You are viewing limited content. For full access, please sign in.

Question

Question

Can Laserfiche forms be used with PCI compliance?

asked on April 7, 2014

In taking credit card information, we understand that PCI compliance is a set of procedures.

Has anyone incorporated Laserfiche forms in that set of procedures?

0 0

Answer

SELECTED ANSWER
replied on April 7, 2014 Show version history

While PCI compliance is generally a set of procedures, there are some elements that will be very difficult to implement. An example of this is standard 3.2.1 from the most recent PCI Data Security Standards document (accessed from here):  

 

Do not store sensitive authentication data after authorization (even if 
encrypted). If sensitive authentication data is received, render all data unrecoverable upon completion of the authorization process. 

 

This can safely be ignored if there is a business justification and the data is stored securely. Removing items from the Forms database is not possible from inside the solution, and we don't support/recommend doing it by editing the database. 

 

Long story short, at the moment, it's difficult at best, and may not be possible at all to meet all PCI compliance requirements.

 

1 0
replied on April 8, 2014

Thank you - that was very helpful in giving my client direction.

0 0

Replies

You are not allowed to reply in this post.
You are not allowed to follow up in this post.

Sign in to reply to this post.