Got Your Number! Taking credit card payments online - your options, security issues and regulations

17
Got Your Number! Taking credit card payments online - your options, security issues and regulations 27 August 2008

description

5 minute microslot talk for Oxford Geek Night 8 on the 27th August 2008.

Transcript of Got Your Number! Taking credit card payments online - your options, security issues and regulations

Page 1: Got Your Number! Taking credit card payments online - your options, security issues and regulations

Got Your Number!Taking credit card payments online - your options,

security issues and regulations27 August 2008

Page 2: Got Your Number! Taking credit card payments online - your options, security issues and regulations

Payment Options

Providers such as PayPal, Google Checkout

A merchant account and Payment Gateway

Page 3: Got Your Number! Taking credit card payments online - your options, security issues and regulations

PayPal etc. Pros

Quick and easy to implement

Donʼt require a merchant account with a bank

It may be that customers are happier giving their details to these companies than to you

Page 4: Got Your Number! Taking credit card payments online - your options, security issues and regulations

PayPal etc. Cons

Canʼt brand the payment screens

Might be a confusing process

Makes you look like a small company

Lack of trust in PayPal etc.

Page 5: Got Your Number! Taking credit card payments online - your options, security issues and regulations

What do you need?

- merchant account with a bank

- a method of processing the payment into that merchant account (payment gateway service)

- decide which method you want to use to take payments

Page 6: Got Your Number! Taking credit card payments online - your options, security issues and regulations

Payment Gateways

You do not usually need to use the payment gateway owned by the bank you have your merchant account with. Shop around, all providers are not equal in ease of integration, features or costs.

Page 7: Got Your Number! Taking credit card payments online - your options, security issues and regulations

Payment Options

“Pay Page” - card details are entered on the gatewayʼs server

API Integrations - card details are entered on your server

Page 8: Got Your Number! Taking credit card payments online - your options, security issues and regulations

Pay Page

Card details are taken on the payment gateway server

- you have no responsibility for card data

- user goes to third party site

- some gateways allow templates to be uploaded to brand payment page

Page 9: Got Your Number! Taking credit card payments online - your options, security issues and regulations

API Integrations

With an API integration you can keep the user on your server all the time and transmit the card data securely to the payment gateway.

Security of the card data is your responsibility during collection and transmission.

Page 10: Got Your Number! Taking credit card payments online - your options, security issues and regulations

Keeping date secure

Use SSL - install a certificate on your server

- provides encryption for the data transfer

- provides reassurance for the user that you are who you say you are

Page 11: Got Your Number! Taking credit card payments online - your options, security issues and regulations

3-D Secure

You will usually need to implement 3-D Secure (Verified by Visa/MasterCard SecureCode) as part of the API integration.

If using “Pay Page” this will be done for you.

Page 12: Got Your Number! Taking credit card payments online - your options, security issues and regulations

Storing card data

You should not store the card data in your database. Send it to the gateway and let them look after it.

Page 13: Got Your Number! Taking credit card payments online - your options, security issues and regulations

If you really need to...

Storing card data means that you or your client need to take responsibility for the security of that data.

Page 14: Got Your Number! Taking credit card payments online - your options, security issues and regulations

PCI DSS

http://pcisecuritystandards.org

The Payment Card Industry Data Security Standard (PCI DSS) applies to anyone collecting and storing credit card data.

That means you.

Page 15: Got Your Number! Taking credit card payments online - your options, security issues and regulations

What do I need to do?

The standards cover everything from data stored online to that stored in your office

(or on hard disks that get sold on eBay...)

Page 16: Got Your Number! Taking credit card payments online - your options, security issues and regulations

Core principles1. Build and maintain a secure network

2. Protect cardholder data

3. Maintain a Vulnerability Management Program

4. Implement Strong Access Control Measures

5. Regularly Monitor and Test Networks

6. Maintain an Information Security Policy

Page 17: Got Your Number! Taking credit card payments online - your options, security issues and regulations

Thank you!

Rachel Andrew

http://www.edgeofmyseat.com

http://www.rachelandrew.co.uk