Payment Card Industry (PCI) Data Security Standard (DSS) compliance is the term given to the new set of rules and regulations for any business involved in the processing of Credit Cards.
Compliance consists of meeting a set of security standards which are available online from the PCI Security Standards Council (www.pcisecuritystandards.org).
We have already made the first key changes to the software with the encryption of the credit card information within the database. The next key step will be to implement changes to the system which will effectively mean that credit card processing takes place off-site. One solution to this is the ICP service from Commidea (www.commidea.com) and we are investigating a similar facility with Datacash (www.datacash.com).
The credit card issuers are not insisting on immediate compliance but that are requiring retailers to immediately put risk mitigation strategies in place to protect their most sensitive data. Retailers must also be able to prove that they are working towards full compliance.
more...