CISP-PCI
Home > Financial Services Information Security Definitions - CISP-PCI
SearchFinancialSecurity.com Definitions (Powered by WhatIs.com)
EMAIL THIS
LOOK UP TECH TERMS Powered by: WhatIs.com
Search listings for thousands of IT terms:
Browse tech terms alphabetically:
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #

CISP-PCI


Show me everything on PCI DSS: Audits and requirements


Word of the Day


DEFINITION -

CISP (Cardholder Information Security Program) and PCI (Payment Card Industry Data Security Standard) are specifications developed and used by credit card companies for the purpose of ensuring and enhancing the privacy and security of financial data.

CISP was authored by Visa USA and mandated in 2001. The requirements of CISP apply to all enterprises that handle Visa cardholder information and payment channels, including:

  • Brick-and-mortar transactions
  • Mail-order transactions
  • Telephone transactions
  • Online transactions

PCI, mandated under CISP in 2004 and co-developed by Visa USA and MasterCard, defines an expanded set of requirements for the protection of credit-card information, including encryption, access control, physical security and operational audits. This standard requires that public networks and Web sites be tested frequently and regularly for compliance by a certified auditor.

Learn more about PCI DSS: Audits and requirements
Download presentations from Financial Information Security Decisions 2009: Download a number of the compelling presentations from the 2009 Financial Information Security Decisions conference.
Financial Information Security Decisions 2008: Presentation downloads: Download a number of the fascinating presentations from the 2008 Financial Information Security Decisions conference.
PCI DSS: Writing an information security policy: The final set of PCI requirements relates to maintaining a security policy, and also addresses awareness training, personnel screening and managing service provider relationships.
PCI DSS requirement: Monitoring and testing security: The fifth focus area of PCI-DSS requires regular monitoring of systems and activity, as well regular testing of controls.
Vendor audit and monitoring contractual rights: Third-party contracts must include vendor auditing and vendor monitoring rights.

LAST UPDATED: 17 Jan 2008

Do you have something to add to this definition? Let us know.
Send your comments to techterms@whatis.com

More resources from around the web:
- Visa USA provides an overview of CISP.
- A printable version of PCI can be downloaded from Visa USA.





FILE EXTENSION AND FILE FORMAT LIST
File Extension and File Format List:
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z #


RELATED CONTENT
Vendor contract management: Regulatory guidance is risk-based
Financial-services firms are subject to many requirements for managing vendor information security risks by contract. Learn how regulatory guidance is...
Vendor audit and monitoring contractual rights
Third-party contracts must include vendor auditing and vendor monitoring rights.
RBS WorldPay agrees to market VeriFone end-to-end encryption
Payment processor will promote VeriFone's technology for end-to-end encryption of payment card data to its merchants.




CISP-PCI White Papers by Financial Security Experts
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts