<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>VersaPay &#187; PCI DSS</title>
	<atom:link href="http://www.versapay.com/tag/pci-dss/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.versapay.com</link>
	<description>Simplify Payment Processing</description>
	<lastBuildDate>Fri, 18 May 2012 16:20:46 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>How does ECRi work for POS developers?</title>
		<link>http://www.versapay.com/company-news/how-does-ecri-work-for-pos-developers/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=how-does-ecri-work-for-pos-developers</link>
		<comments>http://www.versapay.com/company-news/how-does-ecri-work-for-pos-developers/#comments</comments>
		<pubDate>Tue, 01 Jun 2010 15:30:26 +0000</pubDate>
		<dc:creator>VersaPay</dc:creator>
				<category><![CDATA[Company News]]></category>
		<category><![CDATA[ECRi]]></category>
		<category><![CDATA[middleware]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[POS developer]]></category>

		<guid isPermaLink="false">http://www.versapay.com/?p=4312</guid>
		<description><![CDATA[<h2>What is ECRi?</h2>
<p>ECRi (Electronic Cash Register interface) allows POS developers to create cost-effective, PCI compliant payment solutions. ECRi-enabled, standalone POS terminals allow merchants to process payments without transferring sensitive credit card account information to the merchant’s POS system.</p>
<p>POS software developers no longer need to ensure that their application is PA-DSS compliant, because ECRi offloads this responsibility to the merchant’s provider, reducing the headaches and costs associated with credit card fraud. Switching to ECRi offers many benefits for POS developers.</p>
<h2>A simple payment solution</h2>
<p>Integrating ECRi into your POS software involves working with a simple serial interface. This interface makes software development easier and more cost-effective than other payment solutions. This simple integration helps POS developers avoid the hassle of PCI compliance, eliminates the need for middleware, and saves money and time in the development process.</p>
<h3>Save money</h3>
<p>ECRi’s simple serial interface makes integration quick and affordable. POS developers now spend less money developing and maintaining their software.</p>
<h3>Reduce reliance on middleware</h3>
<p>ECRi allows transaction authorization to occur between a standalone POS terminal and the customer’s issuing bank, eliminating the need for costly middleware products to support the payment process.</p>
<h3>Avoid the headaches of becoming compliant</h3>
<p>Most PIN pad payment solutions transfer customer credit card data through the merchant’s POS system, requiring the software to be PCI compliant. Obtaining certification can be a costly and time-consuming process. POS developers who use ECRi avoid this hassle entirely.</p>
<blockquote><p>ECRi is a simple and cost-effective payment solution that boasts a reliable and </p>&#8230; <a href="http://www.versapay.com/company-news/how-does-ecri-work-for-pos-developers/" class="read_more">Read more</a></blockquote>]]></description>
		<wfw:commentRss>http://www.versapay.com/company-news/how-does-ecri-work-for-pos-developers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How does ECRi work for merchants?</title>
		<link>http://www.versapay.com/company-news/how-does-ecri-work-for-merchants/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=how-does-ecri-work-for-merchants</link>
		<comments>http://www.versapay.com/company-news/how-does-ecri-work-for-merchants/#comments</comments>
		<pubDate>Tue, 25 May 2010 15:30:09 +0000</pubDate>
		<dc:creator>VersaPay</dc:creator>
				<category><![CDATA[Company News]]></category>
		<category><![CDATA[ECRi]]></category>
		<category><![CDATA[merchant]]></category>
		<category><![CDATA[PCI DSS]]></category>

		<guid isPermaLink="false">http://www.versapay.com/?p=4308</guid>
		<description><![CDATA[<h2>What is ECRi?</h2>
<p>ECRi (Electronic Cash Register interface) offers a cost-effective, PCI compliant payment solution for merchants. ECRi-enabled, standalone POS terminals allow merchants to process payments without transferring sensitive credit card account information to the merchant’s POS system. This technology offloads PCI compliance issues to the merchant’s provider, reducing the headaches and costs associated with credit card fraud. Switching to an ECRi capable payment solution is easy and offers merchants significant benefits.</p>
<h2>How do merchants benefit from using ECRi?</h2>
<h3>A simple payment solution</h3>
<p>Merchants who operate with an ECRi payment solution can offload PCI compliance requirements to their provider while implementing a future-proofed payment system. The payment system is remotely updated by their provider when upgrades are made available. All these features make for a simple payment solution that takes the headaches and discomfort out of payment processing, allowing merchants to focus on their own business.</p>
