PCI Compliance - Standards and Requirements: A Regulation Overview
In an effort to combat the threat of data theft, all of the leading payment card brands have come up with common industry security requirements that would safeguard sensitive data. The result: the Payment Card Industry (PCI) Data Security Standard.
The purpose of the PCI DSS is to protect cardholder information, reduce debit and credit card fraud, and identify security breaches by imposing strict standards on how cardholder data is handled and stored. Retailers who do not comply with PCI standards may be barred from processing credit card transactions, or face higher processing fees or fines of up to $500,000.
The 12 PCI compliance rules are:
- Install and maintain a firewall configuration to protect data.
- Do not use vendor-supplied defaults for system passwords and other security.
- Protect stored data. Learn more about how 2Encrypt can protect stored data
- Encrypt transmission of cardholder data and sensitive information across public networks. Learn more about how 2Encrypt can help encrypt transmission of sensitive information
- Use and regularly update anti-virus software.
- Develop and maintain secure systems and applications.
- Restrict access to data by business need-to-know.
- Assign a unique I.C. to each person with computer access.
- Restrict physical access to cardholder data.
- Track and monitor all access to network resources and cardholder data.
- Regularly test security systems and processes.
- Maintain a policy that addresses information security.
The most common cause of audit failures are related to rules 3 and 4 of the PCI Standards. Red Iron's 2Encrypt enterprise level encryption decryption solution takes care of these problems.
For a personal evaluation of whether 2Encrypt can help your organization, please Contact Us or Request Information.
Need more information?
- Download the White Paper: Bringing Legacy Systems into Compliance with PCI Standards
- Read the Case Study: Tier 1 retailer solves encryption headache with 2Encrypt
- Read our POS Encryption Module FAQ's







