顯示具有 Certification 標籤的文章。 顯示所有文章
顯示具有 Certification 標籤的文章。 顯示所有文章

2011年6月5日 星期日

PCI DSS Certification - Is It Mandatory To Perform Third Party PCI Compliance Audit And PCI Scan?


PCI DSS certification stands for Payment Card Industry Data Security Standard. PCI Data Security Standard has been established by the top five credit card issuing companies, MasterCard, Visa, American Express, Discover and Japanese Credit Bureau, who took their individual security standards for online transactions and merged them into one, establishing the PCI Data Security Council at the same time. The Council is a self-regulatory body which updates the PCI DSS requirements from time to time, trains companies and issues training certificates for companies who then act as PCI Audit executors, and PCI Qualified Security Assessors QSA.

As the online threats multiply in the direction of where the money is (online), the original 12 rules of PCI DSS compliance has evolved and today, as some affected merchants like to say, the 12 rules have over 200 sub-rules that are difficult to interpret, and correspondingly difficult to fulfill. It likely involves annual reporting by a qualified assessor, QSA, and quarterly scanning of outward-looking internet connections by a ASV, Approved Scanning Vendor. Both of which translate to additional costs to the merchant who must undertake the PCI Data Security Standard certification compliance.

So if you are a merchant processing online or point of sale transactions using credit and debit cards, the question comes up, is it mandatory to perform a PCI compliance audit and a PCI scan through third parties?

We'll point out here the two possible routes for a merchant to avoid costly third party PCI DSS audits and PCI scans and still be PCI compliant. They are: Have fewer than 20,000 payment card transactions in a year, and, Get someone from the company PCI DSS Audit qualified, have them become an ISA, Internal Security Assessor. We will talk about the current PCI DSS 2.0 version.

Have fewer than 20,000 payment card transactions per year

If you are relatively small merchant with fewer than 20,000 transactions in a year, you will be able to fulfill the security requirements by doing an internal security audit and simply fill out a Self-Assessment Questionnaire. There are several types of questionnaires. You can work with your "acquirer", or the bank through which you are processing your payment card payments to determine which questionnaire is right for you and what are the deadlines for submitting them.

Have someone from within your company PCI DSS Audit qualified

On the opposite end of the spectrum, if you are a large merchant, or a large online service organization, and you have more than 20,000 transactions per year, you can avoid hiring a third party PCI DSS Qualified Security Assessor by simply sending one of your IT professionals to one of the PCI DSS standard compliance seminars to become qualified as an Internal Security Assessor, thereby removing the need for external PCI Audits. The PCI data security standard checklist audits can from now on be done in house by an ISA. ISAs must be re-certified every year, and the company can now perform their own security audits and still stay PCI compliant.








For more information on the details of PCI DSS compliance see the PCI Compliance section on the site http://PCIscanning.org.


2011年3月7日 星期一

Green Business certification


When your business thinking will Green, it can be a good idea to think ahead about how a decision to seek a green certification will affect your business. Kind of "Easy Green" now promoted to this Green-driven market brings short-term gains with long-term worries. In the absence of a decision to create an environmentally friendly business format should compromise the integrity of the company's future. It is a worthy better thoughts decision.

Take, for example, the near certainty that certain investigative reporter is sure to examine the growing number of home page certifications that require only a few hundred dollars for payment and a self-evaluation form. The lack of any integrity factors for these types of certifications seem to invite abuse. In other words, a less than honest company serves the same certification as an environmental committed company. This blatant invitation for abuse will certainly come back to haunt companies took the easy route to a world in underlines the problem. Only a fool would believe that these easy to cheat systems will be a bastion of integrity.

Correctly said: "if we cannot measure something, we cannot control it." A green certification logo obvious aim is to provide the public with certain quality assurance to the logo means something more than that the applicant pay a fee and filled in a form. These programmes to promote a basic deception because certification is designed to convey the public's trust in something that is not controlled, or even be audited by an independent expert.

Ask yourself about just how you will feel after deciding to do business with another company which prides itself on its Green profits to win your business, and you discover later that any company with a few hundred dollars could buy the same designation. Do you want to feel cheated and deceived? This will be more than a few businesses take the routing "Easy Green" short-circuiting system rather than to make a realistic commitment ugly fate.

The whole concept of greenwashing have been artificially kept alive due to a business believe that marketing is bending of concepts of lift markets hare and profits. Advertising has always given leeway to turn negatives into positives, words to the realities and minimum settings for maximum. What happens when the quotas of the placing on the market run in requirements for integrity? In the case of environmentalism is called the mongoloid child greenwashing.

If the only way to green observed when measuring or testing, so obvious antidote against greenwashing is a revision of a professional who uses an industry standard compliance, The Green Business League where a commitment years ago to provide training for certification bodies (Auditors) and provide a standard for a green businessthat requires more than good intentions or a symbolic effort. More than 250 Certified Green consultants, provides guidance and audits for companies willing to prove their green value.

This standard has in an executive order recently confirmed by President Obama will require a sustainability officer who is required to project a number of green and sustainable practices for your agency or company. This federal requirements shows that the path forward not a self-acclamation, but documented compliance.

Let us return to the original question. What would be the investigative journalists of criticism to find your company (out of many other easy green enterprises) installed a number of green practices, which had been revised by an independent expert and found to deserve a national certification? You will probably feel pretty good about being the one who stood as the language-use green business.

Audits prove that you keep honest books. Revisions to prevent cheating by manufacturers. Revision of the inventory stop the thefts. No one really wants a revision, unless you know that the review will prove the quality of the work. Those who want to cheat the system withstand audits. One of the fiaskørne in Copenhagen was China's willingness to sign in to any-control Climate Summit mandates, as long as China should not submit a review of the results. What kind of message this revelation to bring you in the clear message. China does not intend to live up to the mandates, although they will put on a show that they are concerned about the environment. This is a classic example of green washing.

Enterprises everywhere should make the obligation to reject Greenwashing by insisting on green certification earned by green practices certified by an independent audit. Accept any Green claim at face value is so foolish as to invite unscrupulous in the world to pay you in monopoly money. Why not play golf with a person who believes, to adjust its score is a good way to impress his friends. If it is not measured cannot be checked; and if there is any revision of green practices, there can be no certification of a green business ... unless you bought it from the Internet!








Michael Richmond is Director of the Green clean Instituteand the primary coach of Certified sustainability Officer training internal sustainability officers.