|
|||
www.ecommerce-guide.com/news/trends/article.php/739361
|
By Mark Merkow, CCP, CISSP April 10, 2001 Visa USA is now offering a helping hand to e-commerce merchants in safeguarding payment card data, and protecting card members, merchants, and member banks from fraudulent uses of stolen payment cards. The Visa Cardholder Information Security Program (CISP) is a comprehensive list of 12 guidelines put out to help merchants meet a May 2001 deadline for safeguarding their e-commerce sites. Specifications and implementation guidance include:
To aid in their implementation, Visa is providing merchants with training sessions, interactive reviews, compliance and monitoring consultation, and information on third party firms specializing in testing and compliance. "Many merchants have already taken steps to lock up payment card data online, and Visa's requirements are like a 'virtual deadbolt'," said John Shaughnessy, senior vice president, Risk Management, Visa U.S.A. "Visa is working with merchants to heighten data security and ultimately increase consumer confidence in e-commerce. Together, we can give consumers the same security online that they have come to expect in the physical world." CISP was created specifically for mail-order/telephone-order (MOTO) and Internet merchants along with any third-party processing agents, but also applies to any type of merchant who accepts transactions in a 'card-not-present' purchasing environment. Why Comply?
Serving as both a carrot and a stick, the CISP helps Visa to accelerate their demands on merchants to do a much better job of credit card security than what's been seen in the past. The new Visa USA Operating Regulations include a monitoring and compliance program that will take effect this year. Failing to live up to these regulations places your ability to accept Visa cards on your Web in jeopardy. Besides that, implementing these countermeasures and compensating controls is simply the right thing to do! Peeking inside Version 5.5 of the CISP, you'll find sections on:
Visa has also provided online collateral to help merchants get started and to answer their questions and concerns. The Visa Merchant Resource Center Web site offers a wide variety of information and training on how to best conduct business electronically, and covers all types of hints and tips for all types of retail merchants. You can also download a copy of the CISP from the site. |