One thing all e-commerce merchants would likely agree on is that they do not want their businesses to be the subject of the next front-page story involving hackers and credit cards.
While the payment card industry has done a very good job of improving computer security through the payment card industry data security standard - or PCI DSS - many merchants remain unaware of what the standard is and why they should care.
Major card brands, including Visa, Mastercard, American Express and Discover, developed the PCI DSS, which establishes a comprehensive framework of policies and procedures that govern all critical aspects of information security.
While all stores must comply with these standards in order to accept credit cards - using PCI-compliant swipe machines for card present transactions, for example - the standards are especially applicable to online stores.
Noncompliant stores risk fines and loss of the ability to accept credit cards. The specific requirements of PCI DSS are explored at www.pcisecuritystandards.org. They include the installation and maintenance of firewall configuration, encrypted transmission of cardholder data, restriction of physical access to data and regular testing of security systems and processing.
Keys to protection
Here are some steps that can be taken by companies that provide online sales to protect sensitive customer data and achieve business growth.
1. Learn about the PCI DSS and develop a gap analysis and remediation plan.
Since noncompliance isn't an option, identify any gaps that exist in the current online sales environment and take steps toward remediation. The previously mentioned Web site can serve as a good starting point in your PCI DSS education, as can working with an e-commerce provider.
2. Only do business with PCI-compliant service providers.
Be sure to verify that the company's shopping cart, online store, payment gateway and Web host are all PCI DSS compliant. If any link in that chain is broken by noncompliance, then the company is noncompliant as well.
Beware of any vendors that downplay the importance of PCI DSS compliance. E-commerce providers (for shopping carts, payment gateways, et cetera) must demonstrate Level-1 PCI DSS compliance to the card brands, which is an expensive undertaking. Providers that are not listed on Visa's global list of PCI-validated service providers are not compliant.
A complete list is available at Visa's Web site, www.usa.visa.com, under the Risk Management and Cardholder Information Security Program headers.
3. Have a well-thought-out incident response plan and follow it.
The time to identify what steps should be taken when data is compromised is well before any incident takes place, not after the problem has occurred and must be handled. Clear thinking can be hard to come by when there is a security breach. Depending on the industry and the extent of the breach, there may be legal notification requirements to address as well.
When a breach does occur, it's important to notify the merchant account provider as quickly as possible so that they can offer assistance.
4. Remember that security is a journey, not a destination.
Ellen Richey, Visa's chief enterprise risk officer, likened combating computer fraud to an arms race during a recent keynote address. Becoming compliant with PCI DSS is just the first step in an ongoing process. Even if the aforementioned steps have been taken, companies still must maintain compliance going forward. Developing written policies concerning such matters as handling and storing customer data and securing wireless networks, plays a role in keeping your data secure.
Taking the appropriate steps to protect customer data enables business leaders to enjoy their work and focus on building and growing business. There are many aspects to owning a business that, while necessary, are not the primary reason people become entrepreneurs. Just as most company leaders would never consider running a business without profit-and-loss and income statements and balance sheets, they also would never knowingly expose sensitive customer data to risk.
Shannon McMurtrey is president and co-owner of Springfield-based McMurtrey, Whitaker & Associates Inc., an e-commerce development company for which the flagship product is the Cart32 platform. He may be reached via www.cart32.com.