PCI FAQ
Questions & answers about PCI
Content
» General Questions
» Registration & Certification Procedure
» Technical Requirements for using the PCI DSS Platform
» Self Assessment Questionnaire (SAQ)
» Scanning Process
» Use of the usd PCI DSS Platform
PCI Terms and Aronyms
We have compiled an overview of the most important of terms and acronyms from the world of PCI.
General questions
Nicht bearbeiten!
Your content goes here. Edit or remove this text inline or in the module Content settings. You can also style every aspect of this content in the module Design settings and even apply custom CSS to this text in the module Advanced settings.
What is the PCI DSS?
What are the objectives of the standard's security requirements?
The standard includes security requirements that pursue the following objectives:
- Establishment and operation of a protected network
- Protection of stored and transmitted cardholder data
- Establishment and operation of a vulnerability management system
- Implementation of effective access control policies
- Regular monitoring and review of the IT infrastructure
- Formulating and enforcing an information security policy
What are the objectives of the standard's security requirements?
PCI DSS comprises twelve security requirements. Organizations are considered PCI-compliant if they meet the following requirements:
- Install and maintain a firewall configuration to protect cardholder data
- Changing the default passwords and security settings specified by manufacturers
- Protection of stored cardholder data
- Encrypted transmission of credit cardholder data on public networks
- Use and regular updating of anti-virus software
- Development and use of secure systems and applications
- Restricting access to cardholder data according to business information needs
- Assigning a unique ID for each person with computer access
- Restrict physical access to cardholder data
- Logging and monitoring all access to network resources and cardholder data
- Regular review of security systems and procedures
- Establishment of a company policy with information security guidelines for employees and contractual partners
Which credit card organizations accept certification according to the PCI Data Security Standard?
Almost all large credit card organizations like VISA, MasterCard, American Express, JCB, Discover accept certification according to the PCI Data Security Standard.
Who must be certified according to the PCI Standard?
For e-commerce merchants, service providers and acquirers, the certification of their systems by accredited providers has been made mandatory by the credit card organizations, if they save and process credit card data or pass it on to third parties.
When do I store, process or forward credit card data?
Nicht bearbeiten!
Your content goes here. Edit or remove this text inline or in the module Content settings. You can also style every aspect of this content in the module Design settings and even apply custom CSS to this text in the module Advanced settings.
I work together with a payment service provider which has taken over all settlement tasks for me. Do I still have to be certified according to the PCI Security Standard?
If you store credit card data on your systems or forward them via your systems, you are required to be certified. If you are not sure, please ask your acquirer or our PCI Competence Center.
Does MasterCard or VISA provide information online regarding the topic of PCI?
Detailed information can be found here:
- Mastercard
http://www.mastercard.com/us/sdp/index.html - Visa
https://www.visa.com.bs/run-your-business/small-business/information-security/ais-program.html - PCI Security Standards Council
http://www.pcisecuritystandards.org
According to what guidelines is a merchant and/or service provider classified?
The merchant and/or service provider is classified according to the guidelines of the credit card organizations. An essential factor for the classification is the annual transaction volume. Detailed information can be found here: MasterCard / VISA / American Express.
Self assessment questionnaire (SAQ)
Nicht bearbeiten!
Your content goes here. Edit or remove this text inline or in the module Content settings. You can also style every aspect of this content in the module Design settings and even apply custom CSS to this text in the module Advanced settings.
Do all questions of the Self-Assessment Questionnaire have to be answered?
Which topics does the Self-Assessment Questionnaire include?
The Questionnaire addresses the 12 main requirements of the PCI Data Security Standard (PCI DSS).