RSI Security

What Data Falls Under PCI Compliance?

Vciso

The Security Standards Council (SSC) of the Payment Card Industry (PCI) has developed many frameworks to protect companies from cybercrime targeting consumers’ credit and debit cards. Among the most widespread of these frameworks is the PCI Data Security Standard, or PCI DSS, which protects nearly all consumer card data processed, stored, transmitted, or otherwise contacted by businesses. It brings us to the question: what data falls under PCI compliance, exactly, and which companies need to comply with PCI’s security standards?

To find out, keep reading.

 

What Data Falls Under PCI Compliance?

The technology that supports payment and money transfers grow increasingly complex every year. And yet, despite changing conventions, cybercriminals seem to find ways to outpace all but the best-protected companies. One of the biggest challenges to fully safeguarding your clients is understanding what exactly needs to be protected, why, and how to protect it.

Below, we’ll break down everything you need to know to keep all protected data safe:

By the end of this article, you’ll understand whether your company needs to comply, why, and how to do so. But before getting into these details, let’s take a look at what PCI compliance is.

 

What Exactly Constitutes PCI Compliance?

Compliance with PCI means following one or more sets of rules set up by the PCI SSC. For most companies, this means implementing the main PCI DSS controls to protect the kinds of information specific to credit and debit cards in particular. However, some other companies may be subject to PCI DSS and one or more other PCI frameworks. What matters most is understanding what information the SSC wants you to protect, why, and how.

The SSC, responsible for authorship and enforcement of PCI compliance, comprises five critical stakeholders in the industry: American Express (AmEx), VISA, MasterCard, JCB International, and Discover. PCI compliance conforms to the standards established by these companies; each one has its particular criteria for which specific data it protects and prioritizes.

 

Assess your cybersecurity

 

What Information Is Subject to PCI Protection

Nearly all payment card and cardholder information are subject to PCI protection — most notably, information on credit cards (name, number, etc.) and accounts connected to them.

In practice, this means many, if not most, companies that process payments are subject to some form of PCI compliance. Per one SSC resource charting differences across the PCI security standards, its three main cybersecurity frameworks apply to the following sets of stakeholders:

Of all these standards, PCI DSS applies to most institutions. The phrase “PCI compliance” often refers to PCI DSS compliance in particular.


Download Our PCI DSS Checklist


Who Exactly PCI Compliance Impacts, and How

As noted just above, PCI DSS requirements apply most broadly across industries. But that doesn’t mean they impact all companies in the same way. Per a PCI DSS compliance support guide published by VISA, the amount of data also matters when it comes to compliance:

Self-report or external verification of compliance is just one (late) step toward protecting cardholder data. The much more significant and important step is implementing the proper controls.

 

Requirements of Full PCI DSS Compliance

There are 12 core requirements of PCI DSS compliance to protect all these forms of data, distributed across categories of cybersecurity. These controls break down as follows:

The body of PCI DSS v.3.2.1 further details all the controls, including testing procedures and guidance for each. Implementing all of them is the key to fully safeguarding cardholder data.

 

Consequences for PCI DSS Noncompliance

Failure to safeguard the information that PCI DSS (and other frameworks) protects will result in both short- and long-term costs. The former, imposed by the SSC, include the following fines:

If these aren’t incentive enough, long-term costs are even more significant. According to a CSO Online analysis, data breach costs average around $146 dollars per record lost. In the event of a “mega breach” that impacts millions of records, companies could lose over $390 million dollars. Professional PCI compliance advisory services are the best way to avoid these and other costs.

 

Cyberdefense for Payment Card Processors

Here at RSI Security, we’re committed to helping companies of all shapes and sizes with their compliance needs, from PCI DSS to HIPAA and beyond. But we also know compliance is far from the end of cyberdefense; it’s just the beginning. To keep your stakeholders safe, you’ll need a robust security architecture complete with analytical tools and staff awareness training.

Now, to return to the question from above: what data falls under PCI compliance? Simple: all cardholder data. But the simple answer belies complex implications. Since the specification is so broad, PCI requirements apply very widely. That means that if you process payments via card, you likely need to comply. Contact RSI Security today to ensure you’re doing so.


Speak with a PCI Compliance expert today – Schedule a free consultation

 

Exit mobile version