Overview

Payment Card Industry (PCI) is a trade group.  However, they publish the PCI Data Security Standard (DSS) for computer security that must be followed in order to process credit card transactions through computer networks. A quick reference for the current PCI DSS is available here: https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Supporting%20Document/PCI_DSS-QRG-v4_0.pdf

PCI DSS has many controls, but 6 main goals:

  • Build and Maintain a Secure Network and Systems

  • Protect Account Data

  • Maintain a Vulnerability Management Program

  • Implement Strong Access Control Measures

  • Regularly Monitor and Test Networks

  • Maintain an Information Security Policy

Why are they asking this?

If an organization is asking about PCI, they are expecting that they may share credit card information with your organization. Failure to follow PCI requirements can lead to penalties and discontinuation of the ability to accept or process credit card transactions.  Part of the requirements is to ensure that all parties with access to this information follow the PCI standards.

What do they expect?

Organizations that are sharing credit card information will expect your organization to be PCI compliant.