<h3>Save more money</h3>
<p>Implementing ECRi into your payment system can save merchants a lot of money. The cost of securing an average network to PCI standards is more than $250,000 per year. With ECRi, sensitive credit card account data is not transferred to the merchant’s POS system. This allows merchants to offload PCI responsibilities to their provider while significantly reducing expenses. ECRi merchants are no longer liable for stolen credit card account data in the event of a breach of their network, and thus avoid massive expenses inherent to the litigation of fraud cases.</p>
<h3>Enhanced functionality</h3>
<p>ECRi payment systems make payment processing easy and &#8230; <a href="http://www.versapay.com/company-news/how-does-ecri-work-for-merchants/" class="read_more">Read more</a></p>]]></description>
		<wfw:commentRss>http://www.versapay.com/company-news/how-does-ecri-work-for-merchants/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI DSS compliance: Why merchants need to care</title>
		<link>http://www.versapay.com/company-news/pci-dss-compliance-why-merchants-need-to-care/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=pci-dss-compliance-why-merchants-need-to-care</link>
		<comments>http://www.versapay.com/company-news/pci-dss-compliance-why-merchants-need-to-care/#comments</comments>
		<pubDate>Thu, 29 Apr 2010 15:30:07 +0000</pubDate>
		<dc:creator>VersaPay</dc:creator>
				<category><![CDATA[Company News]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[PCI DSS]]></category>

		<guid isPermaLink="false">http://www.versapay.com/?p=4117</guid>
		<description><![CDATA[<p>Merchants accepting credit cards in today’s fast-moving business environment should be aware of Payment Card Industry Data Security Standard (PCI DSS), a recent regulatory change that significantly affects the way credit card payments are processed. Many businesses are unaware that storing and handling sensitive credit card account data improperly can lead to large fines, corporate embarrassment and lost sales. In a worst-case scenario, merchants may be unable to process transactions in the future.  All businesses that process transactions are subject to these new regulatory standards, regardless of their size, industry, or processing history.</p>
<p>PCI DSS is a regulatory requirement that aims to increase credit card data security with payment processing. Becoming PCI DSS compliant can be difficult and complicated, and applies all companies that transmit, process, or store credit card account data. Even companies who do not intentionally store credit card data or who use professional POS systems are often unaware of the risks associated with a non-PCI compliant system. You can reduce the present risks by working with a payment processor who understands PCI compliance and who can help you upgrade your payment system to meet today’s standards.</p>
<h2>A real-life example</h2>
<p>PCI DSS compliance is complicated enough that even one of B.C.’s largest companies struggled with it; <a title="B.C. Ferries PCI DSS audit" href="http://www.theglobeandmail.com/news/national/british-columbia/B.C.-ferries-data-security-system-flawed-audit-finds/article1530219/" target="_blank">a recent Globe and Mail article</a> reported that B.C. Ferries recently discovered that they have “glaring deficiencies in the way in which the company is protecting sensitive customer credit card information.” Most notably, B.C. Ferries learned that after all payment transactions, their &#8230; <a href="http://www.versapay.com/company-news/pci-dss-compliance-why-merchants-need-to-care/" class="read_more">Read more</a></p>]]></description>
		<wfw:commentRss>http://www.versapay.com/company-news/pci-dss-compliance-why-merchants-need-to-care/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to switch to chip and PIN</title>
		<link>http://www.versapay.com/company-news/how-to-switch-to-chip-and-pin/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=how-to-switch-to-chip-and-pin</link>
		<comments>http://www.versapay.com/company-news/how-to-switch-to-chip-and-pin/#comments</comments>
		<pubDate>Thu, 15 Apr 2010 15:30:27 +0000</pubDate>
		<dc:creator>VersaPay</dc:creator>
				<category><![CDATA[Company News]]></category>
		<category><![CDATA[chip and PIN]]></category>
		<category><![CDATA[ECRi]]></category>
		<category><![CDATA[PCI DSS]]></category>

		<guid isPermaLink="false">http://www.versapay.com/?p=3904</guid>
		<description><![CDATA[<p>As a merchant looking for the most secure and efficient method of payment, you may have questions about switching to chip and PIN technology.</p>
