{"id":678,"date":"2011-07-20T14:17:16","date_gmt":"2011-07-20T19:17:16","guid":{"rendered":"http:\/\/deliawilsondesign.com\/blog\/?p=678"},"modified":"2012-09-30T07:37:41","modified_gmt":"2012-09-30T12:37:41","slug":"pci-compliance-is-driving-me-crazy","status":"publish","type":"post","link":"https:\/\/wiztech4zc.com\/blog\/pci-compliance-is-driving-me-crazy\/","title":{"rendered":"PCI Compliance is driving me crazy!"},"content":{"rendered":"<p><strong>Well, not me, really, but the customers who want it.\u00a0 And why wouldn&#8217;t they want it?\u00a0 Well&#8230;.<\/strong><\/p>\n<p><strong>PCI compliance is a complicated subject<\/strong> that credit card companies are presently using to charge most small online\u00a0 merchants more money.<\/p>\n<h3>What is PCI compliance?<\/h3>\n<p>Basically, PCI compliance is all about standards of protecting the credit card holder&#8217;s information. The major credit card companies created those standards and made them into hurdles.\u00a0 They aren&#8217;t simple even though most small businesses only do things in a very simple manner.<\/p>\n<p>For instance, most brick and mortar stores use a credit card machine which handles the transaction and prints a receipt that no longer has the credit card number on it. (finally!).\u00a0 Then the retailer puts that receipt into a folder somewhere and holds onto it as long as they are required to.\u00a0 The day&#8217;s batch is processed through that terminal. End of story.<\/p>\n<p><strong>The rules \/ standards cover all sorts of situations that the small merchant does not encounter or practice.\u00a0<\/strong> The biggest thing is about keeping the customer&#8217;s data somewhere so that it could be used later.\u00a0 That&#8217;s the no-no.\u00a0 It&#8217;s never a good idea to do that even if your customer insists you keep it for more charges down the line.<\/p>\n<p>If you do keep it, then there are all sorts of rules\/ recommendations about how it&#8217;s kept. If you&#8217;ve ever taken that online test for pci compliance, you&#8217;ve weeded your way through that stuff before.\u00a0 Of course, you probably didn&#8217;t understand any of it!<\/p>\n<p>They don&#8217;t make those tests for small merchants &#8211; it&#8217;s a generic one test fits all problem.\u00a0 Good grief!<\/p>\n<p>So start the test, answer the questions, fix the ones they don&#8217;t like the answers to and then you pass.\u00a0 There&#8217;s no checking &#8211; it&#8217;s the honor system.<\/p>\n<p><strong>So a brick and mortar store can pass<\/strong> that test no matter what their practices are and never pay an extra cent.<\/p>\n<h3>How does PCI compliance work for online merchants?<\/h3>\n<p>Now if you have an online shop in addition or instead, there is another test you have to pass.\u00a0 Actually, it has nothing to do with you &#8211; only with your hosting company and the scripting on your website.<\/p>\n<p><strong>Zen Cart is PCI compliant.<\/strong> If you have it installed with no mods or changes to the code, the scripting will pass.\u00a0 That&#8217;s the easy part.<\/p>\n<p><strong>The second part is your hosting company<\/strong> and the server your website resides on. The folks that your credit card company has contracted with does a real time, automated scan of your server. And then you fail.<\/p>\n<p>You read the report and can&#8217;t make heads or tails out of it.\u00a0 You ask your web hosting company about it and either they didn&#8217;t answer or swore off any responsibility for the problems.\u00a0 You panic.<\/p>\n<p><strong>Stop right there.<\/strong><\/p>\n<p>If you don&#8217;t pass the test, small merchants may pay an extra $20 a month in processing fees.\u00a0 That&#8217;s the penalty.\u00a0 Nobody yells at you or threatens your ability to take credit card payments. It costs extra.<\/p>\n<p>That&#8217;s no reason to panic.\u00a0 If $20 a month extra in fees is not within your ability to pay, you really don&#8217;t have a business.<\/p>\n<h3>The Technicalities<\/h3>\n<p>The scan looks at your server for what someone has decreed are vulnerabilities. It looks at the versions of the server software. It looks at what ports are open on the server and so on.\u00a0 The results can vary between the scan providers because I assume each create their own code\/robots for doing that.<\/p>\n<p>There&#8217;s a list of the <a href=\"https:\/\/www.pcisecuritystandards.org\/approved_companies_providers\/approved_scanning_vendors.php\" target=\"_blank\">approved companies on\u00a0 the PCI Standards Council website<\/a>. But I was&#8217;t able to find a definitive list of the requirements to become an approved vendor.