Go Back   DevHunters.com l Webmaster Forum - Web Advertising - Web Design - SEO Forums > Webmaster / Coding / Web Design Discussion > Web Security and Virus Support

Web Security and Virus Support This section is for member support and information about virus removal and website security.

Reply
 
LinkBack Thread Tools Display Modes
Old 10-08-2008, 09:39 AM   #1 (permalink)
New Hunter
 

Join Date: Oct 2008
Posts: 2
Hunter Bux: 0
Lord_Webby is on a distinguished road
iTrader: (0)
Default Securely Storing Customer Details

I am creating a site that will be used to hold information about customers and their credit cards. I will not be storing or processing PAN (Primary account numbers) in any way, so I know PCI-DSS (Payment Card Industry - Data Security Standards) do not apply. But does anyone know of any regulations regarding storing customer data in a database?

The Data Protection Act is a bit vague - I can't seem to find information regarding specifics. For instance, I've been told that if you are holding customer data it needs to be on a seperate server to the website. Is this true?

Does anyone know of any specific documents / standards regarding storing customer information entered through the web?

Any help would be appreciated. Thanks.
Lord_Webby is offline   Reply With Quote
Old 10-08-2008, 10:26 AM   #2 (permalink)
Senior Staff
 
Hunter1's Avatar
 
7up Pinball Champion! Baccarat Champion! Chingy Powerballin Champion!
Join Date: Mar 2007
Location: Indiana USA
Posts: 2,296
Hunter Bux: 18,026.33
Hunter1 has much to be proud ofHunter1 has much to be proud ofHunter1 has much to be proud ofHunter1 has much to be proud ofHunter1 has much to be proud ofHunter1 has much to be proud ofHunter1 has much to be proud ofHunter1 has much to be proud ofHunter1 has much to be proud of
iTrader: (9)
Default

I am trying to totally understand your question. Here are some thoughts:

1. Your database is only as secure as it was built from your script maker but someone that knows what they are looking at would have to look and address any types of potential Hack Dangers.

2. Does the script you are using have a setup for an SSL certificate?
Hunter1 is offline   Reply With Quote
Old 10-08-2008, 10:39 AM   #3 (permalink)
New Hunter
 

Join Date: Oct 2008
Posts: 2
Hunter Bux: 0
Lord_Webby is on a distinguished road
iTrader: (0)
Default

Well, so far I have methods for securely writing to the database using PHP and encryption, the site will be hosted on one server with the database on another (both with firewall - database server only allowing connections on the MySQL port). The web server will be using an SSL certificate.
Lord_Webby is offline   Reply With Quote
Reply

Bookmarks

Tags
customer, information, law, secure, storage

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT -5. The time now is 09:24 PM.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0
vBCredits v1.4 Copyright ©2007 - 2008, PixelFX Studios