<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.techsoup.org/cs/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Web Building</title><link>http://forums.techsoup.org/cs/forums/24.aspx</link><description>Strategies and expert advice on all aspects of developing and maintaining an effective Web presence. Topics covered include site-building tools, web design, SEO, analytics and traffic-boosting methods, usability, hosting, and functionality.&lt;br /&gt;Hosted by &lt;a href="http://forums.techsoup.org/cs/members/Yann/default.aspx"&gt;Yann Toledano&lt;/a&gt; of &lt;a href="http://www.ytconsulting.com"&gt;YTConsulting.com&lt;/a&gt;.</description><dc:language>en</dc:language><generator>CommunityServer 2008 SP1 (Debug Build: 30619.63)</generator><item><title>Re: Payment Card Industry Data Security Standard (PCI DSS).</title><link>http://forums.techsoup.org/cs/forums/thread/102148.aspx</link><pubDate>Mon, 31 Aug 2009 20:09:42 GMT</pubDate><guid isPermaLink="false">caa7681b-025a-49ce-809f-7435bfe4d232:102148</guid><dc:creator>BeckyW</dc:creator><slash:comments>0</slash:comments><comments>http://forums.techsoup.org/cs/forums/thread/102148.aspx</comments><wfw:commentRss>http://forums.techsoup.org/cs/forums/commentrss.aspx?SectionID=24&amp;PostID=102148</wfw:commentRss><description>&lt;p&gt;PCI-compliance is a real thing that nonprofits have to be aware of, as many others have stated. We have a couple of articles that discuss new regulatory standards that nonprofits may have to adapt to (depending upon what they do online and what sort of client data is processed) that might be helpful to look at on this topic.&lt;/p&gt;
&lt;p&gt;Many of PCI-compliance regulations also criss-cross with HIPAA compliance (Health Insurance Portability and Accountability Act) so you may need to look into whether your organization needs to comply with the new standards in place from both sets of regulations.&lt;/p&gt;
&lt;ul&gt;
    &lt;li&gt;&lt;a href="http://feeds.techsoup.org/%7Er/TechSoup_Articles/%7E3/j2XeEs2zdlo/2171" class="url"&gt;An Introduction to Transport Layer Security&lt;/a&gt; (covers whether your site needs to have a higher security standard and how to implement SSL/TLS) &lt;/li&gt;
    &lt;li&gt;&lt;a href="http://feeds.techsoup.org/%7Er/TechSoup_Articles/%7E3/CIOTRISTeHY/2165" class="url"&gt;In Search of HIPAA-Compliant Software&lt;/a&gt; (covers both HIPAA and PCI compliance issues)&lt;/li&gt;
    &lt;li&gt;&lt;a title="New Laws for Organizations that Accept Online Payments" class="url" href="http://www.techsoup.org/learningcenter/webbuilding/page6432.cfm"&gt;New Laws for Organizations that Accept Online Payments&lt;/a&gt; (reviews both PCI and HIPAA standards)&lt;/li&gt;
    &lt;li&gt;&lt;a title="A Few Good Methods for Processing Credit Cards" class="url" href="http://www.techsoup.org/learningcenter/funding/page10327.cfm"&gt;A Few Good Methods for Processing Credit Cards&lt;/a&gt; (discusses payment methods and what to look for for PCI-compliance&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Hope these are helpful in your quest for answers and compliance! &lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: RE: Payment Card Industry Data Security Standard (PCI DSS).</title><link>http://forums.techsoup.org/cs/forums/thread/102049.aspx</link><pubDate>Thu, 27 Aug 2009 19:38:25 GMT</pubDate><guid isPermaLink="false">caa7681b-025a-49ce-809f-7435bfe4d232:102049</guid><dc:creator>thepciguy</dc:creator><slash:comments>0</slash:comments><comments>http://forums.techsoup.org/cs/forums/thread/102049.aspx</comments><wfw:commentRss>http://forums.techsoup.org/cs/forums/commentrss.aspx?SectionID=24&amp;PostID=102049</wfw:commentRss><description>&lt;p&gt;Tomas. If you&amp;#39;re self-reporting to your merchant bank, then by all means you want to report that you&amp;#39;re PCI-compliant. Most PCI-approved QSA firms will have detailed forms with room for explanations in them. What these firms can also help you with is deciding whether or not certain requirements apply to your company (encryption, data hosting, etc). It&amp;#39;s worth it to know that if some of the 12 requirements are N/A, you can state that (with a justification) and get out of having to do certain documentation.