Share this article
If your organisation is in the business of accepting credit card payments and making financial transactions with customers, it’s crucial that you comply with the Payment Card Industry Data Security Standard (PCI DSS).
With 11.6 million card transactions performed each day in the UK on average, businesses have a responsibility to maintain a robust and rigorous approach to card security – and this is precisely why PCI DSS was introduced back in 2004 at a time when credit card fraud was on the rise.
Like all security standards and certifications, achieving compliance with PCI DSS focuses on the implementation of safeguards, the establishment of processes policies and procedures, and an awareness of potential vulnerabilities.
More specifically, PCI DSS requires those businesses accepting card payments to protect cardholder data.
For those organisations without large in-house security teams or payment card specialists, understanding how to go about getting PCI compliant can feel like a daunting task. And for that reason more and more organisations are looking for additional support and expertise to help them not only get through the auditing process but also in supporting them to build a compliance framework.
For that reason, at SRM we have launched our Virtual PCI Manager solution – offering the expertise and experience of our consultants to organisations from across a range of industries.
So what does a PCI manager do for you on a day to day basis in terms of specific tasks and responsibilities?
The first thing you should expect from your PCI manager is an in depth knowledge and understanding of the technical and operational requirements involved in keeping payment data secure.
In order to get under the skin of an organisation and understand its current preparedness, a PCI Manager will support clients to benchmark data security processes against all the requirements of PCI DSS.
In practical terms, this will cover the implementation and maintenance of security precautions, from choosing the right anti-virus measures and point-of-sale software and equipment, through to devising procedures on password rules.
It will also fall to the PCI manager to conduct a schedule of regular risk assessment exercises to check for weaknesses, new threats and non-compliance. The latter is an important factor as technology is constantly evolving and there may be changes to legislation and compliance requirements to meet new industry and market challenges.
And when security issues arise and PCI compliance is under threat, your PCI manager will support your business to take effective and timely remedial action.
The PCI manager can also be a vital asset in training your teams to continually monitor and review systems to identify vulnerabilities and eliminate potential threats.
One of the key benefits of outsourcing PCI management to an SRM consultant lies on our ability to offer a flexible and scalable solution that can accommodate an organisation’s needs as it evolves and grows.
Rather than taking the risk of hiring an in-house team member who may or may not have all the requisite experience in data protection, our consultants possess decades of experience and are also fully qualified PCI Security Assessors in their own right.
We can also organise compliance evidence documentation to ensure that PCI compliance integrates with similar regulatory frameworks such as ISO 27001 or GDPR.
If you want to find out more about how SRM can help you with an outsourced PCI manager, click here or call us today on 03450 21 21 51.