I'd recommend starting with the PCI DSS. That standard is required by pretty much all card companies, and compliance is enforced by a self-assessment checklist and/or security assessor. If you plan on storing card information, you must be in compliance with this standard.
Comments
I'd recommend starting with the PCI DSS. That standard is required by pretty much all card companies, and compliance is enforced by a self-assessment checklist and/or security assessor. If you plan on storing card information, you must be in compliance with this standard.
PCI DSS Standard: https://www.pcisecuritystandards.org/security_standards/pci_...
More info on Wikipedia: http://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Secu...