Payment Card Industry Standards: The Nature of Industry Standards

2007-06-20 15:49:53

( Financial )



Authorized by Visa USA in June 2001, the Cardholder Information Security Program (CISP) is an established standard of security designed to protect information on credit cards wherever it is located to guarantee that members, merchants and service providers uphold the maximum payment card industry standards of information security.

In 2004, behind the partnership of Visa and MasterCard, the CISP qualifications were integrated into the Payment Card Industry (PCI) Data Security Standards (DSS) or PCI DSS, to establish a general industry benchmark that is acknowledged worldwide by all major credit card companies. At present, Visa holds the standard and compliance program of PCI DSS.

Application of the Payment Card Industry Standard

Adherence to the payment card industry standard is mandatory for any entity engaged in the administration, collection and transmission of credit card information.

The payment card industry standard is applicable to three principal groups namely the trading firm, investment banks and contractors. Merchants are trade stores that accept credit card payments. Merchant banks handle transactions for the sake of the merchants. Service providers administer, collect or convey cardholder information on behalf of Visa affiliates, businesses or other service contractors.

The card payment industry standards are security prerequisites applicable to all system components which mean “any element of a network, server, or application which is integral or attached to the cardholder information situation.

Dangers of Non-Compliance

The consequence of non-compliance can be harsh. Organizations found violating such payment card industry standards shall be liable to heavy fines for every count of information stealing and this is exclusive of the corrective damages, loss of company integrity and/or even imprisonment which the company officers may encounter.

For third party contractors the consequences could even be greater as this non-compliance could lead to the loss of important business clients. This is due to the fact that businesses are required to make transactions only with third party contractors that adopt the payment card industry standards.

The implication of this is that as the contract of service of merchants terminates and fresh contracts are outlined, the requisites of being industry-compliant compel businesses to transfer to compliant contractors. Organizations that passed the payment card industry standards are drawing huge amounts of new clients, while contractors are losing clients.


All rights Reserved © Tradenet Services srl
Do not duplicate or redistribute in any form.