English

Electronik na Kad Peimen

Lon kain taim olsem, ol peimen ol save wokim o receivim lon wanpela bisnis em save transactim electronikali, wei ol lon usim ol cheq em ino moa save kamap na cas em save kamap plenti taim ol wokim antap lon ol over-the-counter ritail wok. Becos lon dispela sekure natsa blon bankim systim, bank transfe em safe, em sapose dispela kain was em ol wokim wanikain lon ol online transacsion. Kisim na mekim ol kad peimen em save gat moa risk, tasol sapose em gat sampela simpal precausion em gen addresim ol problim em laik kamap. Complianse waintaim sampela standad em ol bisnis requirim lon wokim wok bisnis husait save acceptim kad peimen.

Ol hevi

  • Kisim peimen
    • Kisim peimen taim usim ol fraud pasin o kredit kad wei ol stealim lon em.
      Ol non-complianse waintaim Payment Card Industry Data Securiti Standards (PCI DSS), na waintaim ol penalti blon em.
    • Wei em ino go stret lon ol infomasion protectsion law lon keepim kadholda detail lon ol nugut pupose o holim igo longpela taim.
    • Wokim ol chargebak igo lon ol customa husait em wokim giaman klaim ol non-deliveri, ol guds wei en no stap lon kisim o receivim ol guds wei em bagrap pinis.
  • Mekim Peimen
    • Mekim peimen igo lon ol fraud lain lon ol giaman site o lon ol guds na servis wei em ino stap.
    • Transferim ol moni igo lon ol giaman akount lon ol guds o servis wei em ino stap (ol bank ol em ino save refundim ol moni taim em ol stealim lon dispela kain wei).
    • Phisin imail – wei ol save lon giamanim pasin igo lon enterim ol finansal detail lon ol websit igat fraud lon em.
    • Vishin fone kol – wei ol save giamanim pasin lon mekim ol laik revealim ol finansal detail taim ol usim fone.
    • Ol las tupela toktok em ol exampal blon sosol enginerim.

Safe peimen

  • Kisim peimen
    • Mekim sua ecomerse websit blon yu em sekure lon side blon safti na tu mekim ol customa igat trust lon servise yu providim (lukim Sekure Websit, lon tamblo).
    • Lon kisi, peimen lon peimen kad, mekim sua bisnis blon yu em behainim dispela Payment Card Industry
    • Data Security Standards (PCI DSS), wei requirmen blon ol em ino sem olsem igo lon ‘mershant level’ na kad issua (lukim tamblo lon Complianse Criteria na PCI level).
    • Taim yu dispatchim ol guds, usim ol proof of delivery (POD) lon aviodim ol chargebak.
    • Dependim lon natsa blon bisnis na size blon transacsion, lukluk tu lon acceptim PayPal na ol mobil peimen wei em save providim ol additsional leya blon securiti.
  • Mekim peimen
  • Taim yu mekim online peimen lon wanpela supllia websit o lon wanpela direc peimen, yu mas mekim sua dispela site em sekure. Em bai gat wanpela padlok simbol stap insait lon browsa windo frame, wei em save kamap taim yu attemptim lon log in o wokim registratsion. Mekim sua ol dispela padlok em ino stap lon dispela page em yet … sapose em stap, em bai meanim ol em wanpela fraud site. Dispela web adress mas stat waintaim ‘http://’. Dispela ‘s’ em meanim olsem ‘sekure’. Tingim olsem, dispela bai indicatim olsem link blon yu na websit owna em sekure, na dispela site tu em sekure tu. Yu mas wokim dispela isisi na putim was waintaim tai, yu checkim ol kain olsem ol rong spellim, sampela toktok em ol addim na tu lon karacta na sampela samthing wei em ino luk stret.
  • Usim ol strongpela paswod na ensurim olsem yu keepim privat igo lon ol lain husaot bai usim lon em.
  • Imposim ol strik guidline lon ol employee husait igat dispela kompani peimen kad – na wainatim PIN na paswod protectsion na ol anti-clonim precausion.
  • Tingim olsem taim yu usim wanpela kredit kad em save givim protectsion wei em antap moa lon taim yu usim debit kad o indirek peimen.
  • Yu mas klia wainatim bank blon yu ol liabiliti blon lus em stap insait lon stil o fraud. Readim ol tems na condision gut na sapose yu gat sampela tingting, askim bisnis managa blon banl.

