Artwork

Conteúdo fornecido por THE COMMERCE HERO SHOW and Kalen Jordan. Todo o conteúdo do podcast, incluindo episódios, gráficos e descrições de podcast, é carregado e fornecido diretamente por THE COMMERCE HERO SHOW and Kalen Jordan ou por seu parceiro de plataforma de podcast. Se você acredita que alguém está usando seu trabalho protegido por direitos autorais sem sua permissão, siga o processo descrito aqui https://pt.player.fm/legal.
Player FM - Aplicativo de podcast
Fique off-line com o app Player FM !

Magento 1 EOL and PCI Compliance

3:27
 
Compartilhar
 

Manage episode 242544308 series 1435359
Conteúdo fornecido por THE COMMERCE HERO SHOW and Kalen Jordan. Todo o conteúdo do podcast, incluindo episódios, gráficos e descrições de podcast, é carregado e fornecido diretamente por THE COMMERCE HERO SHOW and Kalen Jordan ou por seu parceiro de plataforma de podcast. Se você acredita que alguém está usando seu trabalho protegido por direitos autorais sem sua permissão, siga o processo descrito aqui https://pt.player.fm/legal.
A common question I see related to Magento 1 reaching End of Life is whether a store that stays on M1 will automatically fail PCI compliance. I’m not a PCI expert, and don't take any of this as official guidance, but generally the answer is, it depends. Security issues within the Magento world are unacceptably high. The credit agencies that officially look at PCI compliance are undoubtedly aware of that problem. At the end of the day, though, with hundreds of thousands of stores on M1, if it’s passed EOL but the rate of hacks is acceptable, I believe they will continue to accept that business. One of the simplest ways to approach this is to keep the software out of scope for PCI compliance by handling payment processing through a third party. (Honestly you should probably be doing that anyway in most cases, even if you are on an officially supported version of Magento.) Even in-scope software that’s past EOL can be supported. Other parties such as Nexcess can provide official support for M1. To stay on the conservative side, you might not want to be on a software that’s past EOL. But the idea that if you are on M1, you are automatically out of PCI compliance isn’t necessarily true. It’s more nuanced than that. We’ll have to see what happens as we hit EOL. Questions will be answered and new precedents will be set.
  continue reading

41 episódios

Artwork
iconCompartilhar
 
Manage episode 242544308 series 1435359
Conteúdo fornecido por THE COMMERCE HERO SHOW and Kalen Jordan. Todo o conteúdo do podcast, incluindo episódios, gráficos e descrições de podcast, é carregado e fornecido diretamente por THE COMMERCE HERO SHOW and Kalen Jordan ou por seu parceiro de plataforma de podcast. Se você acredita que alguém está usando seu trabalho protegido por direitos autorais sem sua permissão, siga o processo descrito aqui https://pt.player.fm/legal.
A common question I see related to Magento 1 reaching End of Life is whether a store that stays on M1 will automatically fail PCI compliance. I’m not a PCI expert, and don't take any of this as official guidance, but generally the answer is, it depends. Security issues within the Magento world are unacceptably high. The credit agencies that officially look at PCI compliance are undoubtedly aware of that problem. At the end of the day, though, with hundreds of thousands of stores on M1, if it’s passed EOL but the rate of hacks is acceptable, I believe they will continue to accept that business. One of the simplest ways to approach this is to keep the software out of scope for PCI compliance by handling payment processing through a third party. (Honestly you should probably be doing that anyway in most cases, even if you are on an officially supported version of Magento.) Even in-scope software that’s past EOL can be supported. Other parties such as Nexcess can provide official support for M1. To stay on the conservative side, you might not want to be on a software that’s past EOL. But the idea that if you are on M1, you are automatically out of PCI compliance isn’t necessarily true. It’s more nuanced than that. We’ll have to see what happens as we hit EOL. Questions will be answered and new precedents will be set.
  continue reading

41 episódios

Todos os episódios

×
 
Loading …

Bem vindo ao Player FM!

O Player FM procura na web por podcasts de alta qualidade para você curtir agora mesmo. É o melhor app de podcast e funciona no Android, iPhone e web. Inscreva-se para sincronizar as assinaturas entre os dispositivos.

 

Guia rápido de referências