31.07.2015 Views

Download

Download

Download

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Why PCI Is Important • Chapter 8 267NOTEAmerican Express, Visa Canada, Discover, and JCB compliance dates for serviceproviders are not well defined. Please check with your acquirer for moreinformation.Compliance ProcessDepending on your company’s merchant or service provider level, you will either need togo through an annual on-site PCI audit, or complete a Self-assessment Questionnaire (SAQ)to validate compliance. In addition to this, you will have to present the results of the quarterlynetwork perimeter scans (which had to be performed by an approved scanningvendor), evidence of internal vulnerability scans, and evidence of application and networkpenetration tests. In other words, you have to prove to the card brands that your companypractices sound patch management and vulnerability management processes.Table 8.5 Compliance Validation for MerchantsLevel American Express MasterCard Visa USALevel 1 Annual on-site Annual on-site review Annual on-site reviewreview by QSA (or by QSA by QSA (or internalinternal auditor if Quarterly scan by ASV auditor if signed bysigned by officer ofofficer of merchantmerchant company)company)Quarterly scanQuarterly scan by ASVby ASVLevel 2 Quarterly scan by ASVAnnual Self-assessment Annual SAQQuestionnaire Quarterly scan by ASVQuarterly scan by ASVLevel 3 Quarterly scan by Annual SAQ Annual SAQASV (recommended) Quarterly scan by ASV Quarterly scan by ASVLevel 4 N/A Annual SAQ Annual SAQ(recommended) (recommended)Quarterly scan by ASV Quarterly scan by ASV(recommended) (recommended)

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!