on the vulnerabilities found during the assessment. This is benchmarked against the scoring matrix provided by PCI DSS;

  • The ASV produces a report containing the PCI DSS status of each scanned network component with recommendations to address the vulnerabilities;

  • The ASV and the merchant shall review the vulnerabilities together and apply suggested fixes to mitigate any perceived risk and maintain compliance to PCI DSS.
Benefits of Compliance
  • By complying with PCI DSS, an organization has taken the appropriate steps to ensure that its customers and their data are secure;

  • One of the benefits of PCI DSS compliance is that the organization will not face a severe penalty if their services are breached. If the analysis after a security incident shows that the company was still compliant at the time of the incident, this will result in lenient treatment by the authorities;

  • More importantly, if your company is a Level 1 or Level 2 merchant, you may be eligible to receive part of the $20 million in financial incentives from Visa;

  • By obtaining PCI DSS compliance status, an organization can attract discounts on transaction costs from the credit card companies.

PCI DSS Compliance: An Overview
Durga Prasad Adusumalli
About the Authors

Chakri Devarakonda works as an Associate Manager, Technical Services at AppLabs, a global IT services company. His responsibilities include handling Security Services, which offers web application penetration testing engagements, product security testing, and network security assessments.

Durga Prasad Adusumalli is a Team Leader, Security Services at AppLabs, a global IT services company. He has over four years experience in Layered Security and Network Assessments.

For more information about Applabs please email info@applabs.com or visit www.applabs.com




Popular Tags
 payment card industry  credit cards  environments  objectives  ASV  retailers  payments  assessments  Visa International  customers  businesses

  • Share this story:
  • BlinkList
  • blogmarks
  • del.icio.us
  • Digg
  • Facebook
  • Google
  • Sphinn
  • MySpace
  • NewsVine
  • Simpy
  • StumbleUpon
  • Technorati
  • E-mail this story to a friend!
  • Print this article!
  • Faves
  • Furl
  • Netvouz
  • Slashdot
  • Spurl
  • Yahoo! Buzz

Facts

ComplianceCrossing Fact #223: ComplianceCrossing is not supported by revenue from employers or recruiters.

Comments

Article ID: 700035    www.compliancecrossing.com

Article Title: PCI DSS Compliance: An Overview

Comment not found for this article.

Comment Comment
Rate This Article
Current rating: 7.7
Related Article

Printable Version    Printable Version PDF Version    PDF Version Email to a Friend    Email to a Friend
Comment    Comment View Comment    View Comment

What Members are Saying
Derek , Philadelphia, PA
I got a job, thanks to EmploymentCrossing. It is the best service in the world.

Andrew , Columbus, GA
The best part about EmploymentCrossing is the simplicity of the site. It is a very user friendly website.

Jamie , Pueblo West, CO
EmploymentCrossing is a very user friendly website and has a fantastic search engine. I always got quick responses to my search criteria.

Keith , Staten Island, NY
EmploymentCrossing's search engine is excellent. You can search jobs on the basis of specific locations and practice areas.

Carolyn , Harrisburg, PA
I would definitely like to join EmploymentCrossing again if I need to switch my job in future. It was a lot more helpful compared to other websites.


To compare ComplianceCrossing with other job sites Click here


Bring Order and Structure to Your Compliance Job Search

You have perseverance and can accomplish anything you put your mind to and finding the ideal compliance job is no exception. We have a tradition of helping our members accomplish anything they set their mind to. With complete information about every compliance job in the market at your fingertips you are going to go far.

You have very high standards for the sort of employer you are working for and also for yourself. You are not afraid to work hard to fulfill your duties because you value security and peaceful living. We give you the tools to pursue your dreams for you and your family.

Become part of a tradition of research excellence that has elevated the careers of countless compliance professionals just like you.

Complete the sign up process today and become part of our site today.

