View Single Post
  #32  
Old 08-19-2009, 06:45 AM
 
mfb mfb is offline
 

Member
  
Join Date: Mar 2009
Posts: 22
 

Default Re: X-Cart and PCI-DSS / PA-DSS compliance

Quote:
Originally Posted by JWait
...
Am I wrong about this?
Partly, according to my interpretation.

As far as I can tell, you can store credit card number and expiration date, but the three or four digit code (CVV2/CVC) code cannot be stored. But, this data must be encrypted where it is stored.

You can be secure and NOT pass PCI-DSS or insecure and pass it.

See https://www.pcisecuritystandards.org/pdfs/pciscc_ten_common_myths.pdf (Warning: PDF), Myth #9
__________________
My name is Steve
4.2.0
Reply With Quote