<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2enclosuresfull.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>The Merchant Processing Guru</title>
	
	<link>http://www.themerchantprocessingguru.com</link>
	<description>Illuminating the Card Processing Industry</description>
	<lastBuildDate>Wed, 20 Feb 2013 22:38:44 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/TheMerchantProcessingGuru" /><feedburner:info uri="themerchantprocessingguru" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><itunes:explicit>no</itunes:explicit><itunes:subtitle>Illuminating the Card Processing Industry</itunes:subtitle><item>
		<title>The Merchant Processing Guru Tip# 37: The 12 requirements of PCI Compliance – Requirement #8</title>
		<link>http://feedproxy.google.com/~r/TheMerchantProcessingGuru/~3/EE5DiHqvawE/</link>
		<comments>http://www.themerchantprocessingguru.com/?p=901#comments</comments>
		<pubDate>Tue, 25 Sep 2012 03:12:37 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[access card]]></category>
		<category><![CDATA[biometric scanning]]></category>
		<category><![CDATA[cardholder data]]></category>
		<category><![CDATA[components]]></category>
		<category><![CDATA[computer access]]></category>
		<category><![CDATA[credentials]]></category>
		<category><![CDATA[credit card processing]]></category>
		<category><![CDATA[cryptography]]></category>
		<category><![CDATA[database]]></category>
		<category><![CDATA[employee]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[Merchant Services]]></category>
		<category><![CDATA[merchants]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[Password]]></category>
		<category><![CDATA[policies]]></category>
		<category><![CDATA[procedures]]></category>
		<category><![CDATA[system]]></category>
		<category><![CDATA[The Merchant Processing Guru]]></category>
		<category><![CDATA[tokenization]]></category>
		<category><![CDATA[two-factor authentication]]></category>
		<category><![CDATA[VPN]]></category>

		<guid isPermaLink="false">http://www.themerchantprocessingguru.com/?p=901</guid>
		<description><![CDATA[The Merchant Processing Guru Tip# 37: The 12 requirements of PCI Compliance – Requirement #8
   
Assign a unique ID to each person with computer access. <a class="more-link" href="http://www.themerchantprocessingguru.com/?p=901">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>The Merchant Processing Guru Tip# 37: The 12 requirements of PCI Compliance – Requirement #8</p>
<p><img class="alignright size-full wp-image-299" title="Password Authentication" src="http://www.themerchantprocessingguru.com/wp-content/uploads/2012/07/Password.jpg" alt="Password Authentication" width="195" height="175" /><br />
Assign a unique ID to each person with computer access. This requirement is requiring authentication for access by administrators, users and applications to any database containing cardholder data and the restriction of any database queries to administrators only.</p>
<p>You must assign a unique user name to each employee before allowing them access to any of your system’s components. Additionally you have 3 options for authenticating each user: A password, an access card or physical device and third biometric scanning or other recognition software.</p>
<p>If accessing the system via remote VPN or any other remote access to your network you should incorporate a two-factor authentication. For example one factor is login &#038; password, the other using tokenization or some other dual-factor authentication method.</p>
<p>Of course passwords should be unreadable to others using strong cryptography and you should ensure proper user identification &#038; authentication management on your system. This should include verification of the user’s identity before resetting a password. Control the addition, deletion or modification of a user’s credentials. Set all first time passwords using a unique value and require that the user change them immediately after first time use. Immediately revoke access to any terminated users and remove inactive user accounts every 90 days. Monitor vendor remote access and limit their access to the time period needed to perform their task. Require a minimum password length of at least 7 characters utilizing both numeric &#038; alphabetic characters and limit the use of the same password within a period of at least one year. Limit repeat access attempts to no more than six before locking out the user &#038; set the lockout for at least 30 minutes or until an administrator enables the user ID. Require the user to re-authenticate after being idle for 15 minutes.  Do not use any group, shared or generic accounts &#038; you should communicate all these policies &#038; procedures to all users with access to cardholder data. </p>
<p>Russell Harverson has over 9 years experience in the credit card processing industry and has built a reputation for “being there” for all his merchants! The goal of The Merchant Processing Guru is to provide you with the right, cost effective processing solution for your individual business needs, no matter how large, small or different, he has done it all. He is your Guru of Merchant Services, shedding light on the credit card processing industry. To contact him via email: theGuru@theMerchantProcessingGuru.com<br />
Or call him at: 1-888-368-GURU (4878) </p>
<img src="http://feeds.feedburner.com/~r/TheMerchantProcessingGuru/~4/EE5DiHqvawE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.themerchantprocessingguru.com/?feed=rss2&amp;p=901</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.themerchantprocessingguru.com/?p=901</feedburner:origLink></item>
		<item>
		<title>The Merchant Processing Guru Tip# 36: The 12 requirements of PCI Compliance – Requirement #7</title>
		<link>http://feedproxy.google.com/~r/TheMerchantProcessingGuru/~3/dEZXxlGPhGo/</link>
		<comments>http://www.themerchantprocessingguru.com/?p=883#comments</comments>
		<pubDate>Mon, 17 Sep 2012 18:58:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[access control system]]></category>
		<category><![CDATA[access rights]]></category>
		<category><![CDATA[authorized]]></category>
		<category><![CDATA[business]]></category>
		<category><![CDATA[cardholder data]]></category>
		<category><![CDATA[credit card processing]]></category>
		<category><![CDATA[login & password]]></category>
		<category><![CDATA[Merchant Services]]></category>
		<category><![CDATA[merchants]]></category>
		<category><![CDATA[networks]]></category>
		<category><![CDATA[privilages]]></category>
		<category><![CDATA[The Merchant Processing Guru]]></category>

