View Full Version : PCI DSS Q&A
- Non-console rdp access for windows systems
- PCI Compliant Fax Solutions (9.6: 3.1, 3.3, 3.4, 4.1, 4.2, 12.8.1, 12.8.2)
- PAN Last 10 Digits
- Fake CA cert created using MD5 collisions
- PCI Security Standards Council Reference #022007249
- Bluetooth Encryption
- Visa Gas Pump Deadline
- File encryption solution.
- Encryption and Key Management solution
- PCI DSS 6.3.2 Clarification
- PCI Standards Presentations
- Help desk access to webserver across the Internet.
- POS terminals vs vulnerability scan
- Scoping Question - DMZ
- Question of Scope
- PCI DSS in Saudia Arabia
- Scope of scan
- Shared Hosting and PCI DSS
- PCI DSS 12.3.4: Interpretaion of device
- Scope Creep?
- Mandatory On-Site Data Center Visits?
- Questions about PCI documentation/reporting
- Questions about encryption of customer data on consultant's laptops
- Questions about 2 ASV requirements
- Basic PCI question
- SSL v2 or V3
- Software piracy
- PCI DSS req. 3.3
- Determining Merchant level
- Complete 3rd Party Outsourcing
- Disaster recovery plan
- Internal Scan Scoping and Procedures Question
- ASV Scans: ICMP ECHO compliant or not?
- PCI DSS req.9.2
- Threat from Keyloggers
- Procedure for unmasking PANs
- PCI Scope for Issuer Banks
- PGP Passphrase storage & usage
- 5.2 - "actively running"
- v1.2: remediation requirements for application vulnerabilities?
- Internal and external
- Cardholder Data Clarification
- Submission of documents with IP addresses
- PCI DSS China?
- Conglomerates, subsidiaries, and acquirers
- How can I get started?
- Acquirer scans
- Contracted Vendors and 12.8
- Shared Hosting - Getting started with PCI
- What is the difference between the Service code and the CID, CAV2, CVC2 and CVV2????
- ...and what exaclty is the "Service Code" used for??
- What about an application that "phones home"?
- PA-DSS and July 2010
- Retailer Phishing Scam
- Verizon Broadband card PCI compliant?
- Hardest Thing About PCI DSS?
- Question of outsourcing payment processing
- Vendors Running CCs over Your Network
- PCI DSS is FUN!! (Compliance from scratch)
- Legacy Code Platform Compliance?
- Unattended POS terminals
- Grocery chain and wireless ordering questions
- I need advice on a 2 factor authentication system
- Code Review or Web Application Firewall
- POS scoping question
- Production vs. Test
- Mag Stripe Reader Compliance
- Non-applicability of external scanning
- Voice Data!
- "No Impact Change Report" for Versioning?
- PCI DSS Antivirus Replacement
- Recovering the Cost of Compliance from Customers
- Domain Controller & FileShare Server
- Removing WEP networks from Scope?
- In or out of scope?
- Workstation Scoping!
- What is a Certificate of Compliance?
- Individual Card Brand Operating Regulations - SAD retention pre authorisation
- Scope of Compliance
- Contrasting PED/EPP with MSR Requirements?
- PCI Documentations
- PCI DSS and Citrix
- SNMP v2
- SNMP community string changes
- Published Versioning Issue, maybe...
- Log Data and Use of UDP
- Insuring against potential PCI related liability
- Req. 9.7.1 media classification
- MQ series and PCI Compliance
- Can we give "Trace" Files to a PCI DSS Compliant software developer?
- Can a Service Provider also be a Shared Hosting Provider?
- What does it take to become a ASV
- HomeATM: First Ever Web PCI 2.0 PED Cert
- Minimizing scope
- Physical security
- E2E Encryption Prescription Is Bad Medicine
- Encrypted transmission of cardholder data
- Acting as an agent for a merchant
- AJAX, Web services and PCI
- IPhone App and PCI
- Deciding which SAQ with Microsoft RMS
- Question on Enterprise Admin access...
- Is Heartland/WorldPay Suspect in Custody?
- Encrypted cardholder data is NOT cardholder data !!??
- 10.2.1 - All individual accesses to cardholder data
- Flat network
- Who should see your SAQ?
- scan validation requirement
- Exception Processing and PCI Requirements
- PCI Services
- Confusion/Conflict Resolution
- Payment Card Industry Swallows Its Own Tail
- PCI SSC Member QSA Training
- I need an advice
- Need Help on Finding Good Payments Industry Resources
- Is "Cards & Payments" a good resource?
- Getting Exceptions from Acquirer?
- PCI DSS req. 4.1
- Call Recording and Screen Scraping
- Acquirer/Issuer banks
- Quarterly scans necessary?
- Service Provider with limited access to card data
- CVV and mail order
- PCI DSS Requirement 10: Track and monitor all access to network resources and cardhol
- IBM ZOS Mainframe and EAL-5
- Can a Level 2,3,4 Merchant get a Level 1 PCI Report on Compliance??
