PDA

View Full Version : PCI DSS Q&A


Pages : 1 [2] 3 4 5

  1. Credit card insurance companies
  2. Review of remote locations
  3. Service Providers and Agents/Sponsors
  4. FIle Integrity Monitoring?
  5. Requirement 6.3.3
  6. Logging and PCI
  7. Requirement 8 - Unique Accounts
  8. Requirement 8.5.5 Remove unused user accounts after 90 days
  9. Quarterly Scans Filing Requirements: the ROC or Acquirer
  10. PCI Question
  11. Policy or Procedure?
  12. PCI DSS Canada
  13. Requirements for hosting
  14. Colloboration and Compliance Reporting
  15. Requirements to HSM
  16. Private Label Cards and PCI DSS
  17. Cost of remaining PCI DSS compliant
  18. Electronic Wallets & PCI
  19. Is this PAN data?
  20. DBA Access to Encrypted Data
  21. Service Provider Certification without CHD
  22. Difference between ASV and QSA?
  23. Internet Kiosk
  24. Sensitive Auth Data?
  25. Testing requirements. 6.3.1 vs 6.4.3
  26. Carriers and NFC app.
  27. CC Data at Rest in Memory
  28. QSA disputes?
  29. Requirement 8.5.8
  30. 4 New PCI SAQ's - SAQ v1.1
  31. Encrypting the PAN when use primary database key
  32. Saq "c"
  33. Storing Encrypted PAN and Truncated PAN together
  34. Payment Apps of the Past
  35. Possible to not store CC data in restaurant environment?
  36. PC-Encrypt software?
  37. Compensating controls for 3.5.2
  38. Collecting Cardholder data on behalf of Merchants
  39. Bank Credit Card Statements
  40. PC Charge by Verfione
  41. 2.2.2 definition of unsafe protocols
  42. Luhn check commercial software recommendation
  43. Requirement 8. UserIDs & Passwords
  44. Define truncation
  45. HSMs becoming a requirement
  46. Pci 8.4
  47. PCI PED and de-installation of payment terminals in 2010
  48. What are the fines that could be imposed?
  49. Non-PAN Cardholder data
  50. Leased line
  51. scanned cheque with PAN
  52. Encryption of backup media
  53. Requirement 2.1
  54. Virtual Slices and PCI DSS 2.2
  55. PCI and Diagnostic Tools
  56. SAQ D, part 4
  57. Section 1 Question
  58. 1.3.9 question
  59. 1.3.8 question
  60. Does use of tokens mean PCI does not apply???
  61. 9.1.1, CCTV and "Sensitive Areas"
  62. PABP Validated Apps
  63. Online backup
  64. Which is the PCI preferred architecture for a small store?
  65. 3.6.7 How to prevent unauthorized key substitution?
  66. ATM's
  67. Agents enter PAN in WebForm (Payment Service). PCI conform?
  68. Shared user accounts
  69. Hosting Provider Contract
  70. Can systems be out of scope even on same network segement?
  71. Service Provider level / gateway
  72. Data Storage
  73. Encryption 3.6 and Vendor Payment Apps
  74. Shredding services
  75. Network segmentation for SMB with standalone CC terminals?
  76. What to do for this type of "compromise"?
  77. Session idle timeout
  78. What is a publicly accessible device 1.3/1.4?
  79. Isolated PCI environment
  80. MSSQL Linked Servers
  81. PAN Truncation on ATM Receipt
  82. Consumer Interfaces to POS kiosk
  83. CC Data in test environments
  84. POS sytems
  85. SQL 2005 Instances for physical separation?
  86. SQL 2005 Key Management acceptable?
  87. SQL 2005 Key Management acceptable?
  88. Compliance benefits of NOT storing cardholder data?
  89. Is protection required for encrypted PANs
  90. Question about network segmentation
  91. Oracle POS
  92. Unencrypted PANs in email
  93. Internet facing IP's Scan
  94. Encryption and Secure Storage of Backup Media (3.4 and 9.5)
  95. Cross Site Tracing
  96. Key management for backup data?
  97. PAN within Excelsheets etc.
  98. SAQ 1.1 Classification
  99. Personal Firewalls (R1.3.9)
  100. How does PCI apply to handwritten credit card transactions?
  101. Hearing Impaired Associate
  102. emailing POS receipt
  103. Things that make me go hmmmm...
  104. Cardholder Data Protection?
  105. Pci-dss 10.2.1 & 10.2.2
  106. One Function per Server (R2.2.1)
  107. section 2.1 default passwords
  108. Unsolicited PANs in free text forms
  109. McAfee ePO
  110. "Virtual Terminals" - vs 1.1 Questionnaire "C" or "D"
  111. Split Knowledge and Dual Control
  112. Postponing yearly pci audit?
  113. Logging of Clerk Activities at POS Terminals
  114. PCI DSS 1.1 requirement 12.10 - question
  115. File Integrity Monitoring at IP-connected terminals
  116. Encryption across Frame Relay
  117. QSA problems?
  118. PCI-DSS Req 8.5.9 to 8.5.15
  119. File Integrity Monitoring & Tracking Users?
  120. PCI-DSS Req. 3.3
  121. Online software, 3rd party vendor (us) -- question!
  122. Domain Controllers
