Vendor 1 QUESTION CCSF RESPONSE

Size: px
Start display at page:

Download "Vendor 1 QUESTION CCSF RESPONSE"

Transcription

1 Vendor 1 QUESTION 1 If we have already filled out the vendor profile application, business tax declaration and local business forms will we need to fill them out again? 2 Is CCSF open to rolling up all 70 merchant IDs into a single Report on Compliance (ROC) or will each merchant validate individual compliance by submitting the appropriate SAQ/ROC? If you have done so, you can simply provide us with your vendor registration number. Each merchant will have to submit an individual appropriate SAQ/ROC. 3 In regards to the PCI workshops mentioned in the scope of work on page 7 (#1): Is it the expectation that workshop content will allow CCSF staff to take the CPIP exam offered by the PCI SSC? Should we assume that the training be structured so that CCSF staff can attain the necessary CPE s to maintain their CPIP? How many CCSF employees should we anticipate attending the workshops? 4 Is it the expectation that the responder be required to create new or update existing policies and procedure to address PCI DSS documentation gaps? 5 Does CCSF currently have an identified list of projects for items mentioned in scope of work #3? 6 As SFO s current QSA is there overlap between the PCI services you requested and the PCI services were already performing. 7 Is it expected that the readiness/gap assessment (page 7 SOW #5) will lead to each department completely their own SAQ or will there be a single level 1 merchant ROC completed by a QSA? 8 In regards to SOW #6, are systems in scope hosted onsite or by a third party? Is there a current inventory of in-scope systems including servers, network devices, applications, databases, etc? No. No. For each workshop, approximately 70 CCSF employees are expected to attend. Workshops can be divided into smaller groups. No. Unknown. Please see response to question #2. Given the different state of technology sophistication across City agencies, the selected vendor will need to advise City agencies as to what documentation is necessary to be completed by City staff in order to obtain compliance certification and assist as needed. There is no City-wide inventory of systems. The vendor will advise departments which systems components need to be included to obtain certification. NOTE: Carefully review the project scope on page 7 of the RFP. The City is not asking vendors to scan and ensure compliance of each environment. The vendor will be assisting the City in obtaining self-certification and will serve as an advisor. The vendor will not scan the Data center environment and City applications. It will be advising the City staff on how to close gaps to help us obtain the required compliance certification. Page 1 of 17

2 9 Is the cardholder data environment segmented from all other systems that do no store process or transmit cardholder data? 10 Does CCSF leverage wireless and/or mobile payment technology to transmit cardholder data? 11 Are CCSF merchants currently quarterly vulnerability scans or yearly penetration tests? a. If so please identify the scope of internal and external IPs addresses. 12 Based on the aggregate transaction volume for MUNI and Port, 24.5m and 5m respectively, has CCSF s acquiring bank determined if these departments are required to validate annual compliance as Level 1 merchants requiring an annual onsite audit and ROC/Attestation of Compliance (AOC)? Vulnerability scans and penetration tests are not part of the RFP. Vendor will advise City agencies which systems and applications require this analysis in order to become compliant. Not applicable - see above. No. Page 2 of 17

3 Vendor 2 QUESTION 1 General Question: a. Do you have an established compliance date within the next six No. months? If so what is it? Do you have a letter from any bank or processor giving you a deadline on any of the entities or threating fines of any kind? i. Please list this out per reporting merchant ID. NA. ii. How many Processors do you have? Do you have any requirements To be determined. for those processors to become compliant? b. If you are a merchant, what is your merchant level? The City is a highly diversified organization. Transaction volume varies from one City department to another. The City is looking for an advisor to help us with our compliance process and determine the appropriate merchant level as identified in the business assessment study of this project. i. From the RFP it seems that there are 25 Merchant IDs throughout the city. If this is the case what is the level for each merchant in need of this assessment? ii. How many MIDs are there throughout the city? c. Have you ever undergone any type PCI assessment in the past? Partially. There are 72 MIDs throughout the City. Some agencies, especially the large ones such as MUNI, have more than one MID. The selected vendor can help the City determine the appropriate merchant level as identified in the business assessment study of this project. 72 MIDs. i. A Compliance Validation Assessment? Partially. ii. A GAP assessment/review? Partially. iii. If so, will we be able to utilize information provided in the past from prior assessors? d. How many IT Operations locations are in scope for compliance, and what is the geographic location of each facility? This RFP covers all City and County San Francisco agencies located in San Francisco and San Mateo area. e. Is there a centralized IT Organization in addition to individual IT teams for the departments? If so what is their role within the scope of this project? f. What are the geographic locations of all the facilities that will fall into scope for this type of project? g. How many data centers are in scope for compliance? What is the geographic location of these data centers? Are any of the data centers owned by you? Are any of the data centers 3rd party data centers? If 3rd party are the data centers PCI compliant? h. Due to the nature of our business our clients expect a certain amount of privacy, when being references. Would CCSF be willing to sign an NDA so we can release these names to meet the requirements of your RFP? If so where should I send a copy of our NDA? NOTE: Carefully review the project scope on page 7 of the RFP. The City is not asking vendors to scan and ensure compliance. The vendor will be assisting the City in obtaining self-certification and serves as an advisor. CCSF has a centralized IT Organization that provides a variety of technology services. The selected vendor for this project, however, will be working with individual departments. This RFP covers all City and County San Francisco agencies located in San Francisco and San Mateo area. This RFP covers all City and County San Francisco agencies located in San Francisco and San Mateo area. The City is a highly diversified organization. Some agencies have their own data center (Dept of Technology, MTA, Airport, PUC, etc) while others rely on external services. NOTE: Carefully review the project scope on page 7 of the RFP. The City is not asking vendors to scan and ensure compliance. The vendor is assisting the City in obtaining self-certification and serves as an advisor. Page 3 of 17

4 i. If answering questions takes longer than expected for CCSF, would there be an extension granted? j. Under The Scope of work. Can you elaborate, for #5, on what you would like accomplish? k. In the RFP there seems to be back end requirements for other compliances. Would HIPAA or any other compliance assessments be a part of this project? If so please explain any other compliance initiatives which are expected. l. Are you looking to have an individual assessment performed on a per department basis and then one as a whole? Would you like reporting to be for each entity or one report on compliance for all? Has CCSF thought through the implications of one report versus multiple reports? If so what are your thoughts on this matter? Yes, if necessary. The selected vendor will serve as an advisor and evaluate how prepared the organization is for any process change, identify organizational needs, and develop a plan to introduce in order for us to obtain the required compliance certification No. We are looking for per department/merchant assessment. However, you may include in your response the benefits of one reporting versus multiple reporting. m. What is the intention of the PCI compliance and certification educational workshops? i. Is it to satisfy the security awareness training components for PCI? ii. Is it to train those PCI Project representatives from each department as they lead efforts for compliance n. Does CCSF expect a project plan developed per department? If so to what level of detail and what happens when dates are missed as a result of CCSF resources? o. Is it the intention that the PCI compliance certification of individual merchants, is in reference to the PCI Compliance to the individual departments? p. Does the assist in documenting CCSF payment card environment, imply the creation of all network/connection/dataflow diagrams, plus the asset inventory of the card holder data environment? What information do you have now for each entity (dataflow, network diagram, inventory, IP#s,? Training and educational workshops are applicable. CCSF expects a project plan developed per department. The City's Treasurer & Tax Collector Office (TTX) will provide oversight of this project. The selected contractor will have to communicate any issues with this project to TTX and renegotiate deadlines. CCSF is looking for a vendor to provide us with the business assessment, gap analysis, and remediation compliance reports. These will be the basis for PCI compliance and certification. The City is looking for advisor that will help us document the City's existing payment card environment and process. This may include diagrams given that the level of documentation available varies by City agency. We are not looking for an inventory of assets. q. What is the intended start/end date for this engagement? Early part of calendar year r. Will there be dedicated CCSF staff to facilitate the project coordination TTX will facilitate and coordinate the project between between departments? departments. s. How many acquirers do you have and who are they? For Card Present, the City utilizes Bank of America Merchant Services (BAMS) and Chase Payment Tech for Card-Not-Present. Depending on the results of assessment review, there may be other indirect acquirers that are not known to TTX. t. What Does Lockbox entail (i.e., mailed in bills with credit card numbers Mailed in payments with checks and card payment information at on them?) times, but very few. u. What position types will be the audience for PCI DSS Training? Senior staff and staff at various organizational levels. v. What are the Goals of the Training program for PCI DSS To educate CCSF employees and set-up compliance policies and processes. w. Has there been budget allocated for this project? If so can you share Proposals should indicate cost of service. what it is? x. Are there any negative repercussions if CCSF does not move forward Not relevant. with this project? Page 4 of 17

