|
Visa and MasterCard have jointly developed a standard for merchants who store, process or otherwise have access to cardholder information. It details the measures that you should take to ensure that the cardholder data you handle is secure. This standard is called the Payment Card Industry Data Security Standard (PCI DSS) and is also endorsed by American Express, JCB and Diners Card.
Merchants are required to adopt the new standard and to review the guidelines against their current business practices.
The exercise will, of course, be useful in itself as it may help to uncover security weaknesses and as it is an ongoing process, you can progressively tighten your procedures in the face of new and unexpected threats.
Frequently Asked Questions
 |
Why have the Card Schemes introduced this programme?
|
 |
Why has MasterCard created an enforcement programme?
|
 |
What happens if I do not comply?
|
 |
What if I already use a third party agent to assess my security?
|
 |
I use a PSP Pay page. Do I still have to undertake compliance?
|
Third Party Agent FAQs
 |
What do you mean by 'agent'?
|
 |
Why do I have to do this?
|
 |
But why should I be concerned?
|
 |
What are Streamline doing about this?
|
 |
What do I need to do?
|
 |
What else can I do?
|
 |
What happens if I don't tell Streamline about my agents?
|
 |
Where can I find out more about the PCI DSS standards?
|
|