Features
RSS FeedE-commerce PCI-DSS compliance
Gordon O'Hara
Jun 18
Retail Up's managing partner discusses new financial regulations and how his company can help
The Tube is back up and running here in London, but it may not be the last shutdown this year… The card companies are coming.
And the websites of UK’s music dealers need to be ready… or face a ‘shutdown’ of their own.
A consortium of credit card companies – having already successfully imposed strict e-commerce credit card processing rules on major companies – are now moving ‘down market’ to impose the same strict requirements on mid-sized and smaller businesses.
In order for stores to continue to accept Visa, MasterCard, American Express and other credit cards, the Payment Card Industry (PCI) Data Security Standards (DSS) will now require stores to provide two proofs of compliance:
• Positive answers to a 240-question survey of internal policies, programming, hosting arrangements and management controls that apply to the site.
• A quarterly scan that includes (on average) 25, 000 or more tests of your site’s ability to prevent hacker and programming attacks that could allow unauthorised access to card numbers and security codes.
The requirements are substantial and should not be underestimated.
The survey requirements include:
• A highly detailed programming policy that can be examined at any time on demand.
• Strict management controls over the methods that new programming is produced, tested and approved.
• Hosting facilities will no longer (in essence) be maintained in the store due to requirements for controlled access by personnel and firewall requirements.
• Increased attention how coding for sites is maintained and credit information is deleted once the transaction is completed.
The programming tests examine:
• Hosting irregularities
• Firewall capabilities
• Coding and programming methods
• How the security certificates and secure socket layers are configured
• The site’s ability to repel common attacks such as SQL injection (a type of database attacks)
• The current status of patches to the server environment (there’s a requirement to have all patches installed every 30 days)
and others.
To meet these requirements generally requires monthly attention from network and programming personnel.
Bank companies that clear credit cards have had the ability to request these reports for some time. However now that most large companies are in compliance dealers report that banks are stepping up enforcement on smaller companies in 2009. Further, the turnaround time that banks impose to meet these requirements can be as little as 15 business days to respond. Banks retain the right to shut down the shopping carts of sites that do not comply.
The dealers most at risk are that use ‘off the shelf’ or free e-commerce software and provide their own hosting. The next riskiest would be in-house programmed sites that have not yet completed the PCI compliance questionnaires or scanning requirements.
The surest way to compliance is to use a service provider that has already been approved for PCI DSS standards. With this approach dealers can have the appropriate questionnaires and scans readily available for bank personnel. This allows the store to focus on the requirements of internal training and monitoring of the staff assigned to manage a site’s credit card information.
Retail Up – the music industry’s largest provider of Website services – announced at LIMS that it is the first music industry company to be a fully PCI compliant service provider. Through the company’s newly PCI Up program, dealers that use Retail Up’s system can be assured that their sites will comply with forthcoming scrutiny of your credit card processing companies and banks. With PCI Up dealers are prepared with immediate access to the required PCI surveys and quarterly scan requirements.
PCI Compliance is the lurking surprise that every dealer will face in 2009. Retail Up’s PCI Up program will help dealers maintain uninterrupted services to their customers and meet the card issuer’s requirements to protect the integrity of credit card data. We invite dealers to learn more by e-mailing us. As a service to the industry, we are offering a PCI Up analysis to determine how their sites can comply with these rules… and prevent the possibility of a shutdown in the future.
