Security for international card-based payment transactions
The PCI DSS is a set of rules developed by the international payment systems Visa, MasterCard, American Express, Discover and JCB International (united in the PCI Security Standards Council) to ensure the security of payments with their payment cards.
Merchants who accept payments with such cards and service providers who support them in doing so must comply with the PCI DSS regulations. The regulations cover IT security best practices:
-
Network security
-
System hardening
-
Encryption
-
Vulnerability management
-
Access and access control
-
Monitoring, logging and regular checks of the network
-
Information security management, processes and policies
So that your customers have confidence in you
Compliance with the PCI DSS requirements makes it much more difficult for attackers to obtain payment data. This ensures a secure payment system and maintains customer confidence.
By complying with the PCI DSS, companies are also already implementing measures to ensure compliance with other compliance requirements, such as the PCI DSS. Facilitate requirements from the EU General Data Protection Regulation (DSGVO) or the IT Security Act, bank regulatory requirements for IT (BAIT) or requirements from international standards such as ISO/IEC 27001.
PCI DSS v4.0 is approaching – we support you in your preparations
The PCI DSS is a mature standard that defines requirements for the secure processing of card data of international payment systems.
Version 3 of the PCI DSS, which – with various updates – has been valid since 2014, will finally expire at the end of March 2024 and will be supplemented by the new version 4.0.
We take the final steps with you to migrate to PCI DSS v4.0.
Please feel free to take advantage of our offers:
1. monthly blog articles, each highlighting a PCI DSS v4.0 topic in more detail.
- September 2023: Timeline for PCI DSS v4.0 migration – What are my next steps?
- October 2023: Roles and responsibilities in PCI DSS v4.0 – How can I meet the new documentation requirements?
- more you will find updated at this place
2. free webinars summarising the changes from PCI DSS v3.2.1 to v4.0 for you once again.
As soon as the exact dates are fixed and the registration is activated, you will find the corresponding links here:
- Webinar on the full PCI DSS scope (January 2023)
- Webinar for Card-Present merchants with SAQ B-IP or P2PE scope (January 2023)
- Webinar for e-commerce merchants with SAQ A scope (January 2023)
- PCI DSS v4.0 workshops tailored to you, in which we specifically present and discuss the requirements relevant to you.
Please contact Ms Jana Ehlers, see contact info. - A gap analysis for your environments and processes. You will receive a list of all open points in your company for PCI DSS v4.0 compliance.
Please contact Ms Jana Ehlers, see contact info. - Consultation packages of your choice, of which you can call up quotas at any time if you have specific queries – by telephone, e-mail, web conference, or in on-site meetings.
Please contact Ms Jana Ehlers, see contact info.
Links on the topic of PCI DSS