{"id":1826,"date":"2011-07-05T09:49:12","date_gmt":"2011-07-05T04:19:12","guid":{"rendered":"https:\/\/www.qadit.com\/blog\/?p=1826"},"modified":"2011-07-05T11:47:39","modified_gmt":"2011-07-05T06:17:39","slug":"understanding-pci-dss-compliance-requirements","status":"publish","type":"post","link":"https:\/\/qadit.com\/blog\/understanding-pci-dss-compliance-requirements\/","title":{"rendered":"Understanding PCI DSS compliance requirements"},"content":{"rendered":"<p style=\"text-align: justify\">Payment Card Industry Security Standards Council (PCI SSC) has prescribed PCI Data Security Standards \u00a0(PCI DSS) for keeping payment cardholder data secure. \u00a0PCI DSS applies to any business that stores, processes, or transmits cardholder data. In practice, this means PCI applies to all merchants that accept card payments, as well as to the member financial institutions and service providers that process the associated transactions. Matrix of the compliance requirements prescribed by PCI SSC is given in the table below. Before studying the table, it would be helpful to understand the terms cardholder data, merchant, service provider, acquirer, application scanning vendor and qualified security assessor.<!--more--><\/p>\n<p style=\"text-align: justify\">\n<p>&nbsp;<\/p>\n<p>Cardholder data \u2013 Cardholder data can be broadly categorized into 2 types. First type is that group of data that can be stored. They include (a) Primary Account Number (PAN), or the 16-digit account number (b) Cardholder name (c) Service code and (d) Expiration data. Second type includes Sensitive Authentication Data (SAD) which cannot be stored following authorization except by issuers. SAD includes full magnetic stripe or equivalent chip data, CAV2\/CVC2\/CVV2\/CID, or the three- or four-digit number used to verify of the card in card-not-present transactions, PIN\/PIN block, used in Chip-and-PIN cards primarily outside the US.<\/p>\n<p style=\"text-align: justify\">\n<p>&nbsp;<\/p>\n<p>Merchant &#8211; All merchants that store, process, or transmit cardholder data<\/p>\n<p style=\"text-align: justify\">\n<p>&nbsp;<\/p>\n<p>Service Provider &#8211; Service Providers are third party organizations that provide services to Merchants and other users related to the processing of card transactions. Service Providers include Authorized Processors, Third Party Processors, Gateway Providers, and any other providers to merchants of point of sale equipment, software, or systems or other payment processing solutions or services.<\/p>\n<p style=\"text-align: justify\">\n<p>&nbsp;<\/p>\n<p>Acquirer &#8211; An\u00a0acquiring bank\u00a0(or\u00a0acquirer) is the\u00a0<a title=\"Bank\" href=\"https:\/\/en.wikipedia.org\/wiki\/Bank\">bank<\/a> or financial institution that accepts credit or debit card payments for products or services on behalf of a merchant.<\/p>\n<p style=\"text-align: justify\">\n<p>&nbsp;<\/p>\n<p>Application Scanning Vendor (ASV) &#8211; Data security firm that has been qualified and trained by the PCI SSC to use a vulnerability scanning solution to determine compliance of their customers with the external vulnerability scanning requirement of PCI DSS Requirement<\/p>\n<p style=\"text-align: justify\">\n<p>&nbsp;<\/p>\n<p>Qualified Security Assessor (QSA) &#8211; Data security assessment firm that has been qualified and trained by PCI SSC to perform PCI DSS onsite assessments<\/p>\n<p style=\"text-align: justify\">&nbsp;<\/p>\n<p style=\"text-align: justify\"><a href=\"https:\/\/www.qadit.com\/blog\/wp-content\/untitled6.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignleft size-full wp-image-1833\" src=\"https:\/\/www.qadit.com\/blog\/wp-content\/untitled6.jpg\" alt=\"\" width=\"696\" height=\"770\" srcset=\"https:\/\/qadit.com\/blog\/wp-content\/uploads\/untitled6.jpg 696w, https:\/\/qadit.com\/blog\/wp-content\/uploads\/untitled6-271x300.jpg 271w\" sizes=\"auto, (max-width: 696px) 100vw, 696px\" \/><\/a><\/p>\n<p style=\"text-align: justify\">&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Payment Card Industry Security Standards Council (PCI SSC) has prescribed PCI Data Security Standards \u00a0(PCI DSS) for keeping payment cardholder data secure. \u00a0PCI DSS applies to any business that stores, processes, or transmits cardholder data. In practice, this means PCI applies to all merchants that accept card payments, as well as to the member financial &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/qadit.com\/blog\/understanding-pci-dss-compliance-requirements\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Understanding PCI DSS compliance requirements&#8221;<\/span><\/a><\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[9,12],"tags":[67],"class_list":["post-1826","post","type-post","status-publish","format-standard","hentry","category-banking","category-itsec","tag-pci-dss"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9AH7Q-ts","_links":{"self":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/1826","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/comments?post=1826"}],"version-history":[{"count":0,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/1826\/revisions"}],"wp:attachment":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/media?parent=1826"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/categories?post=1826"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/tags?post=1826"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}