		<guid isPermaLink="false">http://www.themerchantprocessingguru.com/?p=883</guid>
		<description><![CDATA[The Merchant Processing Guru Tip# 36: The 12 requirements of PCI Compliance – Requirement #7

“Restrict access to cardholder data by business need to know”. <a class="more-link" href="http://www.themerchantprocessingguru.com/?p=883">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>The Merchant Processing Guru Tip# 36: The 12 requirements of PCI Compliance – Requirement #7<br />
<img class="alignright size-full wp-image-299" title="Access Control Diagram" src="http://www.themerchantprocessingguru.com/wp-content/uploads/2012/09/Access-Control-Diagram.jpg" alt="Access Control Diagram" width="195" height="175" /><br />
“Restrict access to cardholder data by business need to know”. So not only should you keep your clients cardholder data secure from outside prying eyes but also you must limit the access to that data to those employees only who actually need access to it to perform their job responsibilities. This includes assigning individual access rights &amp; privileges to those individuals with access to your networks or other locations you store cardholder data.</p>
<p>This requirement also requires that you document written approval by an authorized party and of course that you actually implement an access control system whether it be with login &amp; password, lock and key, whatever serves the purpose.</p>
<p>An access control system with multiple users on a network should include the following:<br />
A default “deny-all” function so when adding a new user you must specifically grant them access,<br />
the ability to assign privileges based on job classification &amp; job functions for example; do not give the cook the same access privileges as a server or a nurse the same access privileges as the billing clerk.<br />
This access control should cover your entire system and it’s components.</p>
<p>Russell Harverson has over 9 years experience in the credit card processing industry and has built a reputation for “being there” for all his merchants! The goal of The Merchant Processing Guru is to provide you with the right, cost effective processing solution for your individual business needs, no matter how large, small or different, he has done it all. He is your Guru of Merchant Services, shedding light on the credit card processing industry. To contact him via email: theGuru@theMerchantProcessingGuru.com<br />
Or call him at: 1-888-368-GURU (4878)</p>
<img src="http://feeds.feedburner.com/~r/TheMerchantProcessingGuru/~4/dEZXxlGPhGo" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.themerchantprocessingguru.com/?feed=rss2&amp;p=883</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.themerchantprocessingguru.com/?p=883</feedburner:origLink></item>
		<item>
		<title>The Merchant Processing Guru Tip# 35: The 12 requirements of PCI Compliance – Requirement #6</title>
		<link>http://feedproxy.google.com/~r/TheMerchantProcessingGuru/~3/8Lk7m4TOPHc/</link>
		<comments>http://www.themerchantprocessingguru.com/?p=855#comments</comments>
		<pubDate>Thu, 02 Aug 2012 19:27:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[applications]]></category>
		<category><![CDATA[business]]></category>
		<category><![CDATA[common sense approach]]></category>
		<category><![CDATA[credit card data]]></category>
		<category><![CDATA[credit card processing]]></category>
		<category><![CDATA[developers]]></category>
		<category><![CDATA[developing software]]></category>
		<category><![CDATA[experience]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[guidlines]]></category>
		<category><![CDATA[level one certified]]></category>
		<category><![CDATA[Merchant Services]]></category>
		<category><![CDATA[merchants]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[public facing]]></category>
		<category><![CDATA[requirements]]></category>
		<category><![CDATA[secure systems]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security patches]]></category>
		<category><![CDATA[software applications]]></category>
		<category><![CDATA[systems]]></category>
		<category><![CDATA[The Merchant Processing Guru]]></category>
		<category><![CDATA[vendor supplied]]></category>
		<category><![CDATA[web-applications]]></category>

		<guid isPermaLink="false">http://www.themerchantprocessingguru.com/?p=855</guid>
		<description><![CDATA[The Merchant Processing Guru Tip# 35: The 12 requirements of PCI Compliance – Requirement #6

