| Do you store sensitive credit card data on your | | | | effort, and money to stay compliant and up-to-date |
| company's own internal system? If so, are you | | | | with current security measures. This also implies a |
| absolutely certain that it is sufficiently protected? And | | | | need for constant monitoring and management and a |
| are you really sure that you understand the | | | | plan of action in case you do detect suspicious |
| consequences of suffering a security breach? | | | | activities or a full security breach. |
| The unfortunate thing is that many companies, even | | | | The unfortunate truth is that in the daily grind of |
| large national chains, are not properly guarded or | | | | regular business, many companies simply don't have |
| prepared for the consequences of insufficient | | | | the time or resources to devote to data security |
| security. These companies have spent millions of | | | | that are, in truth, very necessary. |
| dollars to implement security measures and still they | | | | The major benefit of remote storage, then, is that |
| suffer breaches. | | | | you are trusting this information to a company |
| New solutions were needed to cover some of the | | | | whose business is making sure that it all remains safe. |
| loopholes that had a tendency to crop up in | | | | Nothing else gets in the way of securing their |
| conventional security methods. Remote storage of | | | | systems because their entire business depends on |
| credit card data is one of the easier and more | | | | effectively guarding your sensitive information. |
| obvious choices for data security. | | | | Now consider all the other ways that sensitive |
| Remote storage of credit card data is also a great | | | | information can be compromised on your own |
| way to meet PCI compliance. The PCI DSS (Payment | | | | system. Remember, threats don't just come from |
| Card Industry Data Security Standard) was | | | | outside your company. It only takes a single, ethically |
| developed to help guide companies in their efforts | | | | questionable employee on the inside to cause a lot of |
| toward implementing sufficient security. Now any | | | | problems. |
| company that processes, stores, or transmits credit | | | | There are a couple of requirements in the PCI DSS |
| card information is required to become PCI compliant, | | | | that were created to deal with this very issue. For |
| but this process can be a time consuming and costly | | | | example, the seventh requirement states that you |
| procedure. But remote storage of credit card data is | | | | must "restrict access to cardholder data by business |
| one solution to a number of the PCI DSS | | | | need-to-know", and the ninth requirement mandates |
| requirements. | | | | that you "restrict physical access to cardholder data." |
| The first and most obvious benefit to remote | | | | In any given company there are some specific people |
| storage of credit card data is the simple fact that | | | | who need access to this sensitive information. But |
| criminals can't steel something from you that you | | | | unfortunately, in many given companies, many |
| don't actually have. No matter what security measure | | | | unnecessary people have access to this information. |
| you implement, chances are there's someone out | | | | And should any of those people happen to have |
| there just a couple steps ahead of all the current | | | | criminal inclinations, you could be in a lot of trouble. |
| security systems. In these cases, they find little holes | | | | These are the people who have physical access to |
| in the system and, if you aren't on constant guard, | | | | your systems, and these are the people who are |
| they'll get in and cause some serious damage. But if | | | | most likely to find or steal encryption keys. |
| there's nothing there for them to take, there's no | | | | Remote storage of credit card data is a simple way |
| reason for them to stick around. | | | | to remove this sensitive information from the prying |
| Which brings up another benefit to remote storage | | | | eyes and reaching hands of people who should not |
| systems. If you're going to store and manage | | | | have it. It is possibly one of the best ways to ensure |
| sensitive information on your own system then you | | | | data security and get closer to PCI compliance. |
| must be prepared to spend all the necessary time, | | | | |