Secure Payments, PCI DSS, Regulatory Compliance Blog

Trust but Verify your POS system

February 28th, 2008 by admin Posted in Banking, Card Brands, Merchant, Payment Applications, pa-dss

pabp.pngJay from the USA asks:

If our acquirer provided POS systems, do we need to make sure that the acquirer’s equipment and websites are PCI DSS compliant?

I’ve always said that you should “Trust but Verify”!  It is very common for a merchant to receive or be recommended a certain POS system, application, or platform from their acquirer, processors, or franchise manager.  If you are a merchant who receives such a recommendation, be sure to do your homework.

First, you need to check the Visa website to make sure that POS system/software has undergone rigorous security testing and has been validated as secure under the Payment Application Best Practices (PABP).  You can see a list of qualified products here.

Next, you need to obtain the “Implementation Documentation” or “Implementation Guide” from that POS vendor.  Although your POS may have been validated as secure, there are still a number of things YOU NEED TO DO to operate it in a secure manner.  This documentation or guide is the list of thing you need to do.  Follow it carefully and understand how to protect yourself.

Finally, you are 95% of the way there, you need to continually educate yourself about the difference between compliance and validation, the definition of cardholder data and where to find it, who to contact in the event of a compromise, etc.  You may follow this blog or you may enroll in structured learning.  Either way, you need to keep yourself informed.

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]
  1. 3 Responses to “Trust but Verify your POS system”

  2. By POS Systems on Apr 25, 2008

    I think POS systems have simplified the buying process in large markets. The blog has raised a very important issue. It is essential that we verify that the POS systems used have been tested and the software installed in them is standard.

  3. By Christopher on Jul 17, 2008

    The best prices in the world for POS equipment is http://www.consumerdepot.com

  1. 1 Trackback(s)

  2. Feb 29, 2008: jPOS.org » Blog Archive » Trust but verify your version number

Sorry, comments for this entry are closed at this time.