|
Capita achieves another landmark security standard The new PA-DSS validation will give customers using Capita Software Services’ site-based solutions the same high level of assurance that is already in place for users of its PCI DSS certified managed service. Validation applies to those Payment Management applications that are customer-hosted and used to take payments by credit or debit card when used in conjunction with our Secure Bureau Service (SBS), in which instance no card details are retained on the customer’s own site. Managed by the Payment Card Industry Security Standards Council (PCI SSC), PA-DSS is designed to provide the definitive data security standard for software vendors developing payment applications and includes measures such as ensuring that secure data such as PIN, Card Security Code or magnetic stripe data is not stored. Further information about PA-DSS is available on the PCI SSC website at https://www.pcisecuritystandards.org, where there is a useful FAQ section. Whilst the Payment Card Industry Data Security Standard (PCI DSS) relates to an organisation’s compliance with processes and procedures around card processing, PA-DSS concentrates on the actual payment application. Visa is currently promoting a programme whereby merchants will need to move towards use of PA-DSS compliant software, which is to become mandatory in the USA from July 2010. To achieve PA-DSS validation, users of alternative supplier solutions which demand that card data is held on-site are likely to incur the overhead of managing third-party data encryption software, as well as all the other responsibilities associated with on-site card processing such as management of specialist software, hardware and infrastructure. We are also pleased to announce that our Managed Service solutions (primarily Internet Payments, Touch Tone and Mail Order Telephone Order (MOTO) payments), which first received official Payment Card Industry Data Security Standard (PCI DSS) Level 1 certification in 2007, were successfully re-certified in November 2008. These two announcements clearly demonstrate how Capita remains well ahead of other providers of card processing solutions. For more information about Capita Payment Management, please visit: http://www.capita-software.co.uk/products/paymentmanagement.html |