5 y. Will the CCSF assistance be city employees or contractors? If so what is the average time of employment with the city? Will they have any IT background? z. Will TTX have the authority to mandate the assessments to happen in a timely manner? aa. Will there be a public announcement on which vendor was awarded the business? bb. Do you currently have a way to fill out SAQs? If so which solution do you utilize? If not would you like a solution for this to be included in this RFP? cc. In the appendix there are required forms. Must these be filled out at time of submission or during the contract negotiation phase? dd. In the P-500 document, point 19 page 9. Is liquidated damages a show stopper for CCSF? ee. Can we utilize one of our business partners for the contract negotiation process? 2 Organizational Question: a. Do you intend to use a project manager to facilitate the assessment process? Will the project manager be dedicated to this project? b. Do you contract with any third parties who provide services in the cardholder data environment? c. Are there any specific lead-times, especially related to third parties, which affect the availability of personnel necessary to support the assessment? d. Do you perform any internal application development (including web applications)? e. Do you have a complete set of information security policies to address all PCI DSS requirements? If not is there any base policies and procedures to begin with? CCSF employees, mostly with IT background. No. TTX does not publicly announce the selected vendor for TTX services. Yes, but performed manually. Please feel free to discuss your recommended solution. These forms must be filled out during the contract negotiation phase. Any questions regarding P-500 can be discussed during the contract negotiation phase. That is the solely your decision. The selected vendor is expected to manage the business assessment review and submit the required reports to TTX staff. No. Some Departments have internally developed applications but most rely on third party software. The City has a Dept of Technology Security Group that provides general guidance. Large City agencies have a separate CIO and technology organization with their own separate policies. For a list of approved technology policies by the City's COIT Committee, visit f. Please explain the different methods of accepting credit card transactions for each merchant ID. i. Do you accept Mail Order or Telephone Order transactions? CCSF accepts telephone orders through an IVR system. 1 If you are accepting phone orders, are these calls being Unknown. recorded? Are the credit card numbers being recorded? Are fax transactions recorded? Are transactions recorded? g. If required for each merchant. Have penetration tests been completed? Is penetration testing a part of this RFP? i. If so please explain how many Class C Networks each department has, as well as the PCI application count for each department? ii. Is there a case where penetration testing would go beyond PCI? If so how many Class C environments and how many applications? Penetration testing is not a requirement of this RFP. NA - see above. NA - see above. 3 Environment Question: Page 5 of 17

6 a. Has a data discovery process been performed to identify all storage, processing and transmission of credit card data within the environment? If not is this something that would fall into scope for this project? Given the different state of technology sophistication across City agencies, the selected vendor will need to advise City agencies when and if this documentation is necessary to be completed by City staff in order to obtain compliance certification and assist as needed. NOTE: Carefully review the project scope on page 7 of the RFP. The City is not asking vendors to scan and ensure compliance of each environment. The vendor will be assisting the City in obtaining self-certification and will serve as an advisor. The vendor will not scan the Data center environment and City applications. It will be advising the City staff on how to close gaps to help us obtain the required compliance certification. b. How many acceptance channels are in place for the acquisition of credit card data? CP-POS, CNP-Ecommerce, CNP-MOTO, PIN-Debit, etc. c. Has segmentation of the network environment been implemented to reduce the scope of compliance? Again, given the different state of technology adopted across City agencies, there are multiple acceptance channels. The selected vendor will need to advise staff in City department what documentation is required to obtain PCI compliance and assist as needed. agencies, each agency, especially the large ones, will have unique technology environments. The selected vendor will need to advise staff in City department as to what documentation is required to obtain PCI compliance and assist as needed. d. Are any wireless network technologies utilized in the cardholder environment? unique technology environments and may/may not include wireless. The selected vendor will need to advise staff in City department as to what documentation is required to obtain PCI compliance and assist as needed. e. Are any virtualization technologies utilized in the environment? unique technology environments and may/may not include virtualized environments. The selected vendor will need to advise staff in City department as to what documentation is required to obtain PCI compliance and assist as needed. f. How many different types of operating platforms (e.g., Windows, Unix, mainframe, etc.) are present in your environment? unique technology environments with varying operating platforms. The selected vendor will need to advise staff in City department as to what documentation is required to obtain PCI compliance and assist as needed. g. How many servers are in the cardholder environment? unique technology environments with different types of servers involved. The selected vendor will need to advise staff in City department as to what documentation is required to obtain PCI compliance and assist as needed. h. How many different payment applications are present in your environment? unique technology environments with different types of payment solutions involved. The selected vendor will need to advise staff in City department as to what documentation is required to obtain PCI compliance and assist as needed. Page 6 of 17

7 i. How many different types of databases (e.g., SQL Server, Oracle, etc.) are present in your environment? j. Is Card Holder Data being stored? Is encryption used when storing credit card data? unique technology environments with different types of database solutions involved. The selected vendor will need to advise staff in City department as to what documentation is required to obtain PCI compliance and assist as needed. unique technology environments with different types of database solutions involved. The selected vendor will need to advise staff in City department as to what documentation is required to obtain PCI compliance and assist as needed. k. What degree of consistency do you have within your environment? unique technology environments with different types of solutions involved. The selected vendor will need to advise staff in City department as to what documentation is required to obtain PCI compliance and assist as needed. l. Where are the webservers located? unique technology environments with different types of web servers involved. The selected vendor will need to advise staff in City department as to what documentation is required to obtain PCI compliance and assist as needed. m. How many compliance programs are up and running as of now and Unknown. what are their scopes? n. What type of project management methodology is currently in place? What type of Project Management tools are in use? o. Is there a current report format being used for compliance reporting with CCSF? If so what is it? p. Is there an up to date inventory for each department of all networking equipment, servers, computers, and POS systems? How many of the departments have inventories? Those City agencies that have project management methodologies in place are using the PMI standard or a close variation. The purpose of this RFP is to establish a City-wide compliance program, including a standard for reporting. unique technology environments with different equipment locally controlled. The selected vendor will need to advise staff in City department as to what documentation is required to obtain PCI compliance and assist as needed. q. Is there an up to date cardholder data flow for each department of all networking equipment, servers, computers, and POS systems? How many of the departments have data flow diagrams? r. Is there an up to date network Diagram for each department of all networking equipment, servers, computers, and POS systems? How many departments have editable network diagrams There is no single cardholder data flow. Departments currently vary in their adoption of e-payment solutions. unique technology environments with different level of documentation available. The selected vendor will need to advise staff in City department as to what documentation is required to obtain PCI compliance and assist as needed. Page 7 of 17

