02.02.2013 Views

Maestro Global Rules (PDF) - MasterCard

Maestro Global Rules (PDF) - MasterCard

Maestro Global Rules (PDF) - MasterCard

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Europe Region<br />

8.13 Signature-based Transactions<br />

8. A PCI SSC Forensic Investigator (PFI) has validated that the Merchant<br />

was compliant with milestones one through four of the PCI DSS Prioritized<br />

Approach at the time of the ADC Event or Potential ADC Event.<br />

8.13 Signature-based Transactions<br />

8.13.1 Introduction<br />

Cardholder verification is performed using a signature, which must be verified<br />

by the Merchant. For refund Transactions, the receipt must be signed by the<br />

Merchant rather than the Cardholder.<br />

8.13.2 Certification<br />

The security certification report must indicate which cryptographic techniques<br />

are used to obtain security services such as entity authentication, data<br />

confidentiality or protection against unauthorized modification, deletion or<br />

injection of messages.<br />

The general security requirements for secure cryptographic devices, key<br />

management and operational procedures listed in the section entitled “PIN and<br />

Key Security Requirements,” in Chapter 8 in part 1 and in this Chapter 17 in<br />

part 2 of this rulebook apply.<br />

8.13.3 Signature-based POS Terminals<br />

Signature-based POS Terminals must comply with the following requirements:<br />

1. if the signature is unsatisfactory, the Merchant must be able to indicate the<br />

cancellation of the Transaction to the POS Terminal, or perform a refund;<br />

2. in case of temporary printer malfunction, the POS Terminal should be able<br />

to reprint the receipt, preferably including a duplicate statement, without<br />

repeating the Transaction process;<br />

3. the POS Terminal must be designed to protect the Cardholder from<br />

deception with regard to:<br />

a. the fact that no PIN is required;<br />

b. the normal sequence of Transaction steps;<br />

c. the information printed or displayed;<br />

d. additional data requested;<br />

e. the authorization response;<br />

f. the completion or cancellation of the Transaction.<br />

©1993–2012 <strong>MasterCard</strong>. Proprietary. All rights reserved.<br />

<strong>Maestro</strong> <strong>Global</strong> <strong>Rules</strong> • 9 November 2012 17-49

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!