Innovative Control Systems
PCI DSS Compliance Program

 

PCI DSS The Process The SolutionWhy ICS?PCI Resources

The ICS/Perimeter eSecurity Program

ICS has done an exhaustive search for the right e-security organization to deliver PCI compliance services for our Level 4 merchants.

Perimeter e-Security logo

ICS has partnered with Perimeter e-security because we feel they possess:

  • Unrivaled knowledge and experience

  • PCI Security Council credentials (as both an ASV and QSV)

  • Comprehensive testing and reporting tools

  • A simple, cost-effective deployment approach

How The ICS Program Works

ICS will handle the necessary remediation to your system in order to achieve PCI compliance. Necessary certifications for your sponsoring bank, card processor and all card brands are kept on file, along with supporting evidence.

  • 1st Year Subscription (program start-up)

    • Installation of a scanning hardware device into your site computer network; this is a simple plug-and-play device that can be easily inserted by non-technical staff. The device remains active at all times, but does not interfere with your network or external communications devices.
    • ICS/Perimeter conduct necessary internal and external scans quarterly to detect vulnerabilities, and remediate those vulnerabilities until “passing” scans are achieved.
    • Perimeter provides an on-line SAQ form that is fully editable until submission. ICS will provide appropriate help forms and policy guidelines to help merchants complete the SAQ.
    • The combination of passing scans and a completed SAQ constitute PCI compliance, which Perimeter will document and convey to the merchant in whatever form is required by their processor and/or sponsoring bank. If neither organization requires validation documentation, Perimeter will nonetheless retain all the forms and scan results for 3 years to support future information requests.
    • Quarterly scans will be conducted to confirm ongoing compliance, but the SAQ remains valid for a full year from date of submission.
  • Subsequent Yearly Subscription

    The scanning hardware device will remain in service, and should have a useful life of several years, depending on environment. Only the scanning, remediation and SAQ support service fees apply after the first year.



PCI-Security Standards Council Participating Organization
Common Myths Of PCI DSS Compliance.

VISA Targets Level 4 Merchants

“Now Visa is turning its attention to its smallest, or Level 4, merchants— those that generate fewer than 20,000 Visa ecommerce transactions or 1 million total Visa transactions annually. In May [2010], Visa distributed a bulletin to its 270 merchant acquirers saying they had until July 31 to submit plans on how they intend to bring their Level 4 merchants into PCI complance.”

- [Google News Item]

Costs of Breach Rising

“Web-borne attacks, malicious code, and malicious insiders are the most costly types of attacks, making up more than 90 percent of all cybercrime costs per organization per year: A Web-based attack costs $143,209; malicious code, $124,083; and malicious insiders, $100,300”

- [The Ponemon Institute Jul 26, 2010]