01 May 2008
The British Red Cross (BRC) is considering working with other not-for-profit organisations to meet the demands of new credit card data security requirements.
The charity is struggling with the PCI DSS standard, and has blamed banks for not providing sufficient information to help compliance. It has had to reshuffle IT priorities to accommodate the changes, said head of IT Miguel Fiallos.
“Even though we have to meet a deadline, the communication from the merchant banks in relation to what is wanted is very poor,” he said. Fiallos also said he is working with other charities to share the burden for parts of the process such as testing.
The PCI DSS security standard affects any company transmitting, processing or storing credit card information. Compliance is graded, with merchants divided into four different levels based on the number of transactions they process throughout the year.
“If the charity is accepting transactions over the phone or the internet, it will typically need the card number, expiry date and sometimes the three-digit code on the back of the card,” said Steve Wilson, head of policy compliance management at Visa.
“Charities should not be keeping information after the transaction is completed.”
BRC is undergoing tests under the Qualified Security Assessor programme.
Have your say on this article
Newsletters
Latest stories from Services and Outsourcing
Latest videos
You may also like
Services and Outsourcing jobs
Technology Patent Wars
Case studies from large organisations across all sectors
... And rich media, and flexible working, and peaks in traffic ...
Upcoming Events
Join us for this Computing web seminar, in which the Head of BI at the Co-operative Group Nick Colebourn will be explaining just how he reigned in the Group’s sprawling database estate and how significant savings were realised and data quality improved as a result.
Date: 31 May 2012
Time: 11:00 AM
Live June 13th 11:00am: Register now. During this web seminar we will be looking at the sorts of incidents that can bring data centres grinding to a halt and what can be done about them.
Date: 13 Jun 2012
Time: 11:00 am
Receive the latest jobs direct to your inbox
Are you being paid what you are worth?