I'm just wondering what is the best thing to do with credit card numbers when they are taken in through a secure connection.
Currently we do not store the numbers, but have them emailed to us immediately via PGP. We are thinking about moving to a server that does not offer PGP, so I am trying to find out what is the best thing to do.
Can we store them in a database and retrieve them through some password and referrer based script based on a form in a secure directory? Is this secure enough?
I take the subject very seriously, and I really need some expert help with this one as I am not entirely sure of the risks involved or the options available.
Thanks,
Matt.
Currently we do not store the numbers, but have them emailed to us immediately via PGP. We are thinking about moving to a server that does not offer PGP, so I am trying to find out what is the best thing to do.
Can we store them in a database and retrieve them through some password and referrer based script based on a form in a secure directory? Is this secure enough?
I take the subject very seriously, and I really need some expert help with this one as I am not entirely sure of the risks involved or the options available.
Thanks,
Matt.