E-comm Hosting and Credit Card Info

Last post 04-07-2009 1:35 PM by jstrosch. 2 replies.

Sort Posts:

  • E-comm Hosting and Credit Card Info

    03-02-2009, 12:20 AM
    • Member
      55 point Member
    • asp2go
    • Member since 08-26-2008, 11:42 PM
    • Posts 61

    Can anyone comment on risks or rules of using shared hosting vs VPS with e-commerce applications that may store credit card information. Are there specific rules around this to be aware of.

    Thanks,

  • Re: E-comm Hosting and Credit Card Info

    03-04-2009, 3:48 AM
    • All-Star
      62,477 point All-Star
    • TATWORTH
    • Member since 02-04-2003, 8:34 AM
    • England
    • Posts 12,197
    • TrustedFriends-MVPs

     There are credit card industry rules. Unless you are using an external service like paypal, a shared hosting location is unlikely to qualify as a secure host.

    Credit card information (except the last 4 digits) should be stored in an encrypted form with a log made of all accesses.

    Don't forget to click "Mark as Answer" on the post that helped you.
    This credits that member, earns you a point and marks your thread as Resolved so we will all know you have been helped.
  • Re: E-comm Hosting and Credit Card Info

    04-07-2009, 1:35 PM
    • Member
      70 point Member
    • jstrosch
    • Member since 04-25-2008, 3:32 PM
    • Posts 15

     Two resources that I've used to help try and build secure e-commerce sites are:

    https://www.pcisecuritystandards.org/security_standards/pci_dss_download.html (section 3 & 4)

    http://www.owasp.org/index.php/Handling_E-Commerce_Payments

     One thing i've heard of being a large risk in a shared hosting environemnt is that your security is tied to how well the other sites are built, it's possible that someone can compromise your db/web app. by breaking in through another site (since they're all on the same box).

Page 1 of 1 (3 items)