The is a multifaceted security standard that includes requirements for
- Security Management
- Policies & Procedures
- Network Architecture
- Software Design
This comprehensive standard is intended to help organisations proactively protect customer account data.
If your business processes credit cards transactions or stores credit card information, you have to be PCI compliant. The time and resources required to become PCI compliant can be daunting and if implemented incorrectly can result in a major fine.
There are 12 requirements which must be fulfilled in order to become compliant -
Build and Maintain a Secure Network
- Requirement 1: Install and maintain a firewall configuration to protect cardholder data
- Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters
Protect Cardholder Data
- Requirement 3: Protect stored cardholder data
- Requirement 4: Encrypt transmission of cardholder data across open, public networks
Maintain a Vulnerability Management Program
- Requirement 5: Use and regularly update anti-virus software
- Requirement 6: Develop and maintain secure systems and applications
Implement Strong Access Control Measures
- Requirement 7: Restrict access to cardholder data by business need-to-know
- Requirement 8: Assign a unique ID to each person with computer access
- Requirement 9: Restrict physical access to cardholder data
Regularly Monitor and Test Networks
- Requirement 10: Track and monitor all access to network resources and cardholder data
- Requirement 11: Regularly test security systems and processes
Maintain an Information Security Policy
- Requirement 12: Maintain a policy that addresses information security
Few hosting providers cover even the most basic PCI Compliance requirements. Some, including ForLinux, cover requirement 9 and 12 as part of a managed hosting solution. However, the remaining requirements must still be met in order to process or store credit cards data.
As part of our PCI Hosting package, we can provide a solution which covers all the above requirements for an online business presence. Please see below an example configuration for PCI compliance:
ForLinux can quickly provision a fully PCI accredited solution for you, removing the burden of design, implementation, configuration and continued management of your online PCI solution.
If your business requires a PCI compliant solution or if security is causing you concern, contact our Security Advisor on or complete the Get In touch form to the right of this page.