|
The Payment Card Industry
Data Security Standard (PCI)
Michael E. Smith
Senior Vice President
Enterprise Risk and Compliance
Visa USA
Visa Inc. announced today that as of the
end of 2007, more than three-fourths of the
largest U.S. merchants¹ and nearly two-thirds of
medium-sized merchants² have now validated their
compliance with the Payment Card Industry Data
Security Standard (PCI DSS). Merchants in these
two categories account for approximately
two-thirds of Visa's U.S. transaction volume.
The strong progress is attributed to the efforts
of multiple stakeholders, including acquirers,
merchants and Visa. Visa's multi-tiered strategy
of financial incentives, education and
non-compliance fines has had a direct impact on
increasing compliance among the largest U.S.
merchants from about 12 percent in March 2006 to
77 percent by December 31, 2007. Among
medium-sized merchants, compliance grew from 15
percent in December 2006 to 62 percent as of
December 31, 2007.
"Visa is working to mitigate the risk of data
compromises by securing cardholder information,"
said Michael E. Smith, head of payment system
risk, Visa Inc "In 2007, more U.S. merchants
made good on their commitment to protect
cardholder information than any other year. Visa
is pleased with the progress of merchant PCI DSS
compliance though there is still more to
accomplish with among payment system
participants," he said.
Merchants can visit Visa's online education
center at
www.visa.com/cisp
to learn more about securing customers' payment
card data. The site offers a series of webinars
and security alerts that will help a merchant
better understand the PCI DSS and how to achieve
compliance.
The PCI DSS is an international set of security
requirements for any entity that stores,
processes or transmits cardholder data. The
standards are set by an international body known
as the Payment Card Industry Security Standard
Council that seeks to provide a forum in which
all stakeholders can provide input into the
ongoing development, enhancement and
dissemination of the Data Security Standard.
For more information about
the Council, go to www.pcisecuritystandards.org.
read more...
|