Partner Links

 

 
 
 
 
 
 
 
Home | Products | RippleTech | LogCaster for Payment Card Industry

 

LogCaster for Payment Card Industry (PCI)

The Payment Card Industry (PCI) Data Security Standard, designed to create common industry security requirements, is the result of collaboration between Visa, MasterCard and other credit card companies. PCI applies to all members, merchants and service providers that store, process or transmit cardholder data, whether that data is received in a point of sale, phone, e-commerce or other type of transaction. Additionally, the standard applies to all “system components,” which PCI defines as “any network component, server, or application included in, or connected to, the cardholder data environment.” The date for meeting compliance was June 30, 2005.

PCI includes the following basic requirements:

  1. Build and maintain a secure network
  2. Protect cardholder data
  3. Maintain a vulnerability management program
  4. Implement strong access control measures
  5. Monitor and test networks regularly
  6. Maintain an information security policy
     

Merchants must validate their compliance by submitting the required documentation; documentation must also be available upon request. These requirements may differ slightly from one credit card company to another, but the most comprehensive requirements include three levels of validation:

1. Annual on-site security audit – includes reports on compliance

2. Annual self-assessment questionnaire – addresses any system(s) or component(s) involved in processing, storing or transmitting cardholder data

3. Quarterly network security scan – an automated tool that checks systems for vulnerabilities

 

Key Benefits

     

      Perform a Risk Assessment to see what control objectives need implementation

  • RippleTech’s Risk Assessment Module gives IT organizations the ability to see exactly how each of its systems is configured, if policy settings are in place or if configuration vulnerabilities are present. Additionally, a Risk Assessment allows for automated scanning, management and comprehensive reporting.

      Automate security standards to a set of policies and technical controls for
      implementation and enforcement

  • Based on industry-leading expertise, LogCaster for PCI is preconfigured with specific rules and reports to quickly meet security standards, enabling your company to confidently prove compliance.

      Automate procedures to continuously monitor and report on compliance

  • The RippleTech Reporting Module and the Risk Assessment Module provide both detail and summary views of security data. Reports can be delivered on-demand and can be scheduled for automatic delivery. Reports can be displayed via the Web, Excel, PDF, CSV or emailed directly to you or management so you can continuously monitor and report on the compliance.

 

Other Resources

 
Copyright © PrimaJava Softech