3
Chapter 2
Important Security Notice
The Payment Card Industry Payment Application Data Security Standard (PCI PA-DSS) is comprised of fourteen
requirements that support the Payment Card Industry Data Security Standard (PCI DSS). The PCI Security Stan-
dards Council (PCI SSC), which was founded by the major card brands in June 2005, set these requirements in
order to protect cardholder payment information. The standards set by the council are enforced by the payment
card companies who established the Council: American Express, Discover Financial Services, JCB International,
MasterCard Worldwide, and Visa, Inc.
PCI PA-DSS is an evolution of Visas Payment Application Best Practices (PABP), which was based on the Visa
Cardholder Information Security Program (CISP). In addition to Visa CISP, PCI DSS combines American Express
Data Security Operating Policy (DSOP), Discover Networks Information Security and Compliance (DISC), and
MasterCards Site Data Protection (SDP) into a single comprehensive set of security standards. The transition
to PCI PA-DSS was announced in April 2008. In early October 2008, PCI PA-DSS Version 1.2 was released to
align with the PCI DSS Version 1.2, which was released on October 1, 2008. On January 1, 2011, PCI PA-DSS
Version 2.0 was released. This extends the PCI DSS Version 1.2, which was released on October 1, 2008 and is
effective as of January 1, 2011.
2.1
Applicability
The PCI PA-DSS applies to any payment application that stores, processes, or transmits cardholder data as part of
authorization or settlement, unless the application would fall under the merchants PCI DSS validation. It is important
to note that PA-DSS validated payment applications alone do not guarantee PCI DSS compliance for the merchant.
The validated payment application must be implemented in a PCI DSS compliant environment. If your application
runs on Windows XP, you are required to turn off Windows XP System Restore Points.
2.2
What Does PA-DSS Mean to You?
The following table provides opening points to cover in any discussion with merchants on data storage.
IDTech Windows SDK Guide for Kiosk III/IV #80136501-001