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Payment Card Industry Data Security Standard (PCI DSS).</title><link>http://forums.techsoup.org/cs/forums/thread/99260.aspx</link><pubDate>Mon, 25 May 2009 20:40:12 GMT</pubDate><guid isPermaLink="false">caa7681b-025a-49ce-809f-7435bfe4d232:99260</guid><dc:creator>jtmerch</dc:creator><slash:comments>0</slash:comments><comments>http://forums.techsoup.org/cs/forums/thread/99260.aspx</comments><wfw:commentRss>http://forums.techsoup.org/cs/forums/commentrss.aspx?SectionID=24&amp;PostID=99260</wfw:commentRss><description>&lt;p&gt;I can tell you that PCI compliance is a real initiative that needs to be followed, even by Paypal or other 3rd party users.&amp;nbsp; Some real merchant account providers charge extra for&amp;nbsp;a&amp;nbsp;PCI program that they&amp;#39;ve implemented for their merchants&amp;nbsp;(many more will in the future).&amp;nbsp; But at the least merchants need to find out from their processor is they are PCI compliant because&amp;nbsp;it is not a fake program or scam, but a real initiative that&amp;#39;s not backed by the government to ensure that card data is protected.&lt;/p&gt;
&lt;p&gt;Any questions may be emailed to &lt;a href="mailto:info@donorcharge.com"&gt;info@donorcharge.com&lt;/a&gt; or &lt;a href="mailto:msinfo@merchantseek.com"&gt;msinfo@merchantseek.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Joe&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: Payment Card Industry Data Security Standard (PCI DSS).</title><link>http://forums.techsoup.org/cs/forums/thread/99255.aspx</link><pubDate>Mon, 25 May 2009 15:39:35 GMT</pubDate><guid isPermaLink="false">caa7681b-025a-49ce-809f-7435bfe4d232:99255</guid><dc:creator>gtwyh</dc:creator><slash:comments>0</slash:comments><comments>http://forums.techsoup.org/cs/forums/thread/99255.aspx</comments><wfw:commentRss>http://forums.techsoup.org/cs/forums/commentrss.aspx?SectionID=24&amp;PostID=99255</wfw:commentRss><description>&lt;p&gt;&lt;span style="line-height:115%;font-size:12pt;"&gt;I think it is important to note that PCI DSS compliance is one of several identity data protection areas that may impact non-profits.&lt;/span&gt;&lt;/p&gt;
&lt;div style="margin:0in 0in 10pt;"&gt;&lt;span style="line-height:115%;font-size:12pt;"&gt;For example an organization may have PCI DSS compliant solutions, however, sensitive data could be stolen and exit from data theft&amp;nbsp;from an inside employee.&lt;/span&gt;&lt;/div&gt;
&lt;div style="margin:0in 0in 10pt;"&gt;&lt;span style="line-height:115%;font-size:12pt;"&gt;There is a plethora of others compliance laws to be aware of such as: Red Flag &lt;i&gt;The Gramm-Leach-Bliley, HIPAA, Basel II, Corporate Governance, Identity Theft/SB 1386, ITAR/Export, &amp;nbsp;Control, NASD 2711, Sarbanes-Oxley, Sec 17a-4 and OMB M-06-1.6&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div style="margin:0in 0in 10pt;"&gt;&lt;span style="line-height:115%;font-size:12pt;"&gt;Red Flag enforcement is eminent starting in August 1, 2009. Non-profit entities that defer payment for goods or services&lt;/span&gt; really need to pay attention to be compliant with Red Flag.&amp;nbsp;This is especially critical for those organizations who keep data records on members.&lt;/div&gt;
&lt;div style="margin:0in 0in 10pt;"&gt;&lt;span style="line-height:115%;font-size:12pt;"&gt;Identity theft is off the charts with hostile nations, terrorist organizations and even organized crime seeking to steal personal records. With the economic down turn and mass layoffs, even people on the inside of organizations may become desperate to steal inside information for economic gain.&lt;/span&gt;&lt;/div&gt;
&lt;div style="margin:0in 0in 10pt;"&gt;&lt;span style="line-height:115%;font-size:12pt;"&gt;All organizations should now be as a matter of top down due diligence be reviewing and protecting their sensitive data. The reality is that compliance is very confusing and vendors are leading with&amp;nbsp;fragmented solutions.&lt;/span&gt;&lt;/div&gt;
