This policy sets out the requirements which are necessary to protect the security of all payment card details that are received and processed by Gemporia which are governed by the Payment Card Industry – Data Security Standard (PCI DSS). Compliance with PCI DSS is mandatory for any company or organisation which stores, processes or transmits payment card data. Failure to comply with these requirements could result in data breaches leading to Gemporia being fined by the acquirer with the need for additional controls implemented and losing customers.
The Gemporia IT Director is responsible for ensuring that this document is kept current for the purposes of compliance with the Payment Card Industry Data Security Standards (PCI DSS) initiatives. The document must be reviewed and updated at least annually with the updated version rolled out to all concerned personnel.
This policy applies to all the assets that are covered as per the Gemporia’s Card Holder Environment (CDE).
It is the policy of Gemporia to ensure that all payment card details received and processed by the company is done in accordance with the requirements of the PCI DSS standard. It must be ensured that
This document is aimed at providing the high level statements with regards to Gemporia’s PCI compliance and must be supported by other relevant policies, procedures and processes as deemed necessary.
Date | Description | Who |
---|---|---|
12/10/2014 | Original Document | Andrew Smith |
13/10/2015 | Added physical access details | Andrew Smith |
20/11/2015 | Added 4.18 | Andrew Smith |
30/11/2015 | Added 4.20 and 4.19 | Andrew Smith |
01/12/2015 | Added 4.21 explicitly | Andrew Smith |
01/12/2015 | Updated 4.6 to include all messaging technologies | Andrew Smith |
23/02/2016 | Review, no change | Andrew Smith |
24/05/2016 | Changed TGGC to Gemporia | Andrew Smith |
24/08/2016 | Review, no change | Andrew Smith |
07/11/2016 | Added requirement for staff to be approved by Director for IT before being granted access to CDE | Andrew Smith |
24/11/2016 | Review, no change | Andrew Smith |
24/02/2017 | Review, no change | Andrew Smith |
24/05/2016 | Review, no change | Andrew Smith |