PDA

View Full Version : 4 New PCI SAQ's - SAQ v1.1


dbergert
02-05-2008, 03:28 PM
see:

https://www.pcisecuritystandards.org/tech/saq.htm

and:

https://www.pcisecuritystandards.org/pdfs/instructions_guidelines_v1-1.pdf


A: Card-not-present (e-commerce or mail/telephone-order) merchants, all cardholder data functions outsourced. This would never apply to face-to-face merchants.

B : Imprint-only merchants with no electronic cardholder data storage

B : Stand-alone terminal merchants, no electronic cardholder data storage

C: Merchants with POS systems connected to the Internet, no electronic cardholder data storage

D: All other merchants (not included in Types 1-4 above) and all service providers defined by a payment brand as eligible to complete an SAQ.

bhuebner
02-06-2008, 08:28 AM
The 4 different versions are actually listed on this page, it is not apparent from their links:
https://www.pcisecuritystandards.org/tech/instructions.htm

mdahn
02-06-2008, 08:39 AM
My overview and highlights. http://pcianswers.com/2008/02/06/self-assessment-questionnaire-saq-v11-released/

Read through the FAQ for details on compensating controls and sunset dates for the old v1.0.