SecureConnect Logo
Phone: 888-949-7328 | mySecureConnect Login
 
pci-compliance.jpg

PCI in a box

Step 1 – Cut a hole in the box….

As a recent former PCI QSA (Qualified Security Assessor), it really frustrates me how many products out there that claim they will make you PCI compliant.
Directly in our market space, we have organizations claiming 90%+ compliance out of the box or compliant in xx days. Honestly, this is such a marketing gimmick. But customers fall for it.

Let’s take a look at both of these scenarios:

1. 90%+ compliance out of the box.
Let’s assume there is a PA-DSS application in place and no web facing applications. The customer is a SAQ D, which is pretty typical. Requirement 9 is primarily concerned with physical security. With 26 questions in Requirement 9, and 222 questions in a SAQ D; one is already at 88% for the starting point. So you are indicating, as a remote service provider, you able to classify and shred data and distribute and surrender badges, all without a physical presence? Really? We haven’t even addressed requirement 12 yet. Unfortunately, those that are not in the know believe this propaganda.

2. Compliant in xx days
A service provider cannot guarantee compliance in xx days. First, there are too many variables to implementation, mainly the customer itself. If a customer drags their feet on initiatives beyond a service provider’s control, there is no way to meet the timeline. In addition, compliance for PCI is not a point in time; PCI must be “operationalized”. The SAQ and ASV scans are point in time validation points, but a merchant must maintain this throughout the year.

This type of marketing makes our industry look bad as a whole. As a merchant, you are not becoming more secure with the claims that some service providers are making. While they may offer a decent solution, do not have the expectation that these service providers are the silver bullet. Service providers can assist in compliance but it is the merchant that is responsible for their own compliance. Don’t choose a solution just so you can check a box once a year. As a merchant, be concerned with having a secure environment and compliance will follow. In the long run, your organization will be better off.

Now back to my to SNL short viewing.

BHI SecureConnect Joins HDI to Help Enhance Support Center Operations

Focused on providing outstanding service and support to its growing customer base, BHI SecureConnect is pleased to announce its membership with HDI, the world’s largest training and certification association for technical support professionals.  BHI is confident that active participation in HDI will help further develop its support team and promote a higher degree of customer service that the company strives for on a daily basis.

Having developed a specialized platform to proactively monitor network environments 24 hours a day, 7 days a week, 365 days a year, BHI employs the highest customer support standards through skilled experts and proper training.  Membership with HDI provides access to timely and valuable industry information, standards-based training and resources to better support customer service operations operations. Participation with HDI will hopefully bring improved operations to the company and positively affect BHI customers and their security and PCI compliance needs.

Contact us today to learn more!

Spot Critical Holes in your Infrastructure with a Vulnerability Assessment

Contrary to popular belief, it really isn’t enough to become secure. If you are serious about maintaining your business for the long run, you will have to maintain security — something that is completely different. Maintaining security can get complicated in a world where new security threats are on the horizon all the time, but it’s something that can get easier if you have the right tools.

If you’re serious about securing the important assets of your business, you will need to first start by using a vulnerability assessment to spot critical holes in your infrastructure. From there, you will be able to see exactly what is insecure at the moment, and then fix those problems.

Naturally, you can also take a different approach with a vulnerability assessment by contracting an outside company to not just run the vulnerability assessment for you, but also to generate an action plan based on the report generated from the assessment. This is a great way to delegate your security tasks without worrying about having an insecure system.

No matter what path you ultimately choose, you will need to get started today by getting the vulnerability assessment and seeing if there are any critical holes in your infrastructure. Contact us today!

Would you like 1 or 2 iPods with your Coffee?

A Starbucks employee in Jakarta recently took it upon himself to stock up on iPods purchased with the credit card numbers of customers. According to police sources in Jakarta, the suspect, reprinted daily receipts that included the credit card verification value.

While the fraudster will be prosecuted and serve time, the Starbucks franchise was storing credit card verification codes (presumably after authorization), which is one of the biggest “no nos” in the Payment Card Industry Data Security Standard. The storage of the card verification code is prohibited, along with track data and PIN/PIN block. The franchise should and will be held accountable for storing the information post authorization.

Franchise owners must know what data their point-of-sale system has; it is tough to safeguard or put security and operational measures in place if you are unaware of the data. If you are a franchise owner, take the initiative and do discovery on what data you have. If you are unaware of how to do this, contact your point-of-sale vendor for discovery assistance within the POS or terminal.

Security consultants can also be of assistance and search for data beyond the POS system.

I’ll take a grande latte with that 64GB iPod touch.

Contact us today!

PCI Compliance for the QSR Industry

Without solid compliance, the systems that a QSR-oriented business relies on to process payments and other tasks for customers could be at risk for a security breach. If a breach were to occur and it was found that the proper QSR PCI compliance principles weren’t being practiced, stiff fines and other consequences could result.

At this point, the goal is to effectively implement PCI compliance solutions for the unique network environment in your store. Security isn’t something that should be complicated, especially if you have many employees that will need to be educated and trained on proper security procedures.

The key is to practice smart delegating measures. If security is not your strong suit, it may be best to bring in a company that specializes specifically in helping companies manage their QSR PCI compliance needs in a way that just makes sense. The best way to move forward is to make sure that you get started right away — don’t delay! Contact SecureConnect today!




 
 
Learn More
Why SecureConnect
Packages
Managed Firewall
PCI Compliance
Archived Webinars
SecureConnect Blog
Case Studies
FAQs

SecureConnect Scoop
About Us
Approved Scanning Vendor
Careers
Press Releases
Terms of Use
Privacy Policy
Site Map
Next Steps
Send Informational Packet
Get a Free PCI Scan
Receive Communications from us
Request a Free PCI Consultation
Launch the PCI Wizard
Email Us
Sign Up
mySecureConnect Login
Call Direct: 888.949.7328

Follow SecureConnect
Follow us with RSS feed Subscribe to our RSS feed
Follow us on Twitter Follow us on Twitter
Follow us on Facebook Become a Facebook fan
Follow us on Facebook See our events on Flickr
Visit our profile on Linkedin Join us on Linkedin
© 2010 BHI Advanced Internet, Inc. Provider of SecureConnect®. All Rights Reserved.