What Every, Hotel, Restaurant and Resort Operator Should Know About PCI Compliance

Last year, the hospitality industry became the mostcompliance. Earlier this year ReServe Interactive, a
targeted industry for data breaches according to aleader in hospitality management software solutions,
Global Security Report by Trustwave. Here's a topselected Element as its PCI DSS compliant solutions
five list of what every, hotel, restaurant and resortpartner for its suite of catering, event management,
operator needs to know (and do) about PCIdining reservations and table management software
compliance in 2010:products. Look for partners with technology like
1. If you aren't well versed in it already, get familiar withtokenization and end-to-end encryption, which will likely
the PCI DSS. The Payment Card Industry Datareduce your scope of PCI compliance.
Security Standard, or PCI DSS for short, is a set of4. As of July 1, 2010, all merchants (that's you!) must be
requirements that all businesses-regardless ofusing payment application software that has been
size-must adhere to in order to accept payment cards.validated as Payment Application Data Security
Their purpose is to ensure the security of cardholderStandard (PA-DSS) compliant. A listing of certified
data and to help prevent credit card fraud, hacking,payment applications can be found on the PCI SSC
and other security issues. The standard is enforced bywebsite.
the major credit card companies that make up theBut don't just stop there if you see your software
Payment Card Industry Security Council-Americanprovider listed there - be sure to check that you have
Express, Discover, JCB, MasterCard and Visa.upgraded to the PA-DSS compliant version of the
Merchants fall under four categories of PCI DSSapplication. If your software provider is not on the list,
compliance, depending on the number of transactionsalso check with them to see if they have gone out of
they process each year, and whether thosescope for PA-DSS compliance through a hosted
transactions are performed from a brick and mortarPA-DSS solution like Hosted Payments.
location or over the Internet.If you aren't using a PA-DSS validated application now
PCI compliance for merchants can get a bit tricky:that July 1 has passed, you risk losing the ability to
each payment card brand (Visa, MasterCard, etc.) hasprocess credit and debit card transactions - an
their own requirements for PCI compliance. You needabsolute must for any business in the hospitality
to know the different PCI compliance deadlines andindustry.
requirements for each payment card brand.5. In the coming months, be on the lookout for new
2. If you're an independent hotel, restaurant or resort,iterations of both the PCI DSS and PA-DSS. They are
the onus really is on you to become PCI DSSdue out in October, after the annual PCI compliance
compliant and verify your compliance with eachcommunity meetings in the US and Europe. The PCI
payment card brand. If you are part of a franchise,standards follow a defined 24-month lifecycle, ensuring
reach out to your franchisor to see they havea gradual, phased use of new versions of the
implemented any kind of PCI compliance program forstandard without invalidating current implementations of
their franchisees or if they are offering any advice.the standards or putting any organization out of
3. Research partnerships to ease the burden of PCIcompliance the moment changes are published.