Tell us where to send your access instructions:

Your Email


Total Jobs on EmploymentCrossing
2,382,454
New Jobs This Week on EmploymentCrossing
657,927
  COMPLIANCE JOBS NEAR YOU

  + International Jobs + Work At Home Jobs
  + UK Jobs + Canada Jobs

New search feature using US map. + click here
Looking for a new compliance job in your city? + click here
  TOP 5 JOB SEARCHES
  TODAY'S FEATURED COMPLIANCE JOB
Regulatory Specialist
United States-AZ-Tempe
Under minimal supervision, this position ensures
compliance with governmental laws and regulations.
Implement compliance regulations into business ...

Click to Apply for - ComplianceCrossing.com
Most Recent Articles
Finding Jobs in Regulatory Affairs
Developed in part by the government, jobs in regulatory affairs have been created as a way to help monitor public health by using a form of quality checking on different areas of medicine. Some of those include pharmaceuticals, medical devices, and agrochemicals, veterinary services, along with complementary and cosmetic practices. Of course there ...
Recent Articles:

Search All Articles

   GO 
FREE NEWSLETTER
+
A CHANCE TO WIN A NEW BMW
BMW - ComplianceCrossing.com
"The Job Researcher" is a weekly newsletter that's absolutely jam packed with jobs, career advice, stories, webinars and more. PLUS, a chance to win a new 2010 BMW 328i sedan in Employment Research Institute's annual car giveaway.
 SIGN UP NOW
*Your Email:  
Sign Up on - ComplianceCrossing.com
Only ComplianceCrossing researches and consolidates every compliance job opening it can find and puts all of the job openings it locates in one place.

  • We research and collect compliance job openings from tens of thousands of employer, association, newspaper classified, government, public interest, job board and other websites and post them on our site.
  • ComplianceCrossing has vastly more compliance job openings than any other job board because we actually go out and research jobs instead of just posting jobs employers pay us to post.
  CAREER CONNECT  (From Our Career Blogs)
You think young and feel young.
Submit GET FREE
JOB ALERTS
BE THE FIRST TO KNOW
Learn about jobs before everyone else does. Studies prove the first people to apply to jobs are the most likely to get them. Sign up for job alerts today BMW - ComplianceCrossing.comand be entered to win a new BMW!
What is ComplianceCrossing?
Who Else Is Ready to Never Have to Worry About Recessions and the Compliance Job Market Again?
Why Job Boards Are Evil!
Blow Away Your Competition with ComplianceCrossing
Get More Employers to Respond to Your Applications and Hire You
Why You Are Not Aware of 95% of the Compliance Jobs Out There
Why ComplianceCrossing's Marketing Problem is Good For You
Why It is Important to See Every Job Site There is
Private Versus Public Job Boards
Why You Need to Manage Your Job Search in One Place
Who Else Wants Their Phone Ringing Off the Hook With Quality Job Interviews?
Do Not Use Another Job Board Until You Read This
UNCENSORED REVIEWS!

Bryan , Saint Paul, MI

EmploymentCrossing always helped me stay updated with the jobs available in the market. The daily news on the site was also very informative. I like to read the different archives and the life style column on EmploymentCrossing.

Pamela , Chicago, IL

ComplianceCrossing has more jobs on its pages, than any other similar websites. Amazing!

Bobby , Los Angeles, CA

The jobs on Employmentcrossing are always current. I was excited and pleased with the constant newsletters and market updates. This site is the best online job board.

+ More success stories
+ Share your success story with us
HOW WE WORK

Watch Our Latest Video!