Other Features
- EVENT PREVIEW: Hold your head up
Mar 12
- COMPANY PROFILE: Plugging back in
Mar 11
- COMPANY PROFILE: New York state of mind
Feb 19
- RETAIL: The hub of the matter
Jan 28
- UNDERCOVER: New year, new gear
Jan 28
- COMPANY PROFILE: Stirling work
Jan 25
- INTERVIEW: Behringer touches Midas
Dec 22
- COMPANY PROFILE: Sound pressure
Dec 07
- UNDERCOVER: Christmas is coming, retail aims to get fat
Dec 07
- COMPANY PROFILE: The right focus
Dec 07
- BRAND PROFILE: The year of the Sponge
Nov 06
- UNDERCOVER: The terrible tale of the six-string swiper
Nov 06
- SECTOR SPOTLIGHT: Bully for uke
Oct 26
- UNDERCOVER: Training, tantrums and triumph
Oct 02
- COMPANY PROFILE: In all but name
Oct 02
- COMPANY PROFILE: The pearl in the crown
Oct 02
- COMPANY PROFILE: Right notes
Sep 16
- PRODUCT LAUNCH: In a Class of its own
Sep 16
- SECTOR SPOTLIGHT: Pick 'n' mix
Aug 28
- COMPANY PROFILE: The Fresh prince
Aug 21
- UNDERCOVER: Indoors and online this summer
Aug 21
- SECTOR SPOTLIGHT: Back to school
Aug 14
- BUSINESS OVERVIEW: The sun never sets
Aug 14
- COMPANY PROFILE: Informal introduction
Jul 23
- COMPANY PROFILE: Filling the gap
Jul 22
- SECTOR SPOTLIGHT: The wooden tops
Jul 22
- SHOW REVIEW: A light shines in the east
Jul 09
- COMPANY PROFILE: Servicing needs
Jul 09
- FRONTLINE: It’s getting hot in here
Jul 08
- COMPANY PROFILE: Talking Drumm
Jul 03
- SECTOR SPOTLIGHT: Nota bene
Jun 19
- UNDERCOVER: How to survive price increases
Jun 15
- MIA UPDATE: MfA visits primary schools
Jun 15
- SECTOR SPOTLIGHT: Mic’d up
Jun 03
- COMPANY PROFILE: Fane and fortune
Jun 03
- SECTOR SPOTLIGHT: Saxy beasts
May 22
- UNDERCOVER: Avoiding the Brown stuff
May 07
- LAMBA: Above par
May 07
- Print re-visited
May 07
- SECTOR SPOTLIGHT: Heads up
Apr 23
- PEAVEY: One for the road
Apr 21
- SECTOR SPOTLIGHT: Bass in your face
Apr 21
- BURRLUCK: Blue Monday
Mar 24
- SECTOR SPOTLIGHT: E's are good
Mar 23
- Gone in a click
Mar 23
- COMPANY PROFILE: Business at Bay
Mar 12
- SECTOR SPOTLIGHT: Electric avenue
Mar 09
- MIA: Your trade body needs you
Mar 04
- SECTOR SPOTLIGHT: Waitin’ for the man
Feb 24
- NAMM 2009: Business as usual
Feb 20
- COMPANY PROFILE: Gremlin
Feb 17
- MI PRO RETAIL SURVEY 2009: The results in full
Feb 12
- SECTOR SPOTLIGHT: Peddle faster
Jan 28
- THE LOUDEST BREAKFAST: Paul Marshall shares his NAMM blog
Jan 23
- SECTOR SPOTLIGHT: Rocking on a shoestring
Jan 15
- Marshall: Generation next
Jan 12
- Your epos – a lean, mean, profit machine
Dec 04
- Stratified: Fender in 2008
Dec 03
- Marketplace special: Shipping your music products...
Nov 27
- COVER FEATURE: What people want
Nov 06
- Give your business the gift of web success
Nov 06
- COVER FEATURE: New keys
Oct 13
- NEWS ANALYSIS: Gavin & HK
Sep 10
- ENDORSEMENT: John Etheridge uses DPA
Sep 02
- Life begins...
Aug 26
- SECTOR SPOTLIGHT: The soft parade
Jul 29
- ENDORSEMENT: The Tenorions
Jul 14
- ENDORSEMENT: Paiste teams up with Joey Jordison
Jul 14
- ENDORSEMENT: Paul Weller re-united with Ovation
Jul 03
- ENDORSEMENT: Duncan Lloyd finds Faith
Jul 02
- The Beare necessities
May 16
- Audio techniques
May 01
- MI Pro sitings
May 01
- Aria's moving tale
Apr 08
- Wheat picking, anyone?
Feb 23
- COMPANY PROFILE - AER
Feb 22
- Yamaha manufacturing
Feb 22
- COMPANY PROFILE - Fret King
Feb 22
- NAMM goes global
Feb 22
- COMMENT - Off comms
Feb 22
- Happy New Year
Jan 25
- COMPANY PROFILE - Monacor
Jan 25
- COMPANY PROFILE - Edoru
Jan 25
- COMPANY PROFILE - Warwick
Jan 25
- COMPANY PROFILE - Sutherland
Jan 25
- MI Pro Retail Survey 2008
Jan 25
- Fender - a brand too far?
Jan 25
- NAMM Show - the report
Jan 25
- COMMENT - Down to business
Jan 25
- Real music?
Dec 21
- COMPANY PROFILE - Blackstar
Dec 21
- EMD Imports
Dec 21
- ANALYSIS - JHS/Wilkinson deal
Dec 21
- COMPANY PROFILE - T-Rex
Dec 21
- Music Radar
Dec 21
- INTERVIEW - Shure Distribution
Dec 21
- COMMENT - Drinking it in
Dec 21
- Turning rebellion into money
Nov 23
- COMPANY PROFILE - Sound Post
Nov 23
- COMPANY PROFILE - Freshman
Nov 23
- COMPANY PROFILE - Recording King
Nov 23
- INTERVIEW - Barnes & Mullins
Nov 23
- Gibson goes it alone
Nov 23
- Music China Review
Nov 23
- COMMENT - Global guitars
Nov 23






