16
8. HANDLING CARDHOLDER INFORMATION
SECURELY & PCI DSS
You are responsible for the security of all cardholder and transaction information you
receive, process or store.
Businesses store credit card details for various purposes. While sometimes this is
necessary to support legitimate business practices, storage of card data can lead to theft
of customer information and signicant impact to your business. ANZ recommends that
card data is never stored on your systems.
If your business accepts MOTO (Mail Order/Telephone Order), eCommerce, Pre-
Authorisation or Manual transactions, you must ensure all cardholder data and
transaction records are received, processed and stored in compliance with the Payment
Card Industry Data Security Standard (PCI DSS).
If you need to process MOTO or eCommerce or transactions regularly, talk to ANZ about
our secure eCommerce payment solutions. Using a secure eCommerce solution, like a
Bank-hosted payment page or PCI-compliant payment gateway, can remove most of the
requirements for your business to store or handle card data directly, ensuring enhanced
security for your business.
8.1 PCI DSS – PAYMENT CARD INDUSTRY
DATA SECURITY STANDARD
The PCI DSS is a global security standard developed by Visa®, MasterCard®, AMEX and
other card schemes to ensure consistent security standards for all organisations that
store, process or transmit Cardholder information. Visa® and MasterCard® require all ANZ
merchants to be compliant with PCI DSS.
PCI DSS covers the following principles:
• Build and Maintain a Secure Network
• Protect Cardholder Data
• Maintain a Vulnerability Management Program
• Implement Strong Access Control Measures
• Regularly Monitor and Test Networks
• Maintain an Information Security Policy.
What are the benets of PCI DSS compliance?
PCI DSS compliance assists your business in protecting Payment Card data and
minimising risk of theft of Cardholder information or compromise of your business
systems. Maintaining a PCI DSS compliance program helps your business identify
potential vulnerabilities and may reduce the nancial penalties and remediation costs
from a data breach.