Pa dss And Pabp Do You Know The Difference? |
||||
| By Element Payment Services |
||||
| In 2005, Visa developed the Payment Application Best
Practices (PABP). The purpose of the program was to guide
software vendors in creating secure payment applications
that prevent storage of sensitive cardholder data and
mitigate cardholder data compromises. Three years later, in 2008, the PCI Security Standards Council – made up of the major payment card brands — adopted Visa’s PABP and released it as the Payment Application Data Security Standard, or PA-DSS for short. In doing so, the PA-DSS replaced PABP for the purpose of the Visa’s payment application compliance program. In other words, think PA-DSS, not PABP! The PCI SSC is transitioning all 555 products previously validated under Visa’s PABP over to a consolidated list located at the PCI SSC website, comprised of the validated PABP applications and newly validated PA-DSS applications. All new payment application assessments should undergo PA-DSS validation by a Payment Application Qualified Security Assessor (PA-QSA) and listing with the PCI SSC. Another option is to go out of scope for PA-DSS by transferring the responsibility of handling sensitive cardholder data to a third party. Each payment card brand has different requirements and deadlines for PA-DSS compliance. At least up to this point, Visa has the most stringent deadlines for PA-DSS. View them as well as other PCI compliance deadlines for each payment card brand in our blog post, PCI Compliance Deadlines. |
||||
| Article Source: http://interpret.zar.vg | ||||
| About The Author Headquartered in Phoenix, Arizona, and founded by payment industry experts, Element Payment Services, Inc. provides secure, reliable and innovative payment processing solutions directly to merchants through partnership with leading business management software providers. |
||||
|
||||
| © 2012 interpret.zar.vg |