Level Extreme platform
Subscription
Corporate profile
Products & Services
Support
Legal
Français
PCI Compliance
Message
 
 
To
09/03/2010 16:55:15
General information
Forum:
Visual FoxPro
Category:
Other
Title:
Miscellaneous
Thread ID:
01453510
Message ID:
01453639
Views:
79
>I've been through three audits with Trustwave over the last few years and 15-20K sounds about right.
>
>By now most compliance issues are covered in our product but there are always new ones every year or so. From what I can tell the card associations are pushing to never have cardholder information stored at the merchant site by using a link, a transaction ID, to the payment processor who will have the cardholder information stored there, or farther downstream. For a small shop some of the audit requirements are out of touch with reality, code reviews, change logs, software development life cycle policies that have to be documented, etc. With Trustwave expect an audit to take 3 months and pray you get someone who speaks English and knows what the difference between a desktop or web based app.

But that's the beauty of having a processor who stores the credit card data. They are the ones who have to be PCI compliant, not you. I don't know why a merchant who has a processor would need Trustwave or any other auditor. Maybe software developers who sell POS systems are in a special category.
Previous
Reply
Map
View

Click here to load this message in the networking platform