- Retrieve Customer PIN
- What can be done on the workstation?
- PAN in emails
- Drivers License and SSNs?
- AIX server hardening
- ATM Replacing for PCI Complianct
- Antivirus on Linux, really?
- Security Awareness Acknowledgment
- Requirement 1.0 & 1.1 Scope
- 6.5 development process
- Patch Testing Compensating Control
- Visa mandate June 2009 CVC Required
- AV software
- Advice with Requirement 2.3 on Suse Linux (AS400 LPAR) Power Series??
- Unique ID/Passwords (8.5.8 & 8.5.16
- Scan requirement related to a mainframe
- 6.3.4 Sanitizing Live Data
- 1.3.3 - outbound traffic from the cardholder data environment
- Link to PayPal
- Encryption required for partial cardholder data
- Requirement 7.1
- Reducing scope to web servers
- Walmart commentary
- req 12.5.5
- 11.1 - How do you use wired analysis tools effectively w/wireless analysis tools
- Reporting Requirement For PCI DSS
- Rigid Dates for Future Compliance
- Definition Request
- Insurance Against Breach Exposure
- Yet another scoping question
- level 2 or level 4?
- PCI DSS Remediation Output
- PCI DSS and Business Continuity
- “Incident Response Plan”
- 2-factor logins not required if...
- 1.1.2 Current network diagram.
- Hosted Websites - Merchant Compliance Requirements
- Scoping laptops
- 11.4 IPS/IDS What is needed on large network
- Small Business Server 2003
- section 3.6 - key management
- Outbound Connection Question
- In scope or not in scope that is the question..
- ISeries & LPARS
- Req 3.4
- Question for Retailers with many stores/locations.
- Call Recording Solutions
- Pen testing scope
- Firewall vs IDS
- Feistel Finite Set Encryption Mode (FFSEM)
- Quarterly External Scanning.
- Network segmentation guidance
- Physical Media (paper shredding)
- About the database schema
- About the 3.1 requirement
- Requirement 3.4, Render the PAN unreadable
- Requirement 10.2.4 Audit trails and logs
- Requirement 10.2.7 system-level objects
- 10.3.3 Requirement date and time
- Requirement 10.3.5 Origination of event
- Requirement 10.3.6 resource
- Workstation Host IDS/Firewall as segregation?
- When are companies PCI compliance expire
- Document management thoughts?
- External Scans 11.2 - Disabling perimeter firewalls to accept scanning source
- What is guidance on use of SFTPS sites?
- 9.9.1 Maintain inventory logs
- Merchant Gift Cards
- File Integrity Monitoring - What Files to Monitor
- Split knowledge and dual control & Web Services
- Is it possible to use McAfee HIP to segregate servers?
- Interesting leased line issue
- Can VLAN's be used as network segmentation and if so what would an QSA look for
- Requiremet 1.3.5 Restrict outbound traffic
- Merrick Bank v. Savvis: Potential Game Changer
- Hosting Provider Customers
- DNS Servers - PCI Scope Question
- Unencrypted Emails sent - are we responsible?
- Acquirer question
- End-to-end encryption...how to process the offline/imprint transactions?
- 6.3.7 Review of custom code
- "Risk based"
- What does a 11.1a Report Look Like
- PCI-DSS Confusion
- Tokenization/hashing
- Amex requesting unecrypted CC#s
- A/P Article On PCI
- Level 1 Merchant AOC
- This is where I'm getting my advice
- New to PCI and the Forums
- PCI SAQ C questions.
- DMZ requirement
- "Mastercard gets tough on level 2 merchants"
- Configuration Standards
- dm-crypt and key management
- Install and maintain firewall configuration
- QSA vs. CPISM/CPISA
- More Internal Scoping Questions
- Auditable Event Definition
- Bill Pay Service Providers
- Rogue AP Scans - What are you doing?
- Savvis Files Motion to Dismiss Merrick Bank Lawsuit
- How & in what capacity does your organization store, process and transmit cardholder?
- Question on Email Server
- NAT (Network Address Translation) 1.3.7
- credit recovery and collections department in an issuing bank
- Outsourced development activity
- Segmentation of CDE - Experience in scope reduction /costs
- Req 2.4 Question
- Camera's in DC
- Restaurant bartenders holding tabs open by keeping credit cards behind the bar
- automated access control
- Trusted vs Untrusted
- New Member PCI Questions
- Value of being a Participating Organization?
- 2.2.1 One primary function per server
- PCI DSS - Penetration Test Report
- pci certification
- Requirement 10 question
- verification of equippment which is not in PCI scope
- PCI Incident Response: A Legal Perspective
- 3.2.* Database schemas
- QSAs now want scanning for stored Card Data performed
- Logging
vBulletin® v3.7.4, Copyright ©2000-2010, Jelsoft Enterprises Ltd.