Question

In: Computer Science

YieldMore Company’s senior management has recently decided to accept credit card payments from YieldMore customers both...

YieldMore Company’s senior management has recently decided to accept credit card payments from YieldMore customers both from store locations and online transactions. This decision makes meeting PCI DSS objectives and requirements a necessary consideration in order to validate compliance for enforcement organizations.

As an IT professional of the company, you should make recommendations to IT management to implement best practices of PCI DSS.

Tasks

You are asked to identify appropriate best practices of PCI DSS specific to the company’s IT environment.

  1. Identify the touch points between the objectives and requirements of PCI DSS and YieldMore’s IT environment.
  2. Determine appropriate best practices to implement when taking steps to meet PCI DSS objectives and requirements.
  3. Justify your reasoning for each identified best practice.

Solutions

Expert Solution

The Payment Card Industry Data Security Standard (PCI DSS) is nothing but a set of security requirements that helps businesses to protect their payment systems from unauthorized access.

Here are our five best practices for PCI DSS;

1. Data transparency

The data must only be stored in specific or known locations. And with limited access to protect credit card information. Data Loss Prevention solutions such as Endpoint Protector are used for this purpose

2. Security

The two main ways data can be protected on the move are tokenization and encryption. Tokenization is a method that generates an alternate ID for a card number which can then be used for transactions. Thereby we can reduce the risk of disclosure of card information.

Encryption is a method of converting the data into another form which changes the entire meaning of the data

3. Restrict access rights

By using PCI DSS we can restrict the access of information from unauthorized access and thereby protect our data from disclosure.

4. Document and log everything

PCI DSS document everything underlines the need for organizations to keep records of all its security policies and procedures, its risk assessments, and security incidents.

The requirement of PCI DSS are;

1. Install and maintain a firewall configuration

2. Configure passwords and settings for the system

3. Protect stored cardholder data from authorized access

4. Encrypt transmission of cardholder data by using any one of the encryption methods.

5. Use and regularly update anti-virus software or programs and check whether it is working or not

6. Regularly update and patch systems

7. Restrict access to cardholder data by business need to know

8. Assign a unique ID to each person with computer access

9. Implement logging and log management for future reference

Objectives

1. Build and maintain a secure network

2. Protect cardholder data

3. Maintain a vulnerability management program

4. Regularly monitor and test networks

5. Maintain an information security policy

UPVOTE PLS if you find this useful


Related Solutions

A credit card company wants to test whether, on average, male customers make larger payments on...
A credit card company wants to test whether, on average, male customers make larger payments on their outstanding credit balance each month compared to female customers. Random, independent samples of 20 males and 20 females are selected and monthly payments are compared. Average payment from males = $129.00 with a sample standard deviation of $23.90, and average payments from females = $113.00 with a sample standard deviation of $21.60 (both sigmas unknown). a. Write out Ho and Ha to test...
credit card payments: The outstanding balance on Bill’s credit card account is $3200. The bank issuing...
credit card payments: The outstanding balance on Bill’s credit card account is $3200. The bank issuing the credit card is charging 9.3%/year compounded monthly. If Bill de cides to pay off this balance in equal monthly installments at the end of each month for the next 18 months, how much will be his monthly payment? What is the effective rate of interest the bank is charging Bill?
An individual has Centurion Card from American Express (credit cards). The credit card is most valuable...
An individual has Centurion Card from American Express (credit cards). The credit card is most valuable credit card in the world. Can this individual claim that he/she is a wealthy individual?
Simon recently received a credit card with a 17% nominalinterest rate. With the card, he...
Simon recently received a credit card with a 17% nominal interest rate. With the card, he purchased an Apple iPhone 7 for $380.00. The minimum payment on the card is only $10 per month. If Simon makes the minimum monthly payment and makes no other charges, how many months will it be before he pays off the card? Do not round intermediate calculations. Round your answer to the nearest whole number. month(s)If Simon makes monthly payments of $30, how many...
. A bank has recently begun a new credit program. Customers meeting a certain credit requirement...
. A bank has recently begun a new credit program. Customers meeting a certain credit requirement can obtain a credit card accepted by participating area merchants that carries a discount. Past data show that about 35% of all applicants for this card are rejected. If we let X represent the number of applicants who are approved for this credit card, the probabilities for the values of X can be calculated using the binomial probability distribution. Please answer the following questions...
Identify precautions for accepting the types of payments: cash, check, credit card, and debit card.   
Identify precautions for accepting the types of payments: cash, check, credit card, and debit card.   
A retail company receives most of its revenue from credit or debit card transactions or payments...
A retail company receives most of its revenue from credit or debit card transactions or payments by check. Funds received from credit and debit card transactions automatically deposit in interest bearing accounts. However, the company does receive some cash payments from customers each day. These cash receipts total $7,250,000 annually. The company makes no cash payments to its suppliers or creditors. Money held in the cash account earns no interest. The company estimates that the transaction cost of moving funds...
Simon recently received a credit card with a 15% nominal interest rate. With the card, he...
Simon recently received a credit card with a 15% nominal interest rate. With the card, he purchased an Apple iPhone 7 for $363.75. The minimum payment on the card is only $10 per month. If Simon makes the minimum monthly payment and makes no other charges, how many months will it be before he pays off the card? Do not round intermediate calculations. Round your answer to the nearest whole number. ______month(s) If Simon makes monthly payments of $35, how...
Simon recently received a credit card with a 20% nominal interest rate. With the card, he...
Simon recently received a credit card with a 20% nominal interest rate. With the card, he purchased an Apple iPhone 7 for $410.00. The minimum payment on the card is only $20 per month. If Simon makes the minimum monthly payment and makes no other charges, how many months will it be before he pays off the card? Do not round intermediate calculations. Round your answer to the nearest whole number. ? month(s) If Simon makes monthly payments of $60,...
Jim recently received a credit card with a 15% nominal interest rate. With the card, he...
Jim recently received a credit card with a 15% nominal interest rate. With the card, he purchased a new computer for $2,000.00. The minimum monthly payment on the card is $70 per month. If he makes the minimum monthly payment and makes no other charges, how many months will it take him to pay off the card? 28.57 months 35.57 months 50.25 months 67.20 months 70.57 months
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT