<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: PCI Compliance for Magento</title>
	<atom:link href="http://www.blueacorn.com/magento-blog/pci-compliance-for-magento/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.blueacorn.com/magento-blog/pci-compliance-for-magento/</link>
	<description>Blue Acorn is an eCommerce Consulting Firm specializing in helping online retailers increase sales, profitability, and ROI through eCommerce Services.</description>
	<lastBuildDate>Mon, 23 Jan 2012 14:51:57 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Anon</title>
		<link>http://www.blueacorn.com/magento-blog/pci-compliance-for-magento/comment-page-1/#comment-225040</link>
		<dc:creator>Anon</dc:creator>
		<pubDate>Thu, 19 May 2011 20:22:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.blueacorn.com/?p=1101#comment-225040</guid>
		<description>Any insight into how the integration of Authorize.Net DPM impacts achieving PCI compliance with Magento?</description>
		<content:encoded><![CDATA[<p>Any insight into how the integration of Authorize.Net DPM impacts achieving PCI compliance with Magento?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Garth Brantley</title>
		<link>http://www.blueacorn.com/magento-blog/pci-compliance-for-magento/comment-page-1/#comment-151087</link>
		<dc:creator>Garth Brantley</dc:creator>
		<pubDate>Sat, 19 Feb 2011 21:41:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.blueacorn.com/?p=1101#comment-151087</guid>
		<description>Hi Kevin, I have to say this is one of the most complete (and also clear) articles about Magento and PCI Compliance I have come across.</description>
		<content:encoded><![CDATA[<p>Hi Kevin, I have to say this is one of the most complete (and also clear) articles about Magento and PCI Compliance I have come across.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrick Pitman</title>
		<link>http://www.blueacorn.com/magento-blog/pci-compliance-for-magento/comment-page-1/#comment-149837</link>
		<dc:creator>Patrick Pitman</dc:creator>
		<pubDate>Thu, 17 Feb 2011 18:25:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.blueacorn.com/?p=1101#comment-149837</guid>
		<description>A follow-up to my comment a moment ago: 

My background is that I spent the last decade building a company around a proprietary ecommerce turnkey hosted package (catalog, cart, CMS, email, etc) for niche merchants in US and UK. After a security breach in &#039;06, we underwent a VISA mandated audit and were later called the &#039;posterchild for how to handle a PCI incident&#039; by Discover card. Our system then earned Payment Gateway Level 1 PCI cleared status by auditor SecurityMetrics, after much pain and gnashing of teeth.  I&#039;m no longer running that business; now a consultant helping others on special assignment. Which is the long way of saying, I&#039;m interested in this topic.

One detail about PCI:  the compliance standard is the same regardless of transaction volume, same for all merchants. If you&#039;re a small merchant, your reporting / certification requirements are less, but your responsibility is the same. Your obligation / potential fines / accountability is the same.  Which is why what Kevin and Greg says about encouraging your website to handle card payments in a way that puts it &quot;out of PCI scope&quot; is attractive.</description>
		<content:encoded><![CDATA[<p>A follow-up to my comment a moment ago: </p>
<p>My background is that I spent the last decade building a company around a proprietary ecommerce turnkey hosted package (catalog, cart, CMS, email, etc) for niche merchants in US and UK. After a security breach in &#8216;06, we underwent a VISA mandated audit and were later called the &#8216;posterchild for how to handle a PCI incident&#8217; by Discover card. Our system then earned Payment Gateway Level 1 PCI cleared status by auditor SecurityMetrics, after much pain and gnashing of teeth.  I&#8217;m no longer running that business; now a consultant helping others on special assignment. Which is the long way of saying, I&#8217;m interested in this topic.</p>
<p>One detail about PCI:  the compliance standard is the same regardless of transaction volume, same for all merchants. If you&#8217;re a small merchant, your reporting / certification requirements are less, but your responsibility is the same. Your obligation / potential fines / accountability is the same.  Which is why what Kevin and Greg says about encouraging your website to handle card payments in a way that puts it &#8220;out of PCI scope&#8221; is attractive.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Patrick Pitman</title>
		<link>http://www.blueacorn.com/magento-blog/pci-compliance-for-magento/comment-page-1/#comment-149835</link>
		<dc:creator>Patrick Pitman</dc:creator>
		<pubDate>Thu, 17 Feb 2011 18:22:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.blueacorn.com/?p=1101#comment-149835</guid>
		<description>Hi Kevin, I second David&#039;s question:  what update on CyberSource&#039;s Silent Order Post option and Magento? You mentioned it was in Magento&#039;s roadmap. But ought not a company like yours be able to develop an extension to make it work anyway? Do you have client projects like this that you could elaborate upon?

Hi Andy, I would like to talk with you more about your experiences. I&#039;m working on a UK project where retailer is also using Barclays and I&#039;m interested in setting up a Magento system with payment tokenisation (possibly CyberSource, but you mention Sage Pay?). Your mention of Ebizmarts extension was helpful. Might you contact me at patrick @ e-business coach dot com ?</description>
		<content:encoded><![CDATA[<p>Hi Kevin, I second David&#8217;s question:  what update on CyberSource&#8217;s Silent Order Post option and Magento? You mentioned it was in Magento&#8217;s roadmap. But ought not a company like yours be able to develop an extension to make it work anyway? Do you have client projects like this that you could elaborate upon?</p>
<p>Hi Andy, I would like to talk with you more about your experiences. I&#8217;m working on a UK project where retailer is also using Barclays and I&#8217;m interested in setting up a Magento system with payment tokenisation (possibly CyberSource, but you mention Sage Pay?). Your mention of Ebizmarts extension was helpful. Might you contact me at patrick @ e-business coach dot com ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Andy</title>
		<link>http://www.blueacorn.com/magento-blog/pci-compliance-for-magento/comment-page-1/#comment-144311</link>
		<dc:creator>Andy</dc:creator>
		<pubDate>Tue, 08 Feb 2011 00:19:28 +0000</pubDate>
		<guid isPermaLink="false">http://www.blueacorn.com/?p=1101#comment-144311</guid>
		<description>In the UK, Sage Pay offer a token system that allows you to keep the customer on your site yet store no restricted credit card data (except momentarily in memory). This still allows you to store last 4 digits of the PAN, the card type and expiry date, so you can operate a &#039;saved cards&#039; feature.

Ebizmarts are coming close to launching an extension that will integrate all this in Magento - its pretty neat!

My understanding is that this setup is liable for SAQ-C if you take a strict interpretation of PCI. Roughly, this means you need to know what you are doing, but you can avoid the whole two separate server deal (SAQ-D).

