Hi, Log On or Create Account
Close

Log On

Need Help?

Sales Assistance

800.800.4239 Mon-Fri 7am-7:30pm CT

Answer within 2 hours.



800.800.4239
 
Products Solutions & Services Account Center
More search options
Close

Solutions & Services > Security > PCI Compliance

PCI Compliance



Financial Regulatory Compliance:
An Ever-Evolving Demand

Learn how to better assess risks
and assure compliance.

Read the Whitepaper »

What is PCI Compliance?

PCI Compliance Solutions from CDW ensure your organization’s engagement in payment card transactions adheres to the PCI Data Security (or PCI DSS) Standard.

The PCI DSS is a document drafted by the PCI Security Standards Council, a consortium of representatives from the payment card industry. It provides a yardstick by which networks can be declared either fit or unfit for payment card transactions.

A concise plan to become and remain PCI compliant will eliminate “compliance confusion,” which is likely to put your data at risk. It is essential to expertly navigate through the PCI DSS twelve‑part framework to ensure that your operating networks handle payment card data securely and accurately.

How Will PCI Compliance Benefit My Organization?

Tailoring your network to conform to PCI DSS requirements reduces the risk associated with adopting many different solutions with respect to payment card data security.

Implementing PCI compliance solutions enables your organization to:

  • Accept payment cards without the risk of fines, extra fees, or other penalties
  • Ensure that payment card information is properly protected
  • Improve security overall

The PCI DSS represents a collection of good security practices. If your organization embraces those requirements for its cardholder data environment, it encourages those practices to bleed over into other areas as well.

How Can I Help My Organization Embrace PCI Compliance Solutions?

The first step is to take the mystery out of PCI compliance and evaluate how it can be integrated into your organization as a whole:

  • There’s more to PCI compliance than just IT—All too often, PCI compliance is simply regarded as an IT problem, and IT is given the mission of “making the network compliant.”
  • There are policy components and potential implications for all processes—It’s important to recognize that PCI compliance affects every single organizational unit that handles or relies on payment card data.

The next step is to initiate a project plan. A compliance plan begins with gap analysis. In PCI compliance terms, this means three things:

  • Identifying which systems are in scope for PCI compliance
  • Determining the proper compliance assessment method
  • Identifying the areas and objectives that require work in order to become compliant

What Does PCI Compliance Implementation Look Like?

What Comprises a PCI Compliance Solution?

The PCI DSS is comprehensive and can cascade through many areas of an organization. As a result, there is no one‑size‑fits‑all solution for compliance. There are four basic steps to customize PCI compliance to your organization:

Scope

A plan for compliance should begin with an effort to define—as narrowly as possible—the scope of the cardholder data environment. This often is a subtle and complex question, but minimizing the scope of what must be evaluated for compliance is the single most important factor in most compliance plans.

Evaluation

Once the question of scope is properly settled, the next step is to determine how compliance will be evaluated. For most organizations, this means identifying the proper Self‑Assessment Questionnaire (SAQ). Some organizations will discover that they have special responsibilities because of services they provide, or because of payment processing software they have written.

Obstacles

What obstacles stand between your organization's current state and compliance? Once these have been identified, it is essential to make a project plan to close those gaps. This may require:

  • The acquisition of new technologies
  • Alterations to the current design or use of networks and systems
  • Third‑party services

Execution

Finally, the organization needs to execute that plan and submit the proper materials. Typically, an organization would submit a completed attestation of compliance, along with four passing quarterly external vulnerability scan reports from an Approved Scanning Vendor (ASV), to the organization’s processor or acquiring bank.

Getting Started With PCI Compliance

Your CDW Account Manager and certified specialists are ready to assist you with every phase of choosing and leveraging the right solution for your cardholder data environment. Our approach includes:

  • An initial discovery session to understand your goals, requirements, and budget
  • An assessment review of your existing environment and definition of project requirements
  • Detailed vendor evaluations, recommendations, future design, and proof of concept
  • Procurement, configuration, and deployment of the final solution
  • Ongoing product lifecycle support

The Explosion of BYOD

The Organization: Johnson County Community College
The Location: Overland Park, KS
The Project: Overhauling network infrastructure to support students’ personal devices. Get the story »

Security Partnerships and Certifications

  • Certified Cisco Systems Integrator
  • Certified Ethical Hacker (CEH)
  • CISA (Certified Information Systems Auditor)
  • Cisco Certified Internetwork Expert: Security
  • Cisco Master Security Specialized
  • CISSP (Certified Information Systems Security Professional)
  • CSSLP (Certified Secure Software Lifecycle Professional)
  • Global Certified Incident Handler (GCIH)
  • Global Information Assurance Certification (GIAC)
  • Global Security Essentials Certification (GSEC)
  • HIPAA Academy Certified
  • Homeland Security Certified
  • Mail Security for Exchange Sales Expert
  • Microsoft Certified Systems Engineer: Security
  • PCI Approved Scanning Vendor
  • Symantec AV and Client Security Certification
  • Symantec Control Compliance Suite 8
  • Symantec Control Compliance Suite Sales Expert
  • Symantec Endpoint Protection
  • Symantec Endpoint Sales Expert
  • Symantec Enterprise Security Manager Sales Expert
  • Symantec IM Manager Sales Expert
  • Symantec Mail Security
  • Symantec Network Access Control Sales Expert
  • Symantec Security Management Sales Expert
  • Symantec Security Information Manager 4.5

Contact a Specialist

BizTech Feature: PCI Compliance

CDW Threat Check