PCI Compliance - telephone payment help

Dannypenguin

Free Member
Feb 24, 2021
1
0
Good Evening,

First post here, thanks for having me. I've recently moved my Merchant bank and I'm in the process of a DIY PCI compliance. I've completed the one for my Ecommerce site but now I'm on the one for my telephone payments and it's considerably harder!

We use Opayo and the "MySagePay" system, and we use their terminal through our browser - so if a customer is on the phone with a staff member, they login to their unique Sagepay account and process the payment by typing in the customers details and then their card details.

I'm trying to work out what applies to us and what doesn't, there's few key questions I'm struggling with, the main one being:

"Is inbound and outbound traffic restricted to that which is necessary for the cardholder data environment?" The options are "Yes", "Yes with CCW", "No" and "N/A".

I'm trying to figure this question out, as to me it suggests that the PC that is taking cardholder data should be restricted to that and just that only, but surely that can't be a stipulation? That would suggest that's all the PC can do is card details, but obviously it has to connect to stock system, order system etc all of which are online based so the staff member can enter the order on the system, then take the payment based on the amount the order system generates, etc.

I assume I'm misunderstanding this, if anyone has a way of explaining this in a simple terms I'd be super appreciative? :-)

Many thanks and kind regards,

Dan
 
There are no simple terms and you should really consider stopping phone payments.

The reason behind it is in regards to providing adequate security in your network and manage proper security you would have to go through many hoops that are expensive.

If you fail to understand what they want I can guarantee you you don't have the knowledge to do it.

Looking at all factors for basic security in such environment are. Regularly check of all devices, os patching including cctv systems and network printers. Gotta love network printer for security breaches. Did you ever change the default passwords. Most likley not. Are you exposing ports. Is your Router / Firewall business / enterprise level security e.g deep level inspection up to scratch. Regular security training staff and millions of other things to consider.

If you already struggle to answer traffic questions the list would go on.

What's wrong with payment links?
 
Upvote 0
As an alternative to manual phone payments you could consider using IVR (Interactive Voice Response) which allows customers to key in card details via their phone pad to authorise transactions in a PCI compliant manner and environment. IVR can be used to dial out and receive incoming calls.
 
Upvote 0
Use a Secure Virtual Terminal to take telephone payments without the customer needing to disclose their card details to your business. Instead they can type in their private and sensitive information using their telephone keypad. www.paytia.com
 
Upvote 0

Latest Articles