Attestation of Compliance for Onsite Assessments Service Providers

Similar documents
Attestation of Compliance for Onsite Assessments Service Providers

Attestation of Compliance for Onsite Assessments Service Providers

Attestation of Compliance for Onsite Assessments Service Providers

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard. Attestation of Compliance for Self-Assessment Questionnaire C-VT. Version 2.0

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard

Section 1: Assessment Information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire C and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard

Attestation of Compliance, SAQ A

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance

How To Complete A Pci Ds Self Assessment Questionnaire

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance

Credit Card Processing Overview

CardControl. Credit Card Processing 101. Overview. Contents

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire C-VT and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire P2PE-HW and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance

Payment Application Data Security Standard

Adyen PCI DSS 3.0 Compliance Guide

worldpay.com Understanding the 12 requirements of PCI DSS SaferPayments Be smart. Be compliant. Be protected.

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer

Becoming PCI Compliant

PCI DSS Payment Card Industry Data Security Standard. Merchant compliance guidelines for level 4 merchants

How To Protect Your Business From A Hacker Attack

Agent Registration. Program Guidelines. (For use in Asia Pacific, Central Europe, Middle East and Africa)

Frequently Asked Questions

PCI DSS Overview. By Kishor Vaswani CEO, ControlCase

PCI DSS Compliance Information Pack for Merchants

IT Security Compliance PCI DSS FOR MERCHANTS THE PAYMENT CARD INDUSTRY DATE SECURITY STANDARD WHITE PAPER

Key Steps to Meeting PCI DSS 2.0 Requirements Using Sensitive Data Discovery and Masking

Payment Card Industry (PCI) Data Security Standard ROC Reporting Instructions for PCI DSS v2.0

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008

Registry of Service Providers

PCI Data Security Standards. Presented by Pat Bergamo for the NJTC February 6, 2014

PDQ Guide for the PCI Data Security Standard Self-Assessment Questionnaire C (Version 1.1)

Josiah Wilkinson Internal Security Assessor. Nationwide

Your Compliance Classification Level and What it Means

Policy Title: Payment Cards Policy Effective Date: 5/5/2010. Policy Number: FA-PO-1214 Date of Last Revision: 11/5/2014

Agent Registration. Program Guide. (For use in Asia Pacific, Central Europe, Middle East, Africa)

This appendix is a supplement to the Local Government Information Security: Getting Started Guide, a non-technical reference essential for elected

PCI DSS 3.0 Overview. OSU Business Affairs Business Affairs PIT Crew - Project, Improvement, & Technology Robin Whitlock

La règlementation VisaCard, MasterCard PCI-DSS

A MERCHANTS GUIDE TO THE PAYMENT APPLICATION DATA SECURITY STANDARD (PA-DSS)

Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance

AIS Webinar. Payment Application Security. Hap Huynh Business Leader Visa Inc. 1 April 2009

PCI DSS. CollectorSolutions, Incorporated

2015 PCI DSS Meeting. OSU Business Affairs Projects, Improvement, and Technology (PIT) Robin Whitlock

PCI DSS FAQ. The twelve requirements of the PCI DSS are defined as follows:

PCI Security Compliance

Comodo HackerGuardian. PCI Security Compliance The Facts. What PCI security means for your business

How To Comply With The Pci Ds.S.A.S

Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015

Why Is Compliance with PCI DSS Important?

Payment Card Industry Data Security Standards

FOR A BARRIER-FREE PAYMENT PROCESSING SOLUTION

How To Protect Visa Account Information

Case 2:13-cv ES-JAD Document Filed 12/09/15 Page 1 of 116 PageID: Appendix A

PCI DSS Gap Analysis Briefing

PCI Compliance Overview

What To Do if Compromised. Visa USA Fraud Investigations and Incident Management Procedures

Payment Card Industry Security Standards PCI DSS, PCI-PTS and PA-DSS

Payment Card Industry Data Security Standards Compliance

Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS)

PCI Security Standards Council

Varonis Systems & The Payment Card Industry Data Security Standard (PCI DSS)

Project Title slide Project: PCI. Are You At Risk?

Payment Cardholder Data Handling Procedures (required to accept any credit card payments)

Introduction to PCI DSS

Fraud Protection, You and Your Bank

PCI Standards: A Banking Perspective

The University of Michigan Treasurer s Office Card Services. Merchant Services Policy Document

PCI DSS Compliance Services January 2016

Transcription:

Attestation of Compliance Service Providers Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 2.0 October 2010

