Home > Ask the CIO Experts > Questions & Answers > High risk credit card processing
Ask The CIO Expert: Questions & Answers
EMAIL THIS

High risk credit card processing

Stuart McClure EXPERT RESPONSE FROM: Stuart McClure

Pose a Question
Other CIO Categories
Meet all CIO Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 08 September 2003
What is high risk credit card processing and also outsourced payment processing?

>
E-businesses must ensure business continuity because every minute or hour lost due to downtime means lost and potentially unrecoverable revenue. They must also ensure that the data provided by customers is secure from interception, modification, loss and repudiation.

Credit card processing is the act of taking a credit card number from a cardholder and authorizing it for payment. A company can perform this function in-house or outsource it. The "high risk" part of it comes into play when the systems involved for processing the transaction are compromisable.

Most of the systems involved in credit card processing use a form of point-to-point encryption to make the contents of your credit card secure, however each individual system could be compromised, exposing any decrypted credit card data. And this is where the real risk comes into play. Each point in the link between card swipe to backend database has the potential to be compromised with a vulnerability and then allow an attacker to view the sensitive information.

The keys to strategic security for online payment card processing are:

- Securing end-to-end: Use secure socket layer (SSL) technology
- Securing every point along the stream, from the card swipe device to the backend database
- Educating IT/security managers on best practices and common security pitfalls
- Becoming strategic security by accurately scanning for critical network vulnerabilities on a daily basis, prioritizing the vulnerabilities in terms of risk to your e-business {i.e., anything that if exploited could compromise data or result in a Denial-of-Service (DoS) attack}, then implement the critical patches in a timely fashion, and ensure that the patches are complete -- before an exploit can occur.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Enterprise data security and privacy
GPS devices, geolocation data create privacy, security risks
Health care security, HIPAA compliance on deck for CIOs in Obama era
Network access control: Security advice for enterprise CIOs
Data protection in the cloud: What's good enough?
Healthcare IT standards still not clear
Avoiding gotchas of security tools and global data privacy laws
CIO turns to identity and access management to solve business problem
Data protection quiz for enterprise CIOs
Seven tips to improving enterprise data protection
Employee layoffs pose security risk if systems access not disabled

Enterprise information security management
Leveraging log management for IT and business process efficiency
Information security and risk management guides for CIOs
Talking swine flu and Conficker with the CIO of the CDC
Network access control: Security advice for enterprise CIOs
Evaluating network access control: NAC policy enforcement matters
Enterprise risk management quiz for CIOs
Network access control now addresses multiple needs
Enterprise risk management solutions for CIOs
Gartner: Future IT security jobs to focus on risk management strategy
Avoiding gotchas of security tools and global data privacy laws

IT asset management
Information security and risk management guides for CIOs
GPS devices, geolocation data create privacy, security risks
How CIOs are enabling business activity monitoring with existing tools
Gartner's revised IT spending forecast: Decline exceeds that of 2001
Network access control: A hybrid approach
IT infrastructure tracking software puts CIO in business
IT asset management focus drives Toyota Motorsport
IT security management policies good for the business
CIOs overconfident about protecting intellectual property
Managing mobile computing policies

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



White Papers for the CIO, Application Integration, Data Storage Management, and LAN Management
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2007 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts