Skip to main content

Questions tagged [pci-dss]

An acronym for Payment Card Industry (PCI) Data Security Standard (DSS). A set of rules and policies for protecting information related to card based financial instruments.

0 votes
1 answer
37 views

My company has a small call center. Less than 100 people. Currently we do not do any credit card transactions but are looking to do so in the future. One potential client has us using their ...
Magellan Jim's user avatar
0 votes
1 answer
194 views

If TLS is disabled on a network-attached Hardware Security Module (HSM), but the device still enforces: IP-based access control (only whitelisted client IPs can connect), and PKCS#11 slot PIN ...
user's user avatar
  • 101
5 votes
2 answers
718 views

PCI compliance requires us to rotate passwords, but mainly seems to allow us to attest to the fact that we rotated the passwords based on trust that the work we say we're doing is getting done. But as ...
Peter Turner's user avatar
2 votes
1 answer
208 views

Hypothetical: Company A accepts credit card payments and must be PCI compliant. Company B provides domain registration (but not DNS or web hosting) services to Company A. Some of these domains are ...
Jordan Rieger's user avatar
5 votes
0 answers
74 views

We are a medium sized organization and use Payment Service Providers for all purchases, including credit card and non-credit card purchases. We get yearly audits and our internal payments platform is ...
jtkline's user avatar
  • 51
0 votes
1 answer
88 views

I have established that my business needs to complete a PCI DSS SAQ-D form for attesting PCI compliance... twice - once as a merchant and once as a service provider! Even completing it once is a ...
John Rix's user avatar
  • 133
0 votes
0 answers
101 views

What type of PCI 4.0 Assessment are Service Providers doing when they have no CDE, they do not accept or process credit cards, but instead use another service provider for those services?
Marc F. Schultz's user avatar
2 votes
1 answer
197 views

On my website, payments are done using a PCI-compliant 3rd partner. If the client agrees, I store a TOKEN of the card (returned by the PCI partner). I want to make a new payment with CVV for the ...
Emmanuel Gleizer's user avatar

15 30 50 per page
1
2 3 4 5
47