July 12, 2010

Visa Data Security Alert – PCI Risks in Outsourced E-Commerce Environments Information Technology

Protiviti Flash Report

The scope of the Payment Card Industry - Data Security Standard (PCI-DSS) covers systems that store, process or transmit cardholder data. In traditional e-commerce architecture, this includes public web servers as well as any back-end infrastructure such as additional web tiers, database servers and network infrastructure supporting transaction processing. Outsourcing web-based shopping carts is a common best practice for reducing PCI scope.