Pci?

Discussion in 'Payment Processing' started by VAR Dude, Sep 26, 2008.

  1. #1
    I just got a letter from my bank saying I need to be PCI compliant by October 15th?????? Anyone else get something like this, what does it mean?
     
    VAR Dude, Sep 26, 2008 IP
  2. eddy2099

    eddy2099 Peon

    Messages:
    8,028
    Likes Received:
    568
    Best Answers:
    0
    Trophy Points:
    0
    #2
    Perhaps going through http://www.pcicomplianceguide.org/ would help. Failing which see if the letter includes any other information or contact which you can call to find out what you need to do.
     
    eddy2099, Sep 26, 2008 IP
  3. VAR Dude

    VAR Dude Peon

    Messages:
    9
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #3
    Thanks for the tip. I have read the guide and it looks like I need to set up my servers with a firewall.

    Anyone out there know of a good hosting company that is affordable - Rackspace wants $1,300/mo for a compliant solution.
     
    VAR Dude, Sep 29, 2008 IP
  4. VAR Dude

    VAR Dude Peon

    Messages:
    9
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #4
    Ok, small addition to what it takes to be PCI Compliant. The guide states:

    2.2.1 Implement only one primary function per server (for example, web servers, database
    servers, and DNS should be implemented on separate servers)

    I understand this to mean you will need a firewall, front end web server and a back end database server.

    I have a couple of quotes but both are over $1,300/mo. I don't want to use a gateway, so there has got to be a fix out there that cheaper than a grand a month.

    Any ideas?
     
    VAR Dude, Sep 29, 2008 IP
  5. VAR Dude

    VAR Dude Peon

    Messages:
    9
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #5
    Has anyone found a way to meet the new PCI DSS configuration requirement 2.2.1?
     
    VAR Dude, Oct 1, 2008 IP