Contact Us

Contact Us

Please get in touch using the form below

I prefer to be contacted by:
View our privacy policy
Find out if your organisation has been compromised by the Zerologon Windows server vulnerability. Download Zerologon Detector.

Overview

How to meet the latest payment card industry data security standards

If your business processes card transactions, protecting this highly sensitive information should be a high priority. Failure to introduce and maintain appropriate payment security standards could result in your organisation receiving significant fines and suffering serious reputational damage.

However, putting in place the range of controls needed to achieve compliance with the latest Payment Card Industry Data Security Standards (PCI DSS) can place a strain on your organisation.

As a leading provider of managed security and assessment services, Redscan can help your organisation to understand and implement the technical and operational controls needed to fulfil PCI requirements.

A montage of compliance related security images

About

What is PCI DSS?

The PCI DSS is a minimum set of technical and organisational requirements designed to help businesses protect customers’ cardholder data against fraud through robust payment security.

All organisations that accept or process credit card payments are required to undertake an annual PCI DSS audit of security controls and processes, covering areas of data security such as retention, encryption, physical security, authentication and access management.

PCI DSS is enforced by the founding members of the PCI Council: American Express, Discover Financial Services, JCB, MasterCard and Visa Inc. Organisations deemed to fall short of required payment security standards, or those who are not working towards achieving compliance, are liable to receive a fine.

Application

Who does PCI DSS apply to?

The PCI DSS applies to all organisations that store, process and transmit cardholder data (CHD) and/or sensitive authentication data (SAD). Examples of these types of organisations include merchants, processors, acquirers, issuers, and service providers.

Organisations that outsource payment operations are responsible for ensuring that all account data processed is suitably protected by contracted third parties.

PCI FAQ

PCI DSS frequently asked questions

What cardholder data is protected?

PCI DSS applies to all organisations, such as merchants and service providers, that store, process and transmit cardholder data (CHD) and/or sensitive authentication data (SAD).

Cardholder data includes: Primary Account Number, Cardholder Name, expiration date and service code.

Sensitive authentication data includes full track data (magnetic stripe data or equivalent on a chip) and CAV, CVC, CVV and CID numbers, PINS and PIN blocks.

Can cardholder data be stored?

Under PCI DSS, merchants and service providers are permitted to store cardholder data. Subject to specific usage and protection requirements, some acquirers may permit sensitive authentication data to be stored but only prior to payment authorisation.

What is within the scope of a PCI DSS assessment?

The PCI DSS security requirements apply to all system components included in or connected to an organisation’s cardholder data environment (CDE). The CDE encompasses all people, processes and technologies that store, process, or transmit cardholder and sensitive authentication data.

PCI DSS can apply across the whole of an organisation, or to a subset of it if the CDE has been correctly compartmentalised. System components in scope include network devices, servers, computing devices, and applications.

What’s the difference between merchants and service providers?

A merchant is defined as any entity that accepts payment cards from any of the five founding members of the PCI Security Standards Council (American Express, Discover, JCB, MasterCard or Visa) as payment for goods and/or services.

A service provider, on the other hand, is a business entity that is not a payment brand and is directly involved in the processing, storage, or transmission of cardholder data. If an organisation provides a service that involves only the provision of public network access, such as a telecommunications company providing a communication link, the organisation is not considered a service provider.

Note: Where a merchant stores, processes or transmits cardholder data on behalf of other merchants or services providers, it can also be a service provider.

Requirements

PCI requirements

The PCI DSS version 3.2 encompasses six key objectives, split across a set of 12 requirements.

Key PCI DSS requirements:

  • Build and maintain a secure network
  • Protect cardholder data
  • Maintain a vulnerability management programme
  • Implement strong access control measures
  • Regularly monitor and test networks
  • Maintain an information security policy

Our Services

Our award-winning services

Redscan’s security services are designed to provide the vital assistance needed to make tangible improvements to your organisation’s cyber security posture.

ThreatDetect MDR

Managed Detection and Response

Award-winning support to rapidly detect and respond to the latest threats 24/7

Read more

Assessment Services

Specialist engagements to uncover and address hidden cyber security risks

Read more
A person choosing from a range of Managed Security Services

Managed Security Services

Expert help to manage and monitor your choice of security technologies

Read more

Get in touch regarding PCI DSS

We’d be happy to answer any questions you have.

Two Redscan team members analysing cyber security intelligence

 

I prefer to be contacted by:
View our privacy policy

Resources

Discover our latest content and resources

From the blog
From the blog Case studies Latest news
20th October 2020
Remote working leaving UK businesses more vulnerable to cyber-attacks
New research suggests that while 60% of UK businesses experienced a cyber-attack and 44% of them were hit by a data breach over the past 12 months, 37% don't have a cyber incident response plan.  
6th October 2020
Europol report warns of cybercriminals targeting people working from home
Europol, the European Union police agency, has warned in a new report that cybercriminals are targeting people who are spending more time online due to the pandemic.
2nd October 2020
Redscan releases Zerologon detection tool
Redscan Labs has released Zerologon Detector, a detection tool that can help organisations to determine if they have been compromised as a result of a newly-disclosed, critical vulnerability in Windows Netlogon (CVE-2020-1472). Read more
30th September 2020
Redscan named in Gartner MDR Market Guide
Redscan is one of only two UK-based providers recognised in Gartner’s 2020 Market Guide for Managed Detection and Response. Read more in our press release.