{"id":1836,"date":"2010-05-21T14:47:02","date_gmt":"2010-05-21T21:47:02","guid":{"rendered":"http:\/\/www.pdxtc.com\/wpblog\/?p=1836"},"modified":"2014-12-04T13:16:32","modified_gmt":"2014-12-04T20:16:32","slug":"pci-compliant-web-hosting","status":"publish","type":"post","link":"https:\/\/www.pdxtc.com\/wpblog\/web-hosting\/pci-compliant-web-hosting\/","title":{"rendered":"PCI Compliant Web Hosting"},"content":{"rendered":"<p>There&#8217;s a set of &#8220;requirements&#8221; called Payment Card Industry Data Security Standards (PCI DSS) that was developed by the PCISSC\u00a0 Payment Card Industry Security Standards Council.<\/p>\n<p>I first heard of these &#8220;requirements&#8221; in the bar on the last day at Pubcon Vegas 2008, where someone said &#8220;Trust me, you&#8217;d BETTER learn about it, because they&#8217;ll make your life miserable if you don&#8217;t&#8230;&#8221;, and they were sure right.<\/p>\n<p>In 2009 one of my long time consulting clients actually began GETTING FINED by their processor for not being PCI compliant.<\/p>\n<p>At first the fine was about $40 monthly, but that quickly mushroomed, and all of a sudden, they were told that it was several hundred dollars a month.<\/p>\n<p>We changed shopping carts, then worked with the web host, and all was finally resolved, but it took four months and several thousand dollars. Can you afford that unexpectedly?<\/p>\n<p>Before you ask &#8220;who has the authority to fine them?&#8221; you should know that in their case it was called a &#8220;fee&#8221; and not a &#8220;fine&#8221; and it was imposed by their middleman transaction processor, not Authorize.net or their bank.<\/p>\n<p>The official &#8220;power&#8221; to impose that fee is actually non-existent and totally arbitrary, sort of like blockbuster charging a late fee &#8211; because they can.<\/p>\n<p><strong>Get On Top of PCI Compliance NOW<\/strong><br \/>\nIt likely won&#8217;t be long before EVERYONE that will process the credit card you take on your website will have to decline your business transactions, and this will put you out of business.<\/p>\n<p>This simply designed to provide a standardized set of consistent security measures for merchants to follow that are handling credit card transactions. &#8211; i.e. it&#8217;s for our own good.<\/p>\n<p>Yes it&#8217;s going to be a pain in the ass to get compliant, but it&#8217;s not nearly as bad as trying to recover fraudulent funds that get their transactions reversed after you have shipped or delivered your product, is it?<\/p>\n<p>Worse, will it be as bad as finding out that not only are you being charged a &#8220;fee&#8221; but in fact, your bank will no longer accept your transactions?<\/p>\n<p>All you have to do is check your site with a vulnerability scanner for PCI Compliance. There are a number of them out there, and your bank should offer one to you soon, if they haven&#8217;t already.<\/p>\n<p>In some situations, you may find the need to move to web hosting platform that is claiming compliance that is willing to offer a statement about their compliance, and here&#8217;s our statement&#8230;<\/p>\n<h5>We are not PCI compliant.<\/h5>\n<p>&nbsp;<\/p>\n<p>There &#8211; do you you like that? We also have NO INTENTION of becoming a PCI compliant web host, because in doing so, we&#8217;d open ourselves to liability just by claiming we are.<\/p>\n<p>I just completed an evaluation, and while I won&#8217;t go into the specifics, even though they may be fixable, they are going to be consuming, and we probably won&#8217;t be\u00a0 compliant\u00a0 in 2010.<\/p>\n<p>The most frustrating thing is that the last time we scanned for this, nearly 8 months ago, we DID pass the test, although the test was from a a different source.<\/p>\n<p>Also, note that I&#8217;ve yet to run an audit anywhere recently (6 hosts in the past month) and find a perfect report, so I think the entire industry has some work to do.<\/p>\n<p>If any web hosts want to leave links to their PCI compliance statements as comments, please do!