My Community
September 04, 2010, 06:44:29 AM *
Welcome, Guest. Please login or register.

Login with username, password and session length
News:
 
   Home   Help Search Calendar Login Register  
Pages: [1]
  Print  
Author Topic: Anyone doing PCI with CMOD?  (Read 246 times)
Bud Paton
Newbie
*
Posts: 4

ECM World Wide Technical Sales - CMOD


View Profile
« on: May 26, 2010, 08:34:52 AM »

Has anyone created a PCI compliant system with CMOD? Thanks
Logged
Justin Derrick
Global Moderator
Jr. Member
*****
Posts: 89


CMOD Guru, Consultant, ODUG Board Member


View Profile WWW
« Reply #1 on: May 27, 2010, 09:11:34 AM »

Hi Bud.

I'll answer your question with a question -- I've heard 'PCI' compliance mentioned for probably 5 to 7 years now, but I've never received a decent explanation of what it entails.

Does anyone have a reference to the specifications for PCI compliance?  Are they public?

-JD.
Logged

Call: (866) J-DERRICK   (866-533-7742)
eMail: jd@JustinDerrick.com  
Click: http://www.TenaciousConsulting.com/
Bud Paton
Newbie
*
Posts: 4

ECM World Wide Technical Sales - CMOD


View Profile
« Reply #2 on: May 27, 2010, 11:19:04 AM »

Sorry I should have explained PCI Compliance:
Q: What is PCI?
A: The Payment Card Industry Data Security Standard (PCI DSS) is a set of requirements designed to ensure that ALL companies that process, store or transmit credit card information maintain a secure environment.  Essentially any merchant that has a Merchant ID (MID).
The Payment Card Industry Security Standards Council (PCI SSC) was launched on September 7, 2006 to manage the ongoing evolution of the Payment Card Industry (PCI) security standards with focus on improving payment account security throughout the transaction process.  The PCI DSS is administered and managed by the PCI SSC (www.pcisecuritystandards.org), an independent body that was created by the major payment card brands (Visa, MasterCard, American Express, Discover and JCB.).
It is important to note, the payment brands and acquirers are responsible for enforcing compliance, not the PCI council.
A copy of the PCI DSS is available here.
Logged
Steve Bechtolt
Newbie
*
Posts: 7


View Profile
« Reply #3 on: June 30, 2010, 06:47:26 PM »

We have been working with several of our clients moving towards PCI compliance.  Some steps taken to date include utilizing the User Preview Exit to mask credit card numbers for data that is already loaded into CMOD.  We have also implemented a 3rd-party data encryption solution to encrypt the file systems for all of the CMOD directories: arsdb, cache, etc. This also includes encrypting disk storage pools defined in TSM.
Logged

Steve Bechtolt
IBM Certified Solutions Expert - IBM Content Management - OnDemand Multiplatform
Consulting Services - ECMS l Field Operations - North America l EDS Applications Services
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC Valid XHTML 1.0! Valid CSS!