- Original Poster
- #1
Good Evening,
First post here, thanks for having me. I've recently moved my Merchant bank and I'm in the process of a DIY PCI compliance. I've completed the one for my Ecommerce site but now I'm on the one for my telephone payments and it's considerably harder!
We use Opayo and the "MySagePay" system, and we use their terminal through our browser - so if a customer is on the phone with a staff member, they login to their unique Sagepay account and process the payment by typing in the customers details and then their card details.
I'm trying to work out what applies to us and what doesn't, there's few key questions I'm struggling with, the main one being:
"Is inbound and outbound traffic restricted to that which is necessary for the cardholder data environment?" The options are "Yes", "Yes with CCW", "No" and "N/A".
I'm trying to figure this question out, as to me it suggests that the PC that is taking cardholder data should be restricted to that and just that only, but surely that can't be a stipulation? That would suggest that's all the PC can do is card details, but obviously it has to connect to stock system, order system etc all of which are online based so the staff member can enter the order on the system, then take the payment based on the amount the order system generates, etc.
I assume I'm misunderstanding this, if anyone has a way of explaining this in a simple terms I'd be super appreciative?
Many thanks and kind regards,
Dan
First post here, thanks for having me. I've recently moved my Merchant bank and I'm in the process of a DIY PCI compliance. I've completed the one for my Ecommerce site but now I'm on the one for my telephone payments and it's considerably harder!
We use Opayo and the "MySagePay" system, and we use their terminal through our browser - so if a customer is on the phone with a staff member, they login to their unique Sagepay account and process the payment by typing in the customers details and then their card details.
I'm trying to work out what applies to us and what doesn't, there's few key questions I'm struggling with, the main one being:
"Is inbound and outbound traffic restricted to that which is necessary for the cardholder data environment?" The options are "Yes", "Yes with CCW", "No" and "N/A".
I'm trying to figure this question out, as to me it suggests that the PC that is taking cardholder data should be restricted to that and just that only, but surely that can't be a stipulation? That would suggest that's all the PC can do is card details, but obviously it has to connect to stock system, order system etc all of which are online based so the staff member can enter the order on the system, then take the payment based on the amount the order system generates, etc.
I assume I'm misunderstanding this, if anyone has a way of explaining this in a simple terms I'd be super appreciative?
Many thanks and kind regards,
Dan