
Resources
NOTE: To view the following information in Gujarati, please click here.
Acceptance of credit cards for payment has grown exponentially at small businesses across the US. Hotels of all sizes should be aware of the risk for theft and fraud, and take action to combat this by certifying with the industry standard for handling credit card data, called the Payment Card Industry Data Security Standard (PCI-DSS). The PCI DSS is required for all businesses accepting credit cards.
What is PCI DSS? The five major card networks (American Express, Discover Financial Services, JCB, MasterCard Worldwide, and Visa Inc.) established the PCI DSS as a set of requirements for business of all types to use when configuring their IT and payment-processing environments. Understanding the requirements is the first step. Some businesses will need IT support to ensure all of the requirements are met prior to taking action to certify compliance. (For additional information, please visit www.pcisecuritystandards.org.) The 12 requirements are as follows:
What does a hotel need to do to certify PCI DSS Compliance: There are two components required to validate or “prove” that a business has achieved PCI DSS compliance certification:
The questionnaire and the scanning will help identify if any weaknesses or vulnerabilities exist in the network. These issues must be fixed before PCI DSS certification can be achieved.
Certification with PCI DSS is achieved with both a compliant, passing questionnaire and if necessary for your business, compliant, passing compliant vulnerability scanning. There are many tools available in the marketplace to help hotels achieve these steps easily. Your business may have been automatically enrolled in PCI DSS programs by your bank, processor or acquirer. If you are unsure if you are PCI DSS compliant or enrolled in a program, please call your payment processing provider.
How to get started:
Trustwave (www.trustwave.com) is
a leading provider of compliance and information security to the payment
industry, serving merchants of all sizes. Trustwave is both an Approved
Scanning Vendor and a Qualified Security Assessor, and is certified to
validate organizations’ compliance with the PCI DSS. AAHOA has
partnered with Trustwave to provide certification services at a
preferred price. Please visit www.trustkeeper.net. To ensure
you receive the discounted pricing, in the upper left-hand box, enter
AAHOASAQ1 if you just require access to the PCI
Self-Assessment Questionnaire (SAQ), or AAHOASCAN2 if
you require access to the SAQ and vulnerability scanning.
How do I know if I need to scan?
All IP addresses and Web sites involved in the transmission, storage, or processing of cardholder data must be scanned for your business to be validated as PCI compliant.
|
Enrollment Code |
Examples |
|
AAHOASAQ1 |
Dialup terminals, imprint machines, no Internet-based processing, no electronic cardholder data storage |
|
AAHOASCAN2 |
IP-based terminals, virtual terminals, POS systems connected to the Internet, electronic cardholder data storage |
Trustwave and AAHOA want to make sure that you understand the basics of “PCI”, how it applies to your business, and steps needed to complete your PCI certification through the TrustKeeper portal. Therefore, we strongly encourage you to view the “PCI Compliance 101” Webinar by clicking the link below:
https://trustwave.webex.com/trustwave/lsr.php?AT=pb&SP=MC&rID=57943902&rKey=d54a03c4fd673a7c
In this webinar, Trustwave will answer key questions regarding:
For more information, please contact
Monica Brady
MBrady@trustwave.com
(312) 873-7277
Please consult the following sources for information on specific ways to ensure your hotel acts in accordance with PCI standards.
https://pcisecuritystandards.org/index.php
http://www.pcicompliance.org
http://www.pcicomplianceguide.org
Visa
http://usa.visa.com/merchants/risk_management/cisp_overview.html
http://usa.visa.com/merchants/risk_management/cisp_merchants.html
MasterCard
http://www.mastercard.com/us/merchant/support/merchant_education.html
http://www.iian.ibeam.com/events/mast001/24008/