Ol mershant PCI DSS complianse siteria na PCI level

  • Complianse requiremen em save depen lon wanpela mershant activiti level.
  • Igat fourpela level, wei save lukim lon ol anual namba blon kredit/debit kad transacsion.
  • Taim ol peimen bran save determinim dispela ol complianse level igo lon bran blon yet, ol ackuira save go pas lon determinim dispela complianse validatsion requiremen level blon mershant blon ol yet.
  • Dispela complianse level em ol save setim aut lon tamblo na ol save referim igo lon ol namba blon ol transacsion blon wanwan peimen insait lon onpela yia.
  • Wetha em transacsion o nogat, ol volum blon em save appli tasol igo lon e-comerse transacsion o ol peimen proses igo lon olgeta chanel wei em save decidim seperatli lon ol wanwan peimen bran tasol, wei in generol, em olgeta transacsion ol save includim waintaim.

Level 1 Critiria
Mershant waintaim ova 6 milion transacsion lon wanpela yia, o mershant wei ol infomasion blon em bipo em bagarap and ino stap stret.
Level 1 Validatsion Requiremen
Anual Onsit Security Audit (em ol QSA o Intenal Audit save reveiwim sapose wanpela ofisa blon mershant kompani em signim na em kisim pre-approvim lon wanpela acquira) waintaim ol quarterli netwok securiti skan.

Level 2 Critiria
Mershant waintaim 1, 000, 000 igo lon 6 milion transacsion lon wanpela yia.
Level 2 Validatsion Requiremen
Anual Self Aseesmen Questionia
Quarterli Skan wei wanpela Approved Scanning Vendor (ASV) save wokim.

Level 3 Critiria
Mershant waintaim 20, 000 igo antap lon 1, 000, 000 transacsion lon wanpela peiman bran
Level 3 Validatsion Requiremen
Quarteli Skan wei wanpela Approved Scanning Vendor (ASV) save wokim,
Anual Self Assesmen Questionia

Level 4 Critiria
Mershant igo antap lon 20, 000 ecomerse transacsion o igo antap lon 1, 000,000 non-comerse transacsion lon wanpela peimen bran
Level 4 Validatsion Requiremen
Quarteli Skan wei wanpela Approved Scanning Vendor (ASV) save wokim (gen recomendim o requirim, wei em dependim lon acquira complianse critiria)
Anual Self Assesmen Questionia

Sekure websit

Providim ol sekure websit lon peimen em bai ensurim ol customa safti na lon kisim gutpepla bel na tingting. Plenti ol lain husait save shopim na peim lon ol guds na servis lon online lon nau save recognisim dispela signifanse blon padlok systim insait lon browsa windo fram, wei em save showim taim ol laik lon attemptim lon log in o wokim registratsion – na tu waintaim dispela adress em stat wainatim ‘http://’.

Dispela em showim olsem bisnis blon yu em gat disital cetificat wei wanpela gutpela third party em save usim olsem, VeriSign o Thawte, wei em indicatim olsem ol dispela infomasion ol transmitim onlin lon websit blon yu em ol encryptim na protectim lon husait laik interceptim na stealim lon third party, taim ol usim SSL technologi (lukim lon explanatsion tamblo).

Yu gen obtainim tu wanpela Extended Validation (o EV-SSL) cetificat, wei em indicatim olsem dispela authoriti wei save issuim dispela cetificat em conductim ol chek lon bisnis blon yu.

SSL

SSL (Secure Socket Layer) em ol standad securiti technologi blon establishim ol encryptim link lon serva na wanpela client – web serva (websit) na wanpela browsa tu, o lon wanpela mail serva na mail client kain olsem Microsoft Outlook.

SSL em save allowim ol sekret infomasion kain olsem kredit kad namba, sosol securiti namba, na login credental lon trasmitim lon sekure wei. Plenti taim, ol infomasion ol save salim lon ol browsa na web serva em igo olsem klia text … dispela em save mekim isi lon ol lain lon evedropim o spi lon ol dispela ol kain infomasion. Sapose wanpela atacka em gen interceptim olgeta infomasion wei ol salim lon wanpela browsa na wanpela web serva em gen lukim na usim ol dispela kain infomasion.

Glosari

Wanpela Glosari blon ol tem ol usim lon dispela artikle:

SSL

Secure Socket Layer, em wanpela encrypsion sysim wei em save securim ol intanet communicasion.

PIN

Pesonal Identificasion Namba.