<p>First implemented in Europe, chip and PIN credit cards are widely used in Canada. With the looming deadline of October 2010, Canadian merchants must ensure that they are prepared to <a title="VersaPay chip and PIN technology" href="http://www.versapay.com/?p=3713">adopt chip and PIN technology</a>. After October 2010, merchants who are not chip and PIN compliant risk being liable for any fraudulent charges made against them.</p>
<p>Here are some things to consider when upgrading to chip and PIN technology.</p>
<h2>Software and hardware upgrades</h2>
<p>In order to accept payments using chip and PIN technology, merchants must upgrade to chip and PIN certified hardware. Terminals must have chip and PIN readers and <a title="VersaPay PCI standards" href="http://www.versapay.com/?p=3704">follow PCI standards</a>.</p>
<p>Typically, merchants face few software issues when migrating to chip and PIN. Ask your POS vendor if the current version of their software that you use is certified for chip and PIN transactions. If your POS provider is not PCI compliant, VersaPay offers an inexpensive solution called ECRi.</p>
<h3>What is ECRi?</h3>
<p>ECRi (Electronic Cash Register interface) technology allows merchants to offload PCI compliance responsibilities to their provider. By setting up a PCI compliant payment terminal with ECRi, VersaPay allows merchants to process payments without sending sensitive customer account data through the POS system. This cost-effective integration reduces merchants’ transaction fees and eliminates the headaches associated with becoming PCI compliant.</p>
<h2>How much does it cost to switch to chip and PIN?</h2>
<p>The &#8230; <a href="http://www.versapay.com/company-news/how-to-switch-to-chip-and-pin/" class="read_more">Read more</a></p>]]></description>
		<wfw:commentRss>http://www.versapay.com/company-news/how-to-switch-to-chip-and-pin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is EMV and how does it affect payment processing?</title>
		<link>http://www.versapay.com/company-news/what-is-emv-and-how-does-it-affect-payment-processing/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=what-is-emv-and-how-does-it-affect-payment-processing</link>
		<comments>http://www.versapay.com/company-news/what-is-emv-and-how-does-it-affect-payment-processing/#comments</comments>
		<pubDate>Tue, 30 Mar 2010 15:30:32 +0000</pubDate>
		<dc:creator>VersaPay</dc:creator>
				<category><![CDATA[Company News]]></category>
		<category><![CDATA[chip and PIN]]></category>
		<category><![CDATA[EMV]]></category>
		<category><![CDATA[PCI DSS]]></category>

		<guid isPermaLink="false">http://www.versapay.com/?p=3764</guid>
		<description><![CDATA[<p>As of 2009, more than 944 million EMV compliant chip cards are in use around the world. EMV is a standard that businesses of all sizes, across all industries, adopt to ensure safe and reliable debit and credit card transactions.</p>
<h2>What is EMV?</h2>
<p>EMV is the standard that allows chip and PIN cards to operate with chip-enabled terminals and ATMs.</p>
<p><a title="Link to EMVCo" href="http://www.emvco.com/" target="_blank">EMVCo</a> is a public company that manages, maintains and enhances EMV Integrated Circuit Card Specifications Standards.</p>
<ul>
<li>In 1999, EMVCo was founded by Europay International SA, Mastercard and VISA.</li>
<li>In 2002, Europay International SA was absorbed into Mastercard.</li>
<li>In 2004, JCB (formerly Japan credit Bureau) joined the organization.</li>
<li>In 2009, American Express joined the organization.</li>
</ul>
<p>EMVCo’s main activities are to:</p>
<ul>
<li>Ensure the compatibility and acceptance of chip cards globally.</li>
<li>Develop an internationally recognized standard for chip-based payment processing.</li>
<li>Test and approve processes that evaluate compliance with EMV standards.</li>
</ul>
<h2>How do EMV standards affect my business?</h2>
<p>The introduction of EMV standards brings many changes that affect merchants around the world.</p>
<ul>
<li>EMV standards improve the customer experience. Customer information is protected by cryptographic algorithms, providing improved security between chip cards and chip-reading terminals during transactions.</li>
<li>EMV standards can save you money. Since these standards improve the security of transactions, transactions that follow EMV standards can be subject to lower payment processing fees.</li>
<li>EMV standards reduce your liability for fraudulent activity from lost or stolen payment cards. Notably, as of 2010, merchants without EMV compliant devices are fully liable for the cost of credit </li>&#8230; <a href="http://www.versapay.com/company-news/what-is-emv-and-how-does-it-affect-payment-processing/" class="read_more">Read more</a></ul>]]></description>
