Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...PCI Compliant Hosting?PCI Compliant Hosting?
Previous
 
Next
New Post
4/2/2010 3:32 PM
 

Can anyone recommend a PCI Compliant Host?

Thanks,

Kyle

 
New Post
4/2/2010 3:46 PM
 

Hi Kyle.

As i lead some PCI-Projects in the past i would like to give some clarification to you.

The following list should give you the answer to your question:
- your company does not have to be PCI-DSS compliant as long as you do not store any creditcard-related data and you're using a certified payment module e.g. for your store
- The provider of this module must be PCI-DSS compliant, as the creditcard-data will be stored / handled on their servers
- Payment Module must be PA-DSS compliant

E.g. I would recommend to use the certified Payment-Module, e.g. from 1und1 (Germany)and  use / implement it exactly (!) as documented.

Again, don't handle any CC-Data, even not with an own input dialog or something else. The only place where the customer should be able to type his cc-data in must be the Payment-Module you use.

That means in the end, you can run your site even at home on your notebook, as long as the correct implemented module is NOT on your machine and this is the one and only and really only place where any creditcard data could be entered.

Hope that helps

Kai

 
New Post
4/3/2010 9:02 AM
 
Hi, Just to follow up on Kai, more and more payment gateways are offering IFRAME solutions so all CC info hits their servers, not yours. As soon as you touch any CC info, you need to be PCI compliant. Authorize.Net has this IFRAME solution, Quantum (CDGCommerce) and a few others. If you do need a PCI compliant server, you'll have to pay extra for it. http://www.rackspace.com/managed_hosting/services/security/pci.php Thanks, Mike
 
New Post
4/6/2010 1:18 PM
 

Thanks for the info.

If I have an input screen to accept the CC info and then send it to the gateways via the gateway's component or XML specs and I do not store any credit card info, would this be acceptable?

 

 
New Post
4/6/2010 2:49 PM
 

Definitely not.

You're not allowed to process cc-data in any kind, to store it, you should even don't think about that

Otherwise your whole infrastructure (server, client-pcs accessing it, network.....name it you have it) must be PCI-compliant.

Therefore the supplier deliver an iFrame-version or a java-applett or something else, to have the data entered there and not stored or processed on your machine.

Believe me, you don't really want to become PCI-compliant, as stated before, i lead some projects and it is a mess, at least a bunch of work. And a lot of money.

Cheers

Kai

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...PCI Compliant Hosting?PCI Compliant Hosting?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out