Business Services Industry

Covestic Earns Visa QDSC Status; Now Formally Qualified to Perform PCI Data Security Assessments for Merchants and Service Providers

Business Wire, March 21, 2006

KIRKLAND, Wash. -- Covestic is pleased to announce that Visa USA has named it a Qualified Data Security Company (QDSC). This identifies Covestic as having met Visa's requirements to perform Payment Card Industry (PCI) data security assessments for merchants and service providers who store, process, or transmit payment card data.

When consumers offer their credit or bank card information, they want assurance that their account information is safe. For that reason, Visa USA instituted the Cardholder Information Security Program (CISP) that endorses the PCI data security standard to protect Visa USA cardholder data -- wherever it resides -- and ensures that members, merchants, and service providers handling that data maintain the highest information security standard. Other payment card brands have endorsed the PCI data security standard under their own cardholder security programs.

Covestic now offers merchants and service providers PCI data security assessments for PCI compliance, combined with Covestic's security and business risk management expertise.

--Baseline Compliance Assessment. Covestic's baseline PCI compliance assessment evaluates our client's current level of compliance with the PCI data security standards. Covestic assesses the processes and operations to identify possible data security vulnerabilities. Automated, remote security scanning services and in-depth assessments to validate compliance are also available.

--Control Gap Analysis. Covestic analyzes the results of the baseline compliance assessment and then provides an initial risk assessment to facilitate the management and measurement of ongoing PCI compliance.

--Planning and Roadmap Development. Covestic will build a compliance roadmap and timeline that clearly identify the steps necessary for our client to achieve and maintain PCI compliance. Applying industry best-practices and a structured project management approach, Covestic enables its clients to develop a customized compliance plan.

--Control Design, Implementation, and Remediation. With years of experience in I.T information security and privacy controls for Fortune 500 companies, Covestic is uniquely qualified to ensure on-time, on-budget, and on-target implementation programs for those clients who do not choose to do the work themselves.

--Validation. Following control implementation and remediation, Covestic conducts security and privacy verification to prepare merchant and service provider organizations to pass PCI audits.

Covestic provides flexible options to meet the individual needs of our clients. For more information on Covestic's PCI services, call 425-803-9889 or send e-mail to: pci@covestic.com.

About PCI Compliance

PCI compliance is required of all merchants and service providers who perform credit card transactions that involve the handling, storing, and transmitting of cardholder data. The program applies to all payment channels, including retail, mail/telephone order, and e-commerce. Merchants and service providers must adhere to the payment card industry (PCI) data security standard, which offers a single approach to safeguarding sensitive data for all card brands. Using the PCI data security standard as its framework, major card brands' security programs, such as the Visa USA Cardholder Information Security Program provide the tools and measurements needed to protect against cardholder data exposure, security risks, and compromise across the entire payment industry.

About the Visa USA Cardholder Information Security Program

Separate and distinct from the mandate to comply with CISP requirements is the validation of compliance. Validation is a fundamental and critical function that identifies and corrects vulnerabilities, and protects customers by ensuring that appropriate levels of cardholder information security are maintained. All Visa USA merchants and service providers are required to validate compliance with CISP and the PCI data security standard.

About Covestic

Covestic is a leading business and I.T. consulting firm delivering industry-leading expertise and solutions that address the operational challenges of businesses. These solutions include securing I.T. infrastructures, achieving and maintaining regulatory and standards compliance, improving operational efficiency, increasing infrastructure capacity and scalability, optimizing business process management, reducing costs through optimization of operations and technology, securing wireless and remote management systems, and developing business and I.T. scorecard metrics. Covestic is committed to delivering technology solutions that enable clients to achieve their core business objectives at both strategic and tactical levels. For more information, visit the company's Web site at http://www.covestic.com.

COPYRIGHT 2006 Business Wire
COPYRIGHT 2008 Gale, Cengage Learning

 

BNET TalkbackShare your ideas and expertise on this topic

Please add your comment:

  1. You are currently: a Guest |
  2.  

Basic HTML tags that work in comments are: bold (<b></b>), italic (<i></i>), underline (<u></u>), and hyperlink (<a href></a)

advertisement
advertisement
  • Click Here
  • Click Here
  • Click Here
  • Click Here
advertisement

Content provided in partnership with Thompson Gale