Society of Payment Security Professionals Forum  

Go Back   Society of Payment Security Professionals Forum > Discussion Groups > PCI DSS Q&A

Reply
 
Thread Tools Display Modes
  #1  
Old 01-22-2009, 07:12 AM
lalajane lalajane is offline
Junior Member
 
Join Date: Dec 2008
Posts: 10
Default Questions about PCI documentation/reporting

I'm working on standard document templates for our PCI group (we recently became an ASV and QSAC) and have three questions related to PCI documentation and formats.

1. Do we have to keep the PCI SSC logo on documents such as the ASV and QSA feedback forms, the attestation of compliance, and the compensating controls worksheet, or can we replace it with our logo (or no logo)?

2. Can we make changes to the "style" of documents such as the ASV and QSA feedback forms, the attestation of compliance, and the compensating controls worksheet to match our corporate style (as long at the overall layout is the same and the content doesn't change)?

3. The QSA feedback form in the Validation Requirements for QSAs V1.1a is different than the QSA feedback form available on the web site. For example, the feedback form in the Validation Requirements document has 5 choices for responses, but the form on the web site only has 4. And, the feedback form for the payment brands and others in the Validation Requirements document has 6 questions, but the online form only has 3. Which version of the feedback forms should we use - the versions in the Validation Requirements for QSA or the separate versions on the PCI SSC Web site?

Thanks

Jane Laroussi, CISSP, QSA
Reply With Quote
  #2  
Old 01-30-2009, 06:31 PM
jbhall56's Avatar
jbhall56 jbhall56 is offline
Senior Member
 
Join Date: Feb 2007
Location: Minneapolis, MN
Posts: 1,282
Default

Quote:
Originally Posted by lalajane View Post
1. Do we have to keep the PCI SSC logo on documents such as the ASV and QSA feedback forms, the attestation of compliance, and the compensating controls worksheet, or can we replace it with our logo (or no logo)?
No, you do not need to keep the PCI SSC logos on the forms. As a QSA, you should recieve or have access to the Word versions of the Security Assessment Procedures and other documentation.

Quote:
Originally Posted by lalajane View Post
2. Can we make changes to the "style" of documents such as the ASV and QSA feedback forms, the attestation of compliance, and the compensating controls worksheet to match our corporate style (as long at the overall layout is the same and the content doesn't change)?
As far as I'm aware, any forms that go back to the card brands, PCI SSC or the like must remain "as is."

Quote:
Originally Posted by lalajane View Post
3. The QSA feedback form in the Validation Requirements for QSAs V1.1a is different than the QSA feedback form available on the web site. For example, the feedback form in the Validation Requirements document has 5 choices for responses, but the form on the web site only has 4. And, the feedback form for the payment brands and others in the Validation Requirements document has 6 questions, but the online form only has 3. Which version of the feedback forms should we use - the versions in the Validation Requirements for QSA or the separate versions on the PCI SSC Web site?
We always use the forms from the Web site as they are always keep current.
__________________
Jeff Hall, Director, Risk Advisory Services
RSM McGladrey Inc
801 Nicollet Mall, 11th Floor, West Tower
Minneapolis, MN 55402-2526
612 376 9280 - office
612 395 7280 - facsimile
www.mcgladrey.com

The views presented are those of the writer and are not necessarily those of RSM McGladrey Inc
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 02:35 PM.


Copyright (c) The Aegenis Group, Inc.