red cross first aider with patient
British Red Cross is still unclear about the details it needs to provide

British Red Cross wants more help from banks

Lack of information from banks and cost of implementation are the challenges to overcome in the charity's PCI DSS compliance process

Written by Angelica Mari

The British Red Cross (BRC) is considering working with other not-for-profit organisations to meet the demands of new credit card data security requirements.

The charity is struggling with the PCI DSS standard, and has blamed banks for not providing sufficient information to help compliance. It has had to reshuffle IT priorities to accommodate the changes, said head of IT Miguel Fiallos.

“Even though we have to meet a deadline, the communication from the merchant banks in relation to what is wanted is very poor,” he said. Fiallos also said he is working with other charities to share the burden for parts of the process such as testing.

The PCI DSS security standard affects any company transmitting, processing or storing credit card information. Compliance is graded, with merchants divided into four different levels based on the number of transactions they process throughout the year.

“If the charity is accepting transactions over the phone or the internet, it will typically need the card number, expiry date and sometimes the three-digit code on the back of the card,” said Steve Wilson, head of policy compliance management at Visa.

“Charities should not be keeping information after the transaction is completed.”

BRC is undergoing tests under the Qualified Security Assessor programme.

Further reading

Retailers fail to monitor credit card data access

Many businesses carrying out card payments are unable to track who has been accessing data   More...

Payment security is lagging

Failure to comply with card data rules puts UK businesses at risk   More...

UK business ill-prepared for compliance

Lack of support at board level is a key issue, say survey respondents   More...

Related articles

PCI council sets payment security standard

New rules on the storage of payment details   More...

UK business not meeting data protection deadlines

Board only paying lip service to IT staff   More...

Scammers use charity donations to test card numbers

Watch out for small unauthorised transactions   More...

Experts call for regulation of PCI assessors

NetEvents panel warns of ambiguity in PCI compliance   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

16 May 2008

2.97 MBXP on OLPC, broken dreams and Yahoo fights back More...

15 May 2008

3.28 MBDark fibre, mobile TV and solar power More...

14 May 2008

2.66 MBOnline inequality, mobile thumbprints and corporate raids More...

Poll

HOME WORKING

HOME WORKING

Do you let any or all of your employees work from home?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

OLPC

OLPC to ship with Windows XP

Microsoft teams up with One Laptop per Child project   More...

The Sims

The Sims goes flat-pack with Ikea

Virtual world gets Swedish wood   More...

Advertisement

Microsoft-Yahoo

Yahoo board fights back at Icahn

Investor accused of 'significant misunderstanding' in Microsoft saga   More...

MySpace

Woman charged over MySpace suicide

Lori Drew indicted on federal charges   More...

Advertisement