| The Cardholder Information Security Program (CISP) was originally established by Visa to secure computer systems and data from unauthorized access and loss. From these recommendations evolved a new, industry-wide standard that incorporates much of the CISP and adds additional requirements. This standard is generally referred to as the Payment Card Industry data security standard or, PCI-CISP data security standard.
PCI-CISP is a requirement of private industry that is more stringent than applicable government regulations. Visa has prioritized and defined levels of compliance validation based on the volume of transactions, the potential risk, and exposure introduced into the payment system by merchants and service providers. The penalties for non compliance are severe: If a Visa member fails to immediately notify Visa USA Fraud Control of the suspected or confirmed loss or theft of any Visa transaction information, the member will be subject to a penalty of $100,000 per incident.
Elements of compliance will dovetail with state and federal regulations, such as California Privacy Notification, Sarbanes-Oxley, HIPAA, Gramm Leach Bliley (GLBA), and others.
|