Instructions for Submission The Qualified Security Assessor (QSA) and Service Provider must complete this document as a declaration of the Service Provider s compliance status with the Payment Card Industry Data Security Standard (PCI DSS). Complete all applicable sections and submit to the requesting payment brand. Part 1. Service Provider and Qualified Security Assessor Information Service Provider Organization Information Company Name: Shopify, Inc. DBA(s): Shopify Payments (Canada) Inc. & Shopify Payments (USA) Inc. Contact Name: Andrew Dunbar Title: Director of Risk and Compliance Telephone: (613) 688-3623 E-mail: Andrew.dunbar@shopify.com Business Address: 126 York Street, Suite 200 City: Ottawa State/Province: ON Country: Canada Zip: K1N 5T5 URL: http://www.shopify.com Qualified Security Assessor Company Information Company Name: Coalfire Systems, Inc. Lead QSA Contact Name: Ron Kiss Title: Director Telephone: +44 161 457 1185 E-mail: Rkiss@coalfire.com Business Address: 361 Centennial Parkway, Suite City: Louisville 150 State/Province: CO Country: United States Zip: 80027 URL: http://www.coalfire.com Part 2 PCI DSS Assessment Information Part 2a. Services Provided that WERE INCLUDED in the Scope of the PCI DSS Assessment (check all that apply) Payment Processing-POS Tax/Government Fraud and Chargeback Payments Services Payment Processing-Internet Payment Processing Payment Processing ATM MOTO Issuer Processing Payment Gateway/Switch Clearing and Settlement Account Management 3-D Secure Hosting Provider Loyalty Programs Back Office Services Prepaid Services Merchant Services Hosting Provider Web Managed Services Billing Management Network Provider/Transmitter Hosting Provider Hardware Records Management Data Preparation Others (please specify): Payment Service Provider (PSP), Independent Sales Organization (ISO) List facilities and locations included in PCI DSS review: Shopify Corporate Headquarters 126 York Street, Suite 200 Ottawa, ON, Canada, K1N 5T5 Amazon Web Services Hosted Environment

Part 2b. Relationships Does your company have a relationship with one or more third-party service providers (for example, gateways, web-hosting companies, airline booking agents, loyalty program agents, etc.)? Part 2c. Transaction Processing How and in what capacity does your business store, process and/or transmit cardholder data? Shopify offers payment services to both brick and mortar and e-commerce merchants. Shopify receives transactions from the Internet, performs payment processing internally, then forwards payment data to payment gateways or acquirers for authorizations. Shopify accepts payments originating as both card-present and card-not-present transactions. Finally, Shopify provides a decryption environment for card-present transactions received via the Internet facing payment gateway. Please provide the following information regarding the Payment Applications your organization uses: Payment Application in Use Version Number Last Validated according to PABP/PA-DSS N/A Part 3. PCI DSS Validation Based on the results noted in the Report on Compliance ( ROC ) dated 30 July 2014, Coalfire asserts the following compliance status for the entity identified in Part 2 of this document as of 30 July 2014 (check one): Compliant: All requirements in the ROC are marked in place 1, and a passing scan has been completed by the PCI SSC Approved Scanning Vendor Qualys thereby Shopify has demonstrated full compliance with the PCI DSS version 2. n-compliant: Some requirements in the ROC are marked not in place, resulting in an overall NON-COMPLIANT rating, or a passing scan has not been completed by a PCI SSC Approved Scanning Vendor, thereby (Service Provider Name) has not demonstrated full compliance with the PCI DSS. Target Date for Compliance: An entity submitting this form with a status of n-compliant may be required to complete the Action Plan in Part 4 of this document. Check with the payment brand(s) before completing Part 4, since not all payment brands require this section. Part 3a. Confirmation of Compliant Status QSA and Service Provider confirm: The ROC was completed according to the PCI DSS Requirements and Security Assessment Procedures, Version 2.0, and was completed according to the instructions therein. All information within the above-referenced ROC and in this attestation fairly represents the results of the assessment in all material respects. The Service Provider has read the PCI DSS and recognizes that they must maintain full PCI DSS compliance at all times. evidence of magnetic stripe (that is, track) data 2, CAV2, CVC2, CID, or CVV2 data 3, or PIN data 4 storage after transaction authorization was found on ANY systems reviewed during this assessment. 1 In place results should include compensating controls reviewed by the QSA. If compensating controls are determined to sufficiently mitigate the risk associated with the requirement, the QSA should mark the requirement as in place. 2 Data encoded in the magnetic stripe or equivalent data on a chip used for authorization during a card-present transaction. Entities may not retain full magnetic stripe data after transaction authorization. The only elements of track data that may be retained are account number, expiration date, and name. 3 The three- or four-digit value printed on the signature panel or face of a payment card used to verify card-not-present transactions. 4 Personal Identification Number entered by cardholder during a card-present transaction, and/or encrypted PIN block present within the transaction message.

Part 3b. QSA and Service Provider Acknowledgments Signature of Service Provider Executive Officer Service Provider Executive Officer Name: Tobias Lütke Signature of Lead QSA Lead QSA Name: Ron Kiss Title: Director Title: Date: 11 August 2014 CEO Date: 30 July 2014

Part 4. Action Plan for n-compliant Status Please select the appropriate Compliance Status for each requirement. If you answer to any of the requirements, you are required to provide the date Company will be compliant with the requirement and a brief description of the actions being taken to meet the requirement. Check with the payment brand(s) before completing Part 4 since not all payment brands require this section. PCI Requirement Description Compliance Status (Select One) Remediation Date and Actions (if Compliance Status is ) 1 Install and maintain a firewall configuration to protect cardholder data. 2 Do not use vendor-supplied defaults for system passwords and other security parameters. 3 Protect stored cardholder data. 4 5 6 7 8 9 10 11 12 Encrypt transmission of cardholder data across open, public networks. Use and regularly update antivirus software. Develop and maintain secure systems and applications. Restrict access to cardholder data by business need to know. Assign a unique ID to each person with computer access. Restrict physical access to cardholder data. Track and monitor all access to network resources and cardholder data. Regularly test security systems and processes. Maintain a policy that addresses information security.