		<wfw:commentRss>http://www.versapay.com/company-news/what-is-emv-and-how-does-it-affect-payment-processing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Payment processing in Canada: PCI DSS, part 2</title>
		<link>http://www.versapay.com/company-news/payment-processing-in-canada-pci-dss-part-2/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=payment-processing-in-canada-pci-dss-part-2</link>
		<comments>http://www.versapay.com/company-news/payment-processing-in-canada-pci-dss-part-2/#comments</comments>
		<pubDate>Thu, 18 Mar 2010 15:30:42 +0000</pubDate>
		<dc:creator>VersaPay</dc:creator>
				<category><![CDATA[Company News]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[documentation]]></category>
		<category><![CDATA[payment processing]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[Qualified Security Assessor]]></category>
		<category><![CDATA[safe harbour]]></category>
		<category><![CDATA[self-assessment questionnaire]]></category>
		<category><![CDATA[upgrade]]></category>

		<guid isPermaLink="false">http://www.versapay.com/?p=3704</guid>
		<description><![CDATA[<h2>PCI DSS and your business</h2>
<p>In our previous post, we discussed the <a title="Link to Payment Processing in Canada: PCI DSS, part 1" href="http://www.versapay.com/?p=3668" target="_self">12 requirements of PCI DSS</a>. Today, we&#8217;ll talk about how these requirements will affect your business.</p>
<h3>How does PCI DSS affect your business?</h3>
<p>PCI DSS is dramatically changing credit card payment processing. Here are some costs and benefits you should be aware of.</p>
<ul>
<li><strong>Costly Upgrades</strong>. The state of your current systems will determine how PCI DSS affects your business. If your systems meet the current requirements, then PCI DSS will not affect your business. However, if your systems do not meet PCI DSS requirements, you may have to upgrade your systems. Speak to your payment processor about the most cost-effective way to become PCI DSS compliant.</li>
<li><strong>Safe Harbour Status</strong>. One of the main benefits of becoming PCI DSS compliant is that you will attain safe harbour status. Safe harbour status protects you from fines in the event of a security breach. In the unfortunate event that a customer sues you, the court will be more lenient with you if you have safe harbour status. In order to benefit from safe harbour status, all security requirements must be in place.</li>
<li><strong>Fines</strong>. If your business is not PCI DSS compliant, it may be audited, fined, or sued. In the worst-case scenario, your business may lose the right to process credit cards entirely.</li>
</ul>
<h3>What are the documentation requirements for PCI DSS?</h3>
<p>Documentation requirements depend on your business’s volume of credit card payment processing.</p>
<ul>
<li>Businesses that handle up </li>&#8230; <a href="http://www.versapay.com/company-news/payment-processing-in-canada-pci-dss-part-2/" class="read_more">Read more</a></ul>]]></description>
		<wfw:commentRss>http://www.versapay.com/company-news/payment-processing-in-canada-pci-dss-part-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Payment processing in Canada: PCI DSS, part 1</title>
		<link>http://www.versapay.com/company-news/payment-processing-in-canada-pci-dss-part-1/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=payment-processing-in-canada-pci-dss-part-1</link>
		<comments>http://www.versapay.com/company-news/payment-processing-in-canada-pci-dss-part-1/#comments</comments>
		<pubDate>Tue, 16 Mar 2010 15:34:10 +0000</pubDate>
		<dc:creator>VersaPay</dc:creator>
				<category><![CDATA[Company News]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[payment processing]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.versapay.com/?p=3668</guid>
		<description><![CDATA[<h2>PCI DSS and credit card payment processing</h2>
<p>The Payment Card Industry Data Security Standard (PCI DSS) is the major regulatory change that you are likely to face this year. We recently provided an overview of <a title="Link to Payment processing in Canada: Regulatory changes" href="http://www.versapay.com/?p=3392" target="_self">PCI DSS</a>. In this article, we’ll discuss it in more detail.</p>
<h3>What is PCI DSS?</h3>
<p>The PCI Security Standards Council developed PCI DSS to increase data security in credit card payment processing. The PCI DSS applies to all organizations that transmit, process, or store credit card data. Note that while the PCI Security Standards Council developed PCI DSS, the regulations are actually enforced by credit card associations like Visa, MasterCard and American Express.</p>
