QSA's View on PCI Compliance for Mail Orders


http://blogs.bankinfosecurity.com/posts.php?postID=656

By Peter Spier

 

Despite the Payment Card Industry Security Standards Council's establishment of a Quality Assurance program "to promote consistent interpretation of the PCI standards and ensure [that] quality is maintained" ... the proverbial devil remains in the details.

So, let's for a moment take the complications of technology-based controls out of it and, for simplicity, consider exactly how the PCI Data Security Standard affects a decidedly more "low-tech" form of cardholder data -- hardcopy transactions...