Congratulations! You took the time to become PCI (Payment Card Industry Data Security Standard) compliant by accurately filling out your Self-Assessment Questionnaire (SAQ) and passing all the requirements; remediating your location until you internal and external vulnerability scans passed; and training your employees. Your location is secure now, right? Well, in all honesty, the answer is a resounding maybe.
You must understand that PCI is a good compliance standard, but it is no guarantee that you are actually secure. The PCI standard came about so that merchants who took credit cards would understand and comply with the minimum level of security that the credit card companies demanded to protect their credit cards. While PCI can be daunting, especially if you try to do everything on your own without professional guidance, it is only the minimum precaution you should take when trying to keep your environment safe.
To complicate matters even more, computer hackers do not stand still. They are constantly inventing new ways to break into systems, and protections that were adequate yesterday will no longer keep them out once they develop these new techniques. If you really want to stay secure in the long run, you must constantly have a process to identify new risks to your stores and react to them.
You are probably thinking to yourself, “But I’m not a security expert. How could I possibly find these risks.” You are right, and this can be a challenge. For small merchants in particular without formal training in risk assessment, the task is daunting, so taking a step back might help.
For most brick and mortar locations there are usually 3 primary risks (if your particular location has more complicated data storage, or if sensitive data is moved off-site, then you will have more than these 3). In no particular order, you should be concerned about external hackers and threats; internal issues and malicious employees; and physical theft. For each of these, you must identify your risk; determine what would be affected if you were compromised; protect your assets; and figure out how to mitigate the risk.
The PCI Security Standards Council has released a document to help you understand this process, but it was really designed for large environments with a qualified IT staff. Like many things in PCI, it is sometimes a best practice to admit that you need help and to ask a professional for guidance. It is better to get the help before you are affected than to be surprised later.
566
http://global.networldalliance.com/new/images/slideshows/show566_thumb8641.jpg
Hershey's Chocolate World sweetens experience with 4D show
Hershey's Chocolate World sweetens experience with 4D show
550
http://global.networldalliance.com/new/images/slideshows/show550_thumb8351.jpg
Walmart: A self-service tour
Walmart: A self-service tour
547
http://global.networldalliance.com/new/images/slideshows/show547_thumb8285.jpg
McCormick World of Flavors store
McCormick World of Flavors store
539
http://global.networldalliance.com/new/images/slideshows/show539_thumb8161.jpg
Wireless accessory retailer Cellairis debuts store concept
Wireless accessory retailer Cellairis debuts store concept
522
http://global.networldalliance.com/new/images/slideshows/show522_thumb7843.jpg
The 2012 holiday shopping windows of New York
The 2012 holiday shopping windows of New York
511
http://global.networldalliance.com/new/images/slideshows/show511_thumb7699.png
NCR Mobile Pay solution at City Winery, NYC
NCR Mobile Pay solution at City Winery, NYC
508
http://global.networldalliance.com/new/images/slideshows/show508_thumb7655.jpg
T-Mobile Global Design Concept redesign
T-Mobile Global Design Concept redesign
500
http://global.networldalliance.com/new/images/slideshows/show500_thumb7453.jpg
Glass Handbag store, Las Vegas
Glass Handbag store, Las Vegas
493
http://global.networldalliance.com/new/images/slideshows/show493_thumb7329.jpg
UNIQLO Westfield Garden State Plaza store
UNIQLO Westfield Garden State Plaza store
482
http://global.networldalliance.com/new/images/slideshows/show482_thumb7127.jpg
Bridgelux LED lighting refreshes retail interiors
Bridgelux LED lighting refreshes retail interiors
National Service Center Wireless Networking Services
http://global.networldalliance.com/new/images/products/279.png
279/National-Service-Center-Wireless-Networking-Services
In-store merchandising
http://global.networldalliance.com/new/images/products/4196.png
4196/In-store-merchandising
Digital Signage
http://global.networldalliance.com/new/images/products/4756.png
4756/Digital-Signage
LG M3704CCBA - 37" class (37.0" measured diagonally)
http://global.networldalliance.com/new/images/products/4316.png
4316/LG-M3704CCBA-37-class-37-0-measured-diagonally
Value-Driven LCD with Tuner | 32” NEC E322
http://global.networldalliance.com/new/images/products/4707.png
4707/Value-Driven-LCD-with-Tuner-32-NEC-E322
Sony® SnapLab® Pedestal
http://global.networldalliance.com/new/images/products/Sony_SnapLab_100.gif
159/Sony-SnapLab-Pedestal
Automated Retail KIOSKS
http://global.networldalliance.com/new/images/products/4828.png
4828/Automated-Retail-KIOSKS
Turnkey Digital Out-of-Home
http://global.networldalliance.com/new/images/products/EnQii_turnkey_100.gif
183/Turnkey-Digital-Out-of-Home
Financial Self-Service Solutions
http://global.networldalliance.com/new/images/products/4301.png
4301/Financial-Self-Service-Solutions
Healthcare Solutions
http://global.networldalliance.com/new/images/products/4298.png
4298/Healthcare-Solutions
|
Inside Networld Media Group Network Kiosk Marketplace
|
Popular on Networld Media Group | Other Networld Media Group Sites | Global Partners |
User Comments