Shining a light on PCI Data Security Standards

Last October, the PCI Security Standards Council (SSC) released version 1.2 of the PCI Data Security Standards (PCI DSS). The update includes feedback on how lodging and hospitality organizations deploy security requirements. More than 2,500 queries and suggestions were considered.

Over the past two years, the SSC solicited feedback from stakeholders to improve the standards, thus helping to protect cardholder data and easing compliance.

Version 1.2 fulfills the following PCI Data Security Standards:

  • Provides greater clarity on PCI DSS requirements

  • Offers improved flexibility

  • Manages any evolving risks and threats

  • Incorporates existing and new best practices

  • Clarifies scoping and reporting

  • Eliminates redundant sub-requirements

  • Consolidates documentation

When combined with the data security standards and tools added by the Council within the last year, these revisions will help businesses better understand and develop practices that protect payment data and prevent fraud.

WHAT YOU NEED TO KNOW

Version 1.2 does not introduce new requirements; rather it provides consistent use of terms and greater flexibility, such as decreasing mandatory review of firewalls from a minimum of every 3 months to every 6 months. One significant change concerns the sunset date for the use of Wired Equivalent Privacy (WEP).

New implementations of WEP are disallowed after March 31, 2009, and any use of WEP must be discontinued after June 30, 2010. Keep in mind, this is only for wireless networks that transmit cardholder data or connect to the cardholder-data environment. Many lodging organizations that offer wireless service for guests do so without processing, transmitting or storing cardholder data. As long as guest wireless service is separate from the cardholder data environment, the PCI DSS assessment does not apply.

Another requirement clarified in the release concerns the physical security of primary account numbers. Both electronic and paper forms must be protected, as well as removable electronic media. For lodging establishments keeping copies of the PAN, Requirement 9 addresses physical protection of cardholder data. Beyond changes to the standards, the Council has greatly enhanced communication, education and interpretation of the 12 security requirements.

*The author, Troy Leach, is technical director for the PCI Security Standards Council. For more information on the PCI Security Standards Council or on becoming a participating organization, visit www.pcisecuritystandards.org or email participation@pcisecuritystandards.org..


Acceptable Use Policy
blog comments powered by Disqus

Most Recent

More Recent Articles

Career Center

Quick Job Search
Enter Keyword(s):
Enter a City:

Select a State:

Select a Category:



http://lhonline.com/images/bulk_tv_logo.jpg
Franchise Fact File Top Brands
Brand Company Basics Top Management Companies
Owners & Operators Industry Consultants
Industry Associations Industry Events
Design Firms Purchasing Companies









Free Product Information
News and Trends for the Hotel, Motel, and Hospitality Markets.

Lodging Hospitality eReport
Lodging Hospitality electronic newsletters are FREE to requested subscribers.

Lodging Hospitality Resource Center
The Lodging Hospitality Resource Center is the ultimate resource to find products and services to build, equip, and renovate hotels, motels and resorts.


Press Releases
Post your press releases on LHonline.com.


Subscribe / Renew
Visit our subscription center to subscribe or renew your subscription to Lodging Hospitality.

Webinars
Visit our webinars page to view all our upcoming and on demand webinars.

Whitepapers
Visit our White Papers page to view all our current White Papers.