8 s. Is there an up to date cardholder data flow for each department of all networking equipment, servers, computers, and POS systems? How many of the departments have data flow diagrams that are editable? t. Is there an up to date network Diagram for each department of all networking equipment, servers, computers, and POS systems? How many departments have editable network diagrams? u. Does CCSF have a preferred report format for metrics and Risk? If so what is it? v. What is meant by use of CCSF staff? What are the limits of use of CCSF Staff if any? (note: engagement can t be completed without use of staff so not sure what this really means) w. Will there be CCSF staff dedicated as POC's/Liaisons for each department? Will these people be dedicated to the PCI program while the selected company is engaged? x. What is the reporting structure and lines of accountability between department staff and project owner with CCSF? What will be the escalation process for non-responsiveness on part of CCSF? y. Is there a complete list of 3rd party vendors and gateways? How many of the contracts are set to expire in the next 6 months, next 12 months? z. Will CCSF be giving the selected company control over tasking CCSF employees when making request to support the effort in terms of deadlines? aa. Is there any internal application development done for the city? If so please list departments which have internal application development teams. bb. How many severs are within the card holder environment? cc. Has proper network segmentation taken to reduce the scope of compliance? unique technology environments with different level of documentation available. The selected vendor will need to advise staff in City department as to what documentation is required to obtain PCI compliance and assist as needed. unique technology environments with different level of documentation available. The selected vendor will need to advise staff in City department as to what documentation is required to obtain PCI compliance and assist as needed. Contain all the elements of compliance metrics and risk, customizable and downloadable to a user friendly application. CCSF staff will consist of employees from IT and/or Finance departments who typically work on banking related issues. They will be available on as needed basis. It is expected to have CCSF staff from each City department to work on this project. Their time, however, are not solely dedicated on the PCI program. The City's Treasurer & Tax Collector Office (TTX) will provide oversight of the PCI compliance process for CCSF. The selected vendor will have to communicate or escalate any project issues that may arise to TTX. The list of 3rd party vendors and gateways are not available at this time. This service is expected to reveal these information. Contractor can give direction to CCSF employees for this engagement. unique technology environments with different level of application development efforts. The selected vendor will need to advise staff in City department as to what documentation is required to obtain PCI compliance and assist as needed. unique technology environments with different types of servers involved. The selected vendor will need to advise staff in City department as to what documentation is required to obtain PCI compliance and assist as needed. agencies, each agency, especially the large ones, will have unique technology environments. The selected vendor will need to advise staff in City department as to what documentation is required to obtain PCI compliance and assist as needed. Page 8 of 17

9 dd. Are there any virtualization technologies utilized in the environment? ee. Are your systems being backed up? If so please list the departments that are and how they are backing up? (i.e.: Tape, Disk, Cloud) ff. Do you have anyone working from home? If so what functions do they perform from home? What systems can they access from home? unique technology environments and may/may not include virtualized environments. The selected vendor will need to advise staff in City department as to what documentation is required to obtain PCI compliance and assist as needed. unique technology environments and may/may not include backup solutions. The selected vendor will need to advise staff in City department as to what documentation is required to obtain PCI compliance and assist as needed. Again this is dependent on each department situation. 4 Logistics: a. Are there any considerations which will affect the scheduling of any Vendor is expected to coordinate delivery of advisory services assessment activities (environment freeze, implementation timelines with each department and the Treasurer/Tax Collector Office. etc.)? 5 Vulnerability Scanning: a. How many internal IP addresses are in scope for PCI? This RFP does not require vulnerability scanning but it can be offered as an optional service. The vendor would advise each City agencies as to what would be required to meet compliance requirements. i. Please give a break out of IPs per reporting Merchant ID for each location. This RFP does not require vulnerability scanning but it can be offered as an optional service. The vendor would advise each City agencies as to what would be required to meet compliance requirements. b. Are all IP addresses routable from a centralized location? This RFP does not require vulnerability scanning but it can be offered as an optional service. The vendor would advise each City agencies as to what would be required to meet compliance requirements. c. How many external IP addresses are in scope for PCI? This RFP does not require vulnerability scanning but it can be offered as an optional service. The vendor would advise each City agencies as to what would be required to meet compliance requirements. i. Please give a break out of IPs per reporting Merchant ID for each location. d. Have you ever performed vulnerability scans in the past? e. Are you currently doing any vulnerability scanning? If so for which network and entities? This RFP does not require vulnerability scanning but it can be offered as an optional service. The vendor would advise each City agencies as to what would be required to meet compliance requirements. GENERAL FEEDBACK FROM CITY OF SF These questions are all framed with the understanding that the vendor would deliver vulnerability & network scanning services, which are beyond the scope of this RFP. The RFP requires the vendor to provide educational and advisory services that will assist the City agencies in either becoming PCI compliant. Vendors are encouraged to carefully review the scope of services laid out on page 7 of the RFP. Page 9 of 17

10 Vendor 3 QUESTION 1 How many employees will be a part of the educational workshops? For each workshop, approximately 70 CCSF employees are expected to attend. Workshops can be divided into smaller groups. a. How many workshops will need to be performed? CCSF expects a minimum of two workshop sessions in the first year of engagement. b. Will the workshops be concurrent calendar dates or scheduled for different times of the year? c. Will the workshops be led by an onsite trainer or will they be performed as an online webinar? To be determined. Can be a combination of both. Web training is fine. People just need an opportunity to ask questions. 2 How many Level 4 merchants do you estimate will require selfcertification guidance? 3 Have you previously filed SAQs for the principal merchant businesses within the CCSF? a. Can you tell us how many were submitted of each type (e.g., SAQ A, SAQ B, SAQ C-VT, etc.)? 4 Does the CCSF utilize data centers and are these to be included in the scope of the consulting? Undetermined at this time. Only SAQs were submitted. This RFP covers all City and County San Francisco agencies located in San Francisco and San Mateo area. The City is a highly diversified organization. Some agencies have their own data center (Dept of Technology, MTA, Airport, PUC, etc) while others rely on external services. NOTE: Carefully review the project scope on page 7 of the RFP. The City is not asking vendors to scan and ensure compliance. The vendor is assisting the City in obtaining self-certification and serves as an advisor. a. What are the locations of these data centers? San Francisco/San Mateo area. 5 Number 5 in the Scope of Work references Establish a process with CCSF staff to conduct a compliance readiness assessment. Will this readiness assessment be a part of this RFP or will the planning of the process by which the readiness assessment would be conducted solely in this RFP? Both are part of the scope of the services. Page 10 of 17

11 6 The chart provided on page 5 of the RFI indicates that there are merchants who fall into all four merchant levels as defined by Visa and MasterCard. This includes Level 1 and Level 2 merchants who may requires PCI DSS assessments as well as others who may require penetration testing and/or external vulnerability scanning. Is it accurate that the request for proposal is seeking focused and expert guidance/consulting on PCI matters for each principal merchant and is not asking for the QSA to perform to full validation on compliance for each merchant. Given the different state of technology sophistication across City agencies, the selected vendor will need to advise City agencies as to what documentation is necessary to be completed by City staff in order to obtain compliance certification and assist as needed. There is no City-wide inventory of systems. The vendor will advise departments which systems components need to be included to obtain certification. NOTE: Carefully review the project scope on page 7 of the RFP. The City is not asking vendors to scan and ensure compliance of each environment. The vendor will be assisting the City in obtaining self-certification and will serve as an advisor. The vendor will not scan the Data center environment and City applications. It will be advising the City staff on how to close gaps to help us obtain the required compliance certification. 7 Would you like supporting services such as penetration testing and vulnerability scanning for your merchants included in the proposal? Penetration testing is not a requirement of this RFP. 8 If supporting services are to be performed in addition to the consulting guidance as part of this RFP would you like information provided for any or all of the following: a. Policy templates b. Penetration testing c. External vulnerability scanning 9 If supporting services are to be performed in addition to the consulting guidance as part of this RFP could the following information be provided for each of the principal merchants? a. Is segmentation in place between the principal merchants of CCSF? b. How many total external IPs are owned by each principal merchant? i. How many external IPs are routed and active for each principal merchant? ii. How many virtual hosts are living on these IPs? c. How many externally facing web applications are in use by each principal merchant? i. Please provide a brief description of each application and its use. d. How many physical servers are in use by each principal merchant? i. How many virtual servers are present on each principal merchant s servers? The vendor, as part of this RFP, will primarily serve as an advisor responsible for analysis, advisory and reporting services. This vendor will not be responsible for DSS assessments, scanning, etc. The vendor, however, is welcome to mention and price these services in the response. Page 11 of 17

12 e. How many internal hosts are present within each principal merchant? f. How many different point-of-sale (POS) systems are used within the principal merchants for card-present transactions? g. Are you using any PA-DSS validated applications? Page 12 of 17

