Invia SSC Germany GmbH Successfully Certified acording to PCI DSS

17. August 2020

Invia PCI DSS Core-Team: „IT Infrastructure“ & Software Development “Invia Payment”

About INVIA

The Invia Group is a pan-European market leader in online travel distribution with 1300 employees in 16 offices across 7 countries. In 2019 more than 3 million customers travelled with Invia. The total transaction value was 1.5 billion EUR. The Invia Group operates major travel portals in Germany such as ab-in-den-urlaub.de and fluege.de

The internal payment service provider Invia SSC Germany GmbH was successfully re-certified according to PCI DSS for the fourth time through an on-site audit performed by usd AG in close cooperation with the Invia PCI DSS Core Team. 

Security as a Customer-Oriented Service 

For Invia, certification according to PCI DSS goes beyond mere duty. As a customer-oriented service provider, Invia sees compliance with the strict security requirements for handling credit card data primarily as an important service for its customers.

Matthias Zobel, Information Security Officer at Invia:

“We are glad that we have a security partner at the highest level in usd AG. Year after year, this enables us to implement complex PCI DSS requirements in a pragmatic manner and at the same time to continuously increase our security level. For years, our customers have benefited from the world’s highest security standard for credit card data on all our platforms.” 

Security that Exceeds Compliance 

Even beyond its own certification project, Invia makes efforts to maintain the credit card security of its customers at the highest possible level. At the end of 2018, for example, Invia developed various approaches for compliance solutions for call center agents. Even during the development phase, Invia was in close contact with the PCI experts at usd AG, so that the compliance solutions could be quickly concretized and successfully audited. 

Alexander Bienzeisler,Head of IT Infrastructure & Cloud Solutions at Invia:

“The continuous cooperation with usd AG allows us, as a service provider, to always offer the performance that our customers expect from us. The valuable exchange even beyond the audit ensures that our environments meet the highest compliance requirements within the framework of the PCI-DSS regulations at all times.”

Vinzent Ratermann of usd AG, who conducted the project as lead assessor: 

“Due to Invia’s infrastructure, which is mainly based on open source technologies, the certification project is always a special experience even for us. Despite the aggravating circumstances caused by Covid-19, which meant that a large part of the appointments had to be held remotely, the joint project work went smoothly again this year. We would like to thank the Invia PCI DSS Core Team for the great cooperation and look forward to next year.” 

Also interesting:

DORA Countdown: One Month Left Until the Deadline

DORA Countdown: One Month Left Until the Deadline

DORA, the Digital Operational Resilience Act, will fully apply as of 17 January 2025. We have summarized everything you need to know about the EU regulation, preparation and best practices from our news blog.

Sunset of PCI DSS v4.0 on 31 December 2024: Get Ready!

Sunset of PCI DSS v4.0 on 31 December 2024: Get Ready!

PCI DSS v4.0: In March 2024, version 4.0 of the Payment Card Industry Data Security Standard became mandatory after a two-year transition phase. Just a few months later, version 4.0.1 was released as a minor update of the standard, which will become mandatory on...

Top 3 Vulnerabilities in SSO Pentests

Top 3 Vulnerabilities in SSO Pentests

During their penetration tests (pentests), our security analysts at usd HeroLab repeatedly uncover vulnerabilities that pose significant risks to corporate security. They increasingly encounter the same vulnerabilities. Our blog series "Top 3 Vulnerabilities" presents...

Categories

Categories