The Pci Dss Standard: A Legal Mandate

what law created pci dss standard

The Payment Card Industry Data Security Standard (PCI DSS) is a cybersecurity standard that was created to combat the rising credit card fraud in the late 1990s and early 2000s, which was a result of the introduction of online shopping. It is not a law, but a set of security standards developed by the PCI Security Standards Council (PCI SSC), a private organization. The PCI DSS has been implemented and followed worldwide, with the first version being released in December 2004. Compliance with PCI DSS is required by credit card companies for any organization that processes, stores, or transmits credit card information. While it is not mandated by federal law, some states in the US, such as Nevada, Minnesota, and Washington, have incorporated portions of the PCI DSS into their state laws.

Characteristics Values
What is it? A set of security standards to protect cardholder data and reduce credit card fraud.
Administered by Payment Card Industry Security Standards Council (PCI SSC)
Created by Major credit card companies: MasterCard, American Express, Visa, JCB International, and Discover Financial Services.
Compliance Required by credit card companies for any organisation that processes, stores, or transmits cardholder data.
Compliance validation Annual or quarterly, depending on the volume of transactions.
Compliance levels Four levels, with twelve requirements in total.
Compliance benefits Enhanced customer trust, reduced risk of data breaches, fraud protection, improved standing with partners, stakeholders, and regulators.
Compliance challenges Complexity, cost, ongoing effort, and a changing environment.
Fines Not mandated by federal law. Fines are penalties built into contracts between merchants, payment processors, and card brands.
State law Portions of PCI DSS have been written into state law in Nevada, Minnesota, and Washington.

lawshun

PCI DSS is a security standard, not a law

The Payment Card Industry Data Security Standard (PCI DSS) is a security standard, not a law. It is a set of security policies and global information standards that protect credit and payment card data and transactions. It was created by the Payment Card Industry Security Standards Council (PCI SSC) to better control cardholder data and reduce credit card fraud. Compliance with PCI DSS is mandated by the contracts that merchants sign with the card brands (Visa, MasterCard, etc.) and with the banks that handle their payment processing.

While PCI DSS is not a law, it may compel businesses to pay more attention to IT security and ensure that they adhere to industry best practices when processing, storing, and transmitting cardholder data. It provides a baseline of technical and operational requirements designed to protect payment account data. For example, the PCI P2PE Standard defines security requirements for P2PE Solutions, P2PE Components, and P2PE Applications to protect payment account data via encryption from the point it is captured in the merchant's payment device to the point it is decrypted in a solution provider's environment.

The PCI DSS has twelve requirements for compliance, organized into six related groups known as control objectives. These requirements include installing and maintaining network security controls, protecting stored cardholder data, developing and maintaining secure systems, restricting access to cardholder data, regularly testing the security of systems, and supporting information security with organizational policies.

While PCI DSS compliance is not legally mandated, non-compliance can result in fines from card brands such as Visa and Mastercard. Additionally, compliant entities are shielded from liability in the event of a data breach. It's important to note that these fines are based on contractual penalties rather than government-imposed fines or legal violations.

The UN's Law-Making Powers: Explained

You may want to see also

lawshun

Compliance is mandated by credit card companies

Compliance with PCI DSS is mandated by credit card companies for any organisation that processes, stores, or transmits credit card information. It is a security standard, not a law, and compliance is required by the contracts that merchants sign with the card brands and with the banks that handle their payment processing.

The Payment Card Industry Data Security Standard (PCI DSS) is an information security standard used to handle credit cards from major card brands. It was created to better control cardholder data and reduce credit card fraud, which was on the rise in the late 1990s and early 2000s with the introduction of online shopping. The standard is administered by the Payment Card Industry Security Standards Council (PCI SSC), a private organisation formed in September 2006 by MasterCard, American Express, Visa, JCB International and Discover Financial Services.

The PCI DSS establishes cybersecurity controls and business practices that any company that accepts credit card payments must implement. Credit and debit card numbers are valuable sequences of digits that can be used to make fraudulent purchases and drain money from user accounts. Banks and other credit card issuers will generally refund their customers in these situations, so they have a vested interest in ensuring that credit card numbers are secure.

The PCI DSS has twelve requirements, which are both operational and technical, and the core focus of these rules is always to protect cardholder data. The twelve requirements include installing and maintaining network security controls, protecting stored card data, developing and maintaining secure systems, restricting access to cardholder data, and regularly testing security systems.

Compliance with PCI DSS is mandatory for any business handling cardholder data, and validation of compliance must be performed annually or quarterly depending on the volume of transactions. It is generally mandated by credit card companies and discussed in credit card network agreements. Failure to comply can result in fines, penalties, and increased scrutiny from the payment card brands.

lawshun

It was created to combat rising credit card fraud

The Payment Card Industry Data Security Standard (PCI DSS) is a cybersecurity standard that was created to combat rising credit card fraud. It is a set of security policies and guidelines designed to protect credit and payment card data and transactions. The standard is not a law, but a contract between merchants, payment processors, and card brands.

