1 CommDoo GmbH your Payment Service Provider | Payment Card Industry | Glossary
CommDoo Glossary

Inform yourself
Contact us now

CommDoo Glossary

Inform yourself

Contact us now
Glossary
What do the technical terms mean
Search by Alphabet
Search here for your desired search term
Payment does not have to be complicated. However, there are technical terms that are often not common.
Can we help you
In the upper search bar you can choose between two search options. The search by category and the search by alphabet. Just click on the navigation button above the selection. If you need further information, please contact us. We look forward to hearing from you.

You have not found an entry
Then do not hesitate and contact us. We make every effort to answer all questions as quickly as possible and to keep our glossary up to date in order to provide you with the greatest possible amount of information.
Payment Card Industry
PCI is a globally valid, strict standard for technical, legal and organizational data security. The credit card organizations (e.g. VISA, MasterCard) have developed a uniform, global security and auditing standard called "Payment Card Industry (PCI) Data Security Standard".
PCI testing
PCI is a standard developed from the Visa Account Information Security Program (AIS/CISP), Mastercard Site Data Protection Program (SDP), American Express Security Operating Policy (DSOP), Discover Information Security and Compliance (DISC), and JCB Security Rules. Businesses seeking certification must use a service provider approved by the credit card organizations for PCI testing and certification. Depending on the business model and number of transactions, certification requirements such as self-inspection, self-disclosure and network investigation are repeated annually.
Das PCI Zertifikat
To be able to obtain the PCI certificate, the following regulations must be complied with:

 

  • Installation and maintenance of a firewall to protect data.
  • Changing passwords and other security settings after factory shipment.
  • Protecting the stored data of credit card holders.
  • Encrypted transmission of sensitive data of credit card holders in public computer networks.
  • Use and regular update of anti-virus programs.
  • Development and maintenance of secure systems and applications
  • Restrict data accesses to what is necessary
  • Assigning a unique user ID for each person with computer access.
  • Restricting physical access to credit cardholder data.
  • Logging and auditing all access to credit cardholder data.
  • Regular audits of all security systems and processes
  • Implement and adhere to policies related to information security.