The PCI Toolbox
The Rackspace PCI Toolbox offers the technical infrastructure components you need to be compliant. If it's related to your servers and infrastructure, our
products and network security experts can help you take care of it. Your responsibility for the non-infrastructure aspects of compliance—such as
implementing a corporate security policy and ensuring that your employees are trained on proper cardholder data handling—which is much easier
when the technical infrastructure aspects are addressed.
The cost of implementing a PCI compliance solution in-house is daunting. Even more eye opening are the costs related to not being compliant when you
should be—penalities vary anywhere between $100,000 to $1,000,000. However, the cost of working with Rackspace security staff to help you with
compliance is nominal, especially when you have 24x7x365 availability.
If there's an issue, you have a question or just need advice, someone knowledgeable and experienced will always be available to help you become
compliant and remain that way. It's one more way
Fanatical Support®
is unlike any other kind of support.
Rackspace PCI Toolbox Overview*
All of these products and services are needed to ensure that your infrastructure is PCI compliant. You can purchase them as a package or separately
depending on your security needs.
* Note that a minimum of two servers is required by Payment Credit Card Industry - Data Security Services (PCI-DSS) to be compliant.
General PCI Information
The PCI-DSS (Payment Card Industry - Data Security Standard) is a single security standard comprised of the cardholder security programs from
the 5 major credit card companies. Any organizations that accept, process or store cardholder information must be PCI complaint, including
merchants and third-party providers**. This includes websites that accept payment cards.
Severe penalties and sanctions can be levied against organizations that fail to be PCI compliant:
- Fines up to $500,000 per incident levied by their bank and the card companies
- Banned from allowing customers to use credit cards
- Fines up to $100,000 per incident for not notifying customers of the probable thefts of their information levied by
state governments
As of September 2006, PCI DSS 1.1 includes 12 major requirements for compliance. Violating any of these requirements can trigger an overall
non-compliant status.
**However, according to the PCI DSS documentation, "PCI DSS requirements are applicable if a Primary Account Number (PAN) is stored, processed
or transmitted. If a PAN is not stored, processed, or transmitted, PCI DSS requirements do not apply."