Featured Article
Joan Herbig

PCI Compliance & Small Merchants: Whose Concern Is It Anyway?
Small merchants who want to accept credit cards as part of doing business can find themselves lost in a sea of information when it comes to PCI compliance. While it can be frustrating, the Payment Card Industry Data Security Standard (PCI DSS) has a worthwhile goal, and that is to ensure that credit card transactions are secure and consumers' sensitive data is protected.
At this point you may be thinking: That's all well and good, but isn't it up to my payment service provider to worry about PCI DSS? Shouldn't they be the ones to ensure I don't have a data breach?
Unfortunately, being an innocent bystander to the technology transmitting your payment data doesn't absolve your business should a data security breach occur. In fact, there are many actions only you can take to close security holes in your business systems.
Recent Articles
A Fresh New Start Means a Fresh New Look at your PCI Status
Happy New Year! It’s the time of year where many of us celebrate a fresh start and make new resolutions. Your resolution may have been one of the common ones: get to the gym more, stress less, actually use vacation days this year. Website hackers are no different.
How ISOs & Acquirers Can Assess, Educate and Protect Their Merchants.
The days of simply sending a newsletter or statement stuffer to a merchant describing the PCI requirements may no longer be sufficient to protect the Acquiring community (Sponsor Banks, Processors and ISOs) from the card brand obligations, liability and the impact of state law violations. Approximately 46 states have strict Security Breach Notification Laws and 25 states have Disposal Laws. Some states, Nevada, Massachusetts and Wisconsin specifically mention the Payment Card Industry Data Security Standard (PCI DSS) and/or Information Security Policies.
Security as a Checklist? Think Again.
The concept of summarizing Payment Card Industry (PCI) requirements into a simple checklist is a welcome one, especially for merchants without a dedicated security team and budget.
Is PCI Compliance a Law? Should it be?
Is PCI compliance a law? The short answer is no. The long answer is that while it is not currently a federal law, there are state laws that are already in effect (and some that may go into effect) to force components of the PCI Data Security Standard (PCI DSS) into law. In addition, there is a big push by legislatures and industry trade association to enact a federal law around data security and breach notification.
Read more...
Security vs. PCI Compliance
Reading accounts of highly publicized data breaches over the last few months occurring in companies that are seemingly PCI compliant, begs the question, “does PCI compliance equal security?” The answer is, “it depends.” Unfortunately no business is ever completely secure, but companies can mitigate their risk and make it much harder and more resource intensive for anyone to breach their defenses.
Beyond PCI: Other Regulations to Look For in 2009
Just a few days ago, the Federal Reserve, the Office of Thrift Supervision and the National Credit Union Administration announced the enactment of comprehensive new rules regarding card practices. These rules, which will not take effect until July 1, 2010, impose restrictions on a number of controversial issuer practices, including interest rate increases, late fees and double-cycle billing.

