preview

Essay about PCI Compliance

Good Essays

What is PCI Compliance?

PCI Compliance is maintaining adherence to the PCI DSS standard that was developed by major credit card companies as a “guideline to help prevent credit card fraud” ("PCI DSS"). Credit card fraud has taken the spotlight in the past several years due to the massive growth of e-commerce and online transaction processing. With the proliferation of e-businesses, it has become easier than ever to commit fraud over the internet.
Major credit card issuers such as MasterCard, Visa, American Express, Discover, and JCB International joined together to create a standard known as PCI DSS or Payment Card Industry Data Security Standard. In order to process credit card payments merchants and vendors are required to be …show more content…

In September of 2006 the PCI Data Security Standard was updated to version 1.1 which is currently in-use today. The PCI Security Council works to promote the broad industry adoption of this standard, and also generates tools to assist companies in complying with these standards. Some of the tools are guidelines, scanning requirements, and even a self-assessment questionnaire.
Before the PCI Security Council and Data Security Standard existed, each of the five credit card issuers had their own internal extensive compliance policies. But vendors or merchants who wanted to process more than one type of credit card would have to comply with requirements defined by each card issuer. By coming together under the umbrella of the PCI Security Council these major brands were able to codify their corporate standards into a public standard, and place pressure on organizations that process credit transactions to protect cardholder data against fraud and theft.
The founding organizations not only developed this standard, but also incorporated these standards into their own data security compliance programs. All five organizations share equally in governing the council; have equal input regarding issues; and all the organizations share responsibility for maintaining the PCI Data Security Standard.

Case Study: TJX Companies

In March of 2007, just last year, TJX Companies, owner of TJ Maxx and Marshall’s revealed the extent of damage of a number of

Get Access