
|
|
VisaŽ CISP Requirements.
|
|
The VisaŽ Cardholder Information Security Program is a 12 point program designed to assist anyone who process credit cards, where the customer is not present,
to secure the credit card information.
|
|
|
Program Requirements
|
- Install and maintain a working network firewall to protect data accessible via the Internet.
- Keep security patches up-to-date.
- Encrypt stored data.
- Encrypt data sent across networks.
- Use and regularly update anti-virus software.
- Restrict access to data by business "need to know."
- Assign a unique ID to each person with computer access to data.
- Don't use vendor-supplied defaults for system passwords and other security parameters.
- Track access to data by unique ID.
- Regularly test security systems and processes.
An additional two requirements address administrative and physical security issues:
- Maintain a policy that addresses information security for employees and contractors.
- Restrict physical access to cardholder information.
These top-level principles apply to all entities participating in the Visa payment system that process or store cardholder information and have access to it though the Internet or mail-order/telephone-order.
|
|
We can assist you in meeting all of the above requirements.
Further information about this program can be obtained from Visa's Merchant Resource Center.
Click here
to download a copy of the Cardholder
Information Security Program (cisp55.pdf file 274K).
.
Adobe Acrobat 3.0 is required for viewing PDF documents. Download the free Adobe
Acrobat Reader to view (browse) and print these specifications.
|
|