By : Jessica Lundberg
June 29, 2010 10:39 AM
Since the inception of the first data security standard, most of the focus has been placed on ensuring that a business’ POS software was validated against the latest payment application standard, which is now known as the Payment Application Data Security Standard (PA DSS). Unfortunately, most retailers and restaurant operators believed and still falsely believe that having a PA DSS validated version of POS software is all that is needed to be PCI compliant. PA DSS validated software does not equal PCI compliance…don’t fall into the trap of thinking this way.
The new wave of criminal attacks is not targeted at stealing data from the payment application. Hackers are now getting into sites that have poor network and perimeter security and capture the data as it travels through the computers at the site before being sent to the bank. The scary truth is that these types of attacks work against any software – including those validated as PA DSS – because the hackers are now attacking in transit data instead of stored data. This is just one of the reasons why it has become even more important to protect network and perimeter security and shut down any insecure remote access tools.
6 Things You Can Do Today to Become More Secure
* If you haven’t already, get a PA-DSS validated version of your POS software
* Install a commercial grade, managed hardware firewall – not the one you picked up from Best Buy five years ago
* Use only secure remote access into the business
* Use strong passwords and rotate them every 90 days
* Install anti-virus and keep it updated
* Use POS and BOH for ONLY for transactions and patch those systems – no web surfing