Saudi security forces arrest 21,477 illegal residents in a week    Saudi Arabia delivers sacrificial meat to Egypt and Palestine    Sweden's Prince Carl Philip and Princess Sofia welcome baby girl    Sharifa Al-Sudairi makes historic debut at Asian Winter Games    Palestinian prisoners arrive in Ramallah under Gaza ceasefire deal    Trump revokes Biden's access to classified briefings    Wreckage of missing plane found in Alaska; all 10 aboard presumed dead    Trump vows to fire FBI agents involved in Jan. 6 investigations    Jaecoo J8 launches in Saudi Arabia, marking a new milestone in the Middle Eastern off-road market    Saudi Arabia opens Hajj 1446 registration for domestic pilgrims Priority given to those who have not performed Hajj before, with registration available via Nusuk app and e-portal    Ivan Toney's brace secures Al Ahli victory over Al Fateh in Saudi Pro League    Al Nassr reclaims third place with 3-0 victory over Al Fayha as Jhon Durán shines    Karim Benzema's last-gasp winner sends Al Ittihad to the top of Roshn Saudi League French striker seals dramatic 2-1 victory over Al Taawoun with stoppage-time strike    Salvador Dalí art comes to India for the first time    Crown Prince announces King Salman Automotive Cluster at KAEC    Saudi Arabia's population crosses 35 million, with non-Saudis constituting 44.4%    Heading into a new journey, JAECOO J8 is shaking up the luxury off-road market    GEA hosts mass wedding of 300 couples at "Night of a Lifetime" celebration during Riyadh Season 300 cars and housing as gifts for the newlyweds    Food Culture Festival kicks off in Riyadh's Diplomatic Quarter    Saudi Arabia to present 'The Um Slaim School: An Architecture of Connection' at Biennale Architettura 2025 Syn Architects explore Riyadh's architectural heritage, fostering new pedagogical approaches and global dialogue    Bollywood star Saif Ali Khan 'out of danger' after attack at home in Mumbai    Order vs. Morality: Lessons from New York's 1977 Blackout    India puts blockbuster Pakistani film on hold    The Vikings and the Islamic world    Exotic Taif Roses Simulation Performed at Taif Rose Festival    Asian shares mixed Tuesday    Weather Forecast for Tuesday    Saudi Tourism Authority Participates in Arabian Travel Market Exhibition in Dubai    Minister of Industry Announces 50 Investment Opportunities Worth over SAR 96 Billion in Machinery, Equipment Sector    HRH Crown Prince Offers Condolences to Crown Prince of Kuwait on Death of Sheikh Fawaz Salman Abdullah Al-Ali Al-Malek Al-Sabah    HRH Crown Prince Congratulates Santiago Peña on Winning Presidential Election in Paraguay    SDAIA Launches 1st Phase of 'Elevate Program' to Train 1,000 Women on Data, AI    41 Saudi Citizens and 171 Others from Brotherly and Friendly Countries Arrive in Saudi Arabia from Sudan    Saudi Arabia Hosts 1st Meeting of Arab Authorities Controlling Medicines    General Directorate of Narcotics Control Foils Attempt to Smuggle over 5 Million Amphetamine Pills    NAVI Javelins Crowned as Champions of Women's Counter-Strike: Global Offensive (CS:GO) Competitions    Saudi Karate Team Wins Four Medals in World Youth League Championship    Third Edition of FIFA Forward Program Kicks off in Riyadh    Evacuated from Sudan, 187 Nationals from Several Countries Arrive in Jeddah    SPA Documents Thajjud Prayer at Prophet's Mosque in Madinah    SFDA Recommends to Test Blood Sugar at Home Two or Three Hours after Meals    SFDA Offers Various Recommendations for Safe Food Frying    SFDA Provides Five Tips for Using Home Blood Pressure Monitor    SFDA: Instant Soup Contains Large Amounts of Salt    Mawani: New shipping service to connect Jubail Commercial Port to 11 global ports    Custodian of the Two Holy Mosques Delivers Speech to Pilgrims, Citizens, Residents and Muslims around the World    Sheikh Al-Issa in Arafah's Sermon: Allaah Blessed You by Making It Easy for You to Carry out This Obligation. Thus, Ensure Following the Guidance of Your Prophet    Custodian of the Two Holy Mosques addresses citizens and all Muslims on the occasion of the Holy month of Ramadan    







Thank you for reporting!
This image will be automatically disabled when it gets reported by several people.