&lt;div style="margin:0in 0in 10pt;"&gt;&lt;span style="line-height:115%;font-size:12pt;"&gt;Education and awareness are key components in order for organizations to properly identify what data needs to be protected.&lt;/span&gt;&lt;/div&gt;
&lt;div style="margin:0in 0in 10pt;"&gt;&lt;span style="line-height:115%;font-size:12pt;"&gt;This is an area that I help companies out with and would be glad to answer any questions that you may have through education and awareness.&lt;/span&gt;&lt;/div&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>Re: RE: Payment Card Industry Data Security Standard (PCI DSS).</title><link>http://forums.techsoup.org/cs/forums/thread/99172.aspx</link><pubDate>Thu, 21 May 2009 01:02:14 GMT</pubDate><guid isPermaLink="false">caa7681b-025a-49ce-809f-7435bfe4d232:99172</guid><dc:creator>tomas@schweich.com</dc:creator><slash:comments>0</slash:comments><comments>http://forums.techsoup.org/cs/forums/thread/99172.aspx</comments><wfw:commentRss>http://forums.techsoup.org/cs/forums/commentrss.aspx?SectionID=24&amp;PostID=99172</wfw:commentRss><description>&lt;p&gt;So my non-profit, the California Botanical Society, of which I am the volunteer treasurer, was notified by our merchant service provider that we have to complete our self-assessment questionnaire by June 28th.&amp;nbsp; I&amp;#39;ve read the guidance and learned we need only complete questionnaire SAQ B, because we only use a stand-alone dial-out terminal for our few credit card transactions. We keep no member credit card information in any electronic form, but we do have paper order forms, invoices, and credit card machine tapes that have cardholder data on them. &amp;nbsp; Since our &amp;quot;office staff&amp;quot; consists of a volunteer membership person, a volunteer corresponding secretary, and a work-study student, our processes are pretty informal and, of course, not documented in any way.&amp;nbsp; From my first reading, it looks like we need to do the following to become &amp;quot;compliant:&amp;quot;&amp;nbsp; (1) write an Information Security Policy states defines identification, handling, storage and destruction of cardholder data when it is no longer needed, and that we do not accept cardholder data by way of unencrypted e-mail,&amp;nbsp; (2) document that all cardholder data is kept in locked drawers when not in use, (3) verify that the keys that lock the drawers containing cardholder data are unique to our organization, and available only to persons with need to access the data, (4) buy a crosscut shredder to shred the order forms and machine tapes when we no longer need them. &lt;/p&gt;
&lt;p&gt;Some of questions on the questionnaire are a little tricky.&amp;nbsp; It looks like they are worded so that if you say &amp;quot;Yes&amp;quot; to every one, then, Yes, you are compliant. For example, &amp;quot;9.7.2 Is the media sent by secured courier or other delivery method that can be accurately tracked?&amp;quot;&amp;nbsp; the obvious compliant answer would be Yes.&amp;nbsp; However, in our case I would answer, &amp;quot;No, we never send media with cardholder data anywhere.&amp;quot;&amp;nbsp; Truthful, but the wrong answer for the questionnaire.&amp;nbsp; I was hoping for a place to explain answers. Has anyone been through the web form compliance questionnaire, and was there a place for explanations? &lt;/p&gt;
&lt;p&gt;Finally, we have some work to do before we can give compliant answers to all the questions.&amp;nbsp; There is an option to giving truthful, non-compliant answers, and a date by which we can be compliant.&amp;nbsp; For us botanists who should all be out in the field from now until September or so, I&amp;#39;m tempted to say we can be compliant in 9-10 months. But, I wondering if anyone has completed the questionnaire with non-compliant status and a date for compliance, and what was the reaction from your merchant service provider? &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: Payment Card Industry Data Security Standard (PCI DSS).</title><link>http://forums.techsoup.org/cs/forums/thread/89403.aspx</link><pubDate>Wed, 21 May 2008 22:56:00 GMT</pubDate><guid isPermaLink="false">caa7681b-025a-49ce-809f-7435bfe4d232:89403</guid><dc:creator>dmark2</dc:creator><slash:comments>0</slash:comments><comments>http://forums.techsoup.org/cs/forums/thread/89403.aspx</comments><wfw:commentRss>http://forums.techsoup.org/cs/forums/commentrss.aspx?SectionID=24&amp;PostID=89403</wfw:commentRss><description>PSI DSS (Payment Card Industry Data Security Standards) are real.  PCI is an organization founded by the major card brands; Visa, MC, Amex, Disc, and JCB.  Visa and MC have had security standards in place for a while.  Visa called theirs CISP.&lt;br /&gt;