<p>The PCI DSS has six “control objectives” that include a total of 12 compliance requirements. According to the <a title="Link to PCI Security Standards Council" href="https://www.pcisecuritystandards.org/security_standards/pci_dss.shtml" target="_blank">PCI Security Standards Council</a>, the control objectives are:</p>
<p><strong>Build and Maintain a Secure Network</strong><br />
<em>Requirement 1</em>: Install and maintain a firewall configuration to protect cardholder data.<br />
<em>Requirement 2</em>: Do not use vendor-supplied defaults for system passwords and other security parameters.</p>
<p><strong>Protect Cardholder Data</strong><br />
<em>Requirement 3</em>: Protect stored cardholder data.<br />
<em>Requirement 4</em>: Encrypt transmission of cardholder data across open, public networks.</p>
<p><strong>Maintain a Vulnerability Management Program</strong><br />
<em>Requirement 5</em>: Use and regularly update anti-virus software.<br />
<em>Requirement 6</em>: Develop and maintain secure systems and applications.</p>
<p><strong>Implement Strong Access Control Measures</strong><br />
<em>Requirement 7</em>: Restrict access to cardholder data by business need-to-know.<br />
<em>Requirement 8</em>: Assign a unique ID to each person with computer access.<br />
<em>Requirement 9</em>: Restrict physical &#8230; <a href="http://www.versapay.com/company-news/payment-processing-in-canada-pci-dss-part-1/" class="read_more">Read more</a></p>]]></description>
		<wfw:commentRss>http://www.versapay.com/company-news/payment-processing-in-canada-pci-dss-part-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Payment processing in Canada: Regulatory changes</title>
		<link>http://www.versapay.com/company-news/payment-processing-in-canada-regulatory-changes/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=payment-processing-in-canada-regulatory-changes</link>
		<comments>http://www.versapay.com/company-news/payment-processing-in-canada-regulatory-changes/#comments</comments>
		<pubDate>Tue, 02 Mar 2010 08:17:55 +0000</pubDate>
		<dc:creator>VersaPay</dc:creator>
				<category><![CDATA[Company News]]></category>
		<category><![CDATA[chip and PIN]]></category>
		<category><![CDATA[payment processing]]></category>
		<category><![CDATA[PCI DSS]]></category>
		<category><![CDATA[regulatory]]></category>

		<guid isPermaLink="false">http://www.versapay.com/?p=3392</guid>
		<description><![CDATA[<p>The payment processing industry is facing many exciting changes in 2010. These changes are:</p>
<ul>
<li>Regulatory driven, by PCI DSS, and chip and PIN technology</li>
<li>Consumer driven, by mobile technology and the entry of Visa Debit.</li>
</ul>
<p>These changes present new challenges and opportunities for all card-accepting merchants and include:</p>
<ul>
<li>Regulatory driven changes</li>
<li>Consumer driven changes</li>
<li>PCI compliance</li>
<li>Chip and PIN technology</li>
<li>Mobile technology</li>
<li>Visa debit</li>
</ul>
<p>Over the next few articles, we’ll take a more detailed look at these industry changes. Today, we’ll talk about regulatory driven changes in the payment processing industry.</p>
<h2>Regulatory driven changes</h2>
<h3>Payment Card Industry Data Security Standard (PCI DSS)</h3>
<p>The biggest regulatory change to impact your business in 2010 is the introduction of the Payment Card Industry Data Security Standard (<a title="Link to PCI Security Standards Organization" href="https://www.pcisecuritystandards.org/" target="_blank">PCI DSS</a>).</p>
<h4>What is PCI DSS?</h4>
<p>The PCI DSS is a set of 12 requirements that covers everything from developing a secure network to maintaining an information security policy.</p>
<h4>How does PCI DSS affect your business?</h4>
<p>First, you may have to change your current systems in order to meet PCI DSS standards. If your current payment processing system is up-to-date, you may only need a slight upgrade. If your system is old, it may be worth getting a new system. <a title="Contact VersaPay for a rate quote" href="http://www.versapay.com/?page_id=1251" target="_self">Contact your payment processor</a> to determine which option is best for your business.</p>
<p>Second, you must document your security compliance. There are two categories of PCI DSS merchants. The amount of documentation required depends on which category you are in.</p>
<ul>
<li> Lower level merchants have up to </li>&#8230; <a href="http://www.versapay.com/company-news/payment-processing-in-canada-regulatory-changes/" class="read_more">Read more</a></ul>]]></description>
		<wfw:commentRss>http://www.versapay.com/company-news/payment-processing-in-canada-regulatory-changes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using disk: basic
Database Caching using disk: basic

Served from: www.versapay.com @ 2012-05-21 17:20:19 -->