HOW WE WORK - ComplianceCrossing.com
See Every Compliance Job We Can Find on the Internet!
Unlike other sites, ComplianceCrossing works for you and does not charge employers to post jobs and actually goes out and researches jobs for you. The jobs you see are the jobs we find for you and not the ones employers are paying us to post.
To compare ComplianceCrossing with other job sites
Click here on - ComplianceCrossing.com
USEFUL LINKS

Press Releases

Add ComplianceCrossing to My Favorites
Top 101 Reasons to Sign Up for ComplianceCrossing
Reason 29: ComplianceCrossing is used by many outplacement firms whose job it is to know the market. Imagine having that same information at your own disposal.
  Click here for 100 more reasons  
ComplianceCrossing has the most advanced job-search engine. Period.
Tell Us What You Think   
ComplianceCrossing answers:
Why can't I just use a free method to look for a job?
+ Click here for answer
Free Webinar by Harrison Barnes
Harmonize with the People in Your Environment

Friday, September 3, 2010 at 1:00 PM PDT.
Today at ComplianceCrossing

613 - Jobs found in last 24 Hours 2,708 - Jobs found in last 7 Days 10,520 - Total Jobs Found
Leading Employers Tell a Friend!
Follow ComplianceCrossing.com on Twitter Be a Fan of ComplianceCrossing on Facebook - ComplianceCrossing.com
Your privacy is guaranteed. We will never give out, lease, or sell your personal information. Whitelist ComplianceCrossing
Sign Up  |   About Us  |   History  |   Our Mission  |   Refer A Friend  |   Terms of Use  |   Privacy  |   Post a Job Opening  |   Job-Opening FAQ  |   Testimonials  |   Career Articles

The ComplianceCrossing Guarantee  |   Crossing Sites  |   Browse Jobs  |   Benefits of Working with ComplianceCrossing  |   Site Map

Career Advice  |   Resume Service  |   Resume Distribution Service  |   Post Resume  |   Job Search Course
In a different but related profession? We can help! Explore our related sites:
100KCrossing | AccountingCrossing | AccountManagementCrossing | ActuarialCrossing | AdminCrossing | AdvertisingCrossing | AerospaceCrossing | AgriculturalCrossing | ArchitectureCrossing | Attorney Resume | AuditorCrossing | AutomotiveCrossing | AviationCrossing | BCG Attorney Search | BilingualCrossing | BiotechCrossing | BlueCollarCrossing | BusinessAnalystCrossing | BusinessDevelopmentCrossing | CallCenterCrossing | ChefCrossing | CivilEngineeringCrossing | CLevelCrossing | ClinicalResearchCrossing | ComputerAidedDesignCrossing | ConstructionCrossing | ConsultingCrossing | ContractManagementCrossing | CounselingCrossing | CPlusPlusCrossing | CustomerServiceCrossing | DBACrossing | DentalCrossing | DesigningCrossing | DiversityCrossing | DotNetCrossing | ECommerceCrossing | EdFed | EditingCrossing | EducationCrossing | EmploymentAuthority | EmploymentCrossing | EnergyCrossing | EngineeringCrossing | EntryLevelCrossing | EnvironmentalCrossing | EnvironmentalSafetyHealthCrossing | SAPCrossing | ExecCrossing | FacilitiesCrossing | FinancialServicesCrossing | FoodServicesCrossing | FundraisingCrossing | GISCrossing | GovernmentCrossing | Graduate School Loans | HealthcareCrossing | HelpDeskCrossing | HospitalityCrossing | Hound | HRCrossing | HVACCrossing | InformationTechnologyCrossing | InsurCrossing | IntellectualPropertyCrossing | InternshipCrossing | J2EECrossing | JD2B | JDJournal | JournalismCrossing | Judged | LawCrossing | Law Firm Staff | Law School Loan Report | Law School Loans | Legal Authority | Legal Authority Financial | LogisticsCrossing | ManagerCrossing | ManufacturingCrossing | MarketingCrossing | MediaJobCrossing | Medical School Loans | MilitaryCrossing | NursingCrossing | OccupationalTherapyCrossing | OperationsCrossing | PartTimeCrossing | PharmaceuticalCrossing | PhysicalSecurityCrossing | PhysicalTherapyCrossing | PlanningCrossing | PostdoctoralFellowCrossing | PRCrossing | ResumeApple | ProcurementCrossing | ProductManagerCrossing | ProjectManagementCrossing | PublicInterestCrossing | PublishingCrossing | PurchasingCrossing | QAQCCrossing | RadioCrossing | RealEstateAndLandCrossing | Recruit Attorney | RecruitingCrossing | ResearchingCrossing | RetailCrossing | SciencesCrossing | ScientistCrossing | SellingCrossing | SQLCrossing | TeenagerCrossing | TelecomCrossing | TradingCrossing | TrainingCrossing | TransportationCrossing | TravelingCrossing | TruckingCrossing | TVCrossing | UnderwritingCrossing | VeterinaryCrossing | VolunteerCrossing | WorkAtHomeCrossing | WritingCrossing