Develop and maintain secure systems and applications. <a class="more-link" href="http://www.themerchantprocessingguru.com/?p=855">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>The Merchant Processing Guru Tip# 35: The 12 requirements of PCI Compliance – Requirement #6</p>
<p><img class="alignright size-full wp-image-299" title="Software Security updates" src="http://www.themerchantprocessingguru.com/wp-content/uploads/2012/08/SoftwareUpdates.jpg" alt="Software Security Updates" width="195" height="175" /><br />
Develop and maintain secure systems and applications. This one is probably the most technical and complicated of all the requirements but unless you are developing software yourself for use with credit card processing most of the items in this requirement should not apply to you. Much of this requirement is geared to developers &#038; so should you be utilizing software applications that have been developed by others just make sure they are PCI DSS level one certified, then not everything in this requirement will apply to you but the developer, please make sure however to implement what does apply to you such as the following: </p>
<p>Firstly you are required to install the latest vendor supplied security patches for all software on your systems within one month of release. Scan at least annually all public facing web-applications and make sure there is a web-application firewall in front of public-facing web applications.</p>
<p>Again, my summaries of each requirement are to help explain the requirements in an easy to understand manner, please refer to the PCI DSS and follow its guidelines to become fully compliant. We are now half way through the requirements and as you can see they are a common sense approach to protecting the security of your customer’s credit card data. I hope this series is making it a little less daunting to comply with PCI DSS. Please don’t hesitate to contact me with any questions.</p>
<p>Russell Harverson has over 9 years experience in the credit card processing industry and has built a reputation for “being there” for all his merchants! The goal of The Merchant Processing Guru is to provide you with the right, cost effective processing solution for your individual business needs, no matter how large, small or different, he has done it all. He is your Guru of Merchant Services, shedding light on the credit card processing industry. To contact him via email: theGuru@theMerchantProcessingGuru.com<br />
Or call him at: 1-888-368-GURU (4878)  </p>
<img src="http://feeds.feedburner.com/~r/TheMerchantProcessingGuru/~4/8Lk7m4TOPHc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.themerchantprocessingguru.com/?feed=rss2&amp;p=855</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.themerchantprocessingguru.com/?p=855</feedburner:origLink></item>
		<item>
		<title>The Merchant Processing Guru Tip# 34: The 12 requirements of PCI Compliance – Requirement #5</title>
		<link>http://feedproxy.google.com/~r/TheMerchantProcessingGuru/~3/DvkH4QmP62s/</link>
		<comments>http://www.themerchantprocessingguru.com/?p=848#comments</comments>
		<pubDate>Mon, 30 Jul 2012 21:54:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[anti spyware]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[audit logs]]></category>
		<category><![CDATA[credit card processing]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[malicious software]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Merchant Services]]></category>
		<category><![CDATA[merchants]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[professional]]></category>
		<category><![CDATA[programs]]></category>
		<category><![CDATA[provider]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[server]]></category>
		<category><![CDATA[station]]></category>
		<category><![CDATA[system]]></category>
		<category><![CDATA[The Merchant Processing Guru]]></category>

		<guid isPermaLink="false">http://www.themerchantprocessingguru.com/?p=848</guid>
		<description><![CDATA[The Merchant Processing Guru Tip# 34: The 12 requirements of PCI Compliance – Requirement #5

Use and regularly update anti-virus software or programs <a class="more-link" href="http://www.themerchantprocessingguru.com/?p=848">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>The Merchant Processing Guru Tip# 34: The 12 requirements of PCI Compliance – Requirement #5</p>
<p><img class="alignright size-full wp-image-299" title="Network lock" src="http://www.themerchantprocessingguru.com/wp-content/uploads/2012/07/virus_free.jpg" alt="Network lock" width="195" height="175" /><br />
Use and regularly update anti-virus software or programs. This one really is simple and so this post will be a short one. Here I would invest in a complete security suit from a top rated, professional security software provider that includes not only the anti-virus software but also anti spyware, malware and every kind of known malicious software out there. You can also get it with a firewall which will not replace the firewall required in requirement #1 but enhance it with the required PC software firewall on each system. </p>
<p>You must keep this software up to date and current with all security updates and it must be capable of generating audit logs. Again, this needs to be loaded on each system that is on your network from the server to every station and device that connects to the network. </p>
<p>Russell Harverson has over 9 years experience in the credit card processing industry and has built a reputation for “being there” for all his merchants! The goal of The Merchant Processing Guru is to provide you with the right, cost effective processing solution for your individual business needs, no matter how large, small or different, he has done it all. He is your Guru of Merchant Services, shedding light on the credit card processing industry. To contact him via email: theGuru@theMerchantProcessingGuru.com<br />
Or call him at: 1-888-368-GURU (4878)</p>
<img src="http://feeds.feedburner.com/~r/TheMerchantProcessingGuru/~4/DvkH4QmP62s" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.themerchantprocessingguru.com/?feed=rss2&amp;p=848</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.themerchantprocessingguru.com/?p=848</feedburner:origLink></item>
		<item>
		<title>The Merchant Processing Guru Tip# 33: The 12 requirements of PCI Compliance – Requirement #4</title>
		<link>http://feedproxy.google.com/~r/TheMerchantProcessingGuru/~3/uRWHv9bow7M/</link>
		<comments>http://www.themerchantprocessingguru.com/?p=820#comments</comments>
		<pubDate>Thu, 12 Jul 2012 18:42:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[business]]></category>
		<category><![CDATA[cardholder data]]></category>
		<category><![CDATA[certified]]></category>
		<category><![CDATA[configuration]]></category>
		<category><![CDATA[Credit card]]></category>
		<category><![CDATA[credit card processing]]></category>
		<category><![CDATA[data centers]]></category>
		<category><![CDATA[decrypted]]></category>
		<category><![CDATA[dedicated data connection]]></category>
		<category><![CDATA[dial up]]></category>
		<category><![CDATA[Encryption]]></category>
		<category><![CDATA[End-to-End Encrypted]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[Hypercom]]></category>
		<category><![CDATA[IEEE 802.11]]></category>
		<category><![CDATA[internet]]></category>
		<category><![CDATA[Merchant Processing]]></category>
		<category><![CDATA[Merchant Services]]></category>
		<category><![CDATA[merchants]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[payment]]></category>
		<category><![CDATA[PCI PTS 3.0]]></category>
		<category><![CDATA[processor]]></category>
		<category><![CDATA[public networks]]></category>
		<category><![CDATA[secure facility]]></category>
		<category><![CDATA[SSL encryption]]></category>
		<category><![CDATA[SSL secured gateway]]></category>
		<category><![CDATA[tamper proof]]></category>
		<category><![CDATA[terminal]]></category>
		<category><![CDATA[The Merchant Processing Guru]]></category>
		<category><![CDATA[transmitting]]></category>
		<category><![CDATA[Verifone]]></category>
		<category><![CDATA[Verifone's Vx510]]></category>
		<category><![CDATA[virtual terminal]]></category>
		<category><![CDATA[VoIP]]></category>
		<category><![CDATA[VSP]]></category>
		<category><![CDATA[Vx Evolution]]></category>
		<category><![CDATA[WEP]]></category>
		<category><![CDATA[wifi]]></category>
		<category><![CDATA[WPA2]]></category>