<\/p>\n<p>Since I have my own dedicated server, I get to see the scan results from the different companies. I get to see sites that pass and sites that don&#8217;t.\u00a0 In the end it has more to do with the vendor doing the scan than it does the server.\u00a0 The company that my credit card processor uses can&#8217;t seem to able to scan my server and, therefore, fails. Don&#8217;t know why that&#8217;s so since other companies can manage it.<\/p>\n<p>My alternative is to pay for a scan from another company.\u00a0 Uh, who?\u00a0 How much?\u00a0 Gosh darn, that&#8217;s hard. I started checking and the first company doesn&#8217;t post that info. The one that is presently doing my scans is $249 a year. Divide that by 20 = $22.50 a month. Another prices it at $699 a year. Cheaper to go without compliance!<\/p>\n<h3>PCI Compliant Webhosts<\/h3>\n<p>Okay, now we are talking about something else entirely.\u00a0 There may be PCI compliant servers out there but the hosting companies can&#8217;t (or aren&#8217;t supposed to) advertise themselves as PCI compliant unless their servers have passed the certification for physical PCI compliance. In other words, if the data center the servers rest in are PCI compliant.<\/p>\n<p><strong>There definitely are some and I have no experience with any of them.<\/strong><\/p>\n<p>The companies I recommend folks to for Zen Cart hosting that are PCI compliant or help to manage PCI compliancy are <a href=\"http:\/\/geekhost.ca\/supp\/aff.php?aff=022\" target=\"_blank\">Geekhost<\/a> (certified Zen Cart hosting) and <a href=\"http:\/\/www.shareasale.com\/r.cfm?b=245684&amp;u=513210&amp;m=17701&amp;urllink=&amp;afftrack=\" target=\"_blank\">Glowhost<\/a> who manages my server. Glowhost has a dedicated PCI compliant server program &#8211; not shared hosting. Geekhost is a Canadian company with servers &#8220;up there&#8221; and Glowhost utilizes a datacenter in Atlanta.<\/p>\n<p>The point is though in the end you pay more money for pci compliant servers.\u00a0 Geekhost is a minimum $20 a month for hosting, probably twice as much as shared hosting can be. Their dedicated server rates are better than Glowhost&#8217;s though.<\/p>\n<h3>Confused? Crazy yet?<\/h3>\n<p>Ha, join a very large club.<\/p>\n<p><strong>My recommendation is simple.<\/strong> Don&#8217;t worry about it until the credit card companies jack that monthly cost up ridiculously high or threaten to cut you off. Yeah, right, and cut their own throats!<\/p>\n<p>Don&#8217;t let PCI compliance drive you crazy!<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<div class=\\\"clearBoth><em> Author: Delia Wilson Lunsford, Founder &#038; CEO, WizTech, Inc. <\/em><\/div>\n<!-- AddThis Advanced Settings generic via filter on the_content --><!-- AddThis Share Buttons generic via filter on the_content -->","protected":false},"excerpt":{"rendered":"<p>Well, not me, really, but the customers who want it.\u00a0 And why wouldn&#8217;t they want it?\u00a0 Well&#8230;. PCI compliance is a complicated subject that credit card companies are presently using to charge most small online\u00a0 merchants more money. What is PCI compliance? Basically, PCI compliance is all about standards of protecting the credit card holder&#8217;s [&hellip;]<!-- AddThis Advanced Settings generic via filter on get_the_excerpt --><!-- AddThis Share Buttons generic via filter on get_the_excerpt --><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-678","post","type-post","status-publish","format-standard","hentry","category-e-commerce"],"_links":{"self":[{"href":"https:\/\/wiztech4zc.com\/blog\/wp-json\/wp\/v2\/posts\/678","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wiztech4zc.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wiztech4zc.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wiztech4zc.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wiztech4zc.com\/blog\/wp-json\/wp\/v2\/comments?post=678"}],"version-history":[{"count":9,"href":"https:\/\/wiztech4zc.com\/blog\/wp-json\/wp\/v2\/posts\/678\/revisions"}],"predecessor-version":[{"id":796,"href":"https:\/\/wiztech4zc.com\/blog\/wp-json\/wp\/v2\/posts\/678\/revisions\/796"}],"wp:attachment":[{"href":"https:\/\/wiztech4zc.com\/blog\/wp-json\/wp\/v2\/media?parent=678"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wiztech4zc.com\/blog\/wp-json\/wp\/v2\/categories?post=678"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wiztech4zc.com\/blog\/wp-json\/wp\/v2\/tags?post=678"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}