No thanks, stay here.  

  We notice you are visiting from a U.S. Internet provider. Switch to our U.S. website.

Industry News

Contrary to rumors, operating systems are out of scope for PCI DSS

By Joseph Trigliari

02/02/2010 - Some merchants may have received a letter from a POS terminal vendor saying that Microsoft will discontinue its support of the Windows 200 operating system effective July 1, 2010, a move that would make any merchants using the OS immediately non-compliant.

However, merchants should not heed this warning, as it is unfounded in the PCI DSS, StorefrontBacktalk.com reported.

The payment processing news website cited the FAQ section of the PCI Security Standards Council website, which showed that operating systems are out of scope for the PCI DSS.

"Systems that use operating systems that are no longer supported with new security patches by the vendor, OEM or developer are not necessarily out of compliance. Compensating controls could address risks posed by using older operating systems," StorefrontBacktalk.com cited from the PCI SSC.

The council highlights monitoring firewall logs more frequently than required, as well as isolating and segmenting POS systems from the internet and other systems in the cardholder data environment through the use of firewalls, as possible compensating controls.

Paying attention to in-scope versus out-of-scope data can go a long way to simplify - and reduce the cost of - the payment processing security compliance process, experts advise.ADNFCR-2514-ID-19593882-ADNFCR

Related News - Security and Fraud

Study: PCI compliance a no-brainer among Level Four merchants

10/01/2012

A recent survey by research firm Gartner found nearly one-fifth of retailers and credit card processing services are not compliant with Payment Card Industry Data Security Standards.

Full Article

Tracking spending can be made easy with credit cards

06/12/2011

Many people feel that plastic payment processing options can lead to overspending, but a recent article published by Forbes explains that making payments with credit cards is actually a great way to control costs and track expenses.

Full Article

Keeping business bank accounts safe and secure

11/10/2011

The internet has provided consumers with many new and convenient ways to access their account information, but these advances have also created the need for thorough security measures.

Full Article

Personalized payment chips get fraud prevention upgrade

10/10/2011

Payment chips made by Fiserv will now be further personalized using the Europay MasterCard Visa (EMV) standards, a global credit card payments technology that helps prevent fraud from lost, stolen or counterfeit cards.

Full Article