Security Metrics, working for Barclays who are my merchant services provider, assure me this is SAQ-A, ie simple. It is important to note though that noone at Barclays or SM seem to have a clue about token, and at the end of the day the merchant (not either of them, no matter what advice they provide) is responsible if anything happens (like a server and therefore cardholder data being compromised) so we shall go for SAQ-C I think...</description>
		<content:encoded><![CDATA[<p>In the UK, Sage Pay offer a token system that allows you to keep the customer on your site yet store no restricted credit card data (except momentarily in memory). This still allows you to store last 4 digits of the PAN, the card type and expiry date, so you can operate a &#8217;saved cards&#8217; feature.</p>
<p>Ebizmarts are coming close to launching an extension that will integrate all this in Magento &#8211; its pretty neat!</p>
<p>My understanding is that this setup is liable for SAQ-C if you take a strict interpretation of PCI. Roughly, this means you need to know what you are doing, but you can avoid the whole two separate server deal (SAQ-D).</p>
<p>Security Metrics, working for Barclays who are my merchant services provider, assure me this is SAQ-A, ie simple. It is important to note though that noone at Barclays or SM seem to have a clue about token, and at the end of the day the merchant (not either of them, no matter what advice they provide) is responsible if anything happens (like a server and therefore cardholder data being compromised) so we shall go for SAQ-C I think&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: David</title>
		<link>http://www.blueacorn.com/magento-blog/pci-compliance-for-magento/comment-page-1/#comment-119401</link>
		<dc:creator>David</dc:creator>
		<pubDate>Fri, 31 Dec 2010 06:55:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.blueacorn.com/?p=1101#comment-119401</guid>
		<description>Thanks Kevin, this has been the easiest article to read through and understand the options available in Magento.  I currently use Cybersource SOAP and am interested in knowing more about the Silent Order POST.</description>
		<content:encoded><![CDATA[<p>Thanks Kevin, this has been the easiest article to read through and understand the options available in Magento.  I currently use Cybersource SOAP and am interested in knowing more about the Silent Order POST.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Luke</title>
		<link>http://www.blueacorn.com/magento-blog/pci-compliance-for-magento/comment-page-1/#comment-83554</link>
		<dc:creator>Luke</dc:creator>
		<pubDate>Fri, 05 Nov 2010 04:14:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.blueacorn.com/?p=1101#comment-83554</guid>
		<description>that really helps, thanks I think I will be staying with a PayPal gateway till I get bigger after reading that.  Kinda related question, any recommends for problem solving using Website Payment Pro- PayPal integration and Magento CE 1.4.2.0-beta1  ?  having issues and I have waded through the Magento Forum with no love. Appreciate your knowledge, direction and help.</description>
		<content:encoded><![CDATA[<p>that really helps, thanks I think I will be staying with a PayPal gateway till I get bigger after reading that.  Kinda related question, any recommends for problem solving using Website Payment Pro- PayPal integration and Magento CE 1.4.2.0-beta1  ?  having issues and I have waded through the Magento Forum with no love. Appreciate your knowledge, direction and help.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kevin</title>
		<link>http://www.blueacorn.com/magento-blog/pci-compliance-for-magento/comment-page-1/#comment-59055</link>
		<dc:creator>Kevin</dc:creator>
		<pubDate>Fri, 10 Sep 2010 16:24:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.blueacorn.com/?p=1101#comment-59055</guid>
		<description>Hi Fred, we&#039;re actually working on a project right now integrating MOM with Magento so we could certainly shed some insight into that process.  But in regards to PCI compliance, if you are transmitting any kind of credit card information, there are going to be very strict standards whereby the entire process, from capturing the credit card to storing it in MOM will be held to PCI compliance regulations.  There are also third party tools that can provide a token that you can actually use in Magento and MOM and use that as a reference to the transaction as an option.</description>
		<content:encoded><![CDATA[<p>Hi Fred, we&#8217;re actually working on a project right now integrating MOM with Magento so we could certainly shed some insight into that process.  But in regards to PCI compliance, if you are transmitting any kind of credit card information, there are going to be very strict standards whereby the entire process, from capturing the credit card to storing it in MOM will be held to PCI compliance regulations.  There are also third party tools that can provide a token that you can actually use in Magento and MOM and use that as a reference to the transaction as an option.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Fred</title>
		<link>http://www.blueacorn.com/magento-blog/pci-compliance-for-magento/comment-page-1/#comment-59054</link>
		<dc:creator>Fred</dc:creator>
		<pubDate>Fri, 10 Sep 2010 16:17:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.blueacorn.com/?p=1101#comment-59054</guid>
		<description>We use Mail Order Manager and are looking at options for our online shopping cart (We currently use Sitelink) Do any of the solutions above allow you to import the cc and authorization information into MOM?</description>
		<content:encoded><![CDATA[<p>We use Mail Order Manager and are looking at options for our online shopping cart (We currently use Sitelink) Do any of the solutions above allow you to import the cc and authorization information into MOM?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Greg McGraw</title>
		<link>http://www.blueacorn.com/magento-blog/pci-compliance-for-magento/comment-page-1/#comment-56497</link>
		<dc:creator>Greg McGraw</dc:creator>
		<pubDate>Fri, 03 Sep 2010 14:24:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.blueacorn.com/?p=1101#comment-56497</guid>
		<description>Thanks for the CRE Secure mention in #2, but I wanted to just clarify the &#039;downside&#039;. Actually, CRE Secure private labels part of the redirected domain for free (blueacorn.cresecure.net) but can also completely private label the URL (ie., payments.blueacorn.com) by hosting the subdomain DNS in our PCI data center, for a small fee. Larger enterprise clients demand it. Alo, I appreciate your &#039;straight talk&#039; description of the challenges of managing your own PCI compliance.  The cost of PCI hosting (2 servers min.) is too often not highlighted and frankly represents the largest cost component.  We, along with many industry analysts now, are strong proponents of outsourced payment acceptance mostly because it reduces the business risk associated with a breach along with cost, and not just because it delivers compliance.</description>
		<content:encoded><![CDATA[<p>Thanks for the CRE Secure mention in #2, but I wanted to just clarify the &#8216;downside&#8217;. Actually, CRE Secure private labels part of the redirected domain for free (blueacorn.cresecure.net) but can also completely private label the URL (ie., payments.blueacorn.com) by hosting the subdomain DNS in our PCI data center, for a small fee. Larger enterprise clients demand it. Alo, I appreciate your &#8217;straight talk&#8217; description of the challenges of managing your own PCI compliance.  The cost of PCI hosting (2 servers min.) is too often not highlighted and frankly represents the largest cost component.  We, along with many industry analysts now, are strong proponents of outsourced payment acceptance mostly because it reduces the business risk associated with a breach along with cost, and not just because it delivers compliance.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

