Laptop with Code Banner

How to become PCI Compliant in 2021

COVID-19 has forced change with businesses needing to modernise and embrace digital technologies at an unprecedented pace, or face failure. Those that hastily started trading online for the first time may not yet fully understand their security obligations. Safely handling payment information online is both a moral and legal requirement for all businesses in the UK.

What is PCI DSS?

Launched in September 2006 by the PCI Security Standards Council, Payment Card Industry Data Security Standard (known in short as PCI or PCI DSS) contains a set of 12 security requirements that all online merchants that process, store or transmit payment data must follow to be compliant.

The PCI Security Standards Council was set up by Visa, MasterCard, American Express, Discover, and JCB in an effort to enhance global payment account data security.

We’ll outline the requirements of PCI as well as touch upon how you can increase the security of your website and user data using HSTS (HTTP strict transport security).

PCI Logo

The 12 Requirements of PCI DSS

Firewalls are often a first line of defence against hackers as they block access to unauthorised or unknown entities attempting to access private data.

Computers and physical devices should have firewall software installed, and servers and digital storage should have internet traffic filtering measures in place to prevent authorised access.

Third party systems and products (such as routers, modems or computers) may come packaged with generic passwords and security systems easily accessible by hackers. To comply you should keep a list of all systems and devices that require a password, and ensure that all default and generic passwords on systems and devices are changed to secure passwords.

Card data must be encrypted with particular algorithms that use encryption keys, which in order to be compliant must also be encrypted themselves. Regular maintenance, testing and scanning should be in place to ensure all data is being encrypted, and that no unencrypted data exists.

Data must be encrypted whenever it is transmitted from one location to another (such as payment processors, local stores, offices or digital storage). Data should never be transmitted to unknown locations.

Anti-virus software is required in all devices and systems that handle payment data (such as payment processors, computers and servers). You should ensure that this software is regularly maintained and updated. You should ensure that any devices you purchase have anti-virus systems in place where direct installation of anti-virus isn’t available.

You should ensure that any software, systems or devices (such as payment processors, computers and servers) that you use or develop are maintained and updated frequently. In particular, software products will often include security patches in their updates that should be applied as soon as possible.

Access to cardholder data must be strictly “need to know”. This includes any staff and third parties, only those who need access to this data should be granted access. Any staff member or party who needs access to this data should be well documented and this documentation should be reviewed and updated regularly.

Any individual with access to payment data should have a unique ID and set of login credentials (such as a username, email and password). No individual or group should share login credentials. Unique IDs and access credentials helps secure data, track and monitor activity and improves responses to potential data breaches.

Any cardholder data that is both physically or digitally kept must be stored in a secure location. This includes locking physically or digitally stored data in a room, cabinet or other secure storage unit. Access should be limited, and when data is accessed a log must be kept.

You must track and monitor all access to payment data, including who accessed the data, when and why. You should also document how data flows within your organisation. You should ensure that any software products used to track and monitor are accurate, up to date and secure.

Regular monitoring, tracking and scanning of data, logs, hardware and software in relation to payment data is required. Ensure all software and hardware is up-to-date and test for any vulnerabilities frequently.

Hardware, software, and staff that have access to cardholder data will need to be documented for compliance. How information flows in your organisation and its storage should also be documented.

*unofficial overview of PCI requirements. Read the official guides here: https://www.pcisecuritystandards.org/merchants/

HTTP Strict Transport Security (HSTS)
What is it and how does it improve security?

Implementing an SSL certificate on your website is important not only to comply with PCI standards but to protect your users data as well. In short SSL certificates protect data from hackers by encrypting your users connection to your site. You can find out more about SSL Certificates here. When a valid SSL Certificate is applied your site domain will be prefixed with HTTPS rather than HTTP. This indicates that your users connections are being encrypted.

So what is HSTS?

HTTP strict transport security is a web policy that websites can enforce to instruct web browsers (such as Google Chrome, Firefox, Opera) to load a website over a hypertext transfer protocol secure (HTTPS) connection by default.

Presently, most website servers are set up to redirect users from a HTTP connection to a HTTPS connection, but this occurs after the browser has already attempted to connect over HTTP. This can leave your site vulnerable to attacks and hackers.

HSTS sets out to ensure users connect over a HTTPS connection from the get go, so if a user types in “http://your-domain.com” with HSTS enabled the browser will connect to the site using “https://your-domain.com” immediately, rather than trying to load the HTTP connection first.

Cloud Construct SSL

Important: incorrectly implementing HSTS can cause your website to go down for several days. Please contact us if you wish to find out more about HSTS.

Bag a free SSL Certificate with our web hosting

Did you know that Cloud Construct provide free SSL certificates to all websites hosted by us?

…and that’s not all! With over fifteen years experience in hosting high traffic websites, we have an expert level of understanding of hosting websites and web applications.

We work with industry-leading hosting suppliers, including Rackspace, Amazon AWS, Digital Ocean and 20i to provide hosting solutions appropriate for our clients’ budgets and technical requirements.

Whether you’re looking to host a website, ecommerce store or web app we can discuss and implement a solution that’s right for you.

Why Host your Site With Us?

We understand the importance of having an assessible and running website on brand image. Our hosting package promises a high uptime so you can be sure that your site won’t experience sudden, frequent shutdowns. We will also ensure that your site is able to handle any sudden spikes in web traffic without degrading performance for other visitors.

Page and website speed is important not only for your site visitors but also for Search Engine Optimisation. Our hosting package can help keep your website running smoothly, and if you’re interested in improving site speed and finding out why it’s important you can check out our blog post on the topic here.

We take advantage of global infrastructure to ensure that your website can be served to visitors all around the world.

We use secure servers to store and serve your website, as well as ensuring your data is protected under the ISO/IEC 27000 requirements. Our servers are also PCI Compliant.

We automatically take backups of your website so in the event of a disaster we can quickly and easily recover your website.

You can have full access to your hosting area to manage your site files, domains and more.

LET’S TALK ABOUT WEB HOSTING

To find out about our free SSL Certificates and what hosting solutions we have for you, call us on 01952 898 626email us at [email protected] or send us a message using the contact form below.