Skip to main content

PCI DSS Compliance and Certification

PCI DSS Adaptation and Certification

The PCI Data Security Standard (PCI DSS) is a security standard that defines the set of requirements to manage security, define security policies and procedures, network architecture, software design and all types of protection measures involved in the handling, processing or storage of credit card information. Its purpose is to reduce fraud related to payment cards and increase the security of this data.

PCI DSS is the result of the efforts of the PCI Security Standards Council (PCI SSC), formed by the main payment card issuers (Visa, Mastercard, American Express, JCB and Discover), to enforce and support merchants, service providers and banks in reducing the risk of credit card fraud by protecting the infrastructures that process, transmit or store credit card data.

Any organization that is involved in the processing, transmission or storage of payment card information is affected by the requirements established by PCI DSS.

PCI DSS classifies these organizations as merchants (super/hypermarkets, highways, e-commerce, travel agencies, etc.), service providers (ISP/ASP, payment gateways, card manufacturers, card delivery services, transaction processors, etc.) and financial entities or acquirers (banks, savings banks, credit institutions, etc.).

Internet Security Auditors, with its experience in information security consulting and auditing, is able to help all organizations that are required to define and maintain a compliance program with the requirements demanded by both PCI DSS and PCI SSF, being the first Spanish company to obtain the accreditations (QSA, SSA, ASV, QPA and CPSA) and the only one with presence in Spain and Colombia with the ability to carry out comprehensive PCI DSS and PCI SSF Adaptation and Certification processes in Europe, Latin America and the USA.

 

PCI DSS Adaptation Process

Compliance Analysis and Action Plan

The first step to comply with the PCI DSS requirements is to carry out an analysis of the organization, identify the points in the value chain where payment card information is transmitted, processed or stored and define the environment that must be protected to comply with PCI DSS.

Once this environment has been identified, the risks must be assessed and the compliance program defined, which establishes and maintains the necessary security measures to meet the 12 requirements defined in the standard.

Internet Security Auditors, with its implementation consulting service, aims to provide organizations with all the necessary support and guide them in defining and maintaining the compliance program with PCI DSS.

Learn more

Implementation of Requirements for Adaptation

The Implementation of Requirements for Adaptation executes the compliance program for the non-conformities detected in previous phases, carrying out consulting and advisory activities in any task that must be developed in order to achieve compliance with PCI DSS.

Learn more

PCI DSS Compliance Certification Audit

Internet Security Auditors is accredited by the PCI SSC, through its QSA certificate, to carry out annual on-site audits for all those companies that, due to their annual transaction volume (which varies depending on the credit card brand), require it, having become the first Spanish company to obtain this certification from the PCI SSC. In the audit process, it is verified, by sampling, that the requirements established in PCI DSS are being met. And for all those points that are not met, an action plan is defined to solve the non-conformities.

Learn more

PCI DSS Technical Office (OTP)

As indicated by the PCI SSC in the “Best practices for implementing PCI DSS into business-as-usual processes” of the current version of the standard, complying with PCI DSS does not end with its implementation but implies continuous management of compliance. Internet Security Auditors, through its PCI DSS Technical Office (OTP), offers its clients a service to provide continuity and guarantee the maintenance of compliance with the standard in a practical and effective way, integrated into technological and security operations.

Learn more

Self-Assessment Questionnaire (SAQ)

For all those companies that are not required to perform annual on-site audits, Internet Security Auditors provides a support service for the preparation of the self-assessment questionnaire, previously carrying out a review of the current compliance status with the requirements established by PCI DSS.

Learn more

Quarterly ASV Vulnerability Scans

The execution of quarterly external vulnerability scans by certified ASV providers is one of the requirements established by PCI DSS in section 11.2 with the aim of regularly verifying the security of systems, processes and applications. Internet Security Auditors, thanks to its extensive experience in conducting penetration tests, has passed the necessary tests and obtained ASV certification from the PCI SSC, being able to perform these vulnerability analyses for all those companies that require them as part of their PCI DSS compliance program.

Learn more

Qué opinan nuestros clientes


Do not hesitate to contact us if you need more information

Send us your questions and we will contact you as soon as possible.

Por favor, introduzca un número de teléfono válido.
CAPTCHA
Esta pregunta es para comprobar si usted es un visitante humano y prevenir envíos de spam automatizado.