Security Audits Mandatory for Online Merchants

NEW YORK — In an effort to streamline the credit card industry’s regulations, adult and mainstream companies that accept credit and debit cards over the Internet must comply with a 12-step security audit starting June 30.

With the new standards, all merchants must be certified under the Payment Card Industry (PCI) Data Security Standards, which were developed by a consortium of major payment card companies.

The PCI standards, which specifically address wireless security, detail "lock down" procedures for data, including data housed by third parties and procedures on how a merchant's computer infrastructure should be configured, maintained and secured.

To receive certification under the standard, all merchants must meet the security requirements, which include:

— Installing and maintaining a firewall;

— Not using default passwords;

— Using strong protection for stored data; Implementing controls that restrict data access to a need-to-know basis;

— Assigning a unique identity authentication to each person accessing computer systems;

— Encrypting cardholder data transmitted over public networks;

— Not storing credit card verification codes;

— Installing and regularly updating anti-virus software;

— Developing and maintaining an information security policy;

— Restricting physical access to cardholder data;

— Monitoring and tracking network resources and cardholder data regularly; and,

— Testing security systems and processes frequently.

The rules affect adult and mainstream Internet companies that offer Visa International, JCB International Credit Card, Diners Club International, Discover, American Express and MasterCard International are part of the consortium. American Express, however, refuses to process online adult charges.

Companies that fail to comply will face fines and other penalties, which include, in some instances, being banned from processing transactions using payment cards.

With the new regulations, most online adult companies will be forced to buy automated compliance tester software. Qualys sells a package for under $500.

The new rules ramp up with large companies that process more than six million transactions a year. Those companies must conduct an annual on-site security audit, a quarterly network scan, and an annual self-assessment questionnaire.

Each card company has implemented its own program under the standard — Visa's is called Cardholder Information Security Program.

Most of the larger credit card companies’ data security programs have been in existence for several years, but it was optional. It became mandatory in 2003, but only for the largest merchants.

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More News

Australian Conservatives Raise Concerns About US-Born Online Censor

Long after progressive free speech advocates in Australia questioned E-Safety Commissioner Julie Inman Grant over her campaigns to target adult content, conservatives and libertarians are now raising concerns about the powers granted to the country’s top censor — an unelected former tech exec born in the U.S. — with some calling for her ouster.

Magic Silk Unveils 'Sheer Passion' Line

Magic Silk has introduced its new Sheer Passion line of intimate wear.

Cupcake Girls, Aylo Partner on Educational Video Series for Performers

The Cupcake Girls and Aylo have teamed up to produce a series of educational videos focused on safety standards for adult performers.

Tamara Payton Bell Takes Over Sexpert.com

Tamara Payton Bell has been handed oversight of website Sexpert.com by her mentor, sexuality educator Ava Cadell.

Holiday Products Now Shipping 'Jaguar' Bullet Vibe From Maia Toys

Holiday Products is now carrying the Jaguar bullet vibrator, from Maia Toys.

Le Wand 'Die Cast' Vibrator Featured in Wired Review

Le Wand's Die Cast vibrating massager is featured in a new review on Wired.com.

My.Club Appoints Nicole Aniston Newest Brand Ambassador

My.Club has named Nicole Aniston its newest brand ambassador.

Nalpac, XR Brands Sign Distribution Deal

Nalpac has inked a deal to distribute XR Brands pleasure products.

Elevated X Implements Age Verification Solution, Integration API

Elevated X is now offering age verification services (AVS) through an API.

MojoHost Unveils 'Star Wars Day' Promo

MojoHost will celebrate “Star Wars Day” on Saturday by offering a special discount on new purchases of dedicated servers, VPS and CDN prepay plans throughout the month of May.

Show More