Last week our industry gathered for the annual RSPA (Retail Solutions Providers Association) conference in Las Vegas. Like previous years, many of the educational sessions were dedicated to teaching POS professionals about the current and future requirements of any business that transacts credit card business. Some of us like to joke about Payment Card Industry (PCI) compliance being a "lifestyle" rather than a goal, but it is really no joking matter and something that must be attended to perpetually. The PCI Data Security Standard (PCI-DSS) is with us forever and all merchants must be aware and participate in the requirements their credit card processors impose on them. Cowan's Retail Systems can assist you in many of these areas and welcomes inquires; but to get you started in learning about your responsibilities, we offer the following resources.
The PCI Security Standards Council
This organization controls how credit card security should work. In their own words, "The PCI Security Standards Council is an open global forum for the ongoing development, enhancement, storage, dissemination and implementation of security standards for account data protection".
Find them at: https://www.pcisecuritystandards.org/
The Facts about PCI Software Validations by DCRS Solutions
DCRS Solutions is one of our sister Micros dealerships and an industry leader in both Retail and Hospitality POS (http://www.dcrs.com/). They have written an excellent primer on PCI-DSS, how it came about and where it is going.
"The Facts" pdf
Hackers Pick on the Small Guys by James Bickers
A short article explaining how the trend of credit card breaches is moving away from the large merchants who have embraced effective credit card security to the easier targets at the small merchant sites. This is bad news for the independent business owners and an alert to protect your customer's credit cards.
"Hackers" pdf
Payment Card Data Security for the Restaurant Industry. A white paper from Ambiron TrustWave
Trustwave is one of the few companies throughout the world certified by the credit card brands to perform the full range of solutions – from compliance validation to incident response to point-of-sale security (https://www.trustwave.com/). This in depth article discusses credit card breaches in the restaurant industry and list "best practices" to avoid breaches.
White Paper pdf
RSPA Project PCI. An educational video produced by the Retail Solutions Providers Association
See an interview with a small restaurant operator who actually had to suffer through a credit card data breach and all the fallout afterwards.
Part 1
Part 2
The Payment Card Industry Data Security Standard from the PCI Security Standards Council
This is the holy grail of what merchants need to do and what the fuss is all about -- not for the weak of heart. This 72 page document explains each of the 12 PCI DSS requirements in detail for the version 1.2 standard published in October of 2008.
PCI DSS Standard