Here are some of the key ingredients of a merchant security policy include:
• Conduct periodic vulnerability scans, no less than once a month.
• Scan systems after every change, such as network configurations or deploying new applications.
• Change passwords every 60 to 90 days.
• Identify where critical customer information is stored. Pay careful attention to securing these locations.
• Make certain all remote connections to your network are conducted through a virtual-private network and that the systems on the other side are secure as well.
• Make sure not to use default manufacture passwords while configuring network devices.
• Encrypt all credit card and customer sensitive information at rest.
• Conduct third-party annual penetration tests on your commerce infrastructure to test and verify all your security systems and procedures.
See There Is No Mystery to Protecting Cardholder Data to put these ideas into context.











