Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Code Project
  1. Home
  2. Other Discussions
  3. IT & Infrastructure
  4. Credit Card Information Standards

Credit Card Information Standards

Scheduled Pinned Locked Moved IT & Infrastructure
databasesalesquestion
6 Posts 6 Posters 0 Views 1 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • G Offline
    G Offline
    geekfromindia
    wrote on last edited by
    #1

    Hi Guys, I have recently joined a new company. It's a Healthcare company and builds application for your Insurance providers. Now while going through their application I found that they are storing credit card information in their database. Now if a Insurance company sales person reviews your application he can clearly see your Credit Card No and even CVV* :~. I can clearly see that there is something wrong here. We shouldn't even show credit card information to user himself once entered into system. We can show him last 4 digits and allow him to delete or add another one. I tried arguing with guys here about this but they don't agree. Now are there any standards or proper guidelines about storing or handling credit card information in our websites??? Or you think its ok to show user's CC info to some insurance company's sales rep??? Any suggestions are welcome. Thanks.

    Keep DotNetting!! GeekFromIndia

    L D D J 4 Replies Last reply
    0
    • G geekfromindia

      Hi Guys, I have recently joined a new company. It's a Healthcare company and builds application for your Insurance providers. Now while going through their application I found that they are storing credit card information in their database. Now if a Insurance company sales person reviews your application he can clearly see your Credit Card No and even CVV* :~. I can clearly see that there is something wrong here. We shouldn't even show credit card information to user himself once entered into system. We can show him last 4 digits and allow him to delete or add another one. I tried arguing with guys here about this but they don't agree. Now are there any standards or proper guidelines about storing or handling credit card information in our websites??? Or you think its ok to show user's CC info to some insurance company's sales rep??? Any suggestions are welcome. Thanks.

      Keep DotNetting!! GeekFromIndia

      L Offline
      L Offline
      led mike
      wrote on last edited by
      #2

      geekfromindia wrote:

      I tried arguing with guys here about this but they don't agree.

      Well the are probably wrong, however "The Decider"s[^] frequently are. ;) Regardless of your size, failure to comply can lead to steep financial and operational penalties. link[^]

      led mike

      1 Reply Last reply
      0
      • G geekfromindia

        Hi Guys, I have recently joined a new company. It's a Healthcare company and builds application for your Insurance providers. Now while going through their application I found that they are storing credit card information in their database. Now if a Insurance company sales person reviews your application he can clearly see your Credit Card No and even CVV* :~. I can clearly see that there is something wrong here. We shouldn't even show credit card information to user himself once entered into system. We can show him last 4 digits and allow him to delete or add another one. I tried arguing with guys here about this but they don't agree. Now are there any standards or proper guidelines about storing or handling credit card information in our websites??? Or you think its ok to show user's CC info to some insurance company's sales rep??? Any suggestions are welcome. Thanks.

        Keep DotNetting!! GeekFromIndia

        D Offline
        D Offline
        darkelv
        wrote on last edited by
        #3

        Unless the user is required to search by card number, even so, the less CC information shown, the better. Even so, the CVV* should not be shown, at all.

        1 Reply Last reply
        0
        • G geekfromindia

          Hi Guys, I have recently joined a new company. It's a Healthcare company and builds application for your Insurance providers. Now while going through their application I found that they are storing credit card information in their database. Now if a Insurance company sales person reviews your application he can clearly see your Credit Card No and even CVV* :~. I can clearly see that there is something wrong here. We shouldn't even show credit card information to user himself once entered into system. We can show him last 4 digits and allow him to delete or add another one. I tried arguing with guys here about this but they don't agree. Now are there any standards or proper guidelines about storing or handling credit card information in our websites??? Or you think its ok to show user's CC info to some insurance company's sales rep??? Any suggestions are welcome. Thanks.

          Keep DotNetting!! GeekFromIndia

          D Offline
          D Offline
          DownUnderDev
          wrote on last edited by
          #4

          geekfromindia wrote:

          I tried arguing with guys here about this but they don't agree

          just out of interest how did they argue against such an obvious point? a) i am lazy and i dont want to do anything i am not forced to b) i dont know how to i didnt make the system and am not able to make such changes PS: can i have the IP address of your Database server :laugh:

          "Any intelligent fool can make things bigger, more complex, and more violent. It takes a touch of genius and a lot of courage to move in the opposite direction." -Albert Einstein

          CPalliniC 1 Reply Last reply
          0
          • G geekfromindia

            Hi Guys, I have recently joined a new company. It's a Healthcare company and builds application for your Insurance providers. Now while going through their application I found that they are storing credit card information in their database. Now if a Insurance company sales person reviews your application he can clearly see your Credit Card No and even CVV* :~. I can clearly see that there is something wrong here. We shouldn't even show credit card information to user himself once entered into system. We can show him last 4 digits and allow him to delete or add another one. I tried arguing with guys here about this but they don't agree. Now are there any standards or proper guidelines about storing or handling credit card information in our websites??? Or you think its ok to show user's CC info to some insurance company's sales rep??? Any suggestions are welcome. Thanks.

            Keep DotNetting!! GeekFromIndia

            J Offline
            J Offline
            J4amieC
            wrote on last edited by
            #5

            Just in case, care to let us know the co. name so we can steer about a hundred thousand miles clear?

            1 Reply Last reply
            0
            • D DownUnderDev

              geekfromindia wrote:

              I tried arguing with guys here about this but they don't agree

              just out of interest how did they argue against such an obvious point? a) i am lazy and i dont want to do anything i am not forced to b) i dont know how to i didnt make the system and am not able to make such changes PS: can i have the IP address of your Database server :laugh:

              "Any intelligent fool can make things bigger, more complex, and more violent. It takes a touch of genius and a lot of courage to move in the opposite direction." -Albert Einstein

              CPalliniC Offline
              CPalliniC Offline
              CPallini
              wrote on last edited by
              #6

              DownUnderDev wrote:

              just out of interest how did they argue against such an obvious point?

              No need to argue, they are the Deciders [^]. :-D

              DownUnderDev wrote:

              PS: can i have the IP address of your Database server [Laugh]

              I thought the same. :-D

              If the Lord God Almighty had consulted me before embarking upon the Creation, I would have recommended something simpler. -- Alfonso the Wise, 13th Century King of Castile.
              This is going on my arrogant assumptions. You may have a superb reason why I'm completely wrong. -- Iain Clarke
              [My articles]

              In testa che avete, signor di Ceprano?

              1 Reply Last reply
              0
              Reply
              • Reply as topic
              Log in to reply
              • Oldest to Newest
              • Newest to Oldest
              • Most Votes


              • Login

              • Don't have an account? Register

              • Login or register to search.
              • First post
                Last post
              0
              • Categories
              • Recent
              • Tags
              • Popular
              • World
              • Users
              • Groups