Friday, March 5, 2010

Sage Online Educational Symposium

On March 18th Sage will be holding their Online Educational Symposium. This is a virtual conference that you can attend from the comfort of your own office, and it’s free! This is a great opportunity to network with fellow software users and product experts, attend breakout sessions to learn more about your Sage product, and learn about business topics from keynote speakers.

The agenda for the Online Educational Symposium is as follows:

11am Eastern - Tradeshow / Networking

11:30 am - Welcome / General Session: “Momma Told Me There’d Be Days Like This: Finding Stability in Stressful Times.”

12:30 pm – Product-Specific Educational Sessions –

  • DacEasy: “Getting the Most from the DacEasy Business Center.
  • Sage BusinessVision: “Increasing Profitability with CustomPack.”
  • Sage BusinessWorks: “Put Your Personal Touch on Your Business Forms.”
  • Sage PFW ERP: “Best Practices for Reconciling your General Ledger.”
  • Sage Pro ERP: “Creating Great Reports with the Report Customization Wizard.”

1:30 pm – Tradeshow / Networking

2:00 pm – Product Specific Educational Sessions

  • DacEasy: “Customizing DacEasy Business Forms.”
  • Sage BusinessVision: “Enhanced Analysis Using Microsoft® Excel ®.”
  • Sage BusinessWorks: “Quick Answers to Everyday Questions.”
  • Sage PFW ERP: “Quick Answers to Everyday Questions.”
  • Sage Pro ERP: “Maximizing your Data for Better Reporting.”

3 pm – General Session 2 / Closing Remarks: “Can I have a Side Order of Bad Service with That? Creating Dazzling Customer Service.”

4 pm – Tradeshow / Networking

For more information or to register visit: http://www.sagespecialized.com/20637/index.html

Friday, February 19, 2010

The Truth About PCI Compliance

The Truth About PCI Compliance

If you are using software to process credit card charges, you are processing someone's personal financial information, and you need to ensure that this information is safe from any attempt at compromising it, internal attempts as well as external attempts. Fines of up to $10M have been levied against fairly small businesses.

The Payment Card Industry Data Security Standard (PCI DSS) is a mandatory global standard established by the major card associations to ensure the protection of cardholder data. Based on twelve guidelines, the PCI DSS requires merchants to make their physical and virtual environments secure to ensure protection of cardholder data. As a merchant accepting credit cards as a form of payment, you are required by the card associations to adhere to the PCI DSS. The PCI DSS encompasses the security programs from Visa and MasterCard, Cardholder Information Security Program (CISP) and Site Data Protection (SDP), respectively.

The PCI DSS sets technology requirements such as the use of data encryption, end-user access control, and activity monitoring and logging. It also includes procedural mandates, such as the need to implement formal and documented security policies and vulnerability-management programs. They were developed to ensure that cardholder data is protected throughout the transaction process. Compliance with the standard applies to all types of merchants, retail, Mail Order/Telephone Order, and Internet. All merchants need to follow best practices for storage and destruction of all paper or electronic records containing account numbers or cardholder data. Additionally, merchant service providers processing credit cards need to be PCI compliant.

The more credit card transactions a merchant processes, the more stringent the compliance procedure. For most merchants, compliance consists of passing quarterly or annual network scans and completing an annual self-assessment questionnaire. If you process more than 20,000 e-commerce or 6 million total V/MC transactions per DBA (doing business as) annually, you will need to provide evidence of certification from a V/MC certified vendor. Penalties for failure to comply with the PCI requirements, failure to rectify a security issue, or failure to report a compromise are severe:

  • Possible restrictions on the merchant
  • Permanent prohibition of the merchant’s participation in card association programs
  • A fine of up to $500,000 per incident
  • Violation of applicable federal or state laws
  • Fraud losses perpetrated using the account numbers associated with the compromise (from date of compromise forward)

To read more on this topic, click here.