Artwork

Innhold levert av THE COMMERCE HERO SHOW and Kalen Jordan. Alt podcastinnhold, inkludert episoder, grafikk og podcastbeskrivelser, lastes opp og leveres direkte av THE COMMERCE HERO SHOW and Kalen Jordan eller deres podcastplattformpartner. Hvis du tror at noen bruker det opphavsrettsbeskyttede verket ditt uten din tillatelse, kan du følge prosessen skissert her https://no.player.fm/legal.
Player FM - Podcast-app
Gå frakoblet med Player FM -appen!

Magento 1 EOL and PCI Compliance

3:27
 
Del
 

Manage episode 242544308 series 1435359
Innhold levert av THE COMMERCE HERO SHOW and Kalen Jordan. Alt podcastinnhold, inkludert episoder, grafikk og podcastbeskrivelser, lastes opp og leveres direkte av THE COMMERCE HERO SHOW and Kalen Jordan eller deres podcastplattformpartner. Hvis du tror at noen bruker det opphavsrettsbeskyttede verket ditt uten din tillatelse, kan du følge prosessen skissert her https://no.player.fm/legal.
A common question I see related to Magento 1 reaching End of Life is whether a store that stays on M1 will automatically fail PCI compliance. I’m not a PCI expert, and don't take any of this as official guidance, but generally the answer is, it depends. Security issues within the Magento world are unacceptably high. The credit agencies that officially look at PCI compliance are undoubtedly aware of that problem. At the end of the day, though, with hundreds of thousands of stores on M1, if it’s passed EOL but the rate of hacks is acceptable, I believe they will continue to accept that business. One of the simplest ways to approach this is to keep the software out of scope for PCI compliance by handling payment processing through a third party. (Honestly you should probably be doing that anyway in most cases, even if you are on an officially supported version of Magento.) Even in-scope software that’s past EOL can be supported. Other parties such as Nexcess can provide official support for M1. To stay on the conservative side, you might not want to be on a software that’s past EOL. But the idea that if you are on M1, you are automatically out of PCI compliance isn’t necessarily true. It’s more nuanced than that. We’ll have to see what happens as we hit EOL. Questions will be answered and new precedents will be set.
  continue reading

41 episoder

Artwork
iconDel
 
Manage episode 242544308 series 1435359
Innhold levert av THE COMMERCE HERO SHOW and Kalen Jordan. Alt podcastinnhold, inkludert episoder, grafikk og podcastbeskrivelser, lastes opp og leveres direkte av THE COMMERCE HERO SHOW and Kalen Jordan eller deres podcastplattformpartner. Hvis du tror at noen bruker det opphavsrettsbeskyttede verket ditt uten din tillatelse, kan du følge prosessen skissert her https://no.player.fm/legal.
A common question I see related to Magento 1 reaching End of Life is whether a store that stays on M1 will automatically fail PCI compliance. I’m not a PCI expert, and don't take any of this as official guidance, but generally the answer is, it depends. Security issues within the Magento world are unacceptably high. The credit agencies that officially look at PCI compliance are undoubtedly aware of that problem. At the end of the day, though, with hundreds of thousands of stores on M1, if it’s passed EOL but the rate of hacks is acceptable, I believe they will continue to accept that business. One of the simplest ways to approach this is to keep the software out of scope for PCI compliance by handling payment processing through a third party. (Honestly you should probably be doing that anyway in most cases, even if you are on an officially supported version of Magento.) Even in-scope software that’s past EOL can be supported. Other parties such as Nexcess can provide official support for M1. To stay on the conservative side, you might not want to be on a software that’s past EOL. But the idea that if you are on M1, you are automatically out of PCI compliance isn’t necessarily true. It’s more nuanced than that. We’ll have to see what happens as we hit EOL. Questions will be answered and new precedents will be set.
  continue reading

41 episoder

Alle episoder

×
 
Loading …

Velkommen til Player FM!

Player FM scanner netter for høykvalitets podcaster som du kan nyte nå. Det er den beste podcastappen og fungerer på Android, iPhone og internett. Registrer deg for å synkronisere abonnement på flere enheter.

 

Hurtigreferanseguide

Copyright 2024 | Sitemap | Personvern | Vilkår for bruk | | opphavsrett