13 Vendor 4 QUESTION General Question: 1 What is the timeline for starting and completing this project? This project is expected to start at the beginning of calendar year The service contract will be evaluated at the end of 2 years. 2 Is there a preference for face-to-face training verses online training? Can be a combination of both. Web training is fine. People just need an opportunity to ask questions. 3 Who is to be trained? Technical resources or employees at all levels? Senior staff and staff at various organizational levels. 4 Are there any shared services (e.g., vulnerability scanning, log management, shared data centers, policies and procedures, etc.) among the different merchant IDs, if so, what are those shared services? 5 Is the goal to ultimately implement shared services among the different merchant IDs? 6 The RFP states, "For CCSF locations that use Gateways or third-party vendors, how do you ensure these locations are PCI compliant?" If these providers are not validated services providers, as defined by PCI, does CCSF have the ability and desire to audit the controls performed by these Gateways / third-party vendors? Unknown. This will be determined after consultation with the vendor. CCSF will initially rely on the PCI certificates. 7 The RFP has identified 21 different departments with their associated transaction levels, does that number match up with the number of actual Merchant IDs that will be in-scope for this project? No. There are 72 MIDs throughout the City. Some agencies, especially the large ones such as MUNI, have more than one MID. a. Is it your desire to complete a Report on Compliance (Level 1/2 merchants) and Self-Assessment Questionnaire (Level 3/4 merchants) for each merchant ID? b. It is expected that the bidder will also be executing the ROC or does the CCSF already have a designated QSA that we would be working with to facilitate the effort? c. What is the current compliance status of each of the merchant IDs / department? d. Do network diagrams and data flow diagrams currently exist for each department? 8 Is network segmentation used to reduce the PCI scope? 9 Could you provide more details on what the important factors are to CCSF in selecting a vendor? Specifically of the three project dynamics: quality, cost, and thoroughness; please describe the significance of each? 10 Until the completion of the initial assessment, we will not have a clear understanding of the level and amount of remediation work required. Should we provide a range of hours based on previous experience, or is a different approach suggested by CCSF to estimate that effort (e.g. estimate the initial assessment leaving the remaining phases TBD with respect to hours.)? Project Management Question: Yes, if business review leads to those merchant levels. CCSF will have a separate RFP focused on QSA and/or ASV to complement this project. In 2012, CCSF was in compliance. Unknown Criteria in selecting a vendor is provided on page 11 of the RFP. You may provide a range of hours based on your previous experience in similar role and project scope and size. Page 13 of 17

14 1 Does the Respondent of the RFP have access to CCSF resources to assist with the creation and execution of: policies, procedures, and standards; vulnerability scanning and penetration testing; perform PIN Entry Device inspection; log management, etc.? 2 Do we need to assume that we will be conducting any vulnerability/penetration testing to validate compliance? If so, what should we assume is the scope? 3 In addition to the report to each City Agent, is a report to the TTX required? What frequency? 4 Who is responsible for managing all remediation activities that are identified during the scoping and validation activities? a. If it is the responsibility of the selected Respondent, what authority is granted to the Respondent in executing the work? The vendor, as part of this RFP, will primarily serve as an advisor responsible for analysis, advisory and reporting services. This vendor will not be responsible for DSS assessments, scanning, etc. The vendor, however, is welcome to mention and price these services in the response. Yes, annually. Each department will be managing remediation activities, but selected vendor is expected to submit compliance progress reports for each merchant under review. NA. b. What are the escalation procedures for reporting merchants that are missing project execution deadlines? Scoping Question: The selected vendor will submit reports to TTX. TTX will communicate to individual department. 1 What is the scope of the cardholder environment: Given the different state of technology sophistication across City agencies, the selected vendor will need to advise City agencies as to what documentation is necessary to be completed by City staff in order to obtain compliance certification and assist as needed. There is no City-wide inventory of systems. The vendor will advise departments which systems components need to be included to obtain certification. NOTE: Carefully review the project scope on page 7 of the RFP. The City is not asking vendors to scan and ensure compliance of each environment. The vendor will be assisting the City in obtaining self-certification and will serve as an advisor. The vendor will not scan the Data center environment and City applications. It will be advising the City staff on how to close gaps to help us obtain the required compliance certification. a. How many firewalls are there? b. How many Internet facing systems are part of the cardholder data environment? c. How many Internet facing web applications are part of the cardholder data environment? Page 14 of 17

15 d. How many systems in the cardholder data environment store cardholder data? e. What databases are used in the cardholder data environment? f. How many systems are there in the cardholder data environment and what operating systems do they run? g. How many network devices are considered in-scope? What type of devices are in-scope? h. How many locations are considered in-scope for this assessment? i. Is wireless used to transmit cardholder data? Is wireless segmented out from the rest of the environment? j. How many administrative locations are in-scope (e.g. call centers, back end processing, card storage locations)? This RFP covers all City and County San Francisco agencies located in San Francisco and San Mateo area. Please see chart on page 5 of the RFP (Card Payment Transaction by Department). This RFP covers all City and County San Francisco agencies located in San Francisco and San Mateo area. The City is a highly diversified organization. Some agencies have their own data center (Dept of Technology, MTA, Airport, PUC, etc) while others rely on external services. NOTE: Carefully review the project scope on page 7 of the RFP. The City is not asking vendors to scan and ensure compliance. The vendor is assisting the City in obtaining self-certification and serves as an advisor. k. Is cardholder data shared with any business partners or do thirdparty vendors have access to cardholder systems? How many? Combination of both. The number could not be determined at this point. l. Is tokenization used to reduce scope? Unknown. 2 Are any portions of the cardholder data environment(s) outsourced? If yes, please specify which components/ applications are outsourced? Are these components managed and controlled by the outsourcing service provider? Is the outsourcing service provider included on the Visa list of PCI compliant service providers? 3 How many datacenters host systems that are part of the cardholder data environment(s)? Where are these datacenters located? This RFP covers all City and County San Francisco agencies located in San Francisco and San Mateo area. The City is a highly diversified organization. Some agencies have their own data center (Dept of Technology, MTA, Airport, PUC, etc) while others rely on external services. NOTE: Carefully review the project scope on page 7 of the RFP. The City is not asking vendors to scan and ensure compliance - the vendor is assisting the City in obtaining self-certification and serves as an advisor. Page 15 of 17

16 4 How many of the in-scope applications are PA-DSS certified? Which PA-DSS applications are used? Given the different state of technology sophistication across City agencies, the selected vendor will need to advise City agencies as to what documentation is necessary to be completed by City staff in order to obtain compliance certification and assist as needed. There is no City-wide inventory of systems. The vendor will advise departments which systems components need to be included to obtain certification. NOTE: Carefully review the project scope on page 7 of the RFP. The City is not asking vendors to scan and ensure compliance of each environment. The vendor will be assisting the City in obtaining self-certification and will serve as an advisor. The vendor will not scan the Data center environment and City applications. It will be advising the City staff on how to close gaps to help us obtain the required compliance certification. 5 Are any systems in cardholder data environment virtualized? If virtualization is used, are guest systems that are part cardholder environment reside on the same virtual host as out of scope systems, or do PCI in-scope systems reside on dedicated virtual hosts? 6 Do you have estimated number of live hosts that are internally facing for the various cardholder data environments? Page 16 of 17

17 Vendor 5 QUESTION 1 Has this scope of services been awarded before and if so: No. a. Please provide the name of the prime and sub consultants b. When was the contract awarded? c. How long has City and County of San Francisco been having outside consultants provide these services? d. what was the budget for this last award and was the scope similar? 2 Please provide contact information for prime firms that have shown and interest in this scope of work by having meetings with the City and County of San Francisco, Office of the Treasure and Tax Collector or Procurement and Contracts Department. 3 Please address small and DBE requirements associated with this procurement? NA. We have no small and DBE requirements associated with this procurement. Page 17 of 17

Spokane Airport Board (Spokane International Airport, Airport Business Park, Felts Field) Addendum #1 - Q&A

Spokane Airport Board (Spokane International Airport, Airport Business Park, Felts Field) Addendum #1 - Q&A Spokane Airport Board (Spokane International Airport, Airport Business Park, Felts Field) Request for Proposals (RFP) for PCI DSS COMPLIANCE SERVICES Project # 15-49-9999-016 Addendum #1 - Q&A May 29,

More information

Puzzled about PCI compliance? Proactive ways to navigate through the standard for compliance

Puzzled about PCI compliance? Proactive ways to navigate through the standard for compliance Puzzled about PCI compliance? Proactive ways to navigate through the standard for compliance March 29, 2012 1:00 p.m. ET If you experience any technical difficulties, please contact 888.228.0988 or support@learnlive.com