&lt;br /&gt;
You have to comply or your merchant bank (M&amp;amp;T) will report you to PCI.  There are fines and eventually exclusion from access to credit card clearing.  I know this sounds ominous, but move your website to an organization that is PCI compliant.  Let them deal with the compliance issues.</description></item><item><title>RE: Payment Card Industry Data Security Standard (PCI DSS).</title><link>http://forums.techsoup.org/cs/forums/thread/89124.aspx</link><pubDate>Wed, 14 May 2008 15:54:00 GMT</pubDate><guid isPermaLink="false">caa7681b-025a-49ce-809f-7435bfe4d232:89124</guid><dc:creator>admindir1</dc:creator><slash:comments>0</slash:comments><comments>http://forums.techsoup.org/cs/forums/thread/89124.aspx</comments><wfw:commentRss>http://forums.techsoup.org/cs/forums/commentrss.aspx?SectionID=24&amp;PostID=89124</wfw:commentRss><description>The sender of the email appears to be M&amp;amp;T Bank, the bank that I have a merchant account with and they are telling me to call Security Metrics and the cost is about $150-$200 annually.  The email goes on to tell me to check the visa and mastercard websites and I have been there and it is nothing but confusing.  Since processing credit cards via our website is relatively new...since January, we have only processed about $300 that way since January.  We have another merchant account that is in the office and people pay when they come into the office, with their credit card or over the phone.  That merchant account processing is substantially larger at about $8,000 per month.&lt;br /&gt;
&lt;br /&gt;
I appreciate your help.  I will look at wikipedia and see if I understand the whole thing better.&lt;br /&gt;
&lt;br /&gt;
Karen</description></item><item><title>RE: Payment Card Industry Data Security Standard (PCI DSS).</title><link>http://forums.techsoup.org/cs/forums/thread/89060.aspx</link><pubDate>Mon, 12 May 2008 22:22:00 GMT</pubDate><guid isPermaLink="false">caa7681b-025a-49ce-809f-7435bfe4d232:89060</guid><dc:creator>Christian_SEO</dc:creator><slash:comments>0</slash:comments><comments>http://forums.techsoup.org/cs/forums/thread/89060.aspx</comments><wfw:commentRss>http://forums.techsoup.org/cs/forums/commentrss.aspx?SectionID=24&amp;PostID=89060</wfw:commentRss><description>Uh, who is the sender of this email and how much are they charging to check the security of your site?&lt;br /&gt;
&lt;br /&gt;
I found some links in Google about this including a page in &lt;a href="http://en.wikipedia.org/wiki/PCI_DSS" target="_blank" title="http://en.wikipedia.org/wiki/PCI_DSS"&gt;Wikipedia&lt;/a&gt;.</description></item><item><title>Payment Card Industry Data Security Standard (PCI DSS).</title><link>http://forums.techsoup.org/cs/forums/thread/23767.aspx</link><pubDate>Mon, 12 May 2008 19:57:00 GMT</pubDate><guid isPermaLink="false">caa7681b-025a-49ce-809f-7435bfe4d232:23767</guid><dc:creator>admindir1</dc:creator><slash:comments>0</slash:comments><comments>http://forums.techsoup.org/cs/forums/thread/23767.aspx</comments><wfw:commentRss>http://forums.techsoup.org/cs/forums/commentrss.aspx?SectionID=24&amp;PostID=23767</wfw:commentRss><description>I have received an email telling me that I have to have my website checked due to the new security standards that apparantly have been in place since October 2007 (I think).  I have absolutely no idea what they are talking about.  At the time, I was not processing credit cards via my website but am now.  Can anyone tell me anything about this?</description></item></channel></rss>