Strengthened security
Published in The Saudi Gazette on 27 - 05 - 2016

IN today's world, using credit card is a fact of life. Credit card that we use quite often carries important information that if compromised during the use could cause damage to cardholders, merchants as well as the brands. The credit card carries cardholder data that include the full Primary Account Number (PAN), cardholder name, expiration and service code. Also includes authentication data on the magnetic stripe.
In this era of data-centric living a single breach could throw many people's lives awry. Compromised data, if it falls into wrong hands, could wreak havoc, as it did recently in 2013.
One of the major data breach happened to Target Discount Retail Store. As many as 70 million customers' credit cards were stolen. The credit cards theft happened between Nov. 27 and Dec. 15, 2013. The stolen information had customer names, credit cards or debit card number, the card's expiration date and CVV (card verification value) as well as customer information. This included names, mailing addresses, phone numbers and mail address.
As a result, Target sales dropped and also its share earnings. Also, for the customer, this has increased the possibility of identity theft. Once an identity is stolen, the thief can do a lot of things that would be detrimental to the customer. Among other things, the thief can get new credit card in your name and access your bank accounts.
In 2004, the major credit card brands (Discover, American Express, MasterCard, Visa and JCB) formed the Payment Card Industry Security Standards Council (PCI SSC) to facilitate the development of standards to become as a common set of minimum-security requirements to be implemented by all merchants and service providers that process, store or transmit credit cards information. In June 2005, the PCI SSC announced Payment Card Industry Data Security Standard (PCI DSS) protocol and it went into effect soon.
PCI SSC manages three different standards: the first standard covers everything from the physical security to logical security. Second covers Payment Application Data Standard (PADSS). There are thousands of PADSS compliant applications listed on the PCI DSS website where merchants can buy any off the shelf. The last standard is the PIN Transaction System (PTS). PCI SSC certifies all devices that process credit card PIN number.
PCI applies to every company that accepts credit card this includes retail point-of-sale services and mail/phone order. If your company accepts credit cards as payment for goods or services, then you should be aware of the Payment Card Industry (PCI) data security standards (DSS). These standards were created to protect the credit card information of all consumers.
The awareness should be made clear both to the consumer and the company such that data security is enhanced while reducing the chances of identity theft or a security breach.
There are many benefits for your credit card processing system when it becomes compliant with PCI DSS. The benefit of deploying PCI DSS is you get peace of mind. Knowing that your organization has done everything it can to ensure the safety and security of the customers' payment card data and the deployed standards has been developed thoroughly.
The second benefit of PCI DSS compliance is good customer relationship. Customer will be more comfortable dealing with merchants that are PCI DSS certified because they knew that their credit card information are protected. Improved relationship with customer more often translate into more profits.
Another benefit to PCI DSS compliance is that it becomes an integral part of any vulnerability management plan. Being PCI DSS compliant will drastically reduce the non-compliance findings when performing penetration testing and vulnerability scanning and that in turn will reduce the cost.
Since this protocol is the de-facto standard protocol around the world, it will be easier on other international organization to deal with your organization if you are PCI DSS compliant. In addition, when an organization branches internationally where PCI DSS is mandatory, then this will influence all the company's activities that are related to credit card processing to be PCI DSS compliant
Meeting PCI security requirements is very important to you if your business accepts credit cards for goods or services. Even though PCI is not, in itself, a law. However, PCI DSS is mandatory to all. Nothing is voluntary.
More than 80 percent of data stolen in breaches is payment card data, according to the 2009 Verizon Business Data Breach Report. The biggest challenge for the industry is education. Some of the small businesses don't know that they are responsible to be PCI compliant.
PCI SSC states that if you handle credit card information you must be compliant with PCI standards. That is a global rule. Merchants that do not comply with PCI DSS may be subject to fine, costly forensic audits, etc., should a breach event occur.
The PCI DSS is a set of 12 specific requirements that cover six different goals. It covers what to secure and how to become secure
PCI DSS: Goals
1. Build and maintain a secure network
2. Protect cardholder data
3. Maintain a vulnerability management program
4. Implement strong access control measures
5. Regularly monitor and test networks
6. Maintain an information security policy
PCI DSS: 12 specific requirements
1. Install and maintain a firewall configuration to
protect cardholder data
2. Do not use vendor-supplied defaults for system
passwords and other security parameters
3. Protect stored cardholder data
4. Encrypt transmission of cardholder data across
open, public networks
5. Use and regularly update anti-virus software
6. Develop and maintain secure systems and
applications
7. Restrict access to cardholder data by business
need-to-know
8. Assign a unique ID to each person with computer
access
9. Restrict physical access to cardholder data
10. Track and monitor all access to network resources
and cardholder data
11. Regularly test security systems and processes
12. Maintain a policy that addresses information security


Clic here to read the story from its source.