Society of Payment Security Professionals Forum  

Go Back   Society of Payment Security Professionals Forum > Discussion Groups > PCI DSS Q&A

Reply
 
Thread Tools Display Modes
  #1  
Old 02-26-2009, 10:45 PM
Levis Levis is offline
Member
 
Join Date: Jan 2009
Posts: 50
Default Unattended POS terminals

Hello

based on statue that announces all deployed attended POS PIN acceptance devices must pass testing by a Payment Card Industry (PCI) recognised laboratory and have been approved … Does anybody have any further information about this ? Do you think that here is the possibility, that merchants will have to replace mentioned terminals with PCI certified pos ? Who is responsible for the lab tests, the manufacturer ?

Many thanks for your help and have a nice weekend.

Regards,

Martin

Last edited by Levis; 02-26-2009 at 11:09 PM.
Reply With Quote
  #2  
Old 02-27-2009, 06:26 AM
jbhall56's Avatar
jbhall56 jbhall56 is offline
Senior Member
 
Join Date: Feb 2007
Location: Minneapolis, MN
Posts: 1,282
Default

Go to the PCI SSC Web site at https://www.pcisecuritystandards.org...ratories.shtml for a list of the certified laboratories.

Yes, manufacturers of PIN Pad devices are responsible for obtaining PED certification of their devices.

The card brands and the PCI SSC have mandated the use of PED certified devices for quite a while, so this is nothing new. What is new is the requirement that unattended devices be PED certified by July 2010. We have a number of gas station and convenience store operators that are struggling with the cost of that requirement and are doing their best to comply. What is more interesting is how the financial institution industry will respond as there are a lot of ATMs out there that are not compliant with the latest PED standard.

With the severe downturn in the economy, it will be interesting to see if the Participating Organizations in the PCI SSC push for a delay.
__________________
Jeff Hall, Director, Risk Advisory Services
RSM McGladrey Inc
801 Nicollet Mall, 11th Floor, West Tower
Minneapolis, MN 55402-2526
612 376 9280 - office
612 395 7280 - facsimile
www.mcgladrey.com

The views presented are those of the writer and are not necessarily those of RSM McGladrey Inc
Reply With Quote
  #3  
Old 02-27-2009, 11:47 AM
andrewj's Avatar
andrewj andrewj is offline
Senior Member
 
Join Date: Mar 2007
Posts: 172
Default

The requirement is that all deployed devices must have been evaluated by an approved laboratory by 2010 - not that they are all PCI PED certified. It is acceptable to have devices in the field that are 'pre-PCI' certified; devices that fit into this catagory can be found on the visa PIN website.

The manufacturer is usually responsible for getting devices certified, but this can vary based on contractual arrangements. However, getting certified is not trivial, and (especially with PCI PED v2.x) it is unlikely that devices that have not been designed recently would be compliant.

There is no requirement for unattended devices to have been evaluated by PCI certified laboratories (or to contain an evaluated EPP). The requirement for unattended devices is for them to implement TDES for PIN encryption, and this mandate is not new.

It should also be noted that the overall requirements for unattended devices (Unattended Payment Terminals, or UPTs) has not yet been released as a final version - although it has been released as a draft for some time now. These requirements do not include ATMs - entirely different requirements will be released for these devices, but these standards have not yet been released even as a draft.

People interested in this can email me at andrew.jamieson [at] withamlabs.com (we are one of the PCI PED certified laboratories), and may be interested in the talk I am giving at the ATMIA conference in Sydney, Australia, next month.
Reply With Quote
  #4  
Old 03-08-2009, 01:12 PM
jbhall56's Avatar
jbhall56 jbhall56 is offline
Senior Member
 
Join Date: Feb 2007
Location: Minneapolis, MN
Posts: 1,282
Default

AndrewJ, thanks for straightening me out. I'm not sure what I was thinking when I type up that response. I was obviously on a different path and got all bollixed up in the process. It's what happens to you when you get older.
__________________
Jeff Hall, Director, Risk Advisory Services
RSM McGladrey Inc
801 Nicollet Mall, 11th Floor, West Tower
Minneapolis, MN 55402-2526
612 376 9280 - office
612 395 7280 - facsimile
www.mcgladrey.com

The views presented are those of the writer and are not necessarily those of RSM McGladrey Inc
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 02:43 PM.


Copyright (c) The Aegenis Group, Inc.