PCI-DSS Compliance
The Payment Card Industry Data Security Standard (PCI-DSS) was designed by major card issuers and acquirers to prevent credit card fraud, and applies to organizations which hold, process or pass credit card data during the normal course of business. Compliance must be assessed annually, and for businesses with high volumes of transactions a Qualified Security Assessor must verify that proper PCI-DSS enforcement controls are in place. Enforcement is performed separately by card organizations and acquirers.
Why You Should Care About PCI-DSS Compliance
If you’ve tried to renegotiate your merchant banking relationships recently, you’ll realize why PCI-DSS compliance is so critical to your organization. Banks have started charging higher rates to customers who fail to comply with PCI-DSS requirements. In some instances, merchant banks are refusing to do business with non-compliant organizations. Add to that the liability from legal action should customer credit card data be leaked, audit fees, fines — and the embarrassing public relations scenario that occurs when a breach is made public — and PCI-DSS compliance can quickly rise to the top of any Compliance Manager’s “to-do” list.
What Are The Requirements?
PCI-DSS requires that certain controls be implemented and enforced to protect the privacy of customer credit card data, including:
- 1: Build and Maintain a Secure Network
- 2: Protect Cardholder Data
- 3: Maintain a Vulnerability Management Program
- 4: Implement Strong Access Control Measures
- 5: Regularly Monitor and Test Networks
- 6: Maintain an Information Security Policy
How Can Unity Compliance Software Help?
Unity Compliance Software allows businesses to implement, manage, and report on the internal control structures required for PCI-DSS compliance. Data input templates can easily load PCI-DSS security control standards, and Unity’s Action Plan feature supports control testing and collecting of required supporting evidence: by group, individual, and requirement. Unity’s real-time compliance dashboards manage control and test activity, including remediation and exception handling processes. A reporting module supports preparing ad-hoc reports to track activities, ensuring all major systems have coverage. And Unity’s Electronic Binder reduces the effort and costs associated with PCI-DSS audits or inquiries, providing a single repository for all PCI-DSS compliance controls, supporting evidence, reported issues, and remediation details.
To learn more about how Trintech’s Unity Compliance Software module can help you comply with PCI-DSS, contact us today.

