Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

Standards for collection & storage of banking information?

  • 06-01-2009 3:31pm
    #1
    Registered Users, Registered Users 2 Posts: 24,367 ✭✭✭✭


    Does anyone know of any industry standards similar to PCI-DSS that exist around the area of collection and storage of bank account details?


Comments

  • Registered Users, Registered Users 2 Posts: 2,835 ✭✭✭StickyMcGinty


    well, you'll need to get versed in your Data Protection legislation - especially if your considering using servers abroad to store this data

    Depends on what your responsibilites are, but standards such as ISO-27001 would more than likely apply


  • Registered Users, Registered Users 2 Posts: 24,367 ✭✭✭✭Sleepy


    Thanks StickyMcGinty, I've read the Data Protection legislation alright and noted that there didn't seem to be anything specific regarding encryption levels etc.

    I'm coming at this from the POV of part of a development team creating a web app to collect direct debit mandates.

    The data records may potentially be resting on the web server for a few minutes/hours before being passed through the firewall into a corporate LAN at which point the data protection becomes someone else's concern (ideally I'd like to ensure this happens immediately but I don't have full control over the system) but I want to learn everything I can about any and all standards we may be required to meet with our code and architecture.

    I'll look up ISO-27001 now. Are there any legal requirements or standards enforced by banks etc beyond the Data Protection Act?


Advertisement