PCI Compliance: Difference between revisions
m (clean up, typos fixed: Wikipeda → Wikipedia) |
m (Reverted edits by Richard Symonds (WMUK) (talk) to last revision by Katherine Bavage (WMUK)) |
||
Line 1: | Line 1: | ||
[[File: | [[File:PCI_SAQ.pdf|200px|thumb|right| WMUK PCI Compliance Self-Assessment Questionnaire dated 20-09-2012]] | ||
[[File: | [[File:PCI_Certificate.pdf|200px|thumb|right| WMUK PCI Compliance Certificate dated 20-09-2012]] | ||
Wikimedia UK is compliant with PCI DSS regulations. Wikimedia UK does not directly process financial information. | Wikimedia UK is compliant with PCI DSS regulations. Wikimedia UK does not directly process financial information. | ||
Line 9: | Line 9: | ||
The Payment Card Industry Data Security Standard (PCI DSS) is an information security standard for organizations that handle cardholder information for the major debit, credit, prepaid, e-purse, ATM, and POS cards. | The Payment Card Industry Data Security Standard (PCI DSS) is an information security standard for organizations that handle cardholder information for the major debit, credit, prepaid, e-purse, ATM, and POS cards. | ||
Defined by the Payment Card Industry Security Standards Council, the standard was created to increase controls around cardholder data to reduce credit card fraud via its exposure. Validation of compliance is done annually — by an external Qualified Security Assessor (QSA) for organizations handling large volumes of transactions, or by Self-Assessment Questionnaire (SAQ) for companies handling smaller volumes. (Taken from | Defined by the Payment Card Industry Security Standards Council, the standard was created to increase controls around cardholder data to reduce credit card fraud via its exposure. Validation of compliance is done annually — by an external Qualified Security Assessor (QSA) for organizations handling large volumes of transactions, or by Self-Assessment Questionnaire (SAQ) for companies handling smaller volumes. (Taken from Wikipeda - Payment Card Industry Data Security Standard) | ||
Read more here [http://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard]. | Read more here [http://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard]. |
Revision as of 00:43, 16 January 2013
Wikimedia UK is compliant with PCI DSS regulations. Wikimedia UK does not directly process financial information.
Wikimedia UK has completed a PCI Self-Assessment Questionnaire (SQA) demonstrating compliance.
The Payment Card Industry Data Security Standard (PCI DSS) is an information security standard for organizations that handle cardholder information for the major debit, credit, prepaid, e-purse, ATM, and POS cards.
Defined by the Payment Card Industry Security Standards Council, the standard was created to increase controls around cardholder data to reduce credit card fraud via its exposure. Validation of compliance is done annually — by an external Qualified Security Assessor (QSA) for organizations handling large volumes of transactions, or by Self-Assessment Questionnaire (SAQ) for companies handling smaller volumes. (Taken from Wikipeda - Payment Card Industry Data Security Standard)
Read more here [1].