支付卡行業(yè)安全標(biāo)準(zhǔn)協(xié)會(huì)(PCI SSC)是一個(gè)開放的全球論壇,致力于賬戶數(shù)據(jù)安全標(biāo)準(zhǔn)的持續(xù)發(fā)展、完善、存儲(chǔ)、普及與實(shí)施。
PCI安全標(biāo)準(zhǔn)協(xié)會(huì)的使命是:通過推動(dòng)PCI安全標(biāo)準(zhǔn)的教育和普及,不斷提升支付賬戶數(shù)據(jù)的安全性。該組織由American Express(美國運(yùn)通)、Discover Financial Services(發(fā)現(xiàn)金融服務(wù)公司)、JCB International(JCB國際信用卡公司)、MasterCard(萬事達(dá)卡國際組織)與Visa Inc(Visa公司)共同創(chuàng)建。查詢進(jìn)一步信息,請?jiān)L問官方網(wǎng)站https://zh.pcisecuritystandards.org/minisite/en/。
The Payment Card Industry Security Standards Council, or PCI SSC – often termed simply “the Council” – is an open global forum, launched in 2006, that develops, maintains and manages the PCI Security Standards, which include the Data Security Standard (DSS), Payment Application Data Security Standard (PA-DSS), and PIN Transaction Security (PTS) Requirements.
Our standards cover everything from the point of entry of card data into a system, to how the data is processed, through secure payment applications. We seek to protect and educate industry players such as merchants, processors, financial institutions, and any other organizations that store, process, and transmit cardholder data, around the world.
The Council works to educate stakeholders about the PCI Security Standards, operates programs to train and qualify security professionals in assessing and achieving compliance with PCI Security Standards, and promotes awareness of the need for payment data security to the public.
The Council’s five founding global payment brands -- American Express, Discover Financial Services, JCB International, MasterCard, and Visa Inc. – have incorporated the PCI DSS as the technical requirements for their data security compliance programs. Each founding member also recognizes the practitioners and companies – Qualified Security Assessors and Approved Scanning Vendors -- certified by the PCI Security Standards Council as being qualified to validate compliance to the PCI DSS, making the Council a centralized resource for access to standards and services approved by all five payment brands.
Finally, there is an important differentiator that merchants should know about. The Council does NOT validate or enforce any organization’s compliance with its PCI Security Standards, nor does it impose penalties for non-compliance. These areas are governed by the payment brands and their partners. If you, as a merchant, have questions about requirements for compliance with any PCI Security Standard, deadlines for or reporting of compliance, only the payment brands can supply the answers, not the Council. Start with these links:
American Express: www.americanexpress.com/datasecurity
Discover Financial Services: http://www.discovernetwork.com/merchants/
JCB International: http://partner.jcbcard.com/security/jcbprogram/index.html
MasterCard: http://www.mastercard.com/sdp
Visa Inc: http://www.visa.com/cisp
Visa Europe: http://www.visaeurope.com/ais