PCI QSA Exam
A1.1 - ANS-Multi tenant provider providers need to protect and separate clients
A1.2 - ANS-Multi tenant carrier carriers should facilitate logging and incident response for all
clients
A2.1 - ANS-POI with SSL/early TLS should verify that not liable to acknowledged exploits or
have hazard mitigation in area
A3.1 - ANS-DESV requirement: a PCI DSS application is carried out
A3.2 - ANS-DESV requirement: PCI DSS scope is documented and validated
A3.Three - ANS-DESV requirement: PCI DSS is implemented in BAU activities
A3.Four - ANS-DESV requirement: logical access to the CDE is controlled and managed
A3.5 - ANS-DESV requirement: suspicious events are recognized and spoke back to
Access evaluation cadence (user account and alertness/system account) - ANS-User debts:
Every 6 months
Application/machine money owed: periodically as defined via the TRA
acquirer - ANS-The merchant's bank
AOC - ANS-Attestation of Compliance; a document created to share with other groups that
offers the relevant records but limits the exposure of all information. Akin to an Executive
Summary.
Appendix A1 - ANS-Additional requirements for Multitenant Service Providers
Appendix A2 - ANS-Additional necessities for SSL or Early TLS
Appendix A3 - ANS-Designated Entities Supplemental Validation (DESV)
Appendix B - ANS-Compensating Control facts
Appendix C - ANS-Compensating controls worksheet
, Appendix D - ANS-Customized Approach records
Appendix E - ANS-Customized technique sample templates
Appendix F - ANS-Using SSF to support Requirement 6 data
Appendix G - ANS-Glossary of PCI terms
ASV - ANS-Approved Scanning Vendor; eligible to perform external vulnerability scans for a PCI
engagement.
Audit log records requirement period - ANS-three hundred and sixty five days retained, 3
months available for evaluation
Audit log evaluate cadence (critical) - ANS-Daily
Can cardholder records or SAD be saved after authorization if included? - ANS-Cardholder facts
can, SAD can't.
Cardholder - ANS-Person to whom a financial transaction card is issued, or an extra character
legal to apply the card.
Cardholder Data (CHD) - ANS-Any form of in my view identifiable statistics (PII) associated with
a person who has a fee card, along with a credit score or debit card.
PAN, cardholder call, expiration date, service code
Critical/high patch cadence - ANS-Within 1 month of release
Cryptography suites and protocol review cadence - ANS-Annual
Customized approach - ANS-The entity builds their very own manage the usage of the custom
designed approach steering to fill the spirit of the manage. This is predefined, and need to be
documented with a TRA executed to reveal the mischief is nicely controlled.
Defined method - ANS-The explicitly described necessities on a PCI DSS assessment. These
need to be assessed using the described checking out system except there's a legitimate
commercial enterprise or criminal difficulty, in which a compensating manipulate can be
designed.
Describe the authorization technique - ANS-1. Cardholder requests the acquisition from the
service provider
2. Merchant contacts acquirer
3. Acquirer contacts charge emblem network
A1.1 - ANS-Multi tenant provider providers need to protect and separate clients
A1.2 - ANS-Multi tenant carrier carriers should facilitate logging and incident response for all
clients
A2.1 - ANS-POI with SSL/early TLS should verify that not liable to acknowledged exploits or
have hazard mitigation in area
A3.1 - ANS-DESV requirement: a PCI DSS application is carried out
A3.2 - ANS-DESV requirement: PCI DSS scope is documented and validated
A3.Three - ANS-DESV requirement: PCI DSS is implemented in BAU activities
A3.Four - ANS-DESV requirement: logical access to the CDE is controlled and managed
A3.5 - ANS-DESV requirement: suspicious events are recognized and spoke back to
Access evaluation cadence (user account and alertness/system account) - ANS-User debts:
Every 6 months
Application/machine money owed: periodically as defined via the TRA
acquirer - ANS-The merchant's bank
AOC - ANS-Attestation of Compliance; a document created to share with other groups that
offers the relevant records but limits the exposure of all information. Akin to an Executive
Summary.
Appendix A1 - ANS-Additional requirements for Multitenant Service Providers
Appendix A2 - ANS-Additional necessities for SSL or Early TLS
Appendix A3 - ANS-Designated Entities Supplemental Validation (DESV)
Appendix B - ANS-Compensating Control facts
Appendix C - ANS-Compensating controls worksheet
, Appendix D - ANS-Customized Approach records
Appendix E - ANS-Customized technique sample templates
Appendix F - ANS-Using SSF to support Requirement 6 data
Appendix G - ANS-Glossary of PCI terms
ASV - ANS-Approved Scanning Vendor; eligible to perform external vulnerability scans for a PCI
engagement.
Audit log records requirement period - ANS-three hundred and sixty five days retained, 3
months available for evaluation
Audit log evaluate cadence (critical) - ANS-Daily
Can cardholder records or SAD be saved after authorization if included? - ANS-Cardholder facts
can, SAD can't.
Cardholder - ANS-Person to whom a financial transaction card is issued, or an extra character
legal to apply the card.
Cardholder Data (CHD) - ANS-Any form of in my view identifiable statistics (PII) associated with
a person who has a fee card, along with a credit score or debit card.
PAN, cardholder call, expiration date, service code
Critical/high patch cadence - ANS-Within 1 month of release
Cryptography suites and protocol review cadence - ANS-Annual
Customized approach - ANS-The entity builds their very own manage the usage of the custom
designed approach steering to fill the spirit of the manage. This is predefined, and need to be
documented with a TRA executed to reveal the mischief is nicely controlled.
Defined method - ANS-The explicitly described necessities on a PCI DSS assessment. These
need to be assessed using the described checking out system except there's a legitimate
commercial enterprise or criminal difficulty, in which a compensating manipulate can be
designed.
Describe the authorization technique - ANS-1. Cardholder requests the acquisition from the
service provider
2. Merchant contacts acquirer
3. Acquirer contacts charge emblem network