- Gateway/Processor Compliance Criteria
- Welcome to PCI Answers
- Pen Testing Requirements
- PCI Audit by Internal Audit
- Vendor Compliancy Dates
- PAN (account number / card number) digits to be displayed
- Company move - Physical relocation & PCI
- Rules for small online merchants
- Audit Timing
- Wireless Scanning obligations for merchants
- Fines for Non-Compliance
- Encryption requirements for PANs in databases
- Network Sniffing and PCI
- Disk Encryption
- Compensating Controls - Lack of IDS
- Background Checks
- Mainframe/AS400 Best Practice
- public key authentication
- SQL Database Replication - Does it meet requirement?
- PAN Masking
- Destroying back ups of keys
- Compensating Controls - Requirement 2.2.1
- Compliance and Point of Sales
- non-console access, 2.3
- Incident Response Testing
- PCI DSS Applicability Information
- Back-up Network Q
- Not a Connected entity? (12.10)
- SIEM/ Log monitoring
- PAN in IVR
- sensitive authorisation data
- More (or less) on encryption requirement
- CVV2/CVC2 - yet again.
- Non-Merchant/Service Provider Entity...PCI On-Site Audit Required?
- Limiting the Scope for Assessment
- Section 12.8 requirements
- Terminals - Single Use
- Is virtualization compliant
- POS and PCI requirements
- 2-way encryption
- How to define the environment?
- application types?
- Mainframe Encryption
- Security reports for Audits and Compliance
- Is it allowed to print a full PAN on a customer receipt?
- File Integrity Monitoring - Compensating Controls
- Application Hosting Service Providers
- POS system A/V and spyware
- Evaluating Logging Appliances (10.X)
- Satisfying "dual control" and multiple admins
- Will PCI DSS make small ISOs disappear?
- Enterprise Directories and 8.5.5 Compliance
- Record Retention Policy in a payment card processor
- Cost to become DSS compliant for level 4 merchant?
- PCI item 3.6.4 Periodic Key Changes
- Windows NT and PCI Compliance
- 8.5 Remove inactive user accounts at least every 90 days
- Insurance Companies and their Agents
- POLL: Solutions for meeting PCI Compliance
- POS-Password requirements-Windows passwords
- PCI Compliance project
- Mass network segmentation
- PCI DSS Report Templates
- Limitation of Scope and Active Directory
- Web hosting providers
- Control 6.6
- Legally breaking the DSS
- Split Knowledge and Dual Control PCI Requirement
- PCI compliance and POS software
- Encryption requirement
- Remove the need for Password Complexity in Linux - Use SSH Keys?
- "Data at Rest"
- Encryption with Oracle / Stored Procedures
- Rated audit procedures
- Log Validation Question?
- Patch Mgmt - Vulnerability Scans for Workstations
- CVC2 Authorisation for back orders
- I don't store PCI data, I just issue cards as a small bank...
- 1.3.8 - WLAN - what is this trying to say exactly
- Quarterly network scans
- Use of server virtualization to create network zones
- Cross cut shredder
- PCI requirements in transmitting cardholder data
- Clarification request.
- Expired Self Assessment
- Avionics and PCI
- Masking PAN
- Use of Credit Card Data as reference for identification
- Non-compliance fines in Europe
- Level 4 paper based merchant - PCI/DSS ??
- Card Expenditure Information Management Software
- Removal of Credit Card Data (Outsourced) from Network
- web app accepts credit card numbers
- 6.6 Clarification
- Information Requested!
- some basic information required
- Requirement 8: Unique ID
- Two-factor authentication
- First time unique password
- encrypted email & data stored on server
- Credit Card data location
- Identifying Credit Card Details within Emails
- Type of Firewall
- Mailed Prohibited Data
- Is Amex doing their own thing?
- Third party web hosting
- Internal Audit - L1 Merchants
- Dedicated Credit Card Payment Terminals & CHD Envrionment
- Plesk Software : PCI req 2.2.4
- Credit card vs. debit card algorithm
- Compliance requirements for 3rd parties?
- Split knowledge key
- Section 1.1.4 Clarification.
- Determining strength of a compensating control
- 90 day password change policy
- Level 1 Annual On-Site Security Audit Clarification!
- 3.6.10 Key Custodians form
- Policy
- Req 10 Discrepancies
- Security Tools
- Synchronize router configuration files
- POS and PCI (Yet Again)
- Transmission encryption
- Opions Requested Please.
