Jay from the USA asks:
If our acquirer provided POS systems, do we need to make sure that the acquirer’s equipment and websites are PCI DSS compliant?
I’ve always said that you should “Trust but Verify”! It is very common for a merchant to receive or be recommended a certain POS system, application, or platform from their acquirer, processors, or franchise manager. If you are a merchant who receives such a recommendation, be sure to do your homework.
First, you need to check the Visa website to make sure that POS system/software has undergone rigorous security testing and has been validated as secure under the Payment Application Best Practices (PABP). You can see a list of qualified products here.
Next, you need to obtain the “Implementation Documentation” or “Implementation Guide” from that POS vendor. Although your POS may have been validated as secure, there are still a number of things YOU NEED TO DO to operate it in a secure manner. This documentation or guide is the list of thing you need to do. Follow it carefully and understand how to protect yourself.
Finally, you are 95% of the way there, you need to continually educate yourself about the difference between compliance and validation, the definition of cardholder data and where to find it, who to contact in the event of a compromise, etc. You may follow this blog or you may enroll in structured learning. Either way, you need to keep yourself informed.
Popularity: 41% [?]