wisemonkeys logo
FeedNotificationProfileManage Forms
FeedNotificationSearchSign in
wisemonkeys logo

Blogs

Payment Card Industry - Data Security Standard PCI-DSS compliance for online banking applications

profile
67_Ashish Pandey
Oct 20, 2021
0 Likes
0 Discussions
60 Reads

Payment Card Industry - Data Security Standard (PCI-DSS) compliance for online banking applications

Payment Card Industry - Data Security Standard is an abbreviations(PCI-DSS) . Before 2004, major credit card brands such as American Express, MasterCard, Visa, Discover and JSB used to implement their own version of security programme. They collaborated together to create a universally accepted programme to encourage and improve cardholder data security.but due to this lot of data breach had happened cybercriminal activities has taken place .As a universal Standard, any merchant or service provider that stores,processes or transmits cardholder data is required to comply with this standard. Organizations that misses the mark to fulfill are ignored by the clients (after all, it’s all about their date), and those that undergo security breach and are found out to be out of compliant are possibly fined.But in 2006 the five card companies told to make some security standard council(SSC).PCI Security Standards Council (PCI SSC) It is a standarad not a law which set by security standard council in which the set rules or guidelines regarding Payment cards through banking and banking applications in between merchants and clients .where customers can easily make transaction online .In online banking appliactions adequate security testing to ensure card holder data is never compromised.Run controlled data breach attempts against the bank network on regular basis to ensure network, end-point and web application security.Perform security testing to detect well known vulnerabilities like SQL injection, OS command injection, Cross-site scripting, broken authentication etc.Test for the presence of authorized and un-authorized wireless access points on a quarterly basis.Perform penetration testing – white box and black box – on network layer and application layer at least once a year or after a signification change has been made to the application.Scope of penetration testing is the card holder environment (CDE) + systems and networks connected to it (unless the bank has a segmented network in which the CDE is isolated from other systems).Penetration testing should aim to identify all possible threats and vulnerabilities and try to exploit them to penetrate the system both at the application and network level.Issues identified should be corrected and re-tested until all chances of malicious activity are removed

 


Comments ()


Sign in

Read Next

"Audit" In Data Science

Blog banner

Memory Management

Blog banner

WAKE UP ITS FOOD o'CLOCK...!!!!!

Blog banner

CRISP-DM Methodology

Blog banner

Quality check in IT services

Blog banner

Virtual memory

Blog banner

BrainGate Technology

Blog banner

Security in Cloud Computing Environment using cryptography - Rushabh Modi

Blog banner

Charcoal, Lemon, and DIY Kits: Which “Viral” Dental Trends Are Actually Dangerous?

Blog banner

objectives and functions of operating system

Blog banner

MAILFENCE

Blog banner

Big Data

Blog banner

Kernel Modes: User Mode vs. Kernel Mode - 80

Blog banner

Apple

Blog banner

I Personally

Blog banner

10 Interesting Facts about Attack on Titan

Blog banner

VIRTUAL MACHINES

Blog banner

Why Every Preschooler Learns at Their Own Pace?

Blog banner

PHISHING

Blog banner

Cyber Forensics in Healthcare: Protecting Patient Data and Preventing Breaches

Blog banner

Install Ubuntu Easily

Blog banner

The Power of Cyber Forensic in Solving Crimes

Blog banner

Instagram

Blog banner

The Rise of Polo Tourism in the USA: How Travellers Are Blending Luxury Stays with Elite Sports

Blog banner

Wrike

Blog banner

Strengthening Active Directory Security

Blog banner

Direct Memory Access

Blog banner

Is Pursuing a Dance Career in India Worth it?

Blog banner

Mutual exclusion

Blog banner

ASANA- A Management System.

Blog banner

Healthy Habits Children Learn at Preschool That Last a Lifetime

Blog banner

internet email and it's applications

Blog banner

Service Validation and Testing during the Design Phase

Blog banner

Virtual Machine

Blog banner

Deadlock and Starvation

Blog banner

Understanding Input Based Keylogger Activation Systems: Risks and Mitigation

Blog banner

Study on cyber and network forensic in computer security management

Blog banner

Indian Culture and Tradition

Blog banner

Mobile Survey

Blog banner

IT Service Continuity Management

Blog banner

Data-Driven Prediction of Virtual Item Prices in Online Games

Blog banner

EVOLUTION OF THE MIRCOPROCESSOR

Blog banner