AC 7 Improvements from AC 5.5???
Posted: Thu Jul 22, 2010 2:04 pm
Does anyone have a list of the improvements made to AC 7 versus AC 5.5?
We've invested hundreds of hours of development time into making AC 5.5 a well-oiled machine for our business: bulk print of packing slips, inventory checks during bulk printing with exception reports, credit card capture during bulk printing with exception reports, SEO improvements, special handling for items that must be shipped ground (chemicals) or air (perishable foods), best way shipping, shipping arrival estimators, etc, etc.
However, we don't want to be caught with our pants down when our banks come knocking asking if we're PCI-DSS compliant. In reading through the official 68-page PCI Data Security Standard--Requirements and Security Assessment Procedures, it looks like we have two choices: 1) Switch to a PCI-DSS certified cart such as AC7, or 2) make the necessary customizations to AC 5.5 to bring it into compliance. There are going to be those that say that we have to use a PA-DSS "certified" cart if we are accepting credit cards, but nothing I've read says it has to be certified, only validated (meaning passes the 222 assessment controls and a quarterly security scan from an approved service vendor). It should also be noted that using a PA-DSS certified app doesn't absolve you from having to conform to the rest of the requirements, such as: having a corporate security policy, proper firewall configurations, using an anti-virus, separating the web app and database onto different servers, making sure your call center computers are PCI-compliant (credit card numbers are entered through them), quaterly scans, annual self-assesment, etc, etc.
So, aside from the PA-DSS certification, what improvements have others seen that will generate more customer sales or make life easier for merchants?
Thanks for your help,
Sam
We've invested hundreds of hours of development time into making AC 5.5 a well-oiled machine for our business: bulk print of packing slips, inventory checks during bulk printing with exception reports, credit card capture during bulk printing with exception reports, SEO improvements, special handling for items that must be shipped ground (chemicals) or air (perishable foods), best way shipping, shipping arrival estimators, etc, etc.
However, we don't want to be caught with our pants down when our banks come knocking asking if we're PCI-DSS compliant. In reading through the official 68-page PCI Data Security Standard--Requirements and Security Assessment Procedures, it looks like we have two choices: 1) Switch to a PCI-DSS certified cart such as AC7, or 2) make the necessary customizations to AC 5.5 to bring it into compliance. There are going to be those that say that we have to use a PA-DSS "certified" cart if we are accepting credit cards, but nothing I've read says it has to be certified, only validated (meaning passes the 222 assessment controls and a quarterly security scan from an approved service vendor). It should also be noted that using a PA-DSS certified app doesn't absolve you from having to conform to the rest of the requirements, such as: having a corporate security policy, proper firewall configurations, using an anti-virus, separating the web app and database onto different servers, making sure your call center computers are PCI-compliant (credit card numbers are entered through them), quaterly scans, annual self-assesment, etc, etc.
So, aside from the PA-DSS certification, what improvements have others seen that will generate more customer sales or make life easier for merchants?
Thanks for your help,
Sam