PCI compliance and security

AbleCommerce administrators should not use a known email

Posted by Mike Randolph on July 20, 2010 at 12:34 pm

Increase the security on your AbleCommerce store by NOT using known email addresses for administrative user names.  This makes it even more difficult for a hacker to breach your account as they would have to guess both your user name and your password. This also prevents a hacker from requesting a lost password email for an [...]

Share

Let the buyer beware, most online stores are not worried about your credit card data

Posted by Mike Randolph on July 14, 2010 at 9:45 am

We recently phoned over 300 small merchants, regarding their current solution and PCI compliance.  We found, that most are not worried about PCI compliance (your data).  Most have adopted a wait and see attitude towards PCI Compliance… wait until they see Visa actually put some teeth on their mandates. The editor of Practical eCommerce goes even further stating [...]

Share

There are only 4 PA-DSS certified shopping carts that you can ‘buy now’

Posted by Mike Randolph on July 7, 2010 at 3:18 pm

We typically won’t openly rant about our competition. However, we are hearing so many half truths and misleading information from potential customers about other shopping cart systems claiming to be compliant, certified,  or that their PA-DSS certification is coming soon…incidentally, our certification took over a year to complete.  We’re frankly shocked that given 5 years notice on the July 1st deadline, that only a dozen [...]

Share

Approved Scanning Vendors for PCI compliance

Posted by Mike Randolph on July 7, 2010 at 9:00 am

As part of PCI compliance you are required to test your network on a regular basis. PCI DSS Requirement 11: Regularly test security systems and processes. There are a lot of vendors listed on the Approved Scanning Vendors list but the sole stand out is McAfee Secure, which was originally a Scan Alert product called ’Hacker Safe’ and was rebranded ‘McAfee [...]

Share

The 12 steps to PCI compliance in a Jingle.

Posted by Mike Randolph on July 2, 2010 at 8:00 am

Here’s just the facts without the snazzy video. Build and Maintain a Secure Network Requirement 1: Install and maintain a firewall configuration to protect cardholder data Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters Protect Cardholder Data Requirement 3: Protect stored cardholder data Requirement 4: Encrypt transmission of cardholder [...]

Share

Tomorrow is the deadline for PCI Phase 5

Posted by Mike Randolph on June 30, 2010 at 4:16 pm

Frankly we’re shocked to see only a dozen ecommerce vendors take it seriously and become certified. It will be interesting to see how all this plays out over the next few months. What will the fines be? What happens when an application is decertified?

Related Posts with Thumbnails
Share