|
PCI Compliance
The main focus of our PCI Compliance Group is to keep track of new developments in the PCI Data Security Standards and align our solution portfolio to meet the most stringent data security requirements. For our enterprise-level clients, the most important of the DSS requirement was to ensure security of the cardholder's data with the necessary encryption mechanism in place. Our team has developed and deployed solutions thereby gaining valuable expertise in:
- Integrating transaction switch with a third-party encryption engine.
- Developing automated key management processes for secure retrieval of encryption keys.
- Developing, hashing and masking algorithms to protect cardholder data.
- Developing database-level encryption for small-scale installations.
Our PCI Research and Development Team is poised to make ThoughtFocus a one-stop shop for all PCI DSS required solutions. Some of our initiatives are:
- Development of a web application firewall.
- Development of best practices and procedures for password management.
- Development of OWASP-compliant code review processes.
|
|
|
|
|