TESTIMONIALS

โ€œReceived the latest edition of Professional Security Magazine, once again a very enjoyable magazine to read, interesting content keeps me reading from front to back. Keep up the good work on such an informative magazine.โ€

Graham Penn
ALL TESTIMONIALS
FIND A BUSINESS

Would you like your business to be added to this list?

ADD LISTING
FEATURED COMPANY
Vertical Markets

PCI compliance

by Mark Rowe

A security and compliance company reports that it has achieved global Approved Scanning Vendor status from the Payment Card Industry (PCI) Security Standards Council for a sixth year.

The Payment Card Industry Security Standards Council was formed by Visa, Mastercard, American Express, JCB and Discover Financial Services, to devise international security guidelines for any company that processes, stores, or transmits customersโ€™ payment card details.

The PCI Security Standards Council mandates that all merchants with a presence on the internet must conduct regular security audits of their payment infrastructure to test that they protect customersโ€™ payment card details from being intercepted by hackers and thieves. Businesses that fail to comply risk losing their ability to process online payments, or financial penalties if they are proven to be responsible for a data leak.

External scans of merchantsโ€™ networks must be carried out on a quarterly basis by Approved Scanning Vendors (ASVs) that are vetted by the PCI Security Standards Council.

Commenting on RandomStormโ€™s renewed ASV certification, Andrew Mason, co-founder and Technical Director of RandomStorm said, โ€œSeveral high profile hacks have highlighted the dangers to payment card data stored on merchantsโ€™ systems. While breaches suffered by the largest merchants tend to hit the headlines, retailers and online businesses of all sizes need to follow best practice and be able to quickly detect network intrusions to protect their customers against card fraud. Owing to the increase in malware, botnets and exploit kits, a companyโ€™s security status can change on a daily basis. The best way to achieve ongoing security is through continuous monitoring of network assets, in between scheduled audits.โ€

The firm provides vulnerability scanning and intrusion detection services to help companies to improve and maintain their security posture on a continuous basis. The company is a CESG CHECK security consultancy and certified as a Qualified Security Assessor (QSA) and ASV by the Payment Card Industry Security Standards Council.

References

โ€œPCI DSS Quick Reference Guide, understanding the Payment Card Industry Data Security Standard version 2.0โ€ https://www.pcisecuritystandards.org/documents/PCI%20SSC%20Quick%20Reference%20Guide.pdf

PCI DSS Quick Reference Guide โ€“ โ€œchoosing an Approved Scanning Vendorโ€ https://www.pcisecuritystandards.org/documents/PCI%20SSC%20Quick%20Reference%20Guide.pdf

PCI Compliance Guide โ€“ frequently asked questions http://www.pcicomplianceguide.org/pcifaqs.php

Related News

  • Government

    Reaction to abolition of PCCs

    by Mark Rowe

    Police and crime commissioners are ‘deeply disappointed’ by the Labour government announcement of abolition, the chair of the Association of Police and…

  • Commercial

    Fragmenting world

    by Mark Rowe

    It’s a fragmenting world, according to the emergency medical and security travel aid provider International SOS in its 2025 Risk Outlook report.…