More information

PCI DSS Compliance. 2015 Information Pack for Merchants

PCI DSS Compliance. 2015 Information Pack for Merchants PCI DSS Compliance 2015 Information Pack for Merchants This pack contains general information regarding PCI DSS compliance and does not take into account your business' particular requirements. ANZ recommends

More information

CITY OF CORONA RFP 15-005SB. ADDENDUM No. 2

CITY OF CORONA RFP 15-005SB. ADDENDUM No. 2 CITY OF CORONA ADDENDUM No. 2 Purchasing Division (951) 736-2272 400 S. Vicentia Ave., Ste. 320 purchasing@discovercorona.com Corona, CA 92882 09/22/2014 Scott Briggs Addendum No. 2 for the Evaluation

More information

PCI DSS Gap Analysis Briefing

PCI DSS Gap Analysis Briefing PCI DSS Gap Analysis Briefing The University of Chicago October 1, 2012 Walter Conway, QSA 403 Labs, LLC Agenda The PCI DSS ecosystem - Key players, roles - Cardholder data - Merchant levels and SAQs UofC

More information

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program MERCHANTS Can Level 1 merchants currently use internal auditors to perform an onsite assessment? Yes. However, after June 30,

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance All other SAQ-Eligible Merchants and Service Providers Version 2.0 October 2010 Document

More information

PCI Compliance. How to Meet Payment Card Industry Compliance Standards. May 2015. cliftonlarsonallen.com. 2015 CliftonLarsonAllen LLP

PCI Compliance. How to Meet Payment Card Industry Compliance Standards. May 2015. cliftonlarsonallen.com. 2015 CliftonLarsonAllen LLP 2015 CliftonLarsonAllen LLP PCI Compliance How to Meet Payment Card Industry Compliance Standards May 2015 cliftonlarsonallen.com Overview PCI DSS In the beginning Each major card brand had its own separate

More information

PCI Compliance at The University of South Carolina. Failure is not an option. Rick Lambert PMP University of South Carolina ricklambert@sc.

PCI Compliance at The University of South Carolina. Failure is not an option. Rick Lambert PMP University of South Carolina ricklambert@sc. PCI Compliance at The University of South Carolina Failure is not an option Rick Lambert PMP University of South Carolina ricklambert@sc.edu Payment Card Industry Data Security Standard (PCI DSS) Who Must

More information

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program MERCHANTS Can Level 1 merchants currently use internal auditors to perform an onsite assessment? Yes. However, after June 30,

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance Card-not-present Merchants, All Cardholder Data Functions Fully Outsourced Version 3.0 February

More information

PCI DSS Overview. By Kishor Vaswani CEO, ControlCase

PCI DSS Overview. By Kishor Vaswani CEO, ControlCase PCI DSS Overview By Kishor Vaswani CEO, ControlCase Agenda About PCI DSS PCI DSS Applicability to Banks, Merchants and Service Providers PCI DSS Technical Requirements Overview of PCI DSS 3.0 Changes Key

More information

PCI Compliance. Top 10 Questions & Answers

PCI Compliance. Top 10 Questions & Answers PCI Compliance Top 10 Questions & Answers 1. What is PCI Compliance and PCI DSS? 2. Who needs to follow the PCI Data Security Standard? 3. What happens if I don t comply? 4. What are the basic requirements

More information

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer Complying with the PCI DSS All the Moving Parts Don Roeber Vice President, PCI Compliance Manager Lisa Tedeschi Assistant Vice President, Compliance Officer Types of Risk Operational Risk Normal fraud

More information

Why Is Compliance with PCI DSS Important?

Why Is Compliance with PCI DSS Important? Why Is Compliance with PCI DSS Important? The members of PCI Security Standards Council (American Express, Discover, JCB, MasterCard, and Visa) continually monitor cases of account data compromise. These

More information

IMPORTANT BID ADDENDUM FAILURE TO RETURN THIS BID ADDENDUM IN ACCORDANCE WITH INSTRUCTIONS MAY SUBJECT YOUR BID TO REJECTION ON THE AFFECTED ITEM(S).

IMPORTANT BID ADDENDUM FAILURE TO RETURN THIS BID ADDENDUM IN ACCORDANCE WITH INSTRUCTIONS MAY SUBJECT YOUR BID TO REJECTION ON THE AFFECTED ITEM(S). STATE OF NORTH CAROLINA STATE OF NORTH CAROLINA NC Department of Natural and Cultural Resources Purchasing Office IMPORTANT BID ADDENDUM FAILURE TO RETURN THIS BID ADDENDUM IN ACCORDANCE WITH INSTRUCTIONS

More information

How To Ensure Account Information Security

How To Ensure Account Information Security Global PCI DSS Framework Emöke Bitter Business Leader, Risk Management 26 February 2009 Agenda Introduction Merchants Service Providers Registry of Service Providers Payment Applications Resources Information

More information

IT Security Compliance PCI DSS FOR MERCHANTS THE PAYMENT CARD INDUSTRY DATE SECURITY STANDARD WHITE PAPER

IT Security Compliance PCI DSS FOR MERCHANTS THE PAYMENT CARD INDUSTRY DATE SECURITY STANDARD WHITE PAPER July 9 th, 2012 Prepared By: Mark Akins PCI QSA, CISSP, CISA WHITE PAPER IT Security Compliance PCI DSS FOR MERCHANTS THE PAYMENT CARD INDUSTRY DATE SECURITY STANDARD PCI DSS for Merchants The Payment

More information

PCI DSS Compliance What Texas BUC$ Need to Know! Ron King CampusGuard rking@campusguard.com

PCI DSS Compliance What Texas BUC$ Need to Know! Ron King CampusGuard rking@campusguard.com PCI DSS Compliance What Texas BUC$ Need to Know! Ron King CampusGuard rking@campusguard.com Whoops!...3.1 Changes 3.1 PCI DSS Responsibility Information Technology Business Office PCI DSS Work Information

More information

PCI Compliance Top 10 Questions and Answers

PCI Compliance Top 10 Questions and Answers Where every interaction matters. PCI Compliance Top 10 Questions and Answers White Paper October 2013 By: Peer 1 Hosting Product Team www.peer1.com Contents What is PCI Compliance and PCI DSS? 3 Who needs

More information

PCI Compliance Overview

PCI Compliance Overview PCI Compliance Overview 1 PCI DSS Payment Card Industry Data Security Standard Standard that is applied to: Merchants Service Providers (Banks, Third party vendors, gateways) Systems (Hardware, software)

More information

MasterCard PCI & Site Data Protection (SDP) Program Update. Academy of Risk Management Innovate. Collaborate. Educate.

MasterCard PCI & Site Data Protection (SDP) Program Update. Academy of Risk Management Innovate. Collaborate. Educate. MasterCard PCI & Site Data Protection (SDP) Program Update Academy of Risk Management Innovate. Collaborate. Educate. The Payment Card Industry Security Standards Council (PCI SSC) Open, Global Forum Founded

More information

PCI DSS Presentation University of Cincinnati

PCI DSS Presentation University of Cincinnati PCI DSS Presentation University of Cincinnati Quick PCI Level Set Higher Ed Challenges Getting Compliant Application w/ customers Q& A PCI DSS Payment Card Industry Data Security Standard What is the PCI

More information

Payment Card Industry Data Security Standard Training. Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc.

