02.02.2013 Views

Maestro Global Rules (PDF) - MasterCard

Maestro Global Rules (PDF) - MasterCard

Maestro Global Rules (PDF) - MasterCard

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Security<br />

8.10 Site Data Protection Program<br />

8.10.2 Compliance Validation Tools<br />

As defined in the implementation schedule in Rule 8.10.5 of this rulebook,<br />

Merchants and Service Providers must validate their compliance with the<br />

Payment Card Industry Data Security Standard by using the following tools:<br />

1. Onsite Reviews: The onsite review evaluates a Merchant’s or Service<br />

Provider’s compliance with the Payment Card Industry Data Security<br />

Standard. Onsite reviews are an annual requirement for Level 1 Merchants<br />

and for Level 1 and 2 Service Providers. Merchants may use an internal<br />

auditor or an independent assessor recognized by the Corporation as<br />

acceptable. Service Providers must use an acceptable third party assessor<br />

as defined on the SDP program Web site at www.mastercard.com/sdp.<br />

Onsite reviews must be conducted in accordance with the PCI Security<br />

Audit Procedures document available at www.pcisecuritystandards.org.<br />

2. The Payment Card Industry (PCI) Self-Assessment Questionnaire: The PCI<br />

Self-Assessment Questionnaire is available at www.pcisecuritystandards.org.<br />

To be compliant, each Level 2, 3, and 4 Merchant and each Level 3 Service<br />

Providers must generate acceptable ratings on an annual basis.<br />

3. Network Security Scan: The network security scan evaluates the security<br />

measures in place at a Web site. To fulfill the network scanning requirement,<br />

all Level 1, 2, and 3 Merchants, and all Service Providers, as required by the<br />

implementation schedule, must conduct scans on a quarterly basis using a<br />

vendor listed on the PCI SSC Web site. To be compliant, scanning and risk<br />

remediation must be conducted in accordance with the guidelines contained<br />

in the Payment Card Industry (PCI) Security Scanning Procedures available<br />

at www.pcisecuritystandards.org.<br />

8.10.3 Vendor Compliance Testing<br />

As part of the SDP Program, the Corporation provides a vendor compliance<br />

testing process for vendors that provide network scanning services. Technical<br />

requirements for network scanning vendors are provided in the PCI DSS<br />

Security Scanning Procedures available at www.pcisecuritystandards.org.<br />

For more information, Acquirers should visit the SDP program Web site at<br />

www.mastercard.com/sdp.<br />

At this Web site, the Corporation also will post a listing of all acceptable onsite<br />

assessors for the purposes of meeting the onsite review requirement.<br />

©1993–2012 <strong>MasterCard</strong>. Proprietary. All rights reserved.<br />

8-18 9 November 2012 • <strong>Maestro</strong> <strong>Global</strong> <strong>Rules</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!