Start using BillSmart
and become instantly
Visa and MasterCard compliant.

and save around
$74,000 in the first 12 months. |
The card schemes have introduced a globally mandated program that focuses on data
security. Account Information Security, or AIS, is a Risk Management program
sponsored by Visa and run by Visas members. Site Data Protection, or SDP, is the
same program sponsored by MasterCard and run by MasterCard's members.
Visa AIS
The AIS standards have been developed to set a minimum standard in the
marketplace with regards to the protection of cardholders sensitive account and
transaction information. Visa expects that most entities that process or store account and
transaction information will already exceed these standards.
Who does AIS apply to?
The AIS program is a requirement for all entities participating in the Visa payment
system i.e. those entities that process, store or transmit Visa cardholder account and/or
transaction information, including merchants, processors and Internet payment service
providers.
What are the AIS requirements?
At a basic level, AIS consists of 15 key requirements for protecting Visa cardholder
account and transaction information:
- Establish a hiring policy for staff and contractors
- Restrict access to data on a need to know basis
- Assign each person a unique ID to be validated when accessing data
- Track access to data, including read access, by each person
- Install and maintain a network firewall, if data can be accessed via the Internet
- Encrypt data maintained on databases or files, accessible from the Internet
- Encrypt data sent across networks
- Protect systems and data from viruses
- Keep security patches for software up-to-date
- Do not use vendor-supplied defaults for system passwords and other security parameters
- Do not leave papers/diskettes/computers with data unsecured
- Securely destroy data when its no longer needed for business reasons
- Regularly test security systems and procedures
- Immediately investigate and report to Visa any suspected loss of Account or Transaction
information
- Use only service providers that meet these security standards.
These requirements are based on ISO (International Standards Organization), ANSI
(American National Standards Institute) standards and industry best practices.
MasterCard SDP
If you are compliant with Visa AIS program, your bank should also issue a compliance
statement for MasterCard.
What do I get ?
BillSmart provides a simple and effective
method of processing recurring payments without the need to store credit card details each
month.
|