Companies unclear on credit-card security requirements

By
Follow google news

More than half of the IT professionals in a recent survey said their companies do not fully understand the requirements mandated by the Payment Card Industry (PCI) Data Security Standard.

Visa, MasterCard International, and other payment card companies require merchants and others who process credit-card transactions to comply with the PCI standard for protecting cardholder data.


A survey of 65 IT professionals by encryption firm Protegrity showed that 53.9 percent do not believe their companiees are entirely clear about the PCI requirements, or other regulations such as Sarbanes-Oxley and HIPAA.

Merchants processing more than 20,000 credit-card transactions per year faced a Thursday deadline to comply with the PCI standard. Non-compliance can result in fines and loss of the ability to handle credit-card transactions.

The PCI standard outlines 12 requirements, including encrypting transmission of cardholder data and implementing a vulnerability management program.

Both Visa and MasterCard have said that payment processor CardSystems Solutions was out of compliance with their security requirements. About 40 million credit-cards of all brands were exposed to potential fraud when an attacker broke into CardSystems Solutions' network.

Last week, SC Magazine reported a class-action lawsuit has been filed in California on behalf of credit-card holders and merchants against CardSystems Solutions, Visa, and MasterCard after the security breach that exposed 40 million credit cards to potential fraud.

www.protegrity.com

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

'Copy Fail' Linux privesc bug lay dormant in kernel since 2017

'Copy Fail' Linux privesc bug lay dormant in kernel since 2017

Attacker embeds Claude Code in mass credential harvesting op

Attacker embeds Claude Code in mass credential harvesting op

Medibank reveals attack vector and cost of 2022 security breach

Medibank reveals attack vector and cost of 2022 security breach

Log In

  |  Forgot your password?