31.07.2015 Views

Download

Download

Download

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

262 Chapter 8 • Why PCI Is ImportantIntroductionChances are if you picked up this book you already know something about the PaymentCard Industry (PCI).This chapter covers everything from the conception of the cardholderprotection programs by the individual card brands to the founding of the PCI SecurityStandards Council. Why? To make sure that you have not been misled and that you use theterminology in the right context. Also, many of the questions people ask have their originsin the history of the program, so it only makes sense that we start at the beginning.What is PCI?PCI is not a regulation.The term PCI stands for Payment Card Industry. What people arereferring to when they say PCI is actually the PCI Data Security Standard (DSS), currentlyat version 1.1. However, to make things easy, we will continue to use the term PCI to identifythe industry regulation.Who Must Comply With the PCI?In general, any company that stores, processes, or transmits cardholder data must complywith the PCI. In this book, we are primarily concerned with merchants and serviceproviders.The merchants are pretty easy to identify—they are the companies that acceptcredit cards in exchange for goods or services. However, when it comes to service providers,things get a bit trickier. A service provider is any company that processes, stores, or transmitscardholder data, including companies that provide services to merchants or other serviceproviders.NOTEThe following terms are used throughout this book.■ Cardholder The legal owner of the credit card.■ Cardholder Data At a minimum includes the primary accountnumber (PAN), but also may include the cardholder name, servicecode, or expiration data when stored in conjunction with theaccount number.■ Storage of Cardholder Data Any retention of cardholder data ondigital or analog media. Not limited to digital information. Oftenexcludes temporary retention for troubleshooting or customer servicepurposes.■ Processing of Cardholder Data Any manipulation of cardholder databy a computing resource or on physical premises. Not limited to digitalinformation.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!