Hosted Private Cloud Service Providers: Should They Be PCI Compliant?

October 8, 2014 • Published Categories PCI 101 Tags , , , ,
SSC Mobile and Cloud Guidlines

Question: We are considering moving a server containing cardholder data to a hosted private cloud provider.  Is it necessary that the provider have a PCI DSS assessment of their own and produce an Attestation of Compliance? What if they produce a report from an independent … Read more

Merchants: Know Your Service Providers!

August 7, 2014 • Published Categories PCI 101 Tags , , , , , , , , ,
Know your service provider

Know Your Customer There’s an acronym we use in the payments industry: KYC.  With KYC, which is Know Your Customer, we’re referring to ISOs’ and acquirers’ need to know the type of business each of their merchants conducts. If due diligence for KYC doesn’t take place, … Read more

Visa Issues Security Alert Regarding Insecure Remote Access

July 3, 2014 • Published Categories Industry Topics Tags , , , , , , , , , , , ,

The recent rash of data security breaches stemming from insecure remote access and user credential management issues has prompted Visa to issue a Data Security Alert to all merchants and the acquirers who serve them. Here is the statement from Visa’s email, which ControlScan received … Read more

“Does my backup services business need to be PCI compliant?”

May 6, 2014 • Published Categories PCI 101 Tags , , , ,

Question: I own a small MSP service that offers backup services for customers’ servers. Some of our hospitality customers for which we do nothing but this type of backup believe we need to be PCI compliant. All the data is fully encrypted before it is sent … Read more

5 Best Practices for Securing Your Small Biz

April 23, 2014 • Published Categories Best Practices Tags , , , , , , , , ,
Hosted Payment Technologies

The best way to truly strengthen your business’s security posture—which is the goal of the PCI DSS—is to have a sober understanding of your risk as well as the full scope of your PCI compliance responsibility. Here are five best practices for easily and cost-effectively … Read more

OpenSSL ‘Heartbleed’ Vulnerability Advisory

April 9, 2014 • Published Categories Industry Topics Tags , , ,

ControlScan advises its customers and clients with eCommerce websites, or those which handle sensitive data, that a critical vulnerability has been discovered affecting the OpenSSL 1.0.1 and 1.0.2-beta implementation of the SSL protocol. The vulnerability is known as ‘Heartbleed,’ and should be seen as an … Read more