SECURED PAYMENT

The importance of PCI DSS compliance on an e-commerce website

PCI WHAT IS IS?

PCI DSS (Payment Card Industry Data Security Standard) is a standard created by 5 major credit card companies (Visa, Mastercard, Discover, JCB, and American Express) to ensure the protection of credit card data in any environment where it is stored, transmitted, or processed.

The standard includes various requirements for implementing information security controls with the aim of implementing protection in organizations that handle credit card data through various means such as point-of-sale terminals, e-wallets, websites, vending machines, and ATMs.

PCI COUNCIL

The PCI Council was established to create standards and supporting materials to enhance payment card security. These include tools, measurements, and resources designed to assist organizations in providing secure handling of payment cardholder information at every stage along the way. • The basis for the Council's activity is the PCI Data Security Standard, or PCI DSS for short, which provides a framework for developing reliable and secure credit card payment processes, including prevention, detection, and appropriate response to information security problems.

PCI STANDARD ON GEMS WEBSITE

Credit card processing and payments on the site are carried out through the company PAYME.

Implementing information security is supposed to be a central part of the business's activity. Compliance with the standard's requirements provides protection for the business against fines and lawsuits from international credit card companies in case of unauthorized intrusion into the company's systems and unauthorized access to information (credit card data).

As of the update of this page in June 2022, the PAYME payment system holds authorization certificates for the PCI DSS security standard. The authorization certificate is for PCI DSS level-1 for the years 2022/2023.

PCI DSS level-1 certification for the years 2022/2023.

PCI DSS level-1 certification for the years 2021/2022.

Transaction with 3DSecure

What is 3DSecure?

A standard established by international credit card companies in order to reduce fraudulent transactions in "card-not-present" purchases. This service protects credit cards against fraud during online purchases, and essentially allows cardholders to verify the transaction before it is completed by requesting a one-time personal code that is sent to the purchaser's mobile phone.

The 3DS service provides businesses with the ability to convert "card-not-present" transactions into secure transactions that cannot be repudiated except in the case of "chargeback". See the following video simulation for performing a transaction through 3DS.

The 3DS service on the GEMS website

The buyer enters the payment details on the payment page and clicks "pay."

The buyer is redirected to another page called the verification page where they are asked to enter a 6-digit code. At the same time, the cardholder's credit card company sends an authorization SMS containing the code that the buyer needs to enter.

If an incorrect code is entered, the buyer is asked to enter a correct code.

If a correct code is entered, an attempt is made to complete the transaction until success/failure (checking if there is sufficient balance to complete the transaction, CVV and ID card are valid, etc. See examples below:

Example of a credit card verification SMS sent by a credit card company

Examples of payment verification pages are determined by the cardholder's issuing credit card company

MAX/LEUMICARD

ISRACARD

RATING 2  AVERAGE 5