PCI Compliance Requirements & Secure Payment Systems | Magento

Magento Secure Payment Bridge

DOWNLOAD INFORMATION SHEET

HELPING MERCHANTS ACHIEVE PCI COMPLIANCE

Magento Secure Payment Bridge assists merchants in meeting PCI compliance with this secure payment application. Implementing Payment Bridge with Magento Enterprise Edition saves online merchants money and time when it comes to complying with PCI requirements.

Magento makes PCI compliance easier by separating the Magento Secure Payment Bridge application from our eCommerce platform. This enables updates to the core Magento eCommerce application with new marketing, merchandising and content management capabilities, without having to go through PCI compliance re-assessment of the entire Magento eCommerce platform.

Magento Secure Payment Bridge is PA-DSS certified by our Qualified Security Assessor (QSA) Trustwave, and is provided with a subscription to Magento Enterprise.

ABOUT PCI COMPLIANCE

The PCI Data Security Standard (PCI DSS) was created by the major credit card companies to ensure the adoption of consistent security measures by all merchants. There are 12 requirements for meeting the PCI DSS, broken into 6 groups:

Build and Maintain a Secure Network
REQUIREMENT 1: Install and maintain a firewall configuration to protect cardholder data
REQUIREMENT 2: Do not use vendor-supplied defaults for system passwords and other security parameters

Protect Cardholder Data
REQUIREMENT 3: Protect stored cardholder data
REQUIREMENT 4: Encrypt transmission of cardholder data across open, public networks

Maintain a Vulnerability Management Program
REQUIREMENT 5: Use and regularly update anti-virus software
REQUIREMENT 6: Develop and maintain secure systems and applications

Implement Strong Access Control Measures
REQUIREMENT 7: Restrict access to cardholder data by business need-to-know
REQUIREMENT 8: Assign a unique ID to each person with computer access
REQUIREMENT 9: Restrict physical access to cardholder data

Regularly Monitor and Test Networks
REQUIREMENT 10: Track and monitor all access to network resources and cardholder data
REQUIREMENT 11: Regularly test security systems and processes

Maintain an Information Security Policy
REQUIREMENT 12: Maintain a policy that addresses information security

It is important to note that while Magento Secure Payment Bridge is a PA-DSS compliant application, it must be implemented in a PCI DSS compliant environment. For more information on PCI Compliance please visit the PCI Security Standards Council website.