		<guid isPermaLink="false">http://www.themerchantprocessingguru.com/?p=820</guid>
		<description><![CDATA[The Merchant Processing Guru Tip# 33: The 12 requirements of PCI Compliance – Requirement #4

Encrypt transmission of cardholder data across open public networks. <a class="more-link" href="http://www.themerchantprocessingguru.com/?p=820">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>The Merchant Processing Guru Tip# 33: The 12 requirements of PCI Compliance – Requirement #4<br />
<img class="alignright size-full wp-image-299" title="Network lock" src="http://www.themerchantprocessingguru.com/wp-content/uploads/2012/07/network_lock.jpg" alt="Network lock" width="195" height="175" /><br />
Encrypt transmission of cardholder data across open public networks. I will explain first what the open, public network means and the different ways you can be transmitting across your network and how this affects you. An open  public network basically means any network connected to the internet as once your data leaves your network, even if your network&#8217;s sole use is for transmitting credit card data, you are transmitting over the public internet. If you are transmitting cardholder data via the internet in your business, either via an internet enabled terminal, a virtual terminal or a wireless device that is either Wifi enabled or has a dedicated data connection you should be using an industry accepted form of encryption such as IEEE 802.11 for wireless, otherwise known as WPA2. WEP is no longer accepted as an approved encryption method for wireless where the transmission of cardholder data is conducted.</p>
<p>When using a virtual terminal or selling items on the web you must have an SSL secured gateway where your customer’s cardholder information is entered for purchase of your product or service. You will know if it is secured when you are on the payment screen and in the URL at the beginning you will see https:// (The `s’ indicates an SSL secured page).</p>
<p>You might say that you are using a dial up terminal through a phone line so this does not apply to you. Well if you are using an analog POTS line (Plain Old Telephone Service), you may be right but should you be on a system such as VoIP then you are in fact transmitting the data over the internet as VoIP translates your sound waves to a digital signal and sends it as packets over the internet which is then vulnerable to hackers.</p>
<p>There are terminals that are emerging in the market that are End-to-End Encrypted so that no matter what happens to the data, it cannot be decrypted by anyone other than the processor with the key in their own data centers. This is the wave of the future as even a WPA2 encrypted wireless network is still not 100% secure. The best example of this is Verifone’s Vx510 VSP, this terminal uses SSL encryption as well as triple DES encryption. It encrypts the information as you swipe the card on the card reader itself, before it goes anywhere else and the encrypted card information is transmitted from the terminal over the internet to the processor directly and only then as it reaches the processor is it decrypted in their secure data center. This terminal is tamper proof and will not allow anyone to change it’s configuration. It can only be programmed at the processor’s secure facility, so no one who is not authorized can load anything into the terminal. Verifone has also recently launched a new line of Vx terminals that they are calling the Vx Evolution, I have yet to try any of these so I cannot talk about them yet. These newer Vx Evolution terminals are reported to be PCI PTS 3.0 certified and are all End-to-End encrypted which just confirms the industry shift to a higher level of encryption. Verifone is the industry leader in credit card processing terminals manufacturing and has recently purchased Hypercom their largest US competitor.</p>
<p>Russell Harverson has over 9 years experience in the credit card processing industry and has built a reputation for “being there” for all his merchants! The goal of The Merchant Processing Guru is to provide you with the right, cost effective processing solution for your individual business needs, no matter how large, small or different, he has done it all. He is your Guru of Merchant Services, shedding light on the credit card processing industry. To contact him via email: theGuru@theMerchantProcessingGuru.com<br />
Or call him at: 1-888-368-GURU (4878)</p>
<img src="http://feeds.feedburner.com/~r/TheMerchantProcessingGuru/~4/uRWHv9bow7M" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.themerchantprocessingguru.com/?feed=rss2&amp;p=820</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.themerchantprocessingguru.com/?p=820</feedburner:origLink></item>
		<item>
		<title>The Merchant Processing Guru Tip# 32: The 12 requirements of PCI Compliance – Requirement #3</title>
		<link>http://feedproxy.google.com/~r/TheMerchantProcessingGuru/~3/FLIDeGfYQEk/</link>
		<comments>http://www.themerchantprocessingguru.com/?p=787#comments</comments>
		<pubDate>Mon, 09 Jul 2012 16:23:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[access]]></category>
		<category><![CDATA[account number]]></category>
		<category><![CDATA[billing]]></category>
		<category><![CDATA[business]]></category>
		<category><![CDATA[business purposes]]></category>
		<category><![CDATA[businesses]]></category>
		<category><![CDATA[cardholder data]]></category>
		<category><![CDATA[compliant]]></category>
		<category><![CDATA[credit card processing]]></category>
		<category><![CDATA[cryptographic keys]]></category>
		<category><![CDATA[customer]]></category>
		<category><![CDATA[customer vault]]></category>
		<category><![CDATA[customers]]></category>
		<category><![CDATA[CVV2]]></category>
		<category><![CDATA[data]]></category>
		<category><![CDATA[disposal policy]]></category>
		<category><![CDATA[experation date]]></category>
		<category><![CDATA[future payments]]></category>
		<category><![CDATA[information]]></category>
		<category><![CDATA[magnetic strip]]></category>
		<category><![CDATA[Merchant Services]]></category>
		<category><![CDATA[merchants]]></category>
		<category><![CDATA[payments]]></category>
		<category><![CDATA[pin number]]></category>
		<category><![CDATA[procedure]]></category>
		<category><![CDATA[reoccurring charges]]></category>
		<category><![CDATA[secured]]></category>
		<category><![CDATA[SSL secured online gateway]]></category>
		<category><![CDATA[The Merchant Processing Guru]]></category>
		<category><![CDATA[track data]]></category>
		<category><![CDATA[truncation]]></category>
		<category><![CDATA[unsecured]]></category>