- Back-out procedures
- External Scans?
- Regarding separation of servers
- PCI DSS Novice Questions...
- cvv2 in voice recordings....
- 10.2.7 Creation and deletion of system-level objects.
- Enrypted Data Delivery
- Does PCI DSS apply to my company?
- apps that have nothing to do with credit card info?
- "system components"??
- Shared web hosting and the tiny merchant
- Use of Network Services Provider
- Application Encryption Vs TDE for cards stored in a DB
- CVV2 data -ok to store and then forward?
- Remote Access question
- 12.8.1
- 3.2 Question re. duration
- Re-Audit Question
- Rc4
- Application Layer Firewall/Content Filtering - Decrypt SSL packet for inspection?
- Factors
- California AB 779 Payment Verification Code and Value
- Two Factor Authentication - Cisco Secure Remote VPN
- PCI DSS, PCI PIN, Merchant and Service Provider
- Definition of System Level Object
- Is a hosting provider responsible for PCI compliance of its customer's application
- Firewall Packet Filtering
- Shared user name and password
- Outlook forms that send credit card info
- 2.2.1--Clarification Request.
- Web Application Scope
- The practical definition of Host Intrusion Detection
- Software, hardware firewall
- Network Layer Penetration Testing
- Compensating Controls PCI DSS 3.4
- Truncation of data
- Definition of "system configuration standards"
- timescales
- 5.1 Clarification Request.
- Open Items Question
- QSA required to evaluate/affirm compensating controls?
- Scope with truncated data?
- Scan / Fax of CHD - Advice please!
- Service charges
- pci policy
- Is DMZ required?
- Level 1 service provider?
- Credit card terminals on LAN
- Web Application Scope - Another
- e-commerce transactions and payment gateways
- hardcoding passwords in code
- Application Scope
- Which Windows event logs to monitor?
- 3.6.6 - Split knowledge of keys
- DR Hosting Provider
- Level 4 Merchant with no Online Transactions
- Network Segmentation
- 6 Million per Vendor or Combined?
- Service Provider
- Payment Service Provider Exempt From 12.8?
- Questions To The PCI SSC
- Split knowledge / Proper storage of keys - Data at rest scenario
- Do Cardholders have to be PCI DSS compliant?
- Firewall placement and PCI compliance
- Proxy based firewalls
- Merchant vs. Service Provider
- Contactless Payments / RFID Readers
- Proprietary Encryption Algorithms
- Self Assessment Questionaire
- Safe Harbor
- Source Code Analysis and Web Application Scanners?
- HP3000 - PCI Compliant Device?
- Small merchant - Need help understanding questions
- PCI and compliance deadline
- Hosting Provider Compliance?
- SSL v2 and PCI DSS Compliance
- Hashed and Truncated Data
- Validation at DBA level
- Using secure web site only
- Scanning Procedures and Mail Servers
- Requirement 9.2 Visitors/Personnel easily distinguishable
- Network "scope" / Segmentation Question
- Date for 6.6 to be 'in place'?
- Segmentation question "Communicating into the CHE"
- Required to comply?
- MPLS - private or public
- Question about HSM-less batch processing
- Please advise on this weird compliance situation
- PCI DSS General clarifications
- Encrypt data other than PAN
- Regarding ssl connection on a server
- Network Security
- Question on wireless segmentation
- Service Accounts and PCI Compliance
- Vulnerable Payment Applications
- Quarterly Vulnerability Scans
- 4.1.1. clarification
- Remote Travel Agents Working From Home
- 1.3.4 and SBS 2003
- Website with Frames - Scope Question
- Firewall for internal server
- Versions of software
- Wireless device compliance
- Compliance dates
- Bank Tactics
- Req 1.3.9 and jumpstations
- Requirement 8.4, stored passwords
- Point of Sale Logging
- Confusion on MasterCard Reciprocal Clause
- Service Provider w/o Acquirer - Does that make sense?
- Wireless confusion
- POS logging - IBM 4690
- Internet Merchants - In or out of scope
- Internet Merchants - In or out of scope
- Firewall requirement on servers
- App Pen Testing Requirement by Breach App FW?
- Hashing Versus Encryption
- Keeping a Commerce Website Out of Scope
- Requirement 2.3, encrypting non-console access
- 8.5 and Application Service Providers
- cc data discovery tools
- Pci 1.1
- PCI compliance in desktop application
- 3rd Party Application/Colocation Facility Question
- requirement 6.6
- PSP Full Compliance