Forum Moderators: buckworks

Message Too Old, No Replies

The PCI PA-DSS and July 2010

Are your payment applications compliant?

         

MrWumpus

6:16 pm on Aug 4, 2009 (gmt 0)

10+ Year Member



I'm surprised not to see more mention here of the PA-DSS (payment application data security standard) set to take effect July 2010.

[pcisecuritystandards.org ]

What it means for us is that neither our order management software nor our shopping cart vendors have released PA-DSS compliant versions of their products. So imagine you are a small business with 10 years of custom code, scripts, macros, etc, interfacing your shopping carts and your order management/CRM and you can't even begin working on migrating this to the PA-DSS versions because they don't exist. And you have 11 months left.

I can't imagine us meeting the July 2010 compliance deadline, so we will be at risk of fines. No one really seems to know what those fines are, but obviously if customer payment data is compromised through your site while you are non-PCI compliant, you are subject to hefty fines. I asked Visa what sort of enforcement would take place, and they said ask your acquiring bank. I asked our acquiring bank and all they have said is, "July 2010 is the deadline."

If you visit the official PCI site, you'll see a list of compliant PA-DSS applications. Currently there are only three shopping carts listed.

So what will you be doing until July 2010? Are you already not storing credit cards and using an external gateway and a PA-DSS compliant shopping cart?

As far as I can see the only way around using compliant applications is to code your own custom ones (securely of course) which are then not subject to the PA-DSS. At this pace, that might be the only (extremely expensive) solution if we want to meet the deadline.

Leosghost

6:33 pm on Aug 4, 2009 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



The website's ( that you linked to ) nav is unusable in Opera ..their TOS appears to be of the "arriving at our webpage makes you bound by our TOS" kind of rubbish ( arent those TOS illegal in the USA ? ) and appears to be US only thing ..and an LLC

So presumably it has no remit outside of the USA ..and is it even official ?

..if it's nav worked ..

One might be able to find out ..
but the "about us" opens .."drops down"
to the left ..
and thus under "news and events" ..
and if you move the mouse ..
to get to the "faq" etc on the dropdown ...
the nav closes ..

Fail.

and whadda ya know ..to join them costs $2500.oo ..fail and scam

LifeinAsia

6:45 pm on Aug 4, 2009 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



If they are smart (yes, that's always a big if), they will make their changes so that they are backwards compatible. So people using the updated applications should need to little, if any, modification to their own code once their PA-DSS version is done. I haven't really looked into it, but I image that most of the changes would be done internal to their systems and pretty much transparent to users.