Updated July 14, 2008
Many ecommerce web hosting companies are now offering
services that provide professional assistance in ahieving Payment
Card Industry (PCI) Compliance. Rather than putting pieces of software
and hardward together a hosting service can accommodate a service
whereby all is packaged together for the merchant's convenience.
PCI Compliance is based on a set
of security tools that provide the basis to insure compliance with
the new banking regulation which applies to online businesses that
accept, process, or store credit card information.
In our opinion, and we have staff
with 20+ experience in computer technology and security, the compliance
is only a polictical tool so that Visa and Mastercard companies
(which are really an association of the 5000+ banks) to retain control
over their industry and not allow the government to interfere with
their domination of the credit card industry. The self declared
regulations and the penalties and punishments are forcing smaller
businesses to suffer the costs of these regulations and allow wealthier
companies to consolidate their forces and dominate their market
at the expense of the little guy. This is in our opinion anti-competition
since small companies do not have the money to pay for security
audits and other expenses associated to these mandates.
If you do not adhere to their demands,
then you are subject to penalties and sanctions by banks - yes,
sanctions. So, you must meet the demands of the banking industry
or you may feel that you are an evil dictator building evil weapons
of destruction and being sanctioned for wanting to sell your products
and services on the Internet.
Out of every $100 spent with a credit
card, about $1 goes to VISA Association and about $1 goes to the
issuing bank that issued the credit card to the consumer or business
owner.
Total credit card transactions
in US during 2007 was nearly $1.4 trillion.
VISA
marketshare in 2007 accounted for nearly 50% of transactions
MasterCard
marketshare in 2007 accounted for nearly 35% of transactions
American
Express marketshare in 2007 accounted for nearly 10% of transactions
Discover
Card marketshare in 2007 accounted for nearly 5% of transactions
Based on these numbers, VISA's revenue
from fees collected from credit card use topped $70 billion (1%
x 50% x $1.4 trillion).
But remember 1% also goes to the
issuing bank (which is also a member of the association - so therefore
this banks actually get paid directly and indirectly - twice).
Top 5 Issuing Credit Card
Companies
Bank
of America
JP Morgan
Chase
Citigroup
American
Express
Capital
One
Therefore to consolidate control
of their industry and to make certain that the government does not
get involved in their affairs, PCI Compliance Regulation was introduced
that has created so much frustration and headaches for small businesses
that want to sell their products and services online. We hear from
these business every day and sympathize with their anguish trying
to adhere to a mandate by those companies strong enough to bully
and force compliance without any outrage by the media and the government
against this 'small-business' punishing politically-motivated
regulation.
However, here we will attempt to
help small businesses as best as we can to comply and survive this
aparthied.
The PCI regulation requires the
following compliance:
Anti-virus Protection
Firewall
Customer Network Scanning Services
File Sustem Integrity Solution
Intrusion Detection System
Server Logging System
Electronic Security Management System
Physical System Security
SSL Secure Certificate System
VPN (Virtual Private Network) Management and Access
There are however some hosting companies
that are uniting to establish a system that makes it easier and
more convenient for online merchants. These hosting companies should
be commended for their efforts to help establish a business-friendly
service even though it is being provided with a small fee attached.
Good Luck.
|