AbleCommerce Gold Merchant Guide |
Configure Menu
This section covers the following topics:
Find the Security menu
Additional Security MeasuresWhat you won't see in AbleCommerce are many transparent security features. Email Security Email is not a secure method of communication and should never be used for transmitting sensitive information. AbleCommerce does not include credit card account details or passwords in any of the default email notifications. By design, email will be used as a verification process only. User's will be required to receive an email and respond via a unique link in order to reset a password or be verified. Encrypted Config Files The database.config and encryption.config files are used to store sensitive information concerning your AbleCommerce installation. These files are encrypted so that your connection string and encryption key remain protected. Debug Logging Payment gateway integrations provided by AbleCommerce all support optional debug logging. The debug log files generated by our integrations never include sensitive card data. Sensitive data such as credit card numbers and CVV2 are redacted. Third party developers who create new payment integrations are strongly advised to follow the same procedure. Debug logs must not contain sensitive data in order to achieve PCI DSS compliance. Legacy Credit Card Data While magnetic stripe data, card validation values or codes, and PINs or PIN block data are not (and never have been) stored within the database/software, AbleCommerce has tools available to securely delete sensitive data should the need arise. To securely delete the data, we will overwrite it with dummy text and then remove it from the database. This will ensure the data does not reside anywhere on disk or in memory when it is removed.
|