Skip to main content

Questions tagged [pci-dss]

An acronym for Payment Card Industry (PCI) Data Security Standard (DSS). A set of rules and policies for protecting information related to card based financial instruments.

0 votes
1 answer
90 views

I’m evaluating a scenario involving shared workstations in a PCI‑scoped environment where multiple authenticated users access the same application on the workstation throughout the day. Observed ...
Ken Pyzik's user avatar
0 votes
1 answer
64 views

My company has a small call center. Less than 100 people. Currently we do not do any credit card transactions but are looking to do so in the future. One potential client has us using their ...
Magellan Jim's user avatar
0 votes
0 answers
87 views

I have been asked to implement a new payment system that uses Google/Apple Pay's Direct integration (using Tokenized PANs (DPAN), not clear cards) as well as a similar Tokenized PAN retrieved from our ...
APagonis's user avatar
0 votes
1 answer
231 views

If TLS is disabled on a network-attached Hardware Security Module (HSM), but the device still enforces: IP-based access control (only whitelisted client IPs can connect), and PKCS#11 slot PIN ...
user's user avatar
  • 101
1 vote
2 answers
171 views

I’m trying to understand a PCI DSS SAQ A requirement that says: "All elements of the payment page(s)/form(s) delivered to the customer’s browser originate only and directly from a PCI DSS ...
Lachgar Nour Eddine's user avatar
5 votes
2 answers
747 views

PCI compliance requires us to rotate passwords, but mainly seems to allow us to attest to the fact that we rotated the passwords based on trust that the work we say we're doing is getting done. But as ...
Peter Turner's user avatar
1 vote
1 answer
251 views

I have an app where a person enters their card number, the cardholder's name, the expiration date and the cvv. I am now making it pci/dss-compliant. I will store the card number in an encrypted way. ...
gisly's user avatar
  • 113
2 votes
1 answer
223 views

Hypothetical: Company A accepts credit card payments and must be PCI compliant. Company B provides domain registration (but not DNS or web hosting) services to Company A. Some of these domains are ...
Jordan Rieger's user avatar
3 votes
1 answer
216 views

This Q pertains to PCI DSS v4.0 SAQ A - previous Q&A only touched on previous versions of PCI. Since 4.0, merchants that accept credit card payment, even if they only iframe or link to their ...
bukwyrm's user avatar
  • 131
5 votes
0 answers
85 views

We are a medium sized organization and use Payment Service Providers for all purchases, including credit card and non-credit card purchases. We get yearly audits and our internal payments platform is ...
jtkline's user avatar
  • 51
6 votes
1 answer
327 views

Payment facilitators like Stripe provide card payment terminals to their customers. These devices must be periodically inspected, per requirement 9.5.1.2. How does the payment facilitator handle this, ...
aantia's user avatar
  • 161
0 votes
1 answer
94 views

I have established that my business needs to complete a PCI DSS SAQ-D form for attesting PCI compliance... twice - once as a merchant and once as a service provider! Even completing it once is a ...
John Rix's user avatar
  • 133
1 vote
1 answer
88 views

I'm evaluating a contract management software that claims PCI compliance for my CC data. However, I am going to use the software to issue contracts to my customers where they directly enter credit ...
BambiBundle's user avatar
0 votes
0 answers
119 views

What type of PCI 4.0 Assessment are Service Providers doing when they have no CDE, they do not accept or process credit cards, but instead use another service provider for those services?
Marc F. Schultz's user avatar
25 votes
3 answers
8k views

We have recently developed a web application with a RESTful API backend. This web app need to have a certain security certification (something called PCI-DSS), and thus it is being scanned ...
Dantre's user avatar
  • 353

15 30 50 per page
1
2 3 4 5
47