There are several main areas to focus on when it comes to meeting the PCI requirements from network security, anti-virus software to applications and segregation of encryption of data.
The range of PCI DSS requirements will vary according to which level a merchant is on. Very big e-commerce websites will be on level one which involves needing to comply with a lot more protocol than a company on level four who, since they process far fewer transactions, has a more restricted list.
One area of compliance which needs the attention of all companies is that of making sure that firewalls are strong and up-to-date. Companies must also make sure that any default passwords supplied by vendors are changed and are adequate in terms of security.
If an e-company stores sensitive data then this is an area which a PCI auditor will be very interested in. Customer information, especially credit card details must be encrypted in line with PCI standards, and stored in a safe area.
A big area of compliance is around the use of anti-virus software and its upgrading and use. There needs to be a penetration test in order to be designated DSS ready. This will be done by a qualified PCI assessor.
The first thing you need to do in order to become compliant with PCI measures is to get in contact with a Scan Vendor which is recognised by the PCI. Their compliance consultants will be able to advise you about what you need to do in order to meet compliance regulations, with regard to your particular company.
You can also download a form for assessment purposes known as a PCI Self-Assessment Questionnaire which will give you a good indication of which areas you need to concentrate on in order to become PCI compliant.