<\/p>\n<p><strong>What EXACTLY is the Standard? <\/strong><br \/>\nThe standard includes these 12 requirements for maintaining a secure operation:<\/p>\n<p><strong>Build and Maintain a Secure Network<\/strong><\/p>\n<ul>\n<li>Requirement 1: Install and maintain a firewall configuration to protect cardholder data<\/li>\n<li>Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters<\/li>\n<\/ul>\n<p><strong> Protect Cardholder Data<\/strong><\/p>\n<ul>\n<li>Requirement 3: Protect stored cardholder data<\/li>\n<li>Requirement 4: Encrypt transmission of cardholder data across open, public networks<\/li>\n<\/ul>\n<p><strong> Maintain a Vulnerability Management Program<\/strong><\/p>\n<ul>\n<li>Requirement 5: Use and regularly update anti-virus software<\/li>\n<li>Requirement 6: Develop and maintain secure systems and applications<\/li>\n<\/ul>\n<p><strong> Implement Strong Access Control Measures<\/strong><\/p>\n<ul>\n<li>Requirement 7: Restrict access to cardholder data by business need-to-know<\/li>\n<li>Requirement 8: Assign a unique ID to each person with computer access<\/li>\n<li>Requirement 9: Restrict physical access to cardholder data<\/li>\n<\/ul>\n<p><strong> Regularly Monitor and Test Networks<\/strong><\/p>\n<ul>\n<li>Requirement 10: Track and monitor all access to network resources and cardholder data<\/li>\n<li>Requirement 11: Regularly test security systems and processes<\/li>\n<\/ul>\n<p><strong> Maintain an Information Security Policy<\/strong><\/p>\n<ul>\n<li>Requirement 12: Maintain a policy that addresses information security<\/li>\n<\/ul>\n<p>So there it is &#8211; right <a href=\"https:\/\/www.pcisecuritystandards.org\/security_standards\/pci_dss.shtml\" target=\"_blank\">from the horses mouth<\/a> &#8211; You&#8217;re gonna get screwed, and may have to move your hosting.<\/p>\n<p><strong>What can you do now?<\/strong><br \/>\nTry this free <a href=\"http:\/\/www.hackerguardian.com\/hackerguardian\/learn\/pci_free_scan.html\" target=\"_blank\" rel=\"nofollow\">PCI Compliance scan from Comodo<\/a>. The last one we ran, got us back a 39 page report.<\/p>\n<p>The report is self explanatory <em>if you&#8217;re a tech person<\/em>. If not, then you&#8217;ll need to run it by your computer service folks or admins so they can explain what&#8217;s a server issue for your web host, and what might actually be related to your shopping cart, your website, your interface, etc.<\/p>\n<p>After that, start looking for a host that is willing to say they&#8217;re PCI Compliant. Then, run a test on a URL they host, and don&#8217;t just take their word for it. Remember, if they turn out not to be, YOU are the one that gets screwed.<\/p>\n<p>And again, if you have any recommendations,\u00a0 please be sure to leave a link to their actual compliance statement. I&#8217;ll update this post in the future&#8230;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>There&#8217;s a set of &#8220;requirements&#8221; called Payment Card Industry Data Security Standards (PCI DSS) that was developed by the PCISSC\u00a0 Payment Card Industry Security Standards Council. I first heard of these &#8220;requirements&#8221; in the bar on the last day at Pubcon Vegas 2008, where someone said &#8220;Trust me, you&#8217;d BETTER learn about it, because they&#8217;ll [&hellip;]<\/p>\n","protected":false},"author":76,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[14],"tags":[359],"class_list":["post-1836","post","type-post","status-publish","format-standard","hentry","category-web-hosting","tag-pci-compliance"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>PCI Compliant Web Hosting<\/title>\n<meta name=\"description\" content=\"There&#039;s a set of &quot;requirements&quot; called Payment Card Industry Data Security Standards (PCI DSS) that was developed by the PCISSC\u00a0 Payment Card Industry\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.pdxtc.com\/wpblog\/web-hosting\/pci-compliant-web-hosting\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"PCI Compliant Web Hosting\" \/>\n<meta property=\"og:description\" content=\"There&#039;s a set of &quot;requirements&quot; called Payment Card Industry Data Security Standards (PCI DSS) that was developed by the PCISSC\u00a0 Payment Card Industry\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.pdxtc.com\/wpblog\/web-hosting\/pci-compliant-web-hosting\/\" \/>\n<meta property=\"og:site_name\" content=\"Scott Hendison&#039;s Old Search Commander Blog\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/SearchCommander\" \/>\n<meta property=\"article:published_time\" content=\"2010-05-21T21:47:02+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2014-12-04T20:16:32+00:00\" \/>\n<meta name=\"author\" content=\"Scott\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@shendison\" \/>\n<meta name=\"twitter:site\" content=\"@shendison\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Scott\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/web-hosting\\\/pci-compliant-web-hosting\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/web-hosting\\\/pci-compliant-web-hosting\\\/\"},\"author\":{\"name\":\"Scott\",\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/#\\\/schema\\\/person\\\/3142c7d28dc676725ac62cd6c9de8371\"},\"headline\":\"PCI Compliant Web Hosting\",\"datePublished\":\"2010-05-21T21:47:02+00:00\",\"dateModified\":\"2014-12-04T20:16:32+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/web-hosting\\\/pci-compliant-web-hosting\\\/\"},\"wordCount\":893,\"commentCount\":7,\"keywords\":[\"pci compliance\"],\"articleSection\":[\"Web Hosting\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/web-hosting\\\/pci-compliant-web-hosting\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/web-hosting\\\/pci-compliant-web-hosting\\\/\",\"url\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/web-hosting\\\/pci-compliant-web-hosting\\\/\",\"name\":\"PCI Compliant Web Hosting\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/#website\"},\"datePublished\":\"2010-05-21T21:47:02+00:00\",\"dateModified\":\"2014-12-04T20:16:32+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/#\\\/schema\\\/person\\\/3142c7d28dc676725ac62cd6c9de8371\"},\"description\":\"There's a set of \\\"requirements\\\" called Payment Card Industry Data Security Standards (PCI DSS) that was developed by the PCISSC\u00a0 Payment Card Industry\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/web-hosting\\\/pci-compliant-web-hosting\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/web-hosting\\\/pci-compliant-web-hosting\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/web-hosting\\\/pci-compliant-web-hosting\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"PCI Compliant Web Hosting\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/#website\",\"url\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/\",\"name\":\"Scott Hendison&#039;s Old Search Commander Blog\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.pdxtc.com\\\/wpblog\\\/#\\\/schema\\\/person\\\/3142c7d28dc676725ac62cd6c9de8371\",\"name\":\"Scott\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ba275e23c0aad37526141e715b54cd3eeac27b071e4395b2b39e801ca68355d6?s=96&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ba275e23c0aad37526141e715b54cd3eeac27b071e4395b2b39e801ca68355d6?s=96&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ba275e23c0aad37526141e715b54cd3eeac27b071e4395b2b39e801ca68355d6?s=96&r=g\",\"caption\":\"Scott\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/shendison\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"PCI Compliant Web Hosting","description":"There's a set of \"requirements\" called Payment Card Industry Data Security Standards (PCI DSS) that was developed by the PCISSC\u00a0 Payment Card Industry","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.pdxtc.com\/wpblog\/web-hosting\/pci-compliant-web-hosting\/","og_locale":"en_US","og_type":"article","og_title":"PCI Compliant Web Hosting","og_description":"There's a set of \"requirements\" called Payment Card Industry Data Security Standards (PCI DSS) that was developed by the PCISSC\u00a0 Payment Card