Payment Card Industry Data Security Standard Training. Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc. Payment Card Industry Data Security Standard Training Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc. March 27, 2012 Agenda Check-In 9:00-9:30 PCI Intro and History

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Self-Assessment Questionnaire D Service Providers For use with PCI DSS Version 3.1 Revision 1.1 July 2015 Section 1: Assessment

More information

1/18/10. Walt Conway. PCI DSS in Context. Some History The Digital Dozen Key Players Cardholder Data Outsourcing Conclusions. PCI in Higher Education

1/18/10. Walt Conway. PCI DSS in Context. Some History The Digital Dozen Key Players Cardholder Data Outsourcing Conclusions. PCI in Higher Education PCI in Higher Education Walter Conway, QSA 403 Labs, LLC Walt Conway PCI consultant, blogger, trainer, speaker, author Former Visa VP Help schools become PCI compliant Represent Higher Education at PCI

More information

Case 2:13-cv-01887-ES-JAD Document 282-2 Filed 12/09/15 Page 1 of 116 PageID: 4879. Appendix A

Case 2:13-cv-01887-ES-JAD Document 282-2 Filed 12/09/15 Page 1 of 116 PageID: 4879. Appendix A Case 2:13-cv-01887-ES-JAD Document 282-2 Filed 12/09/15 Page 1 of 116 PageID: 4879 Appendix A Case 2:13-cv-01887-ES-JAD Document 282-2 Filed 12/09/15 Page 2 of 116 PageID: 4880 Payment Card Industry (PCI)

More information

What s New in PCI DSS 2.0. 2010 Cisco and/or its affiliates. All rights reserved. Cisco Systems, Inc 1

What s New in PCI DSS 2.0. 2010 Cisco and/or its affiliates. All rights reserved. Cisco Systems, Inc 1 What s New in PCI DSS 2.0 2010 Cisco and/or its affiliates. All rights reserved. Cisco Systems, Inc 1 Agenda PCI Overview PCI 2.0 Changes PCI Advanced Technology Update PCI Solutions 2010 Cisco and/or

More information

PCI DSS 3.0 and You Are You Ready?

PCI DSS 3.0 and You Are You Ready? PCI DSS 3.0 and You Are You Ready? 2014 STUDENT FINANCIAL SERVICES CONFERENCE Linda Combs combslc@jmu.edu Ron King rking@campusguard.com AGENDA PCI and Bursar Office Role Key Themes in v3.0 Timelines Changes

More information

PCI DSS 3.0 Overview. OSU Business Affairs Business Affairs PIT Crew - Project, Improvement, & Technology Robin Whitlock

PCI DSS 3.0 Overview. OSU Business Affairs Business Affairs PIT Crew - Project, Improvement, & Technology Robin Whitlock PCI DSS 3.0 Overview OSU Business Affairs Business Affairs PIT Crew - Project, Improvement, & Technology Robin Whitlock 01/16/2015 Purpose of Today s Presentation To provide an overview of PCI 3.0 based

More information

Payment Card Industry - Achieving PCI Compliance Steps Steps

Payment Card Industry - Achieving PCI Compliance Steps Steps CUR RITY SE Data Security Requirements for K-12 January 28, 2010 Payment Card Industry (PCI) SE CUR RITY 1 Welcome To Join The Voice Conference Dial 866-939-3921 Technical issues press 0 Q & A We ll leave

More information

Protecting Your Customers' Card Data. Presented By: Oliver Pinson-Roxburgh

Protecting Your Customers' Card Data. Presented By: Oliver Pinson-Roxburgh Protecting Your Customers' Card Data Presented By: Oliver Pinson-Roxburgh Agenda Trustwave Overview PCI Scope Compromise Statistics PCI Makes Business Sense Registration Process TrustKeeper Features Support

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance Merchants with Only Imprint Machines or Only Standalone, Dial-out Terminals Electronic Cardholder

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Standard Attestation of Compliance for Self-Assessment Questionnaire D Service Providers Version 3.1 April 2015 Section 1: Assessment Information Instructions for Submission

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.0 February 2014 Section 1: Assessment Information Instructions for Submission

More information

How To Protect Your Credit Card Information From Being Stolen

How To Protect Your Credit Card Information From Being Stolen Visa Account Information Security Tool Kit Welcome to the Visa Account Information Security Program 2 Contents 1. Securing cardholder data is everyone s concern 4 2. Visa Account Information Security (AIS)

More information

Data Security Standard (DSS) Compliance. SIFMA June 13, 2012

Data Security Standard (DSS) Compliance. SIFMA June 13, 2012 Payment Card Industry (PCI) Data Security Standard (DSS) Compliance SIFMA June 13, 2012 EisnerAmper Consulting Services Group Overview of EisnerAmper Fifth fhlargest accounting firm in the Metro New York

More information

How To Protect Your Business From A Hacker Attack

How To Protect Your Business From A Hacker Attack Payment Card Industry Data Security Standards The payment card industry data security standard PCI DSS Visa and MasterCard have developed the Payment Card Industry Data Security Standard or PCI DSS as

More information

PCI DSS. CollectorSolutions, Incorporated

PCI DSS. CollectorSolutions, Incorporated PCI DSS Robert Cothran President CollectorSolutions www.collectorsolutions.com CollectorSolutions, Incorporated Founded as Florida C corporation in 1999 Approximately 235 clients in 35 states Targeted

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.0 February 2014 Section 1: Assessment Information Instructions for Submission

More information

HOW SECURE IS YOUR PAYMENT CARD DATA? COMPLYING WITH PCI DSS

HOW SECURE IS YOUR PAYMENT CARD DATA? COMPLYING WITH PCI DSS HOW SECURE IS YOUR PAYMENT CARD DATA? COMPLYING WITH PCI DSS August 23, 2011 MOSS ADAMS LLP 1 TODAY S PRESENTERS Presenters Francis Tam, CPA, CISA, CISM, CITP, CRISC, PCI QSA Managing Director, IT Security

More information

DATA SECURITY. Payment Card Industry (PCI) Compliance Steps for Organizations May 26, 2010. 2010 Merit Member Conference

DATA SECURITY. Payment Card Industry (PCI) Compliance Steps for Organizations May 26, 2010. 2010 Merit Member Conference 2010 Merit Member Conference Compliance Steps for Organizations May 26, 2010 Payment Card Industry (PCI) 1 Welcome 2 Welcome Q & A We ll leave time to address questions during the last 15 minutes of the

More information

North Carolina Office of the State Controller Technology Meeting

North Carolina Office of the State Controller Technology Meeting PCI DSS Security Awareness Training North Carolina Office of the State Controller Technology Meeting April 30, 2014 agio.com A Note on Our New Name Secure Enterprise Computing was acquired as the Security

More information

PCI DSS. Payment Card Industry Data Security Standard. www.tuv.com/id

PCI DSS. Payment Card Industry Data Security Standard. www.tuv.com/id PCI DSS Payment Card Industry Data Security Standard www.tuv.com/id What Is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is the common security standard of all major credit cards brands.the

More information

PAYMENT CARD INDUSTRY (PCI) ANNUAL TRAINING DECEMBER 10, 2009 WESTERN ILLINOIS UNIVERSITY OFFICE OF THE CTSO & BUSINESS SERVICES

PAYMENT CARD INDUSTRY (PCI) ANNUAL TRAINING DECEMBER 10, 2009 WESTERN ILLINOIS UNIVERSITY OFFICE OF THE CTSO & BUSINESS SERVICES PAYMENT CARD INDUSTRY (PCI) ANNUAL TRAINING DECEMBER 10, 2009 WESTERN ILLINOIS UNIVERSITY OFFICE OF THE CTSO & BUSINESS SERVICES AGENDA PCI Players and Roles Merchant Requirements Keys To Successful PCI

More information

Property of CampusGuard. Compliance With The PCI DSS

Property of CampusGuard. Compliance With The PCI DSS Compliance With The PCI DSS Today s Agenda PCI DSS Introduction How are Colleges and Universities Affected? How Do You Validate Compliance? Best Practices Q&A CampusGuard Full-Service QSA/ASV Firm We Know

More information

Credit Card Risks: Update on PCI Compliance Monday, May 23 2:40pm 3:55 CPE: 2

Credit Card Risks: Update on PCI Compliance Monday, May 23 2:40pm 3:55 CPE: 2 Credit Card Risks: Update on PCI Compliance Monday, May 23 2:40pm 3:55 CPE: 2 Joe Helmy, VP Emerging Verticals, MasterCard Jennifer Cooperman, MBA, CPFO, Treasurer, City of Portland, OR Tod Burton, Financial

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.0 February 2014 Section 1: Assessment Information Instructions for Submission

More information

Comodo HackerGuardian. PCI Security Compliance The Facts. What PCI security means for your business

