Tasks attached
Topic: Explain PCI compliance to the database administrator at a large retailer. Consider the consequences for non-compliance.
Read and respond to below two student’s discussions (150 words) reflecting on your own experience, challenging assumptions, pointing out something new you learned, and offering suggestions.
#1. Posted by Nithin
Top of Form
If we are in the health care industry network must comply with the Health Insurance Portability and Accountability Act (HIPAA) standards. The bottom line is that organizations need to secure and protect their networks. When the data on the corporate network contains personal information about patients, customers, or employees, a breach of security can have implications far beyond the company.
“The credit card industry banded together to develop the Payment Card Industry (PCI) Data Security Standards (DSS) to ensure that credit card customer information if adequately protected and to protect the industry” – (Branden R. Williams, Anton Chuvakin, & Tony Bradley. (2007)). Breached of customer information lead to lost money and damaged reputations, and the credit card industry wants to protect itself from financial loss or eroded consumer confidence in credit cards as a means of transacting money.
Credit card fraud and identity theft are both epic problems that continue to grow each year. Certainly, credit card fraud and identity pre-date the age of the Internet. It is an ironic fact that the things that make your life easier, improve efficiency, and make things more convenient, also make crime easier, and more convenient. These breaches are often targeted at consumer credit card information, and threatened to tarnish the reputation of the credit card industry, so the major credit card vendors banded together to develop the Payment Card Industry (PCI) Data Security Standards (DSS). In essence, the credit card data and transactions and maintain the public trust in credit cards as a primary means of transacting money. If you want to accept credit cards as payment or take part in any step of the processing of the credit card transaction, you must comply with the PCI DSS or face stiff consequences.
PCI is not a regulation. In general, any company that stores, process, or transmits cardholder data must comply with the PCI. A service provides is any company that processes, stores, or transmits cardholder data, including companies that provide services to merchants or other service providers. Depending on our company’s merchant or service provider level, you will either need to go through an annual on – site PCI audit, or complete a Self – assessment Questionnaire to validate compliance. In addition to this, we will have to present the results of the quarterly network perimeter scans, evidence of internal vulnerability scans, and evidence of application and network penetration tests. We must prove to the card brands that our company practices sound patch management and vulnerability management processes. While PCI does not require penetration tests to be performed by a third party.
In 2001, VISA and MasterCard each instigated basic levels of credit card security compliance programs, in which both retailers, banks and organizations that provided cardholder authentication and authorization services were required to demonstrate compliance.
“We only take a small number of credit cards, so we don’t need to be PCI complaint. You can never store cardholder data. I use a PCI complaint point – of – sale system, so therefore I am PCI complaint. PCI is the law” – (Zimmerman, J. (2017)).
Any organization processes customer payment cards must comply with the Payment Card Industry’s Data Security Standard or face possible fines and a great potential for this sensitive information to be compromised. Leading the PCI compliance program’s development is a prudent way for a RIM professional to raise awareness of information governance (IG) priorities and, perhaps, take a step toward a broader IG career.
“Information governance and records and information management professionals will readily agree that protecting sensitive information is a top job priority and that it has become more difficult and risky because of the explosion of electronic information” –( Altepeter, A. (2013)).
Bottom of Form
#2. Posted by Ragini
Since the inception of technology and online as well as cashless payment methods, it has been easier to access such funds if the systems used and the access cards used are not secured. None the less, banks have seen it an empowering business sector where the individuals can use their money via credit and debit cards. The internet has also made it possible to extend the use of such cards by the use of online payment methods and plans. Therefore, this resulted in what is known as PCI Compliance which stands for Payment Card Industry compliance. This stands for the technical and legal standards that all businesses that accept credit and debit card payments must follow with the sole aim of protecting the users of the cards.
In simpler terms, the PCI Standards, Council or regulations are set for businesses to ensure that a company uses secure channels to transmit, collect and store vital data that relates to card payment methods. Not only are the policies set with the aim of securing the cards, but also to ensure that the identities of the individuals are also guaranteed at all times (Ani Miteva, 2017).
Consequences on non-Compliance
As much as the policies might be seen to be simple and not as important, understanding the effects that one will end up facing is more enlightening to how vital the standards are essential. Is a business the interacts with card payment methods and fails to comply to the Payment Card Industry standards, below is a collective list of some of the consequences that the business will have to face and answer to (Wilson, Roman & Beierly, 2018):
· A company fails with complying to the PCI standards, then it is liable to face heavy monthly penalties and fines that range from $5,000 to $100,000.
· Lawsuits are also the next line of action that takes place for any company that does not comply with PCI regulations. Such lawsuits result to millions and billions of dollars being pained or even companies being shut down especially if a breach is experienced.
· If a business also fails to take into regards the value and importance of PCI compliance, then they will have to dig into their resources to compensate their clients with several insurance policies such as identity theft theory, credit card monitoring among other insurance and services.
· A company that also fails to be PCI compliant ends up losing its valued reputation and ends up not being a haven for customers.
Above are but a few of the most important consequences that a non-compliant business will end up going through. Nonetheless, this shows how valuable PCI compliance is suitable for any business that is customer oriented and cares for the people it interacts with.