		<guid isPermaLink="false">http://www.themerchantprocessingguru.com/?p=787</guid>
		<description><![CDATA[The Merchant Processing Guru Tip# 32: The 12 requirements of PCI Compliance – Requirement #3

Protect stored cardholder data. First of all let me say that if you do not need to store card holder data then don’t. <a class="more-link" href="http://www.themerchantprocessingguru.com/?p=787">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>The Merchant Processing Guru Tip# 32: The 12 requirements of PCI Compliance – Requirement #3</p>
<p><img class="alignright size-full wp-image-299" title="Password screen" src="http://www.themerchantprocessingguru.com/wp-content/uploads/2012/07/cardholder-data-protection.jpg" alt="Password" width="175" height="150" /><br />
Protect stored cardholder data. First of all let me say that if you do not need to store card holder data then don’t. Many businesses however need to keep cardholder data on file to make future payments from their customers easier for themselves and their customer. So if this describes you and your business then you must be very careful how and where you store this data and there is still certain data that is not allowed under PCI to store such as the 3-4 digits on the back of the card (CVV2), anyone’s pin number for debit cards or the full track data from the magnetic strip of the card. Basically all you can store is the cardholder name, expiration date and the account number which needs to be unreadable through truncation of at least the second set of 6 digits, the first 6 &amp; last 4 being readable. These must be secured using cryptographic keys.</p>
<p>You must implement a disposal policy and procedure of the cardholder data that is gathered so as not to have it unsecured anywhere and to dispose of the information stored after it is no longer needed. You are also required to limit access to this information to only those who need to have access to it for business purposes.</p>
<p>If you do need to store cardholder information for future payments you have many options today that will allow you to do so in a compliant manner depending upon your business needs. Should you have the need for monthly reoccurring charges that are charged at the same time every month for the same amount then a simple SSL secured online gateway with reoccurring billing enabled is a great option. However should you need to keep a card on “file” for an unknown future billing amount and date then you can store your customer information in a secure online “customer vault”.</p>
<p>Russell Harverson has over 9 years experience in the credit card processing industry and has built a reputation for “being there” for all his merchants! The goal of The Merchant Processing Guru is to provide you with the right, cost effective processing solution for your individual business needs, no matter how large, small or different, he has done it all. He is your Guru of Merchant Services, shedding light on the credit card processing industry. To contact him via email: theGuru@theMerchantProcessingGuru.com<br />
Or call him at: 1-888-368-GURU (4878)</p>
<img src="http://feeds.feedburner.com/~r/TheMerchantProcessingGuru/~4/FLIDeGfYQEk" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.themerchantprocessingguru.com/?feed=rss2&amp;p=787</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.themerchantprocessingguru.com/?p=787</feedburner:origLink></item>
		<item>
		<title>The Merchant Processing Guru Tip# 31: The 12 requirements of PCI Compliance – Requirement #2</title>
		<link>http://feedproxy.google.com/~r/TheMerchantProcessingGuru/~3/p3wsWgHpb1Y/</link>
		<comments>http://www.themerchantprocessingguru.com/?p=763#comments</comments>
		<pubDate>Mon, 02 Jul 2012 17:21:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[best practice]]></category>
		<category><![CDATA[credit card processing]]></category>
		<category><![CDATA[credit card terminals]]></category>
		<category><![CDATA[encrypt]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[industry]]></category>
		<category><![CDATA[IT company]]></category>
		<category><![CDATA[Merchant Processing]]></category>
		<category><![CDATA[Merchant Services]]></category>
		<category><![CDATA[merchants]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[PCI compliant]]></category>
		<category><![CDATA[PCI DSS Prioritized approach]]></category>
		<category><![CDATA[PCI DSS Requirements]]></category>
		<category><![CDATA[POS systems]]></category>
		<category><![CDATA[requirements of PCI Compliance]]></category>
		<category><![CDATA[routers]]></category>
		<category><![CDATA[securing your data]]></category>
		<category><![CDATA[securing your network]]></category>
		<category><![CDATA[security parameters]]></category>
		<category><![CDATA[system configuration standards]]></category>
		<category><![CDATA[system passwords]]></category>
		<category><![CDATA[The Merchant Processing Guru]]></category>
		<category><![CDATA[vendor passwords]]></category>
		<category><![CDATA[VPN]]></category>
		<category><![CDATA[web-based administrative access]]></category>
		<category><![CDATA[wireless devices]]></category>

		<guid isPermaLink="false">http://www.themerchantprocessingguru.com/?p=763</guid>
		<description><![CDATA[The Merchant Processing Guru Tip# 31: The 12 requirements of PCI Compliance – Requirement #2

