Which is the following responsibility of a QIR? - Answers Install payment applications in a
manner which supports the customers PCS DSS compliance.
What does the Councils Standards Include? - Answers The Council's standards include the PCI
Data Security Standard, the Payment Application Data Security Standard, the Point-to-Point
Encryption Standard, the PIN Transaction Security Point of Interaction, Hardware Security
Module and PIN standards, the Card Production standards, and all of their supporting
documents.
What happens in the clearing process? - Answers In the Clearing process, the acquirer and
issuer need to exchange purchase information to complete the transaction.
The process includes:
1. The acquirer sends purchase information to the payment brand network.
2. The payment brand network sends purchase information to the issuer, which prepares data
for the cardholder's statement.
3. The payment brand network provides complete reconciliation to the acquirer.
This process usually occurs within one day in North America and may vary in other countries.
When does PCI DSS apply? - Answers wherever cardholder data is being stored, processed or
transmitted. It therefore applies to all entities involved in payment card processing, including
merchants, processors, acquirers, issuers, and service providers, as well as all other entities
that store, process, or transmit cardholder data or sensitive authentication data.
What are some of the acquirers responsibilities? - Answers For working with merchants and
their service providers to ensure that they:
Review and understand PCI DSS
Understand their compliance and validation requirements
Validate and report compliance to the acquirer
Maintain on-going compliance
Read and incorporate on-going communications
QSA Responsibility - Answers In all cases, the QSA must first evaluate and document how the
compensating control meets the intent of the requirement.
,ISA Responsibility - Answers As compliance is an ongoing process, internal assessors should
help their stakeholders to understand PCI DSS requirements, meet compliance obligations and
increase their security awareness if needed.
PA QSA Roles - Answers The PA-QSA's role is to perform assessments according to the PA-DSS
security assessment procedures and per their PA-QSA validation requirements, to render
opinions about an application's compliance status, to adequately document the results of their
review, and to submit all required documentation to PCI SSC. Both QSAs and PA-QSAs are
required to maintain an internal quality assurance program to ensure their work meets
expectations.
Acquirer Roles - Answers it is the acquirer who is responsible for the compliance validation of
their merchants. This could involve determining the merchant's reporting method, accepting
compensating controls, as well as any necessary actions resulting from data breaches such as
passing on fines and supporting forensic investigations.
QIR Installation - Answers Assessors are encouraged to review any QIR documentation for
information that may help with the PCI DSS assessment. However, it's important to remember
that, while the QIR documentation may provide useful information about what to look for, the
application or environment may have changed since the installation took place, and the
information documented by the QIR may no longer represent the current configuration. A
Qualified Installation, therefore, does not remove the need for a proper PCI DSS assessment or
reduce the level of testing to be performed.
Service Provider - Answers The definition for a service provider is a business entity directly
involved in the processing, storage, or transmission of transaction data or cardholder data on
behalf of another merchant or service provider.
Service providers also include companies that provide services which control or could impact
the security of cardholder data. Examples may include providers of managed firewalls, IDS and
other security services, as well as hosting providers and other entities. So to confirm, when an
entity is processing, storing or transmitting cardholder data on behalf of another entity, or they
have access to another entity's cardholder data, they are a service provider.
Entities using third party service provider? - Answers Entities often use third-party service
providers to store, process, or transmit cardholder data on their behalf, or to manage system
components - such as routers, firewalls, databases, physical security, and/or servers - in their
CDE.
Entities should clearly identify the services and system components which are included in the
scope of their service provider's PCI DSS assessment, as well as the PCI DSS requirements
, covered by the service provider and any requirements which need to be covered by the entity
itself.
There are two options for third-party service providers to validate compliance: They can undergo
a PCI DSS assessment on their own and provide evidence to their customers to demonstrate
their compliance; or, if they do not undergo their own PCI DSS assessment, they can have their
services reviewed during the course of each of their customers' PCI DSS assessments.
If the third party undergoes their own PCI DSS assessment, they should provide sufficient
evidence to their customers to verify that the scope of the service provider's PCI DSS
assessment covered the services applicable to the customer and that the relevant PCI DSS
requirements were examined and determined to be in place. The specific type of evidence
provided by the service provider to their customers will depend on the agreements and/or
contracts in place between those parties.
Entities using third party service providers will also need to apply PCI DSS Requirement 12.8 to
each service. We will look at this requirement in more detail later in the course.
Requirement 12.9 states that a service provider must maintain a template, to provide to their
clients that states they will agree to maintain all applicable PCI DSS controls. This template will
vary depending on the type of service provider the entity is and the type of services purchased
by th
Reducing Impact of Breach - Answers It is important to understand that even if it is difficult to
*prevent* such an attack, controls should be in place to help *detect* the skimmer and reduce
the impact of the breach.
A defense against modified terminals - Answers A defense against rogue or modified terminals
is good terminal inspection and inventory practices. If a new terminal appears or a terminal
disappears from one store and shows up at another, this should be noticed when the device is
inspected and serial numbers are checked. The inspection should also detect the skimmer. She
told them they would need to periodically inspect the devices as instructed in requirement 9.9.2,
looking for any signs of tampering.
Beth also helped train the staff to be aware of suspicious behavior, per requirement 9.9.3. The
Toasty Tavern employees know repairmen need to show ID before touching the registers, and to