Alex Rivera | Logout

How is 'processing credit card data' defined (PCI)?

Asked 2010-02-26T16:26:37.137
10

If i have a web application and i receive credit card data transmitted via a POST request by a web browser over HTTPS and instantly open a socket (SSL) to a remote PCI compilant card processor to forward the data and wait for a response, am i allowed to do that? or is this receiving the data with my application and forwarding it already subject of "processing credit card data"?

if i create an iframe that is displayed in a client browser to enter cc data and this iframe posts the data via HTTPS to remote card processor (directly!) is this already a case of processing credit card data? even if my application code 'doesnt touch' the entered data with any event handlers?

i'm interested in the definition "credit card data processing". when does it start to be a cc data processing application? can somebody maybe point me to that section in PCI-DSS standard that clearly defines when you start to 'be a processing application'?

Thanks,

Edit
Report

1 Answer

5

You transmit the data, even if you don't do anything with it yourself. Therefore, you do fall under PCI compliance rules.

PCI DSS v .2.1, Page 5, under PCI DSS Applicability Information:

PCI DSS requirements are applicable if a Primary Account Number (PAN) is stored, processed, or transmitted. If a PAN is not stored, processed, or transmitted, PCI DSS requirements do not apply.

PCI DSS section 4.1, for example, requires encryption when transmitting over public/open networks, which you have covered with SSL and HTTPS at both ends.

But there's not just the requirements concerning direct dealings with card data. There's also user authentication controls, such as in PCI DSS section 8.x, particularly for users with access to cardholder data or administrative capabilities.

While there are sections you can ignore since you don't store the card data, there are other sections that deal with things like network security, firewalls, antivirus, access control, monitoring and tracking, testing, etc.

answered 2010-02-26T16:38:42.350

Your Answer