In the past, credit card companies have developed and maintained their own data security programs to protect cardholder data. Visa CISP, MasterCard SDP and American Express Data Security Operating Policy (DSOP) are examples of such programs. In December 2004, the Payment Card Industry (PCI) Data Security Standards - a comprehensive set of data security requirements - were adopted by all major credit card companies. These standards replace companies' individual programs and bring to the industry a consistent set of standards for data security.
The purpose of the PCI Data Security Standards is to ensure that all financial institutions, merchants, e-commerce companies, and their agents and service providers are employing basic security standards to protect and secure all credit cardholder data. More specifically, organizations are responsible for having the necessary security policy, systems and auditing infrastructure in place to protect and secure the strict privacy of credit card and customer data throughout the entire transaction process.
Protegrity delivers solutions for organizations looking for a comprehensive solution to accelerate compliance with the Payment Card Industry (PCI) Data Security Standards.
There are two core elements to our solution:
(1) Protecting data - Defiance Data Protection System (DPS) is an encryption and hashing software product that provides organizations with a security solution that protects credit card information from all reasonable threats - internal and external. With Defiance DPS, companies can meet PCI compliance by defining, monitoring, and managing security policies across the enterprise; by defining and monitoring levels of data access; and by protecting data from 'super user' access. Defiance DPS is superior to other data encryption offerings based on these key criteria:
(2)Application Security - With regulation 6.6 of PCI 1.1, it is required that you protect your web application from application attacks, such as cross-site scripting or SQL Injections. Protegrtiy's Defiance™ Threat Management System (TMS) is a web application security product that is specifically designed to protect web and web services applications that credit card processors use to collect and display customer credit card information. In combination with Defiance DPS this is the most comprehensive application and database security offering specifically targeting PCI compliance requirements. Defiance TMS exceeds the protection and performance of other web application security products based on the following criteria: