PCard_Admin
07-19-2007, 06:44 AM
Hi,
Our company builds software that allows card users to view and edit electronic transaction files issued by their card-providing bank. As such, this software does not process any card payments and only uses the card number to identify the card holder.
No other data is stored, such as expiry date, pin, card holder address etc.,
Could anyone advise if this type of management information software falls under PCI DSS, and if so, at what level?
Many thanks for any help....
Our company builds software that allows card users to view and edit electronic transaction files issued by their card-providing bank. As such, this software does not process any card payments and only uses the card number to identify the card holder.
No other data is stored, such as expiry date, pin, card holder address etc.,
Could anyone advise if this type of management information software falls under PCI DSS, and if so, at what level?
Many thanks for any help....