Making your Website PCI Compliant

The Payment Card Industry (PCI)’s Data Security Standard is increasingly being demanded by tech savvy clients, so it is important that your hosting provider is able to offer PCI Compliant Hosting.

PCI Compliant Hosting providers have grown in importance as the scale of financial transactions are more and more being done online. At BNS we implement the major aspects of PCI standards to make these PCI standard hosting services. Both physical and logical barriers are in place to restrict access and secure data to only those individuals that are properly authenticated and authorized to access the servers.

We employ things like certificate based security, encrypted communications,  IP access control list, full audit entry logs and physical access control measures that employ biometrics.

How to make your website PCI Compliant?

Step 1: Find out the level of PCI Compliance needed:

  • Level 1: Merchants which process over 6 million annual transactions or have already suffered an attack resulting in compromised data·  
  • Level 2: Merchants which process between 150,000 to 6 million annual transactions
  • Level 3: Merchants which process between 20,000 and 150,000 annual transactions
  • Level 4: Merchants which process less than 20,000 annual transactions

The requirements for each level are:

  • Level 1: Annual on-site security audit and quarterly network security scan.
  • Level 2 and 3: Annual self assessment questionnaire and quarterly scan by an approved PCI scanning vendor
  • Level 4: No need to report compliance but must maintain compliance

Step 2: Engage a PCI approved scanning vender to have your Web site scanned for vulnerabilities.  Be sure to continue the scanning on a quarterly basis.

Step 3: Report your compliance by sending the PCI scan and self-assessment to your merchant bank.

If you want to know more about PCI standards:

PCI Security Standards

PCI Self Assessment

PCI FAQs

Feel free to contact us about your PCI compliant hosting requirements

Double Web Bandwidth:Website Mirroring Service

Double your BandwidthIf your visitors are constantly unable to visit your website because of limited bandwidth and similar limitations, then try our Web Mirroring Service.

WebMirroring effectively doubles the available webservers for your site. It is perfect for serving up more web traffic by using more webservers.  Web Mirroring Service will have mirror image of your current website stored in our servers and this helps out your origin webserver by taking up some of the extra load. This instantly adds an extra webserver.

This service is perfect for handling sudden traffic surges!

Our webmirroring service is available for both the US and Asian target markets. By having mirror copies of your website in either our Asian or US servers, your website visitors will be closer to your content.  This improves the user experience.

Web mirroring Service is easy to implement. We only need to make some minor DNS modifications. Web mirroring service coupled with our global geographically aware DNS service combines to ensure that clients are directed to the closest specified server.

Just engage the service and we deploy this service for you. Email us at team[at]bnshosting.net for more details.

.ASIA Land Rush

Consider registering your site under the soon to be launched .asia domain name. There is .asia sunrise time period now. 

The Sunrise refers to the period of time prior to the launch of the new .asia top-level domain during which owners of trademarks are eligible to register a .asia domain name containing the owned mark, for example: nike.asia, sony.asia

The Landrush refers to the initial period of public availability of the new .asia top-level domain. Interested registrants who qualify for the CER can submit their entries now for the .asia Landrush priority registration. 


When does .asia become available to the public?
General availability of .asia is March 2008

Homeservice.ph For Work At Home and Home Based Work

BNShosting has just enabled the automatic building of resumes on the Homeservice.ph site.

The homeservice.ph is a web site that caters to work-at home job applicants and job searchers. The web site also caters to home based work such as interior decorators and home planners, carpenters, plumbers, painters, electricians, gardeners and the like for home improvement projects.

Homeservice.ph also caters to health and lifestyle services like manicurist, hair and make up artists, spa services and the like. Other services include home tutoring and language specialists.

Registration is free for all. No fees are charged to employers seeking to employ qualified candidates in the zip code/zone that they are looking to place them for. So please take the time to refer this to your ‘suki’s and help them market their skills and succeed!

Homeservice web site is growing our community of registered providers. If you have an organization that wants to provide this free service to your members, please let us know and we will want to work with you to achieve that!