Do not use vendor-supplied defaults for system passwords and other security parameters <a class="more-link" href="http://www.themerchantprocessingguru.com/?p=763">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>The Merchant Processing Guru Tip# 31: The 12 requirements of PCI Compliance – Requirement #2</p>
<p><img class="alignright size-full wp-image-299" title="Password screen" src="http://www.themerchantprocessingguru.com/wp-content/uploads/2012/06/password-on-screen.jpg" alt="Password" width="175" height="150" /><br />
Do not use vendor-supplied defaults for system passwords and other security parameters. This one is actually fairly simple but many still do not change vendor passwords on their security devices this requirement asks for them to be changed on. The reason for this is quite simple, the vendor default passwords are so widely known that it is easy for a hacker to try this first when trying to gain access and they are likely to know pretty much all default passwords or can find them out with a simple search.</p>
<p>To be clear you must change the vendor default password on everything that is connected to your network including routers, POS systems, wireless devices, credit card terminals etc. This requirement also asks that you implement and update regularly your system configuration standards and encrypt any web-based administrative access via VPN. If this is beyond your technical abilities, please look into hiring an IT company to help you do this, it is so important and it will not cost that much to have an IT company do these things.</p>
<p>With these first 2 posts you should have a good idea of what securing your network means and that it really is not overly burdensome but is basically a best practice anyway to securing your data and that of your customers. You are now well on your way to understanding what PCI is and what you need to do to become compliant. Again, this is just a summary so please refer to the PCI DSS Requirements for more information as there are particular requirements that they have and I do not cover everything in this summary. You can find a great resource here for the PCI DSS Prioritized approach to becoming PCI compliant: <a href="http://bit.ly/Lg1LFj" target="_blank">PCI DSS Prioritized Approach</a></p>
<p>Russell Harverson has over 9 years experience in the credit card processing industry and has build a reputation for “being there” for all his merchants! The goal of The Merchant Processing Guru is to provide you with the right, cost effective processing solution for your individual business needs, no matter how large, small or different, he has done it all. He is your Guru of Merchant Services, shedding light on the credit card processing industry. To contact him via email: theGuru@theMerchantProcessingGuru.com<br />
Or call him at: 1-888-368-GURU (4878)</p>
<img src="http://feeds.feedburner.com/~r/TheMerchantProcessingGuru/~4/p3wsWgHpb1Y" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.themerchantprocessingguru.com/?feed=rss2&amp;p=763</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.themerchantprocessingguru.com/?p=763</feedburner:origLink></item>
		<item>
		<title>The Merchant Processing Guru Tip# 30: The 12 requirements of PCI Compliance – Requirement # 1</title>
		<link>http://feedproxy.google.com/~r/TheMerchantProcessingGuru/~3/BtbFaJ7eFRs/</link>
		<comments>http://www.themerchantprocessingguru.com/?p=748#comments</comments>
		<pubDate>Tue, 26 Jun 2012 01:21:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[business]]></category>
		<category><![CDATA[Card Processing]]></category>
		<category><![CDATA[cardholder]]></category>
		<category><![CDATA[compliant]]></category>
		<category><![CDATA[configuration]]></category>
		<category><![CDATA[credit card processing]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[IT company]]></category>
		<category><![CDATA[IT person]]></category>
		<category><![CDATA[Merchant Processing]]></category>
		<category><![CDATA[Merchant Services]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[overview]]></category>
		<category><![CDATA[Password]]></category>
		<category><![CDATA[PCI requirements]]></category>
		<category><![CDATA[PCI Security Standards]]></category>
		<category><![CDATA[public access]]></category>
		<category><![CDATA[Requirement]]></category>
		<category><![CDATA[router]]></category>
		<category><![CDATA[sensitive information]]></category>
		<category><![CDATA[The Merchant Processing Guru]]></category>
		<category><![CDATA[wifi]]></category>