Comodo HackerGuardian. PCI Security Compliance The Facts. What PCI security means for your business Comodo HackerGuardian PCI Security Compliance The Facts What PCI security means for your business Overview The Payment Card Industry Data Security Standard (PCI DSS) is a set of 12 requirements intended

More information

Payment Card Industry (PCI) Data Security Standard ROC Reporting Instructions for PCI DSS v2.0

Payment Card Industry (PCI) Data Security Standard ROC Reporting Instructions for PCI DSS v2.0 Payment Card Industry (PCI) Data Security Standard ROC Reporting Instructions for PCI DSS v2.0 September 2011 Changes Date September 2011 Version Description 1.0 To introduce PCI DSS ROC Reporting Instructions

More information

Payment Card Industry Data Security Standard (PCI DSS) v1.2

Payment Card Industry Data Security Standard (PCI DSS) v1.2 Payment Card Industry Data Security Standard (PCI DSS) v1.2 Joint LA-ISACA and SFV-IIA Meeting February 19, 2009 Presented by Mike O. Villegas, CISA, CISSP 2009-1- Agenda Introduction to PCI DSS Overview

More information

Frequently Asked Questions

Frequently Asked Questions PCI Compliance Frequently Asked Questions Table of Content GENERAL INFORMATION... 2 PAYMENT CARD INDUSTRY DATA SECURITY STANDARD (PCI DSS)...2 Are all merchants and service providers required to comply

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire Instructions and Guidelines Version 1.1 February 2008 Table of Contents About this Document... 1 PCI Data Security Standard

More information

June 19, 2013. Bobbi McCracken, Associate Vice Chancellor Financial Services. Subject: Internal Audit of PCI Compliance.

June 19, 2013. Bobbi McCracken, Associate Vice Chancellor Financial Services. Subject: Internal Audit of PCI Compliance. RIVERSIDE: AUDIT & ADVISORY SERVICES June 19, 2013 To: Bobbi McCracken, Associate Vice Chancellor Financial Services Subject: Internal Audit of PCI Compliance Ref: R2013-03 We have completed our audit

More information

PCI Compliance 101: Payment Card. Your Presenter: 7/19/2011. Data Security Standards Compliance. Wednesday, July 20, 2011 2:00 pm 3:00 pm EDT

PCI Compliance 101: Payment Card. Your Presenter: 7/19/2011. Data Security Standards Compliance. Wednesday, July 20, 2011 2:00 pm 3:00 pm EDT PCI Compliance 101: Payment Card Industry Basics Data Security Standards Compliance Wednesday, July 20, 2011 2:00 pm 3:00 pm EDT This complimentary webinar is brought to you by ASAE-Endorsed Business Solutions

More information

Payment Card Industry Data Security Standard

Payment Card Industry Data Security Standard Payment Card Industry Data Security Standard Office of the State Treasurer Ryan Pitroff Banking Services Manager Ryan.Pitroff@tre.wa.gov PCI-DSS A common set of industry tools and measurements to help

More information

Project Title slide Project: PCI. Are You At Risk?

Project Title slide Project: PCI. Are You At Risk? Blank slide Project Title slide Project: PCI Are You At Risk? Agenda Are You At Risk? Video What is the PCI SSC? Agenda What are the requirements of the PCI DSS? What Steps Can You Take? Available Services

More information

Achieving PCI Compliance for Your Site in Acquia Cloud

Achieving PCI Compliance for Your Site in Acquia Cloud Achieving PCI Compliance for Your Site in Acquia Cloud Introduction PCI Compliance applies to any organization that stores, transmits, or transacts credit card data. PCI Compliance is important; failure

More information

Understanding Payment Card Industry (PCI) Data Security

Understanding Payment Card Industry (PCI) Data Security Understanding Payment Card Industry (PCI) Data Security Office of the State Controller November 2010 State of North Carolina The Enemy Major Security Breaches TJ-Max Heartland Hannaford Foods BJ s Wholesale

More information

What are the PCI DSS requirements? PCI DSS comprises twelve requirements, often referred to as the digital dozen. These define the need to:

What are the PCI DSS requirements? PCI DSS comprises twelve requirements, often referred to as the digital dozen. These define the need to: What is the PCI standards council? The Payment Card Industry Standards Council is an institution set-up by American Express, Discover Financial Services, JCB, MasterCard Worldwide and Visa International

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire Instructions and Guidelines Version 3.2 May 2016 Document Changes Date Version Description October 1, 2008 1.2 October 28,

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.0 February 2014 Section 1: Assessment Information Instructions for Submission

More information

Network Test Labs Inc Security Assessment Service Description Complementary Service Offering for New Clients

Network Test Labs Inc Security Assessment Service Description Complementary Service Offering for New Clients Network Test Labs Inc Security Assessment Service Description Complementary Service Offering for New Clients Network Test Labs Inc. Head Office 170 422 Richards Street, Vancouver BC, V6B 2Z4 E-mail: info@networktestlabs.com

More information

E Pay. A Case Study in PCI Compliance. Illinois State Treasurer. Dan Rutherford

E Pay. A Case Study in PCI Compliance. Illinois State Treasurer. Dan Rutherford E Pay A Case Study in PCI Compliance Illinois State Treasurer Dan Rutherford What is PCI? The Payment Card Industry s Data Security Standard states: PCI Data Security Requirements applies to all members,

More information

Whitepaper. PCI Compliance: Protect Your Business from Data Breach

Whitepaper. PCI Compliance: Protect Your Business from Data Breach Merchants often underestimate the financial impact of a breach. Direct costs include mandatory forensic audits, credit card replacement, fees, fines and breach remediation. PCI Compliance: Protect Your

More information

This appendix is a supplement to the Local Government Information Security: Getting Started Guide, a non-technical reference essential for elected

This appendix is a supplement to the Local Government Information Security: Getting Started Guide, a non-technical reference essential for elected This appendix is a supplement to the Local Government Information Security: Getting Started Guide, a non-technical reference essential for elected officials, administrative officials and business managers.

More information

An article on PCI Compliance for the Not-For-Profit Sector

An article on PCI Compliance for the Not-For-Profit Sector Level 8, 66 King Street Sydney NSW 2000 Australia Telephone +61 2 9290 4444 or 1300 922 923 An article on PCI Compliance for the Not-For-Profit Sector Page No.1 PCI Compliance for the Not-For-Profit Sector

More information

PCI 3.1 Changes. Jon Bonham, CISA Coalfire System, Inc.

PCI 3.1 Changes. Jon Bonham, CISA Coalfire System, Inc. PCI 3.1 Changes Jon Bonham, CISA Coalfire System, Inc. Agenda Introduction of Coalfire What does this have to do with the business office Changes to version 3.1 EMV P2PE Questions and Answers Contact Information

More information

AISA Sydney 15 th April 2009

AISA Sydney 15 th April 2009 AISA Sydney 15 th April 2009 Where PCI stands today: Who needs to do What, by When Presented by: David Light Sense of Security Pty Ltd Agenda Overview of PCI DSS Compliance requirements What & When Risks

More information

Registration and PCI DSS compliance validation

Registration and PCI DSS compliance validation Visa Europe A Guide for Third Party Agents Registration and PCI DSS compliance validation October 2015 Version 1.1 Visa Europe 2015 Contents 1 Introduction... 4 1.1 Definitions of Agents... 4 2 Registration

More information

Becoming PCI Compliant

Becoming PCI Compliant Becoming PCI Compliant Jason Brown - brownj52@michigan.gov Enterprise Security Architect Enterprise Architecture Department of Technology, Management and Budget State of Michigan @jasonbrown17 History

More information

PCI COMPLIANCE REQUIREMENTS COMPLIANCE CALENDAR

PCI COMPLIANCE REQUIREMENTS COMPLIANCE CALENDAR PCI COMPLIANCE REQUIREMENTS COMPLIANCE CALENDAR AUTHOR: UDIT PATHAK SENIOR SECURITY ANALYST udit.pathak@niiconsulting.com Public Network Intelligence India 1 Contents 1. Background... 3 2. PCI Compliance

More information

A Compliance Overview for the Payment Card Industry (PCI)

A Compliance Overview for the Payment Card Industry (PCI) A Compliance Overview for the Payment Card Industry (PCI) Many organizations are aware of the Payment Card Industry (PCI) and PCI compliance but are unsure if they are doing everything necessary. This

More information

Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions

Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions PCI/PA-DSS FAQs Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions What is PCI DSS? The Payment Card Industry Data

More information

How Secure is Your Payment Card Data?

