Fidelio Cruise SPMS meets PCI PA-DSS Requirements
As credit card security becomes a growing challenge throughout the retail and service sectors, complying with the PCI DSS requirements is vital for any organisation that processes, stores or transmits credit card information.
Fidelio Cruise is proud to announce that the Ships Property Management System Version 7.30.750 has been certified by the PCI SSC as a payment application that fully complies with the PCI PA-DSS security standards.
In its capacity as a vendor of application software that processes credit card data, Fidelio Cruise recognises the importance of meeting the PCI SSC credit card security requirements. Just as merchants and service providers, cruise and ferry operators need to protect themselves and their customers from fraudulent activities by ensuring that their systems are PCI compliant, Fidelio Cruise must also ensure that its software solutions are fully compliant with the regulations and do not in any way interfere with or prevent its customers' data security arrangements.
Fidelio Cruise has therefore engaged with its customers to design, build and maintain secure networks to protect cardholder data, create and maintain a vulnerability management program, implement strong access controls, maintain an information security policy and monitor and test networks on a regular basis.
PCI standards apply to all organisations or merchants, regardless of size or number of transactions, which accept, store or transmit any cardholder data. In other words, if any customer buys goods or services from an organisation or a merchant and uses a credit card as a means of payment, then the PCI DSS requirements automatically apply.
Measures adopted and validated as part of certification process, to ensure its customers' full compliance with the PCI SSC standards include:
- Develop secure applications
- No retention of full magnetic stripe, card validation code or value (CAV2, CID, CIV2, CW2) or PIN block data
- Log application activity
- No storage of cardholder data on a server connected to the internet
- Provide secure remote software updates
- Facilitate secure remote access to application
- Encrypt sensitive traffic over public networks
- Encrypt all non-console administrative access
- Maintain instruction documentation and training programs for customers, re-sellers and integrators
Abbreviations
PCI SSC – Payment Card Industry Security Standard Council
PCI DSS – Payment Card Industry Data Security Standard
PCI PA-DSS – Payment Card Industry Payment Application Data Security Standards
For more information, please visit: PCI Security Standards