<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.techsoup.org/cs/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Web Building</title><link>http://forums.techsoup.org/cs/forums/24.aspx</link><description>Strategies and expert advice on all aspects of developing and maintaining an effective Web presence. Topics covered include site-building tools, web design, SEO, analytics and traffic-boosting methods, usability, hosting, and functionality.&lt;br /&gt;Hosted by &lt;a href="http://forums.techsoup.org/cs/members/Yann/default.aspx"&gt;Yann Toledano&lt;/a&gt; of &lt;a href="http://www.ytconsulting.com"&gt;YTConsulting.com&lt;/a&gt;.</description><dc:language>en</dc:language><generator>CommunityServer 2008 SP1 (Debug Build: 30619.63)</generator><item><title>RE: Are you compliant with the new data-security laws?</title><link>http://forums.techsoup.org/cs/forums/thread/77717.aspx</link><pubDate>Thu, 22 Mar 2007 22:52:00 GMT</pubDate><guid isPermaLink="false">caa7681b-025a-49ce-809f-7435bfe4d232:77717</guid><dc:creator>acceptiva</dc:creator><slash:comments>0</slash:comments><comments>http://forums.techsoup.org/cs/forums/thread/77717.aspx</comments><wfw:commentRss>http://forums.techsoup.org/cs/forums/commentrss.aspx?SectionID=24&amp;PostID=77717</wfw:commentRss><description>Just a comment/correction to this article.  The PCI DSS requirements do actually state that anyone that has a webpage that connects to a processor, even a third party processor, must meet the level 4 merchant requirements, i.e., questionnaire and annual scan.  This means that finding a third party processor will NOT absolve you from the need to meet the level 4 requirements.  The reason for this is that even though you may not store or process credit cards, it is still possible for crooks to access the server that hosts your webpage (that in-turn connects to the third party processor) and redirect traffic to a fraudulent site that looks like your third party processor site.</description></item><item><title>RE: Are you compliant with the new data-security laws?</title><link>http://forums.techsoup.org/cs/forums/thread/77311.aspx</link><pubDate>Wed, 07 Mar 2007 14:39:00 GMT</pubDate><guid isPermaLink="false">caa7681b-025a-49ce-809f-7435bfe4d232:77311</guid><dc:creator>marcial1</dc:creator><slash:comments>0</slash:comments><comments>http://forums.techsoup.org/cs/forums/thread/77311.aspx</comments><wfw:commentRss>http://forums.techsoup.org/cs/forums/commentrss.aspx?SectionID=24&amp;PostID=77311</wfw:commentRss><description>Our organization doesn&amp;#39;t accept payments online via credit card but we do process payments via our bank&amp;#39;s ACH system.  Is there published guidance on the requirements to protect this type of information and is there a self assessment questionaire available?</description></item><item><title>RE: Are you compliant with the new data-security laws?</title><link>http://forums.techsoup.org/cs/forums/thread/77303.aspx</link><pubDate>Wed, 07 Mar 2007 00:07:00 GMT</pubDate><guid isPermaLink="false">caa7681b-025a-49ce-809f-7435bfe4d232:77303</guid><dc:creator>eddschott</dc:creator><slash:comments>0</slash:comments><comments>http://forums.techsoup.org/cs/forums/thread/77303.aspx</comments><wfw:commentRss>http://forums.techsoup.org/cs/forums/commentrss.aspx?SectionID=24&amp;PostID=77303</wfw:commentRss><description>The information provided in this article seems to imply that these guidelines are for any organization that touches credit card data, not only organizations that take online credit card payments. It seems to me that this important article to should moved to a different category than "web building".</description></item><item><title>Are you compliant with the new data-security laws?</title><link>http://forums.techsoup.org/cs/forums/thread/19731.aspx</link><pubDate>Thu, 01 Mar 2007 21:59:00 GMT</pubDate><guid isPermaLink="false">caa7681b-025a-49ce-809f-7435bfe4d232:19731</guid><dc:creator>wcook</dc:creator><slash:comments>0</slash:comments><comments>http://forums.techsoup.org/cs/forums/thread/19731.aspx</comments><wfw:commentRss>http://forums.techsoup.org/cs/forums/commentrss.aspx?SectionID=24&amp;PostID=19731</wfw:commentRss><description>In his article &lt;a href="http://www.techsoup.org/learningcenter/webbuilding/page6432.cfm"&gt;New Laws for Organizations that Accept Online Payments&lt;/a&gt;, Andrew Conry-Murray writes that states and countries have recently created laws that require organizations that accept payments online to take certain measures to protect their constituents&amp;#39; data. After reading the article, feel free to share your questions or comments here.</description></item></channel></rss>