thePCI Portal

Author: Ed

COVID and Compliance (April 27, 2020)

Compliance assessment activities and regular compliance activities (i.e. penetration tests, employee training, etc) may be disrupted during COVID. Retail locations may be closed, staff may be unavailable. Obviously human safety trumps any PCI DSS compliance concerns.  Merchants and QSAs do have questions about compliance in COVID times. We are still awaiting to hear  from the acquirers…

Data Flow Diagrams

The Report on Compliance suggests that Cardholder data-flow diagrams may also be included as a supplement to the description of how cardholder data is transmitted and/or processed.  Regardless they are great way to communicate and document the CDE and PCI DSS scope. FAQ Article Number 1178 from February 2011 … An important prerequisite to reduce…

Can switches get updates from the internet and remain PCI compliant?

Assessed entity question:  Can switches get updates from the internet, and remain PCI compliant? QSA’s Sarcastic Question: Where else do patches come from?  🙂  I presume you mean the device actively getting updated from the internet. QSA’s Real Questions: What kind of switches do this? What is the exact mechanism? What is the direction of…

Critical Cybersecurity Hygiene project “Patching the Enterprise”

What is the Critical Cybersecurity Hygiene project “Patching the Enterprise”? The objective of this project is to demonstrate a proposed approach for improving enterprise patching practices for general IT systems. Commercial and open source tools will be used to aid with the most challenging aspects of patching, including system characterization and prioritization, patch testing, and…

Functionality testing to verify that the change does not adversely impact the security of the system

What are Assessor’s thoughts on requirement 6.4.5.3? 6.4.5.3 Functionality testing to verify that the change does not adversely impact the security of the system. 6.4.5.3.a For each sampled change, verify that functionality testing is performed to verify that the change does not adversely impact the security of the system. Thorough testing should be performed to…

eye on PCI v4

full speed ahead on PCI v4

August 25 2020: The council is still analyzing feedback from previous RFC (plan is to comment on all feedback).  Council is preparing the next RFC while updating supporting documents (glossary, prioritized approach, SAQs, etc) and training.   An extended transition period is planned. 3.2.1 to be retired 2 years AFTER the release of v4.0.  Future…

What is e-Commerce?

If I take payments from customers only via an application on their mobile handheld device, is that ecommerce?     (Should my assessor check e-commerce off in my ROC and AOC?)  The application is one I distribute and not a browser. What is e-Commerce? The term ecommerce is not in the PCI SSC Glossary.  There…