		<guid isPermaLink="false">http://www.themerchantprocessingguru.com/?p=748</guid>
		<description><![CDATA[The Merchant Processing Guru Tip# 30: The 12 requirements of PCI Compliance – Requirement # 1
What I will try to do in this series is summarize the main objectives of each of the PCI requirements <a class="more-link" href="http://www.themerchantprocessingguru.com/?p=748">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>The Merchant Processing Guru Tip# 30: The 12 requirements of PCI Compliance – Requirement # 1</p>
<p><img class="alignright size-full wp-image-299" title="PCI Secure Network" src="http://www.themerchantprocessingguru.com/wp-content/uploads/2012/06/secure_network.jpg" alt="PCI Secure Network" width="175" height="150" /><br />
What I will try to do in this series is summarize the main objectives of each of the PCI requirements, giving you an easy to follow &amp; understand overview of what you need to do to become compliant. Please keep in mind though that this is a summary, so please refer to the PCI Security Standards for a full description of what is required of your business.</p>
<p>Requirement #1. Install and maintain a firewall configuration to protect cardholder data. Sounds simple right? Got Firewall, good to go! Unfortunately just having a firewall does not fulfill this requirement, there are steps that you need to take to make sure your firewall is not only in existence but PCI requires that it be configured in a certain way, which I will specify, have periodic tests and procedures in place to make sure your firewall is effectively doing what it needs to do. Of course if you have a network, they are referring to a physical firewall in your router or some other standalone device, not a software firewall. Configuration should include restricting the flow of traffic from unknown sources, prohibit public access to any cardholder sensitive information and in addition, have personal firewall software on any wireless device or personal computers that have access to your network. This also means that if you are allowing wifi connectivity to the public (your customers, visitors etc.),  you should at  a minimum have a password on it that you change periodically and limit access to the rest of your network. But the best solution would be to have a separate network for your public wifi access.</p>
<p>If you have a network and do not have an IT person on staff who can configure this for you then I suggest that you find an IT company who understands these requirements and has had experience implementing networks that adhere to these requirements in other businesses.</p>
<p>Russell Harverson has over 9 years experience in the credit card processing industry and has build a reputation for “being there” for all his merchants! The goal of The Merchant Processing Guru is to provide you with the right, cost effective processing solution for your individual business needs, no matter how large, small or different, he has done it all. He is your Guru of Merchant Services, shedding light on the credit card processing industry. To contact him via email: theGuru@theMerchantProcessingGuru.com<br />
Or call him at: 1-888-368-GURU (4878)</p>
<img src="http://feeds.feedburner.com/~r/TheMerchantProcessingGuru/~4/BtbFaJ7eFRs" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.themerchantprocessingguru.com/?feed=rss2&amp;p=748</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.themerchantprocessingguru.com/?p=748</feedburner:origLink></item>
		<item>
		<title>The Merchant Processing Guru Tip# 29: So why is PCI so important anyway?</title>
		<link>http://feedproxy.google.com/~r/TheMerchantProcessingGuru/~3/LixHq5608-k/</link>
		<comments>http://www.themerchantprocessingguru.com/?p=716#comments</comments>
		<pubDate>Tue, 19 Jun 2012 19:57:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[12 requirements]]></category>
		<category><![CDATA[acquire]]></category>
		<category><![CDATA[Associations]]></category>
		<category><![CDATA[breach]]></category>
		<category><![CDATA[business]]></category>
		<category><![CDATA[cardholder data]]></category>
		<category><![CDATA[cardholder data security]]></category>
		<category><![CDATA[Compliance]]></category>
		<category><![CDATA[credit card data]]></category>
		<category><![CDATA[credit cards]]></category>
		<category><![CDATA[data breaches]]></category>
		<category><![CDATA[data theft]]></category>
		<category><![CDATA[forensic audits]]></category>
		<category><![CDATA[HIPAA violation]]></category>
		<category><![CDATA[industry]]></category>
		<category><![CDATA[investigate]]></category>
		<category><![CDATA[medical industry]]></category>
		<category><![CDATA[merchant account]]></category>
		<category><![CDATA[merchant agreement]]></category>
		<category><![CDATA[Merchant Processing]]></category>
		<category><![CDATA[minimum standard]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[patient information]]></category>
		<category><![CDATA[PCI]]></category>
		<category><![CDATA[PCI compliant]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[PCI program]]></category>
		<category><![CDATA[regulate]]></category>
		<category><![CDATA[safeguard]]></category>
		<category><![CDATA[small business]]></category>
		<category><![CDATA[The Merchant Processing Guru]]></category>
		<category><![CDATA[threat]]></category>
		<category><![CDATA[video interview]]></category>

		<guid isPermaLink="false">http://www.themerchantprocessingguru.com/?p=716</guid>
		<description><![CDATA[The Merchant Processing Guru Tip# 29: So why is PCI so important anyway?