Want to Focus Your Compliance Job Search on a Different Geographic Area?
Akron Jobs  |  Albuquerque Jobs  |  Anaheim Jobs  |  Anchorage Jobs  |  Arlington Jobs  |  Atlanta Jobs  |  Aurora Jobs  |  Austin Jobs  |  Babylon Jobs  |  Bakersfield Jobs  |  Baltimore Jobs  |  Baton Rouge Jobs  |  Birmingham Jobs  |  Boston Jobs  |  Buffalo Jobs  |  Chandler Jobs  |  Charlotte Jobs  |  Chesapeake Jobs  |  Chicago Jobs  |  Chula Vista Jobs  |  Cincinnati Jobs  |  Cleveland Jobs  |  Colorado Springs Jobs  |  Columbus Jobs  |  Corpus Christi Jobs  |  Dallas Jobs  |  Denver Jobs  |  Detroit Jobs  |  Durham Jobs  |  El Paso Jobs  |  Fort Wayne Jobs  |  Fort Worth Jobs  |  Fresno Jobs  |  Garland Jobs  |  Greensboro Jobs  |  Henderson Jobs  |  Hialeah Jobs  |  Honolulu Jobs  |  Houston Jobs  |  Indianapolis Jobs  |  Islip Jobs  |  Jacksonville Jobs  |  Jersey City Jobs  |  Kansas City Jobs  |  Laredo Jobs  |  Las Vegas Jobs  |  Lexington Jobs  |  Lincoln Jobs  |  Long Beach Jobs  |  Los Angeles Jobs  |  Louisville Jobs  |  Lubbock Jobs  |  Memphis Jobs  |  Mesa Jobs  |  Miami Jobs  |  Milwaukee Jobs  |  Minneapolis Jobs  |  Nashville Jobs  |  Newark Jobs  |  New Orleans Jobs  |  New York Jobs  |  Norfolk Jobs  |  North Hempstead Jobs  |  Oakland Jobs  |  Oklahoma Jobs  |  Omaha Jobs  |  Orlando Jobs  |  Oyster Bay Jobs  |  Philadelphia Jobs  |  Phoenix Jobs  |  Pittsburgh Jobs  |  Plano Jobs  |  Portland Jobs  |  Raleigh Jobs  |  Reno Jobs  |  Riverside Jobs  |  Rochester Jobs  |  Sacramento Jobs  |  San Antonio Jobs  |  San Diego Jobs  |  San Francisco Jobs  |  San Jose Jobs  |  Santa Ana Jobs  |  Scottsdale Jobs  |  Seattle Jobs  |  Saint Louis Jobs  |  Stockton Jobs  |  Saint Paul Jobs  |  Saint Petersburg Jobs  |  Tampa Jobs  |  Toledo Jobs  |  Tucson Jobs  |  Tulsa Jobs  |  Virginia Beach Jobs  |  Washington DC Jobs  |  Wichita Jobs  |  Winston-Salem Jobs
Employment Research Institute
ComplianceCrossing - #1 Job Aggregation and Private Job-Opening Research Service — The Most Quality Jobs Anywhere
ComplianceCrossing is the first job consolidation service in the employment industry to seek to include every job that exists and not charge employers to post jobs on its site.

ComplianceCrossing uses sophisticated technology and manual work to comb employer websites and other job boards for jobs and bring them all to its site.