Making your Website PCI Compliant

The Payment Card Industry (PCI)’s Data Security Standard is increasingly being demanded by tech savvy clients, so it is important that your hosting provider is able to offer PCI Compliant Hosting.

PCI Compliant Hosting providers have grown in importance as the scale of financial transactions are more and more being done online. At BNS we implement the major aspects of PCI standards to make these PCI standard hosting services. Both physical and logical barriers are in place to restrict access and secure data to only those individuals that are properly authenticated and authorized to access the servers.

We employ things like certificate based security, encrypted communications,  IP access control list, full audit entry logs and physical access control measures that employ biometrics.

How to make your website PCI Compliant?

Step 1: Find out the level of PCI Compliance needed:

  • Level 1: Merchants which process over 6 million annual transactions or have already suffered an attack resulting in compromised data·  
  • Level 2: Merchants which process between 150,000 to 6 million annual transactions
  • Level 3: Merchants which process between 20,000 and 150,000 annual transactions
  • Level 4: Merchants which process less than 20,000 annual transactions

The requirements for each level are:

  • Level 1: Annual on-site security audit and quarterly network security scan.
  • Level 2 and 3: Annual self assessment questionnaire and quarterly scan by an approved PCI scanning vendor
  • Level 4: No need to report compliance but must maintain compliance

Step 2: Engage a PCI approved scanning vender to have your Web site scanned for vulnerabilities.  Be sure to continue the scanning on a quarterly basis.

Step 3: Report your compliance by sending the PCI scan and self-assessment to your merchant bank.

If you want to know more about PCI standards:

PCI Security Standards

PCI Self Assessment

PCI FAQs

Feel free to contact us about your PCI compliant hosting requirements

Bangko ng Kalumpit – Online

Bangko ng Kalumpitwas incorporated and made itself within reach in the midst of those who need its services. Its focal vision of being a channel in the filtration of the wealth and resources of the nation to the countryside was pervaded to and formed integral part of its organization.

Bangko ng Kalumpit is a family corporation and its founding officers and Board of Directors are Former RTC Judge Hermin E. Arceo President and Chairman of the Board; Mr. Ariel S. Arceo, Ms. Carol S. Arceo, Mr. Rodolfo E. Arceo and Mr. Eriberto E. Arceo as members.

Manned by pro-people and service-oriented work force, the Bank in no time at all, was accepted by the public as a partner in the rural economic development. It is now the well that small and medium scale industries draw financial resources from whenever they are in need of economic assistance to sustain the growth of their businesses and has become a by-word in the community as it gives generous participation on community projects and cater to the needs of the rural folks.

Pinoy Weekly Online

Philippine NewsPinoy Weekly Online is an online publication about the latest news, public opinion, Philippine culture and the latest in sports and showbiz. The website is purely in Filipino/Tagalog.

PINOY WEEKLY is a weekly progressive publication which mainly concentrates on publishing investigative reports and new about important community discussions.

BNS now with 24/6 tech-support!

BNS clients are now guaranteed of 24/6 technical support.  Yes, that’s right. That would mean 24 hours of phone, email and online chat support which will give our valued clients better and more effective service.

Phone support: +63-075-6143247; +63-075-522-5089

Email support: team[at]bnshosting.net

Or click our Live Support Online button in our website.

Joomla exploit fix

As many web developers now frequently use Joomla as their application, we have researched a fix to block some common Joomla exploits. This article contains tips on what codes ca be placed in your .htaccess file inside your httpdocs directory.

########## Begin – Rewrite rules to block out some common exploits
#                             
# Block out any script trying to set a mosConfig value through the URL
RewriteCond %{QUERY_STRING} mosConfig_[a-zA-Z_]{1,21}(=|\%3D) [OR]
# Block out any script trying to base64_encode crap to send via URL
RewriteCond %{QUERY_STRING} base64_encode.*\(.*\) [OR]
# Block out any script that includes a <script> tag in URL
RewriteCond %{QUERY_STRING} (\<|%3C).*script.*(\>|%3E) [NC,OR]
# Block out any script trying to set a PHP GLOBALS variable via URL
RewriteCond %{QUERY_STRING} GLOBALS(=|\[|\%[0-9A-Z]{0,2}) [OR]
# Block out any script trying to modify a _REQUEST variable via URL
RewriteCond %{QUERY_STRING} _REQUEST(=|\[|\%[0-9A-Z]{0,2})
# Send all blocked request to homepage with 403 Forbidden error!
RewriteRule ^(.*)$ index.php [F,L]
#
########## End – Rewrite rules to block out some common exploits

Local Government Development Foundation – Online

LOGODEF is a Manila-based non-stock, non-profit organization established on March 21, 1989 for the purpose of providing professional services to local governments in support of central government efforts to promote the continuing development of Philippine local authorities.

The Foundation is one of the major institutional partner of the Konrad Adenauer Foundation (KAF) in strengthening local political institutions in the Philippines. The organization is also an advocate of interlocal cooperation. It’s main objectives include helping local governments help themselves is the basic philosophy of the Foundation in the promotion of local autonomy and self reliance towards the attainment of effective decentralization.

Konverg.com

empowering web technologiesKonverg is a Business Technology company dedicated to helping businesses owners get empowered with the latest web technologies.

It aims to provide the best and most relevant business applications with the lowest total cost of ownership to small and medium enterprises. In a competitive business world, Konverg believes in creating an “equalizing” force to small businesses by providing latest business tools for Customer Relationship Management (CRM), Financial Management, Salesforce Automation and Business Intelligence that are otherwise available only to large enterprises with their huge IT Infrastructures and budgets.

Konverg is a private company with offices in the US, Middle East and the Philippines.

Microsoft Hosting Conference

Pictures from the conference:

The departure area of the Bangkok International Airport

Thai International Airport

JJ Jager of SWSOFT in one of the technical sessions showing off billing and hosting automation provisioning:

JJ Jager, SWSOFT

Mr Alvin Lim, Director, Hosting and Software Services, communications and Media Sector, Asia Pacific with Mr Wilson Chua, President, BNS

Alvin Lim Microsoft Director, Hosting and Software Services Asia Pacific

BNS to Attend Hosting Day in Thailand

 

BNS is attending the Microsoft Hosting Day South East Asia and India. This event will be held at theClaming haven of The Metropolitan Hotel in the urban hubbub of Bangkok. This invitations only event provides an excellent opportunity for BNS to share ideas and best practices and learn from key hosters in the South East Asia and Indian continent.

Hosting Day South East Asia and India is a must-attend event that offers a unique opportunity to network with key Microsoft Executives, and industry players among which includes JJ Jager of SWSoft (Parallels.com) who will be a speaker about parallels hosting automation.

Program Highlights:

• The Microsoft Vision for Software + Services

• Virtualization in Hosting using Hyper-v

• Microsoft & Communications Sector perspective on hosting business

• Public Sector as an opportunity segment

• Windows Server Hosting Guidance

• Microsoft Hosting, Rules of Engagement: Microsoft Licensing

• Hosted Dynamics: The buzz around Hosted CRM

• Building New Channels to Reach SMBs with SaaS-Based Services

• SaaS Incubation Center Program Workshop

• Selling Business Email and Attached Services to SMBs

• Unified Communications and Windows Mobile technical session

• Unified Communications and Windows Mobile session

• Windows Mobile Workshop

• Hosting Rich Internet Applications with Silverlight