PCI FAQ
Questions & Answers About PCI
Nicht bearbeiten!
Your content goes here. Edit or remove this text inline or in the module Content settings. You can also style every aspect of this content in the module Design settings and even apply custom CSS to this text in the module Advanced settings.
What is the PCI DSS?
What are the objectives of the standard's security requirements?
The standard includes security requirements that pursue the following objectives:
- Establishment and operation of a protected network
- Protection of stored and transmitted cardholder data
- Establishment and operation of a vulnerability management system
- Implementation of effective access control policies
- Regular monitoring and review of the IT infrastructure
- Formulating and enforcing an information security policy
What are the PCI DSS requirements?
PCI DSS comprises twelve security requirements. Organizations are considered PCI-compliant if they meet the following requirements:
- Installation and maintenance of network security controls (NSCs) to protect cardholder data
- Changing the default passwords and security settings specified by manufacturers
- Protection of stored cardholder data
- Encrypted transmission of credit cardholder data on public networks
- Use and regular updating of anti-virus software
- Development and use of secure systems and applications
- Restricting access to cardholder data according to business information needs
- Assigning a unique ID for each person with computer access
- Restrict physical access to cardholder data
- Logging and monitoring all access to network resources and cardholder data
- Regular review of security systems and procedures
- Establishment of a company policy with information security guidelines for employees and contractual partners
Who is required to comply with PCI DSS?
Why do I have to comply with the proof of credit card security (PCI DSS)?
When do I store, process, or forward credit card data?
How do I provide PCI DSS proof of compliance?
– an annual onsite audit by a Qualified Security Assessor (QSA) officially approved by the PCI Security Standards Council (QSA)
– an annual self-assessment questionnaire (SAQ).
Merchants and/or service providers are classified in accordance with the requirements of the credit card organizations. A key factor in the classification is the annual transaction volume. Detailed information can be found here: MasterCard / VISA / American Express
According to what guidelines is a merchant and/or service provider classified?
Which credit card organizations accept certification according to the PCI Data Security Standard?
What does compliant mean?
This means that these companies are protected by the “safe harbor rule” as long as they can demonstrate that they comply with the requirements. In the event of data theft or misuse, the company can therefore expect partial or complete exemption from fines imposed by credit card organizations or the acquirer after analysis by a forensic expert.
Nicht bearbeiten!
Your content goes here. Edit or remove this text inline or in the module Content settings. You can also style every aspect of this content in the module Design settings and even apply custom CSS to this text in the module Advanced settings.
What are the consequences of not complying with PCI DSS?
What are the advantages of implementing PCI DSS?
- Increased data security and protection for your customers
- Increased customer confidence and, as a result, a possible increase in credit card use and sales
- Greater protection against financial losses and damages due to security breaches
- Protection of the company's image
- Assessment of the security protection of systems for storing, processing, and/or transmitting cardholder data
- Data minimization and avoidance lead to a reduction in business risk
- Network structuring reduces the costs of maintaining PCI compliance
How often do I have to provide PCI DSS proof of compliance?
I work together with a payment service provider which has taken over all settlement tasks for me. Do I still have to be certified according to the PCI Security Standard?
If you store credit card data on your systems or forward them via your systems, you are required to be certified. If you are not sure, please ask your acquirer or our PCI Competence Center.
How can I check whether my service provider is PCI DSS compliant?
- Visa
https://www.visa.com/splisting/searchGrsp.do - MasterCard
https://www.mastercard.com/content/dam/public/mastercardcom/globalrisk/pdf/SP_Post_List_11-01-24.pdf
Alternatively, you can contact the service provider directly and ask them for their PCI certificate.
Why do I also have to include credit card payments via another acquirer in my PCI DSS compliance documentation?
Does MasterCard or VISA provide information online regarding the topic of PCI?
Detailed information can be found here:
- Mastercard
http://www.mastercard.com/us/sdp/index.html - Visa
https://www.visa.com.bs/run-your-business/small-business/information-security/ais-program.html - PCI Security Standards Council
http://www.pcisecuritystandards.org
What is a "Customized Approach"?
Compared to the classic approach, in which the requirements must be implemented exactly as specified in the standard, the so-called "Customized Approach" brings more flexibility to the implementation of the requirements. For example, you can use existing processes and measures that are required by other norms or standards and have already been implemented in your company for your PCI DSS certification. To do this, you need to analyze the intent of a requirement together with your QSA and show how your individual implementation fits the intent of the requirement.
Self assessment questionnaire (SAQ)
Nicht bearbeiten!
Your content goes here. Edit or remove this text inline or in the module Content settings. You can also style every aspect of this content in the module Design settings and even apply custom CSS to this text in the module Advanced settings.
Which SAQ is right for me?
Alternatively, you can use the following guidelines:
- As a service provider, always select SAQ D-SP.
- For merchants in e-commerce, SAQ A and A-EP apply.
- For payments via POS terminal, merchants will find themselves in SAQ B, B-IP, or C.
- MOTO transactions are covered for merchants via SAQ A or C-VT.
Each of the above SAQ types requires specific technical requirements. If you do not meet these requirements (for example, by storing credit card data yourself), SAQ D is the correct choice for you.
The PCI DSS provides a selection guide here (https://www.pcisecuritystandards.org/document_library/) in the document “SAQ Instructions and Guidelines” (especially page 18). In addition, our PCI Compliance Platform (pci.usd.de) has an SAQ selection wizard that you can use free of charge.
Do all questions of the Self-Assessment Questionnaire have to be answered?
Nicht bearbeiten!
Your content goes here. Edit or remove this text inline or in the module Content settings. You can also style every aspect of this content in the module Design settings and even apply custom CSS to this text in the module Advanced settings.
Which topics does the Self-Assessment Questionnaire include?
Which topics does the Self-Assessment Questionnaire include?
The Questionnaire addresses the 12 main requirements of the PCI Data Security Standard (PCI DSS).
