PCIParanoid
03-13-2009, 06:33 AM
We currently have MSR's in our environment (Magnetic Strip Readers). The PCI-PED Security requirements state that we need to inventory PED's (obtain and track information about each PED device and comply with a list of approved PED devices) but it does not talk about MSRs and how they are handled.
So I have three questions about MSRs please:
1) Are MSR's supposed to be treated the same way as PEDs and follow the PCI-PED standards?
2) More specifically, are MSR's supposed to be inventoried/documented like the PEDs? Are they supposed to have a list of approved "MSR" devices like PEDs do?
3) If they are not supposed to be treated the same as PED's, why?
TIA for patience and help!
So I have three questions about MSRs please:
1) Are MSR's supposed to be treated the same way as PEDs and follow the PCI-PED standards?
2) More specifically, are MSR's supposed to be inventoried/documented like the PEDs? Are they supposed to have a list of approved "MSR" devices like PEDs do?
3) If they are not supposed to be treated the same as PED's, why?
TIA for patience and help!