Security

Payment Card Industry (PCI) compliance

The Payment Card Industry (PCI) has developed the Payment Application Data Security Standard (PA-DSS) program to assist software vendors in creating secure payment applications. This program helps ensure compliance of the software solution with the PCI Data Security Standards (DSS). The policies and guidelines in the program help maintain a secure retail Point-of-Sale environment.

The Advanced Store solution supports requirements for the retailer’s organization to remain compliant with the PCI DSS. NCR Voyix recommends for retailers to follow their corporate security guidelines to meet and maintain their business needs. For more information about the PCI DSS and PCI PA-DSS, refer to the official documentation at www.pcisecuritystandards.org.

Federal Information Processing Standards (FIPS) compliance

The Advanced Store solution uses FIPS compliant algorithms. NCR Voyix recommends for retailers to apply these guidelines on all the servers and terminals across the enterprise.

Encryption protocol compliance

The Advanced Store solution supports the Transport Layer Security (TLS) 1.2 requirement. This protocol provides enhanced security encryption for protecting payment data. NCR Voyix recommends for retailers to apply the TLS requirement on all the servers and terminals across the enterprise.

Note

The default encryption key provided with Advanced Store should be changed before first use in a production environment. For more information, refer to Encryption Key Maintenance Utility.