How Secure is Your Payment Card Data? How Secure is Your Payment Card Data? Complying with PCI DSS SLIDE 1 PRESENTERS Francis Tam, CPA, CISA, CISM, CITP, CRISC, PCI QSA Managing Director, IT Security Practice PCI Practice Leader Francis has

More information

PCI Compliance. What is New in Payment Card Industry Compliance Standards. October 2015. cliftonlarsonallen.com. 2015 CliftonLarsonAllen LLP

PCI Compliance. What is New in Payment Card Industry Compliance Standards. October 2015. cliftonlarsonallen.com. 2015 CliftonLarsonAllen LLP cliftonlarsonallen.com PCI Compliance What is New in Payment Card Industry Compliance Standards October 2015 Overview PCI DSS In the beginning Each major card brand had its own separate criteria for implementing

More information

PCI Security Compliance

PCI Security Compliance E N T E R P R I S E Enterprise Security Solutions PCI Security Compliance : What PCI security means for your business The Facts Comodo HackerGuardian TM PCI and the Online Merchant Overview The Payment

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.0 February 2014 Section 1: Assessment Information Instructions for Submission

More information

Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance

Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance A Non-Technical Guide Essential for Business Managers Office Managers Operations Managers Compliant? Bank Name

More information

PC-DSS Compliance Strategies. 2011 NDUS CIO Retreat July 27, 2011 Theresa Semmens, CISA

PC-DSS Compliance Strategies. 2011 NDUS CIO Retreat July 27, 2011 Theresa Semmens, CISA PC-DSS Compliance Strategies 2011 NDUS CIO Retreat July 27, 2011 Theresa Semmens, CISA True or False Now that my institution has outsourced credit card processing, I don t have to worry about compliance?

More information

RFQ Section 1. What is your highest known merchant level (1, 2, 3, or 4) as assigned by your acquirer?

RFQ Section 1. What is your highest known merchant level (1, 2, 3, or 4) as assigned by your acquirer? # SAIC CoM 2014 RG R79343 1. What is your highest known merchant level (1, 2, 3, or 4) as assigned by your acquirer? 2. Approximately how many credit card transactions do you process per year? 300,000;

More information

PCI Compliance. Crissy Sampier, Longwood University Edward Ko, CampusGuard

PCI Compliance. Crissy Sampier, Longwood University Edward Ko, CampusGuard PCI Compliance Crissy Sampier, Longwood University Edward Ko, CampusGuard Agenda Introductions PCI DSS 101 Chip Cards (EMV) Longwood s PCI DSS Journey Breach Statistics Shortcuts to PCI DSS Compliance

More information

Technical breakout session

Technical breakout session Technical breakout session Small leaks sink great ships Managing data security, fraud and privacy risks Tarlok Birdi, Deloitte Ron Borsholm, WTS May 27, 2009 Agenda 1. PCI overview: the technical intent

More information

Vanderbilt University

Vanderbilt University Vanderbilt University Payment Card Processing and PCI Compliance Policy and Procedures Manual PCI Compliance Office Information Technology Treasury VUMC Finance Table of Contents Policy... 2 I. Purpose...

More information

It is important to note, the payment brands and acquirers are responsible for enforcing compliance, not the PCI council.

It is important to note, the payment brands and acquirers are responsible for enforcing compliance, not the PCI council. PCI FAQ And MYTHS FREQUENTLY ASKED QUESTIONS (FAQ): Q: What is PCI? A: The Payment Card Industry Data Security Standard (PCI DSS) is a set of requirements designed to ensure that ALL companies that process,

More information

Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS)

Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS) Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS) What is PCI DSS? The 12 Requirements Becoming compliant with SaferPayments Understanding the jargon SaferPayments Be smart.

More information

Top PCI 3.0 Challenges for Chain Merchants. March 11, 2015

Top PCI 3.0 Challenges for Chain Merchants. March 11, 2015 Top PCI 3.0 Challenges for Chain Merchants March 11, 2015 Webinar Program Wednesday, March 11, 2015 Presentations 3PM 3:45PM Eastern Questions & Answers 3:45PM 4:00PM Eastern Agenda Cybercrime PCI DSS

More information

Data Security & PCI Compliance & PCI Compliance Securing Your Contact Center Securing Your Contact Session Name :

Data Security & PCI Compliance & PCI Compliance Securing Your Contact Center Securing Your Contact Session Name : Data Security & PCI Compliance Securing Your Contact Center Session Name : Title Introducing Trevor Horwitz Pi Principal, i TrustNet t trevor.horwitz@trustnetinc.com John Simpson CIO, Noble Systems Corporation

More information

Payment Card Industry (PCI) Data Security Standard. Attestation of Compliance for Self-Assessment Questionnaire C-VT. Version 2.0

Payment Card Industry (PCI) Data Security Standard. Attestation of Compliance for Self-Assessment Questionnaire C-VT. Version 2.0 Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Self-Assessment Questionnaire C-VT Version 2.0 October 2010 Attestation of Compliance, SAQ C-VT Instructions for Submission

More information

Payment Card Industry Compliance Overview

Payment Card Industry Compliance Overview January 31, 2014 11:30am 12:30pm Central Hosted by: Texas.gov Presented by: Jayne Holland Barbara Brinson Payment Card Industry Compliance Overview Securing Government Payments Audio Dial In: 866-740-1260

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.0 February 2014 Section 1: Assessment Information Instructions for Submission

More information

UCSB Credit Card Processing and PCI Compliance

UCSB Credit Card Processing and PCI Compliance UCSB Credit Card Processing and PCI Compliance Sandra Featherson Associate Director of Controls Campus Credit Card Coordinator May 2011 Agenda Campus Credit Card Process Overview Terminology Approval/Acceptance

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance Imprint Machines or Stand-alone Dial-out Terminals Only, no Electronic Cardholder Data Storage

More information

A MERCHANTS GUIDE TO THE PAYMENT APPLICATION DATA SECURITY STANDARD (PA-DSS)

A MERCHANTS GUIDE TO THE PAYMENT APPLICATION DATA SECURITY STANDARD (PA-DSS) A MERCHANTS GUIDE TO THE PAYMENT APPLICATION DATA SECURITY STANDARD (PA-DSS) The mandatory guide for storing, processing or transmitting cardholder information Overview and applicability Any application

More information

PCI on Amazon Web Services (AWS) What You Need To Know Understanding the regulatory roadmap for PCI on AWS

PCI on Amazon Web Services (AWS) What You Need To Know Understanding the regulatory roadmap for PCI on AWS PCI on Amazon Web Services (AWS) What You Need To Know Understanding the regulatory roadmap for PCI on AWS David Clevenger November 2015 Summary Payment Card Industry (PCI) is an accreditation body that

More information

Whitepaper. PCI Compliance: Protect Your Business from Data Breach

Whitepaper. PCI Compliance: Protect Your Business from Data Breach Merchants often underestimate the financial impact of a breach. Direct costs include mandatory forensic audits, credit card replacement, fees, fines and breach remediation. PCI Compliance: Protect Your

More information

Payment Card Industry Standard - Symantec Services

Payment Card Industry Standard - Symantec Services Payment Card Industry Standard - Symantec Services The Payment Card Industry Data Security Standard (PCI, or PCI DSS) was developed by the PCI Security Standards Council to assure cardholders that their

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.1 April 2015 Section 1: Assessment Information Instructions for Submission

More information

Payment Card Industry Data Security Standards Compliance

Payment Card Industry Data Security Standards Compliance Payment Card Industry Data Security Standards Compliance Please turn off, or to vibrate, all cell-phones/electronics Expected course length: 1 Hour Questions are welcomed. Who Created It? & What Is It?

More information

PCI Compliance 3.1. About Us

PCI Compliance 3.1. About Us PCI Compliance 3.1 University of Hawaii About Us Helping organizations comply with mandates, recover from security breaches, and prevent data theft since 2000. Certified to conduct all major PCI compliance

More information