This is the 2.3 Beta release version of Magento documentation. Content in this version is subject to change. For additional versions, see Magento Documentation and Resources.
PCI Compliance Guidelines
The Payment Card Industry (PCIPayment Card Industry: Refers to debit and credit cards and their associated businesses.) has established a set of requirements for businesses that accept payment by credit card over the Internet. In addition to maintaining a secure server environment, merchants who handleIn programming, a name used to reference an object. customer credit card information must meet the following guidelines:
Install and maintain a firewall configuration to protect cardholder data.
Protect stored cardholder data.
Encrypt transmission of cardholder data across open, public networks.
Use and regularly update antivirus software.
Develop and maintain secure systems and applications.
Restrict access to cardholder data by business need to know.
Assign a unique ID to each person with computer access.
Restrict physical access to cardholder data.
Track and monitor all access to network resources and cardholder data.
Regularly test security systems and processes.
Maintain a policy that addresses information security.
To learn more, see: Magento Approach to PCI Compliance.
As your business grows, you may be required to file a compliance report on an annual basis. PCI reporting requirements increase in proportion to merchant level, but are waived for businesses that process fewer than 20,000 credit card transactions per year. To learn more, visit the PCI Security Standards Council website.
A quick rating takes only 3 clicks. Add a comment to help us improve Magento even more.