Friday, November 16, 2012

pci-dss-compliance-and-multilingual-business-process-outsourcing ...

PCI DSS For BPO Contact Centers CallPoint PCI DSS Compliance and multilingual Business Process Outsourcing organizations   why is it safe for your outsourced contact center to handle online payments?

(ControlCase)

Your e-Commerce business is growing and you need a better customer service but you are worried that outsourcing can jeopardize your clients? sensitive financial data? ?The best way to find a Business Process Outsourcing provider that is safe to work with and don?t compromise your business is to partner with PCI Compliance standard certified companies.

So what are the key aspects you need to know with regards to PCI-DSS Compliance? Here is what the official Q&A says:

Q: What is PCI?

A: The Payment Card Industry Data Security Standard (PCI DSS) is a set of requirements designed to ensure that ALL companies that process, store or transmit credit card information maintain a secure environment.? Essentially any merchant that has a Merchant ID (MID).

The Payment Card Industry Security Standards Council (PCI SSC) was launched on September 7, 2006 to manage the ongoing evolution of the Payment Card Industry (PCI) security standards with focus on improving payment account security throughout the transaction process.? The PCI DSS is administered and managed by the PCI SSC (www.pcisecuritystandards.org), an independent body that was created by the major payment card brands (Visa, MasterCard, American Express, Discover and JCB.).

Q: To whom does PCI apply?

A: PCI applies to ALL organizations or merchants, regardless of size or number of transactions, that accepts, transmits or stores any cardholder data. Said another way, if any customer of that organization ever pays the merchant directly using a credit card or debit card, then the PCI DSS requirements apply.

Q: Where can I find the PCI Data Security Standards (PCI DSS)?

A: The Standard can be found on the PCI SSC?s Website:

https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml

Q: If I only accept credit cards over the phone, does PCI still apply to me?

A: Yes. All business that store, process or transmit payment cardholder data must be PCI Compliant.

Q: Do organizations using third-party processors have to be PCI compliant?

A: Yes. Merely using a third-party company does not exclude a company from PCI compliance. It may cut down on their risk exposure and consequently reduce the effort to validate compliance.? However, it does not mean they can ignore PCI.

Q: Are debit card transactions in scope for PCI?

A: In-scope cards include any debit, credit, and pre-paid cards branded with one of the five card association/brand logos that participate in the PCI SSC ? American Express, Discover, JCB, MasterCard, and Visa International.

Q: What are the penalties for noncompliance?

A: The payment brands may, at their discretion, fine an acquiring bank $5,000 to $100,000 per month for PCI compliance violations. The banks will most likely pass this fine on downstream till it eventually hits the merchant. Furthermore, the bank will also most likely either terminate your relationship or increase transaction fees.? Penalties are not openly discussed nor widely publicized, but they can catastrophic to a small business.

It is important to be familiar with your merchant account agreement, which should outline your exposure.

Q: Can the full credit card number be printed on the consumer?s copy of the receipt?

A: PCI DSS requirement 3.3 states ?Mask PAN when displayed (the first six and last four digits are the maximum number of digits to be displayed).? While the requirement does not prohibit printing of the full card number or expiry date on receipts (either the merchant copy or the consumer copy), please note that PCI DSS does not override any other laws that legislate what can be printed on receipts (such as the U.S. Fair and Accurate Credit Transactions Act (FACTA) or any other applicable laws). See the italicized note under PCI DSS requirement 3.3 ?Note: This requirement does not apply to employees and other parties with a specific need to see the full PAN, nor does the requirement supersede stricter requirements in place for displays of cardholder data (for example, for point of sale (POS) receipts).? Any paper receipts stored by merchants must adhere to the PCI DSS, especially requirement 9 regarding physical security.

Q: What if a merchant refuses to cooperate?

A: PCI is not, in itself, a law. The standard was created by the major card brands such as Visa, MasterCard, Discover, AMEX, and JCB. At their acquirers/service providers discretion, merchants that do not comply with PCI DSS may be subject to fines, card replacement costs, costly forensic audits, brand damage, etc., should a breach event occur.

Myth: You only have to be PCI compliant with the majority of criteria.

Fact: The pass mark for PCI is 100%, so if you fail even one of the criteria, you are not PCI compliant. The standard is not meant to be something to strive for; it is essentially a foundation, a basis for further security measures. Failing to achieve even one of the requirements, is failing to meet a basic standard for handling cardholder information. All companies that routinely handle this type of data should be aiming to exceed the standard. It?s just good business.

Myth: ??? As a merchant, I did not sign anything saying I would be complaint; therefore, I don?t need to be.

Fact: The PCI standard forms part of the operating regulations that are the rules under which merchants are allowed to operate merchant accounts. The regulations signed when you open an account at the bank state that the VISA regulations have to be adhered to. Even if you have been in business for decades, PCI still applies if you store, process or transmit credit cards.

In our own experience at CallPoint ? one of the biggest providers of customer care services in Eastern Europe to pan-European and global e-Commerce companies ? boosting PCI-DSS Compliance is of crucial importance to being able to safely support debit and credit card operations via phone or e-mail. The general feedback from our customers is that PCI-DSS Compliance has been one of the key factors to work with us. This refers to an equal extent to the provided IT infrastructure and physical environment as well as the processes and workflows our employees follow when complying with the highest information security industry standards.

Even more so: the fact that our company is PCI-DSS certified by an external Approved Scanning Vendor (ASV) has enhanced our partners? perception of CallPoint being a BPO organization at which their payment processes are ?in safe hands?.

What is your opinion on the Payment Card Industry Data Security Standard (PCI DSS) and what in your view is critical to assure sensitive and financial data safety for an e-Commerce outsourced customer care project?

Source: http://www.multilingual-bpo.com/pci-dss-compliance-and-multilingual-business-process-outsourcing-organizations-why-is-it-safe-for-your-outsourced-contact-center-to-handle-online-payments/

jessica simpson chris brown 911 Google Docs masterchef Dictionary.com Chicago teachers strike

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.