02.02.2013 Views

Maestro Global Rules (PDF) - MasterCard

Maestro Global Rules (PDF) - MasterCard

Maestro Global Rules (PDF) - MasterCard

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Security<br />

8.10 Site Data Protection Program<br />

a. Any Merchant having greater than 20,000 total combined <strong>MasterCard</strong><br />

and <strong>Maestro</strong> e-commerce Transactions annually but less than or equal<br />

to one million total combined <strong>MasterCard</strong> and <strong>Maestro</strong> e-commerce<br />

transactions annually; and<br />

b. Any Merchant meeting the Level 3 criteria of Visa.<br />

To validate compliance, Level 3 Merchants must successfully complete:<br />

a. An annual self-assessment; and<br />

b. Quarterly network scans conducted by a PCI SSC ASV.<br />

4. Level 4 Merchants<br />

Any Merchant not deemed to be a Level 1, Level 2 or Level 3 Merchant is<br />

deemed to be a Level 4 Merchant. Compliance with the Payment Card<br />

Industry Data Security Standard is required for Level 4 Merchants; however<br />

validation of compliance (and all other <strong>MasterCard</strong> SDP Program Acquirer<br />

requirements set forth in Rule 8.10) is optional. However, a validation of<br />

compliance is strongly recommended for Acquirers with respect to each<br />

Level 4 Merchant in order to reduce the risk of Card data compromise and<br />

for an Acquirer to potentially gain a partial waiver of related assessments.<br />

To validate compliance with the Payment Card Industry Data Security<br />

Standard, Level 4 Merchants must successfully complete:<br />

a. An annual self-assessment; and<br />

b. Quarterly network scans conducted by a PCI SSC ASV.<br />

If a Level 4 Merchant has validated its compliance with the Payment Card<br />

Industry Data Security Standard and effective 1 July 2012, the Payment<br />

Card Industry Payment Application Data Security Standard as described<br />

in this section, the Acquirer may, at its option, fulfill the reporting and<br />

requirements described in Rule 8.10.4 of this rulebook.<br />

8.10.5.2 Service Providers<br />

Effective 1 July 2012, all Service Providers that use any third party-provided<br />

payment applications must validate that each payment application used is listed<br />

on the PCI Security Standards Council Web site at www.pcisecuritystandards.org<br />

as compliant with the Payment Card Industry Payment Application Data<br />

Security Standard, as applicable. The applicability of the PCI PA-DSS to third<br />

party-provided payment applications is defined in the PCI PA-DSS Program<br />

Guide.<br />

1. Level 1 Service Providers<br />

A Level 1 Service Provider is any TPP (regardless of volume) and any<br />

DSE that stores, transmits, or processes more than 300,000 total combined<br />

<strong>MasterCard</strong> transactions and <strong>Maestro</strong> Transactions annually.<br />

©1993–2012 <strong>MasterCard</strong>. Proprietary. All rights reserved.<br />

<strong>Maestro</strong> <strong>Global</strong> <strong>Rules</strong> • 9 November 2012 8-23

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!