What information to be sought from Service Providers to validate its PCI DSS Compliance?

Note: The post written here considering only the Level 1 Service Providers.

As a part of due-diligence or Request for Proposal / Information, clients should verify/validate its merchant / service provider on the PCI DSS Compliance before getting into business or as on going activity if already partnered with Service Providers. The following documents will provide you with reasonable level of assurance to ensure the service provider is compliant with the PCI DSS Standards.

You can also visit the VISA and Master Card Service Providers listing to verify their compliance status,

  1. VISA Service Provider Listing: http://www.visa.com/splisting/searchGrsp.do
  2. MasterCard Compliant Service Provider List: http://www.mastercard.com/us/company/en/whatwedo/compliant_providers.html

Which document to be obtained from Level 1 Service Provider / Merchants to verify its PCI DSS Compliance?

High Level Documents:

  1. CoC “Certificate of Compliance” – certificate issued by PCI-QSA companies to service providers after validating Service Providers PCI compliance. It provides you the assurance that Service Provider has undergone PCI Assessment for the current year mentioned in the certificate and complied with PCI DSS Standard. In addition to the certificate, the payment processing web sites (Considering E-Commerce Sites) may also contains the digital seal issued by the QSA Companies which has the Start date and Expiry date of the PCI Compliance. Level 1 Merchants / Service providers are required to validate their PCI Compliance on Yearly basis by PCI QSA or by an ISA.

Continue reading

Security Considerations in Software Procurement

BSA | The Software Alliance along with Data Security Council of India (DSCI), has released the latest study titled, “Security considerations in software procurement by government agencies in India”,

It takes a detailed look at the Indian government’s and its various agencies’ existing software procurement policies and outlines global best practices for software procurement.

Very Good document helps in developing the procurement process / creating RFP.  All credits goes to DSCI & BSA.

I have also decided to write my next post based on this guide , discussing about what information should be asked in RFP / RFI towards PCI DSS & PA DSS Compliance from the service providers.

Download Link: http://mcaf.ee/n51ou