<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PCI DSS - Query in Governance, Risk, Compliance</title>
    <link>https://community.isc2.org/t5/Governance-Risk-Compliance/PCI-DSS-Query/m-p/47995#M519</link>
    <description>&lt;P&gt;I would reach out to the external company requesting assistance answering the auditors. They should be able to help you identify what belongs on them, what belongs on you and how to best respond.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Oct 2021 14:39:25 GMT</pubDate>
    <dc:creator>denbesten</dc:creator>
    <dc:date>2021-10-20T14:39:25Z</dc:date>
    <item>
      <title>PCI DSS - Query</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/PCI-DSS-Query/m-p/47990#M517</link>
      <description>Hi all&lt;BR /&gt;&lt;BR /&gt;In a previous life I was a PCI DSS auditor. I want your opinion on the following:&lt;BR /&gt;&lt;BR /&gt;My organisation processes all pan / credit card numbers using a dedicated / external company / payment gateway.&lt;BR /&gt;&lt;BR /&gt;We do not actually store credit cards on our network.&lt;BR /&gt;&lt;BR /&gt;I have just inherited PCI DSS compliance… and people are pumping resources at it and running around like chooks with their heads cut off!&lt;BR /&gt;&lt;BR /&gt;We even have a PCI QSA/ assessor telling me we need to “scan” our entire network (thousands of systems), to prove we don’t have any credit card numbers… but my argument is that are been audited and subjected to a standard… that isn’t applicable! !!! Because we don’t process PANS on our network.&lt;BR /&gt;&lt;BR /&gt;What are your thoughts&lt;BR /&gt;&lt;BR /&gt;Luke</description>
      <pubDate>Wed, 20 Oct 2021 13:13:03 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/PCI-DSS-Query/m-p/47990#M517</guid>
      <dc:creator>Elemental</dc:creator>
      <dc:date>2021-10-20T13:13:03Z</dc:date>
    </item>
    <item>
      <title>Re: PCI DSS - Query</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/PCI-DSS-Query/m-p/47995#M519</link>
      <description>&lt;P&gt;I would reach out to the external company requesting assistance answering the auditors. They should be able to help you identify what belongs on them, what belongs on you and how to best respond.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2021 14:39:25 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/PCI-DSS-Query/m-p/47995#M519</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2021-10-20T14:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: PCI DSS - Query</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/PCI-DSS-Query/m-p/48006#M520</link>
      <description>As I understand it SSF is making it harder to keep systems out of scope, it sounds like you are undergoing SSF not PA-DSS?&lt;BR /&gt;&lt;BR /&gt;We've been PA-DSS certified since it started, never had to scan outside the limited scope of the software/hardware that handled CC's.</description>
      <pubDate>Thu, 21 Oct 2021 15:23:48 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/PCI-DSS-Query/m-p/48006#M520</guid>
      <dc:creator>bkwalker</dc:creator>
      <dc:date>2021-10-21T15:23:48Z</dc:date>
    </item>
    <item>
      <title>Re: PCI DSS - Query</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/PCI-DSS-Query/m-p/48008#M521</link>
      <description>&lt;P&gt;You may not be processing any credit card data, but who has the encryption keys when sending to your processor.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Main question to ask is "can my company see any credit card data (pan, cvv)?&amp;nbsp; If you can prove you can't see any of this data, everything should be out of scope.&amp;nbsp; If you can't prove this then I understand why the assessor wants you to scan everything.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Oct 2021 16:31:08 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/PCI-DSS-Query/m-p/48008#M521</guid>
      <dc:creator>rbrenis</dc:creator>
      <dc:date>2021-10-21T16:31:08Z</dc:date>
    </item>
    <item>
      <title>Re: PCI DSS - Query</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/PCI-DSS-Query/m-p/48012#M522</link>
      <description>&lt;P&gt;If you're using a hosted payment page linked from your website or are using end to end encryption from PEDs to your payment provider then your scope of compliance work is much reduced but not entirely eliminated.&amp;nbsp; Completing the SAQ questionnaire should indicate where you need to focus.&amp;nbsp; In term of card holder data discovery it's still worth doing, because there could still be legacy card data somewhere on your IT estate that has been retained in error.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2021 10:34:36 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/PCI-DSS-Query/m-p/48012#M522</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2021-10-22T10:34:36Z</dc:date>
    </item>
    <item>
      <title>Re: PCI DSS - Query</title>
      <link>https://community.isc2.org/t5/Governance-Risk-Compliance/PCI-DSS-Query/m-p/48056#M528</link>
      <description>Even though you do not process credit card transactions, you could have pans stored on your network in emails, reporting, and spreadsheets. Associates could download the data from the third party, copy the pan from the screen, or receive it from the customer during a support call. I am sure that the assessor had run into this before and wanted to make sure it was not an issue on your network before certifying it. The project to correct this can be very time consuming.</description>
      <pubDate>Tue, 26 Oct 2021 16:33:18 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Governance-Risk-Compliance/PCI-DSS-Query/m-p/48056#M528</guid>
      <dc:creator>L3strl-ma</dc:creator>
      <dc:date>2021-10-26T16:33:18Z</dc:date>
    </item>
  </channel>
</rss>

