Sunday, April 17, 2011

Payment Card Industry Data Security Standard Handbook

Posted by Bunseth Lik On 1:39 AM 0 comments

The PCI DSS is a standard that has evolved over many years by the efforts of the major payment card brands. Prior to PCI DSS, the major payment card brands individually developed various standards to improve the security of sensitive information used by the payment card industry. Visa USA had originally launched the Cardholder Information Security Program (CISP) in June 2001. From then until March 2004, these audit procedures underwent several revisions and continued to grow and evolve to address the many facets of protecting sensitive cardholder data. There was also early collaboration between MasterCard and Visa in an attempt to validate and protect cardholder data. During these early attempts at collaboration, some gaps and inconsistency occurred between the separate programs. Although well intentioned, the relationship had a number of problems. The list of approved vendors was not well maintained and there was no clear way for security vendors to get added to the list. Another signifi cant problem was that the other major payment card brands, such as Discover, American Express, and JCB (Japan Credit Bureau), were running their own programs and there was little collaboration across the entire industry.

Mediafire

0 comments:

Post a Comment