Addressing the PCI Data Security Standard within Commerce+

The following topics deal with each of the detailed PCI requirements that pertain to Commerce+. Some of the requirements are directly related to the Commerce+ software package. Other requirements are unrelated, or indirectly relate to the Commerce+ software package. For example, indirect requirements can affect your use of the operating system security features to secure Commerce+ files.

For each requirement that directly affects Commerce+, the requirement is reprinted in italics and addressed point by point. In some cases, it is an explanation or confirmation that the requirement is met. In others cases, you must enable or disable features.

For several of the requirements that are related only to PCI compliance (and not to Commerce+) you are referred directly to the PCI DSS for details. Ensure that you keep up with the rapid pace of changing security requirements.

Tip: Each of the section numbers in this section corresponds to the numbering of the subsections of the PCI DSS document.

Required fixes and modifications for PCI compliance

In addition, it is recommended that you apply security fixes as recommended in the Commerce+ Security Bulletins.

You can subscribe to security bulletin notifications using your IBMid:
  1. Go to My notifications.
  2. Lookup and subscribe to notifications for your Commerce+ product. For example, Commerce+.
  3. Select Options > Edit.
  4. Ensure that the Security bulletin document type is selected.
    Note: All document types are selected by default.
  5. Click Submit.

Summary of specific configuration actions required in your Commerce+ implementation

While it is recommended to read each of the requirement sections to fully understand how Commerce+ addresses the PCI-DSS, the following list summarizes the changes that you must make to a typical Commerce+ installation by using default settings. Read each page carefully to understand how to complete the changes.
Note: This summary does not include changes that you must make to your site operations. Review each requirement section carefully for details on operations and procedures that you must complete in conjunction with using Commerce+. For example, reviewing your business audit logs daily or using secure removal tools to delete old encryption assets.