Industry","og_url":"https:\/\/www.pdxtc.com\/wpblog\/web-hosting\/pci-compliant-web-hosting\/","og_site_name":"Scott Hendison&#039;s Old Search Commander Blog","article_publisher":"https:\/\/www.facebook.com\/SearchCommander","article_published_time":"2010-05-21T21:47:02+00:00","article_modified_time":"2014-12-04T20:16:32+00:00","author":"Scott","twitter_card":"summary_large_image","twitter_creator":"@shendison","twitter_site":"@shendison","twitter_misc":{"Written by":"Scott","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.pdxtc.com\/wpblog\/web-hosting\/pci-compliant-web-hosting\/#article","isPartOf":{"@id":"https:\/\/www.pdxtc.com\/wpblog\/web-hosting\/pci-compliant-web-hosting\/"},"author":{"name":"Scott","@id":"https:\/\/www.pdxtc.com\/wpblog\/#\/schema\/person\/3142c7d28dc676725ac62cd6c9de8371"},"headline":"PCI Compliant Web Hosting","datePublished":"2010-05-21T21:47:02+00:00","dateModified":"2014-12-04T20:16:32+00:00","mainEntityOfPage":{"@id":"https:\/\/www.pdxtc.com\/wpblog\/web-hosting\/pci-compliant-web-hosting\/"},"wordCount":893,"commentCount":7,"keywords":["pci compliance"],"articleSection":["Web Hosting"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.pdxtc.com\/wpblog\/web-hosting\/pci-compliant-web-hosting\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.pdxtc.com\/wpblog\/web-hosting\/pci-compliant-web-hosting\/","url":"https:\/\/www.pdxtc.com\/wpblog\/web-hosting\/pci-compliant-web-hosting\/","name":"PCI Compliant Web Hosting","isPartOf":{"@id":"https:\/\/www.pdxtc.com\/wpblog\/#website"},"datePublished":"2010-05-21T21:47:02+00:00","dateModified":"2014-12-04T20:16:32+00:00","author":{"@id":"https:\/\/www.pdxtc.com\/wpblog\/#\/schema\/person\/3142c7d28dc676725ac62cd6c9de8371"},"description":"There's a set of \"requirements\" called Payment Card Industry Data Security Standards (PCI DSS) that was developed by the PCISSC\u00a0 Payment Card Industry","breadcrumb":{"@id":"https:\/\/www.pdxtc.com\/wpblog\/web-hosting\/pci-compliant-web-hosting\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.pdxtc.com\/wpblog\/web-hosting\/pci-compliant-web-hosting\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.pdxtc.com\/wpblog\/web-hosting\/pci-compliant-web-hosting\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.pdxtc.com\/wpblog\/"},{"@type":"ListItem","position":2,"name":"PCI Compliant Web Hosting"}]},{"@type":"WebSite","@id":"https:\/\/www.pdxtc.com\/wpblog\/#website","url":"https:\/\/www.pdxtc.com\/wpblog\/","name":"Scott Hendison&#039;s Old Search Commander Blog","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.pdxtc.com\/wpblog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.pdxtc.com\/wpblog\/#\/schema\/person\/3142c7d28dc676725ac62cd6c9de8371","name":"Scott","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/ba275e23c0aad37526141e715b54cd3eeac27b071e4395b2b39e801ca68355d6?s=96&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/ba275e23c0aad37526141e715b54cd3eeac27b071e4395b2b39e801ca68355d6?s=96&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/ba275e23c0aad37526141e715b54cd3eeac27b071e4395b2b39e801ca68355d6?s=96&r=g","caption":"Scott"},"sameAs":["https:\/\/x.com\/shendison"]}]}},"_links":{"self":[{"href":"https:\/\/www.pdxtc.com\/wpblog\/wp-json\/wp\/v2\/posts\/1836","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.pdxtc.com\/wpblog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.pdxtc.com\/wpblog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.pdxtc.com\/wpblog\/wp-json\/wp\/v2\/users\/76"}],"replies":[{"embeddable":true,"href":"https:\/\/www.pdxtc.com\/wpblog\/wp-json\/wp\/v2\/comments?post=1836"}],"version-history":[{"count":0,"href":"https:\/\/www.pdxtc.com\/wpblog\/wp-json\/wp\/v2\/posts\/1836\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.pdxtc.com\/wpblog\/wp-json\/wp\/v2\/media?parent=1836"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.pdxtc.com\/wpblog\/wp-json\/wp\/v2\/categories?post=1836"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.pdxtc.com\/wpblog\/wp-json\/wp\/v2\/tags?post=1836"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}