Wednesday, March 10, 2010

Do We Certify For PCI?


No, what we do is properly take care of the all the technical requirements for business computers in order to prepare them to pass quarterly scans by an authorized PCI DSS scanning vendor. We will even put the client in touch with 'Security Metrics' a leader in certifying merchants for PCI compliance when they are scan ready.

This is going to be a separate charge for the client by 'Security Metrics' who will assess them for what they need based on what they are currently using (phone, swipe machine(s), computer(s) etc.) to take credit card information with. The client should expect to fill out a questionnaire (likely sent via email) as well as a scan performed on their IP address by the vendor.

When they pass they will be issued a certificate (via email) that they can display at their place of business or online if they are an e commerce merchant. They will be scanned automatically every quarter after that and they will be charged yearly for this service.

Home businesses are especially  vulneralbe to hackers, arguably the most vulnerable simply because they are usually not well protected. Intruders will zero-in on home users because it is easy and requires very little work on their part to do so.

Would you leave the curtains open to a window facing a busy street while you change clothes or bathe? Would you tuck your precious children into bed at night and leave the window open with a ladder leading down to the backyard? Of course not, but most home businesses are blindly using their computers with a false sense of security that literally leaves their sensitive information exposed. cyber-crooks sneak in unseen and start exploiting a home business computers 'always on' broadband connections and the typical home use programs such as chat rooms, Internet games and file sharing applications.

And once a bad guy is in they have no problem installing hacker tools specifically developed to log every key stroke a user types. So your banking passwords and any credit card information being typed on an infected computer (theirs or a customers) are easily in the hands of a criminal faster than a bull frog can zap a fly!

Being in compliance is not voluntary, if a merchant wants to keep their privilege of taking credit card payments they must follow the rules of compliance in accordance with The PCI Security Standards Council.

 Check out the link for the company site for more information about Security Metrics.

No comments:

Post a Comment