Before I get into the 12 requirements of PCI DSS Compliance I wanted to reiterate why this is so important <a class="more-link" href="http://www.themerchantprocessingguru.com/?p=716">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>The Merchant Processing Guru Tip# 29: So why is PCI so important anyway?</p>
<p>Before I get into the 12 requirements of PCI DSS Compliance I wanted to reiterate why this is so important in the first place. We still do not hear stories every evening on the news about data breaches, so is this even a real concern? The answer is a resounding YES! If you wait for a breach to happen to someone on your street or you begin to hear about it more often and plan to implement a PCI program as and when the threat becomes apparent, it just may be too late and it could cost you your business.</p>
<p>Anyone with a merchant account who processes any credit cards at all, even one a year, not only must be PCI compliant but is more vulnerable that you can even begin to fathom. The first reason to become PCI compliant is because when you sign a merchant agreement you are contractually responsible and bound to the acquirer to meet all requirements of PCI DSS. This means that if you do not become compliant within a certain amount of time you are in violation of the merchant agreement and you are fully responsible for any breach that occurs. Above all, a breach could be so devastating to a small business that the fines and required forensic audits alone could put you out of business. A forensic audit that is ordered by the associations to investigate how the breach occurred could cost as much as $10,000 or more, even if you are not at fault, and the fines from the Associations could be as high as $30 &#8211; $50 for each card number that was stolen and in most cases thousands of card numbers are stole, you do the math!</p>
<p>Another great reason is just to protect your customer’s cardholder data. Breaches occurred long before PCI compliance even existed and the increase in this crime over the years, along with the lack of response from the industry to safeguard against this has brought the Associations to regulate it and create a minimum standard for cardholder data security that everyone needs to adhere to. But the fact of the matter is that we should all be as concerned, if not more so, about protecting our customers data than we are about covering our backside if something were to happen…</p>
<p>The data breach of TJ Maxx in 2006 was easily executed from a laptop in a car in the parking lot. The criminals were able to easily access the stores wifi and download all the information that they wanted from their network that was completely open. Since then PCI DSS was established and most of these big box stores have implemented all the PCI requirements and now the hackers have moved on to smaller, easier targets for the most part. This leaves the small business owners who have not yet taken PCI compliance as seriously, vulnerable to attack.</p>
<p>If you are in the medical industry a PCI data breach is also a HIPAA violation, if you think about it a patient’s credit card data is patient information just like any other patient information. So if you have to comply with HIPAA, PCI DSS should be incorporated with your HIPAA policies and procedures and you should adhere to the 12 PCI requirements as fervently as to HIPAA regulations. Your practice may depend on it. Unfortunately, the medical industry is one of the industries that are seeing a huge increase in data theft.</p>
<p>Still not convinced? Here is a video interview of someone who experienced a data breach first hand and was brave enough to share and warn others about it:</p>
<p><iframe src="http://www.youtube.com/embed/JsfUdY89lJc" frameborder="0" width="420" height="315"></iframe></p>
<img src="http://feeds.feedburner.com/~r/TheMerchantProcessingGuru/~4/LixHq5608-k" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.themerchantprocessingguru.com/?feed=rss2&amp;p=716</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.themerchantprocessingguru.com/?p=716</feedburner:origLink></item>
		<item>
		<title>The Merchant Processing Guru Tip# 28: PCI Compliance – Where to begin?</title>
		<link>http://feedproxy.google.com/~r/TheMerchantProcessingGuru/~3/f3_AL0GlTxw/</link>
		<comments>http://www.themerchantprocessingguru.com/?p=657#comments</comments>
		<pubDate>Mon, 21 May 2012 18:57:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[12 requirements]]></category>
		<category><![CDATA[Acquirer]]></category>
		<category><![CDATA[best practices]]></category>
		<category><![CDATA[ControlScan]]></category>
		<category><![CDATA[credit card processing]]></category>
		<category><![CDATA[leading authority]]></category>
		<category><![CDATA[merchant]]></category>
		<category><![CDATA[Merchant Processing]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[PCI approved vendor]]></category>
		<category><![CDATA[PCI requirements]]></category>
		<category><![CDATA[PCI Security]]></category>
		<category><![CDATA[processing solution]]></category>
		<category><![CDATA[quarterly scan]]></category>
		<category><![CDATA[secure yournetwork]]></category>
		<category><![CDATA[Self Assessment Questionnaire]]></category>
		<category><![CDATA[technical]]></category>
		<category><![CDATA[The Merchant Processing Guru]]></category>
		<category><![CDATA[thriving business]]></category>
		<category><![CDATA[validate PCI compliance]]></category>
		<category><![CDATA[white paper]]></category>

		<guid isPermaLink="false">http://www.themerchantprocessingguru.com/?p=657</guid>
		<description><![CDATA[The Merchant Processing Guru Tip# 28: PCI Compliance – Where to begin?
You could say the first place to begin is to identify what level of merchant you are <a class="more-link" href="http://www.themerchantprocessingguru.com/?p=657">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
				<content:encoded><![CDATA[<p>The Merchant Processing Guru Tip# 28: PCI Compliance – Where to begin?<br />
</br><br />
You could say the first place to begin is to identify what level of merchant you are, so you know what is required of you.  See the chart below  so you can determine what level you fit in to. Don’t be fooled by the chart though, most level 3 &amp; 4 merchants look at the chart and think that they only have to complete a “Self Assessment Questionnaire”, have a quarterly scan completed on their network every quarter by a PCI approved vendor and validate PCI compliance with the Acquirer. This is not necessarily true as they are assuming at this point that you have completed steps 1 thru 12 of the PCI requirements. If you have not gone through each one of these requirements and fulfilled every requirement then you are not compliant! I will go through each of these 12 requirements in my next several posts and explain the steps you need to take in each one to help you understand what you need to do to become compliant.<br />
</br><br />
<img src="http://www.themerchantprocessingguru.com/wp-content/uploads/2012/05/PCI-Merchant-Levels.png" alt="PCI Merchant Levels" title="PCI Merchant Levels" width="460" height="463" class="aligncenter size-full wp-image-59" /><br />
</br></p>
<p>Meanwhile a really good white paper was released last Monday by ControlScan, a leading authority in the PCI compliance space, that explains the main steps a merchant should take to become PCI compliant. It is a great overview of the best practices any merchant should take. It gets a little technical in places but don’t let that alarm you, this information can help you hire the right IT or PCI Security people to help you take the steps necessary to secure your network. Basically, if you need help becoming PCI compliant get the help, it could mean the difference between building a thriving business or going out of business, it’s that simple!<br />
</br><br />
Here is the link to the white paper from ControlScan:<br />
</br></p>
<p><a href="http://www.controlscan.com/whitepapers/top_5_security_best_practices.php" target="_blank">www.controlscan.com</a><br />
</br><br />
Russell Harverson has over 9 years experience in the credit card processing industry and has build a reputation for “being there” for all his merchants! The goal of The Merchant Processing Guru is to provide you with the right, cost effective processing solution for your individual business needs, no matter how large, small or different, he has done it all. He is your Guru of Merchant Processing, shedding light on the credit card processing industry. To contact him via email: theGuru@theMerchantProcessingGuru.com<br />
Or call him at: 1-888-368-GURU (4878)</p>
<img src="http://feeds.feedburner.com/~r/TheMerchantProcessingGuru/~4/f3_AL0GlTxw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.themerchantprocessingguru.com/?feed=rss2&amp;p=657</wfw:commentRss>
		<slash:comments>4</slash:comments>
		<feedburner:origLink>http://www.themerchantprocessingguru.com/?p=657</feedburner:origLink></item>
	<media:rating>nonadult</media:rating></channel>
</rss>
