Print This Article Post Comment Add To Favorites Email to Friends Ezine Ready

Is Remote Storage Of Credit Card Data A Valid Option?

By: Andy Eliason Home | Business


The PCI DSS requires that anyone who stores, processes, or transmits sensitive credit card information must do everything they can to protect that information. This can be accomplished in-house, or the payment processing can be outsourced to another company. Which begs the question: Is remote storage of credit card data a valid option? How does it compare to storing data yourself?

The PCI DSS is made up of 12 requirements which can be broken down into more than 200 individual security controls. Some of these security measures can and/or must be taken care of by the merchant in-house. There are, however, a number of requirements that can conveniently be covered by remote storage of credit card data.

The third requirements of the PCI DSS requires simply that you â€Protect cardholder data.†On the surface that seems like a distressingly broad and generalized requirement. Luckily it has been divided up into more than 20 different controls to express exactly what is required by it.

Encryption is a big part of this requirement. If you are going to retain information on your system it must be encrypted. The problem here is that sometimes companies don't understand exactly how encryption works, or what, exactly, constitutes valid or sufficient security. And even when encryption techniques are properly implemented, there's a whole other set of requirements regarding the protection of encryption keys.

Remote storage of credit card data can help you alleviate this problem. When you store your information in a secure vault off-site, you are working with a company (or should be working with a company) that specializes in data encryption.

On top of that, the first control listed under the third requirement states that merchants should â€Keep cardholder data to a minimum,†and â€limit storage amount and retention time to that which is required for business, legal, and/or regulatory purposes.†This practically encourages a merchant to choose remote storage of credit card data because then someone else gets to deal with the required procedures here. And these people, if you've chosen the right company to partner with, can maintain sufficient security measures and keep this data out of the hands of criminals.

Other requirements of the PCI DSS can be satisfied with remote storage of credit card data. These include requirements seven, eight, and nine. Seven states that you must restrict access to cardholder data by business need-to-know. Eight requires a unique ID for anyone with computer access. And nine says that you must restrict physical access to cardholder data.

How does remote storage of credit card data help you with these requirements? Some of them are obvious. Requirements nine is simple. Physical access is completely restricted because the data is nowhere on your system. The same is applies to requirement seven. When your data is stored remotely, only very specific people will have access to the information, and, in respect to requirement number eight, they will have (or should have) an ID attached to them so activities on sensitive systems can easily be tracked.

PCI compliance can be a complex, expensive, and time consuming endeavor. As more and more consumers become weary of conducting transactions with credit cards, the PCI SSC is going to do more to ensure a safe environment that encourages consumerism. Still, many companies have opted to procrastinate implementing proper security and reaching compliance because of the complexities involved.

Remote storage of credit card data is one of the best ways to reduce those complexities and take important steps toward PCI compliance.

Above all, the most important thing to remember is that a criminal cannot steal what you don't have. Storing important data off-site means you are no longer a target for people with criminal intentions.



Article Source: http://www.eArticlesOnline.com

About the Author:
Andy Eliason is a writer at Main10, Inc. If you'd like to learn more about the possibilities associated with remote storage of credit card data, or becoming PCI compliant, visit Braintree Payment Solutions today.

Tags: , , , , ,

Please Rate this Article

 

Not yet Rated

Click the XML Icon Above to Receive Business Articles Via RSS!

Recent Related Articles From Business

  • Why Choose Remote Storage Of Credit Card Data?
    By: Andy Eliason | Mar 7th 2008
    One of the best solutions to cover some of the loopholes that have a tendency to crop up in conventional security methods is remote storage of credit card data. Read

  • Planning For The Payment Card Industry Data Security Standard
    By: Andy Eliason | Mar 14th 2008
    The Payment Card Industry Data Security Standard (PCI DSS) was created to help guide companies toward higher standards of security to protect sensitive cardholder data. Planning ahead for the necessary changes is just good business sense. Read

  • Options For Those Needing A Bad Credit Credit Card
    By: Bradley Carson | Sep 11th 2006
    It's a fact that the credit card issuers are predisposed towards those with excellent credit. But let's face it, not everyone has superior credit. There are times when life has thrown in a few punches that can cause financial hardship that in turn damages your credit. If you're presently in this position, don't fret, there ... Read

  • Bad Credit Credit Card Offers
    By: Edward Vegliante | Mar 26th 2007
    Having less than perfect credit does not cancel out your credit card options. In fact, just the opposite is true. These days, credit card lenders issue plastic for every need under the sun. This includes cards designed specifically for those with poor credit. By taking advantage of a bad credit credit card, you can get back ... Read

  • What Is A Bad Credit Credit Card?

    A bad credit credit card is a phrase which describes credit cards issued to individuals with bad credit ratings. "Bad credit credit cards" provide a chance for people with less than perfect credit to obtain a credit line and possibly improve their credit rating. Although these creditcards will carry rather "unfriendly" term ... Read

  • Understanding Credit, Credit Card Debt Consolidation And Credit Restoration
    By: Dale Jones | Apr 16th 2008
    When you start looking for credit, credit card debt consolidation and credit restoration companies you have a few choices. Learn what those choices are and how they can help you. Read

  • Best Bad Credit Credit Cards Offers In Uk
    By: devid anderson | Jul 29th 2010
    Do you have a bad credit rating in the market of credit cards? Is it getting difficult for you to get a credit card in UK for your needs? There are a lot of websites that provide information about various bad credit credit card providers. Read

  • Bad Credit Credit Cards: How To Use Them
    By: Edward Vegliante | Feb 9th 2008
    If you've had trouble with credit in the past, it can be difficult to find lenders who will issue you more credit. This is not the case with bad credit credit cards. These cards are specifically designed for those who need to rebuild their credit rating. If you make the right moves, a bad credit credit card can be your tick ... Read

  • Poor Credit Credit Card
    By: Jessica Lamber | Feb 15th 2009
    Review of poor credit credit cards and the different options available. Read

  • Selecting Bad Credit Credit Cards
    By: devid anderson | Sep 20th 2010
    What exactly do we mean by bad credit credit cards? These are the credit cards that are specially designed for people who have a bad credit and who wish to rebuild their credit reputation. Read


Copyright © 2005-2011 eArticlesOnline, LLC - All Rights Reserved
Terms of Service | Privacy Policy