Has anyone on this board heard of this? It is something set up by Visa
and Mastercard stating that if you are taking payments you need to
adhere to a list of requirements.
I am working with a client who wishes to use Authorize.NET as a payment
gateway. We currently encrypt all of our credit cards, and we handle
sessions using a database and GUIDs.
My client is telling me that the way we are doing session is not PCI
compliant. Does anyone know what he is talking about?
Thank you for any insight.
Danielle
>> Stay informed about: PCI Security Standard