From our months of operations, we have noticed that the secret to success for skill providers is to create the impressive resume that highlights their skills and lets the employers know about them and choose them from among the crowd.

Homeservice already has such an option built in and it is free to use.

Warning about Copyright Infringement

BNS would like to remind our hosted clients to respect IPR (Intellectual Property Rights) of copyright owners. It is to warn everybody about Copyright Infringement of software. If one is not careful with the software they use, they might be charged with software piracy which is punishable by law.

One of our clients just got an email from a copyrighted software about their use of vbulletin software which was unlicensed by the hosted clients.  Not only is this embarrasing, it could subject the site owner to possible legal liabilities.

The owner of the software has the right to sue, and if one is proven guilty of copyright infringement, charges includes an immediate order to stop using the software, confiscation of other items involved, paying the owner of the copyright any profits you received from using the software and other damages.

Spotlight: Danalex Graphics

Danalex Graphics and Call Center is a multi-service company based in Hawaii and in the Philippines. They provide the most effective communication and graphic design tools to help their clients get the necessary support for a successful business while maintaining their corporate identity out of a reasonable price, at the same time, experience a guaranteed total satisfaction from their services.

Danalex Graphics provide Graphic Design, Web Design and Development and Telemarketing Services.

Gods-answer-to-cancer.com

God’s Answer to Cancer is an inspiring site which was put up by the members of Charismatic ‘Inter-Faith Church Ministries Inc”. who have been promoting anti cancer and health.

According to Bishop Dr. Howard E. May, the website is not about medicine; but about ENERGY. By charging your body with “energy”, boosting what is called the Energy of Life, or “Chi” Energy, you can heal yourself by energizing your immune system Kill the bad germs and stop the diseases caused by parasites! Parasites are known to cause many of our diseases!
Health is about energy! Energy is life! Here is the Truth to change your life!

Internet Security Update: Rootkits

From Pandasecurity.com

Current-day cyber-criminals work for financial gain, usually by developing software for third parties.

Regardless of the final objective -stealing confidential information or crashing systems- the basic requirement for targeted attacks to be successful is to go unnoticed. That’s the reason behind the enormous increase in malware* using rootkit techniques.

Rootkits in themselves are not malicious. However, they have become the perfect weapon for cyber-crime due to their capacity to go unnoticed by security solutions (they hide as kernel modules and low level hooks, and by patching undocumented operating system functions).

Common myths

Contrary to popular belief, rootkits can be detected and it’s also false that there is nothing that your company can do to protect itself from them and the programs they hide (tailor-made to act remotely).

Send A Christmas Gift to the Philippines

Looking to send a christmas gift to the philippines now that Christmas is just around the corner? Look no further than at Barangay.ph. This is where you will find the largest selection of products under one “roof” from the most prominent vendors in the Philippines.

Check out some of the site’s offerings. Its electronics section offers Apple Ipods…although there is no mention of the iPhone- one of my Christmas wish list. This site is ideal if you want to send a birthday present, a large appliance, a special little something or prefer to one-stop shop with a credit card instead of assembling and shipping a balikbayan box.

Useability Analysis:
Doing some shopping on the site, it appears that you have to be a registered customer before you can access the final checkout counter.

I used my google toolbar’s autofill to quickly fill in the form. Filling the form was thus made quickly. I also noticed that they have breadcrumb trails at the top. Another useful navigation tool.

However, the site requires that you agree to their return policy. I was NOT able to locate where the return policy was. So this is one minor feedback for improvement of the site.

The credit card form was secured by SSL certificate from GTE cybertrust. So I don’t have any trust issues there.

The site also provides additional info on their site that includes upcoming information about Associations, banks and Chruches. The information about Churches will allow one to keep in touch with one’s faith.

While the site accepts payment via Credit card,  I wonder if it also accepts Paypal?

Here are some items from the site that are on my personal takam takam list: Tuyo!

And then after eating my meal with the bottled tuyo. I can finish off with the delectable almond crunch! Yummy!