PCI DSS was developed by the Payment Card Industry Security Standards Council (PCI SSC), which was formed by major credit card companies including MasterCard, American Express, Visa, JCB International, and Discover Financial Services. The council created PCI DSS to establish cybersecurity controls and business practices that any company accepting credit card payments must implement.

The primary goal of PCI DSS is to safeguard and optimize the security of sensitive cardholder data, such as credit card numbers, expiration dates, and security codes. The standard's security controls help businesses minimize the risk of data breaches, fraud, and identity theft. Compliance with PCI DSS ensures that businesses adhere to industry best practices when processing, storing, and transmitting credit card data, fostering trust among customers and stakeholders.

PCI DSS has twelve requirements for compliance, organized into six related groups known as control objectives. These requirements include installing and maintaining network security controls, protecting cardholder data with strong cryptography during transmission, regularly testing security systems, and restricting access to cardholder data.

While PCI DSS compliance is not mandated by federal law in the United States, some state laws, such as those in Minnesota, Nevada, and Washington, have incorporated the standard, requiring compliance by merchants doing business in those states. Compliance with PCI DSS is mandatory for all merchants globally and is enforced by the major card brands, who may impose fines and penalties for non-compliance.

Creating a Motion: Navigating Family Law

You may want to see also

lawshun

It is administered by the Payment Card Industry Security Standards Council

The Payment Card Industry Security Standards Council (PCI SSC) is a global forum that brings together payments industry stakeholders to develop and drive the adoption of data security standards and resources for safe payments worldwide. It was formed by American Express, Discover Financial Services, JCB International, MasterCard, Visa Inc., and UnionPay on 7 September 2006, with the goal of managing the ongoing evolution of the Payment Card Industry Data Security Standard (PCI DSS). The PCI DSS is a widely accepted set of policies and procedures intended to optimise the security of credit, debit and cash card transactions and protect cardholders against misuse of their personal information. It is not a law or legal regulatory requirement, and compliance is instead mandated by the contracts that merchants sign with the card brands and the banks that handle their payment processing.

The PCI DSS defines security requirements to protect environments where payment account data is stored, processed, or transmitted. It provides a baseline of technical and operational requirements designed to protect payment data throughout the payment lifecycle. The standard's security controls help businesses minimise the risk of data breaches, fraud and identity theft. Compliance with PCI DSS also ensures that businesses adhere to industry best practices when processing, storing and transmitting credit card data.

The PCI SSC has created six major goals for PCI DSS: Build and maintain a secure network and systems, protect stored account data, protect cardholder data with strong cryptography during transmission over open, public networks, develop and maintain secure systems and software, restrict access to system components and cardholder data, and identify users and authenticate access to system components.

The PCI SSC operates programs to train, test, and qualify organisations and individuals who assess and validate compliance, to help merchants successfully implement PCI standards and solutions. The council lays down several security standards that organisations in different industry segments must implement. For example, PCI PTS covers manufacturers of PIN-based devices, and PCI PA-DSS governs payment application security.

lawshun

Some US states have incorporated it into state law

The Payment Card Industry Data Security Standard (PCI DSS) is an information security standard used to handle credit cards from major card brands. It was created to better control cardholder data and reduce credit card fraud. The standard is administered by the Payment Card Industry Security Standards Council (PCI SSC), and its use is mandated by the card brands.

While PCI DSS is a security standard and not a law, some US states have incorporated it into state law. In 2007, Minnesota enacted a law prohibiting the retention of some types of payment card data more than 48 hours after authorization of a transaction. This was followed by Nevada in 2009, which required compliance by merchants doing business in that state with the current PCI DSS and shielded compliant entities from liability. The Nevada law also allows merchants to avoid liability by other approved security standards. In 2010, Washington became the third state to incorporate PCI DSS into state law, with the passing of HB 1149, which amended the state's breach notice law. Unlike Nevada's law, entities are not required to be PCI DSS-compliant; however, compliant entities are shielded from liability in the event of a data breach.

Frequently asked questions

PCI DSS, or Payment Card Industry Data Security Standard, is a set of security policies that protect credit and payment card data and transactions.

No, PCI DSS is not a federal regulation. Compliance with the standard is mandated by credit card companies and discussed in credit card network agreements. However, some states in the US, such as Nevada, Minnesota, and Washington, have incorporated parts of the PCI DSS into state law.

The PCI DSS standard was created by the Payment Card Industry Security Standards Council (PCI SSC), a private organization formed by MasterCard, American Express, Visa, JCB International, and Discover Financial Services.

The PCI DSS standard was developed due to the introduction of online shopping and rising credit card fraud in the late 1990s and early 2000s. The lack of security measures, such as using firewalls and encrypting cardholder data, led to significant losses for businesses and payment card companies. The PCI DSS standard aims to provide a uniform standard for card payment security worldwide.

The PCI DSS standard applies to any organization that processes, stores, or transmits credit card information. This includes merchants, service providers, processors, acquirers, issuers, and financial institutions.

Written by
Reviewed by

Explore related products

Share this post
Print
Did this article help you?

Leave a comment