|
CallCopy's cc: Discover Suite helps maintain compliance with Payment Card Industry (PCI) Data Security Standard (DSS)
cc: Discover has an optional bcc: Security module that enables several features that have been developed with respect to the PCI DSS, including:
Protect Cardholder Data - Access to audio and screen recordings is managed at the user level. You have the ability to restrict
each user's ability to access recordings (audio and/or screen capture).
Disk Encryption - Video and audio files are stored using on-the-fly-encrypted disks. No data stored on an encrypted volume can be read (decrypted) without using the correct password/keyfile(s) or correct encryption keys.
Network Encryption- Our bcc: Security includes SSL encryption for all client-server communications, both in recording and in playback. We can also provide encryption for all recordings stored in our system.
Blackouts- The PCI DSS require that card security codes (CID, CAV2, CVC2, CVV2) are not stored. CallCopy's Blackout feature is able to receive start and stop triggers to define the beginning and end of a period within a call that contains this information, effectively pausing the recording of both voice and screen.
User Security and Audits- bcc: Security includes an extensive activity tracking system, providing a database of all activity in the system. You will be able to conduct full trace audits to determine who has accessed any recording in the system for playback, export, or any other critical functions. User permissions include the ability to deny an individual user the right to reset their own password, preventing general users from creating overly-simple passwords.
What is PCI?
PCI stands for Payment Card Industry. The PCI Security Standards Council was founded by American Express, Discover Financial Services, JBC, MasterCard Worldwide, and Visa International. The Council's stated mission is "To enhance payme
nt account data security by fostering broad adoption of the PCI Security Standards."
|
Who Enforces PCI?
While the PCI Security Council established and maintains the Data Security Standards (DSS), each card brand still manages its own compliance programs. If you have questions or concerns regarding your company's compliance status or the r
isks and penalties for falling out of compliance, we recommend you contact the payment brands you are contracted with.
|
PCI Security Vendor Alliance
CallCopy is a member of the PCI Security Vendor Alliance to ensure our products and solutions will meet the PCI needs
of our customers.
The mission of Payment Card Industry (PCI) Security Vendor Alliance (SVA) is to provide products and
services for the affected members of the payment card industry including retailers, E-commerce
companies financial institutions, payment processors, POS vendors and any other organizations that
must achieve compliance with the PCI Data Security Standards. The PCI SVA will also complement the
objectives of the major card payment brands by helping educate the payment card industry about the
business value of achieving PCI DSS compliance.
|
|