  123. Flying under the level 1 radar
  124. ISP's and other network providers need to comply?
  125. PCI Compliant merchant hacked.
  126. Yet Another scope type question
  127. 3.3 requirement
  128. Physical Security of computers used for entering data
  129. AV & patching for POS
  130. Application Scanning Requirements
  131. Questionnaire C
  132. Is this considered "transmitting"
  133. Reporting Requirements
  134. Finding cardholder data
  135. 1.1 Firewall/Router Rule Review
  136. PCI-DSS Scope
  137. internal web-server
  138. Printed PAN's
  139. Hannaford Breach questions?
  140. Encryption plan for card data stored in SQL Server 2000
  141. Quarterly PCI scan
  142. Tandem and Compensating Controls
  143. Data Storage
  144. Credit Learning Systems
  145. Does the absense of items on the various SAQs mean they are inapplicable?
  146. Application Account
  147. Hashed PAN as Customer ID
  148. Question about Connected entities (12.10)
  149. PODCast Mistake
  150. Audit or assessment?
  151. Forum Idea - FAQ Sticky Post ?
  152. L2tp/ipsec Vpn
  153. Anti-Virus Solution
  154. Removal of stored CVVs in retrospect
  155. Data Storage -- Requirement 3
  156. Pci Report Templates
  157. Card Holder Data Environment - Scope
  158. Requirement 9 Clarification Please
  159. POS compensating controls
  160. Data Center Camera Recommendations?
  161. Web Server may not access DB Server?
  162. ASV Quarterly Scan Results and Compliance Status
  163. Level 4 requirements
  164. Here's a thought provoking question
  165. COM Components for PCI compliance
  166. Risks around 1.3.2
  167. How to handle third party in PCI environment
  168. Large E-mail Data Store with Card Data
  169. 11.4 IDS/IPS - Core and/or Gateway Required?
  170. PCI DSS without PAN
  171. Huge intranet, class as what?
  172. Windows DEP for AV?
  173. PCI DSS not working in Asian Banking System
  174. Data lost by third party
  175. YASQ (Yet Another Scope Question) - SSH
  176. Communicating with PCI-SSC, or trying to.
  177. 12.5.5 Monitor and Control All Access
  178. ASV Scan Requirements
  179. POS log
  180. One Primary Function Per Server
  181. Card data search tool
  182. Credit Card Statement Conundrum
  183. Using WFP
  184. Network segmentation question
  185. Requirement 1.4 clarification
  186. Key Custodians
  187. Clarification of the 6.6 claritication
  188. PCI Scope
  189. Software based WAF for IIS
  190. Addressing Requirement 8.1
  191. Vulnerability Scan....focus only on the Highs???
  192. Ibm Mainframe
  193. Are Forensic Examinations A Scam?
  194. Third party question
  195. Non Validated Application and Compliance.
  196. Non PCI DSS Compliant Hosting Provider and Audit.
  197. 1.3.8
  198. 3.4 Pan
  199. Cost of Forensic Audit for PCI Breach
  200. PCI DSS Compliance Deadline.
  201. ASV scan reports
  202. 10.2.7 - system-level object
  203. Real world split key/dual control without a HSM
  204. black list / hotcard files
  205. SSL Extension better or worse?
  206. Anti-Virus Logs
  207. Requirement 10.x and HP NonStop
  208. Syslog forwarding agent for MSSQL?
  209. Lunardi’s grocery store PIN PAD Breach
  210. Requirement 9.6 Clarification
  211. Saq C?
  212. Co-server locations
  213. Encryption on “Private” Networks?
  214. PA-DSS list
  215. Backup of Card Data
  216. Segmentation and VLANs
  217. 11.5 and AIX
  218. Password changes stupid question
  219. Truncation of Bank Account Numbers
  220. vulnerability scans
  221. PCI Requirement 12.8
  222. Sniffing Card Data @ Dave & Busters
  223. PCI SSC to release PCI DSS version 1.2 in October 2008
  224. connected entities/third parties
  225. PCI DSS and VOIP
  226. DATA ENCRYPTION - PCI Requirement 3.4
  227. Signature cpature devices
  228. Key management on a POS
  229. Key management on a POS
  230. Service provider or payment gateway
  231. Questionnaire "C"
  232. CC Scan Tools
  233. Application Logs Req. 3.4
  234. Business and Personal Liability
  235. Retired operating systems
  236. req 9.9
  237. PCI and SANs
  238. Franchise & PCI Compliance
  239. Scoping question regarding remote access to data centre.
  240. sahring space in our data center
  241. SAN Drives and Requirement 9.10.2
  242. ASV requalification question
  243. PCI DSS requirement 3.4 hash require a salt?
  244. Wips
  245. Audit non-integrated EFT company
  246. FIM/HIPS list
  247. SAQ D and Standalone Payment Terminals
  248. Another breach
  249. PCI DSS requirements for IAM
  250. Logging all Admin/Root activity (10.2.2)