- Original Poster
- #1
Hi,
I am sorry as I am sure this will have been covered before but I can't seem to find.
My merchant (Globalpayments) has just sent me a letter saying I need to now be PCI DSS compliant.
99.99% of my business is face to face, direct entry into a there terminal.
Perhaps 5 or 6 times a year I might take a payment over the phone but I could easily stop this (poss use paypal online instead but I could easily do without any form of not present)
In these cases I do not write or store the information anywhere, I just type into there terminal again, with the procedure & security checks, even asks for post code numbers & address numbers so there is no way I have the wrong client or details. Perhaps I should know & records these transactions but do not write the details anywhere are the are so very rare.
Looking at the PCI secuirity Standards .net www I would come under "others" D
the SAQ for this is 49 pages of tick boxes etc & not always very clear or obvious.
I do have clients Names & address etc stored on computer but absolutely no financial details, no DOB or any other personal information.
The invoice amounts are on my database but that is it.
Nothing that could possibly compromise a card payment is stored on computer.
The terminal machine goes straight to the phone line so must be impossible to access any information via a network.
Someone could sit at my computer and would never be able to gets any card details.
I can't see why I need such a complicated form.
I am fairly sure my network is safe anyway, it is wireless but proper high level wifi secuirty, passwords etc. firewalls etc.
I appreciate this is good in that it makes people think and if you are processing & storing details it really important to protect this data.
Do I really need to fill in 200 questions on my network & IT security.
Fine for questions on protecting my terminal & prevent skimming etc.
Surely the following in most cases would do.
Do you store card or other financial information on clients Yes/No
if NO
Do you protect your terminal: supervise, protect access, train staff, cameras etc etc
Yes
OK thats fine.
I can sign up to there recommend Global Fortress from* £3.50 for there shop/service, which is fine if I needed a shop?!?
BUT what I find astonishing is, "the alternative" to use another provider or use the SAQ but this will incur an admin fee that starts* from £3 + Vat per month.
WHAT!!
Whilst only a small amount of money, what admin? why should have to pay not to have a service, especially if I have done a SAQ & I have said I am compliant do they have to analize the form & re-read every month.
I wanted to be a bit more informed before I phone, I suspect they are simply going to say you need compliance & subscribe to our service.
Sorry bit of a rant, the tone of the letter I got was not pleasant, "...non-compliance charge of 15p per transaction & min £50 per month until you are compliant....We are enforcing this on all merchants regardless of how transaction are processed"
I understand they need to make people aware & improve security but somehow I suspect it will always be the big companies that seem to have the security breeches and assume they have huge budgets & IT departments but the smaller companies get alarming letters & spend valuable time trying to work out what to do.
I might change merchant anyway, I know I will prob have to comply also but just don't like the way they go about things.
Any advise
I am sorry as I am sure this will have been covered before but I can't seem to find.
My merchant (Globalpayments) has just sent me a letter saying I need to now be PCI DSS compliant.
99.99% of my business is face to face, direct entry into a there terminal.
Perhaps 5 or 6 times a year I might take a payment over the phone but I could easily stop this (poss use paypal online instead but I could easily do without any form of not present)
In these cases I do not write or store the information anywhere, I just type into there terminal again, with the procedure & security checks, even asks for post code numbers & address numbers so there is no way I have the wrong client or details. Perhaps I should know & records these transactions but do not write the details anywhere are the are so very rare.
Looking at the PCI secuirity Standards .net www I would come under "others" D
the SAQ for this is 49 pages of tick boxes etc & not always very clear or obvious.
I do have clients Names & address etc stored on computer but absolutely no financial details, no DOB or any other personal information.
The invoice amounts are on my database but that is it.
Nothing that could possibly compromise a card payment is stored on computer.
The terminal machine goes straight to the phone line so must be impossible to access any information via a network.
Someone could sit at my computer and would never be able to gets any card details.
I can't see why I need such a complicated form.
I am fairly sure my network is safe anyway, it is wireless but proper high level wifi secuirty, passwords etc. firewalls etc.
I appreciate this is good in that it makes people think and if you are processing & storing details it really important to protect this data.
Do I really need to fill in 200 questions on my network & IT security.
Fine for questions on protecting my terminal & prevent skimming etc.
Surely the following in most cases would do.
Do you store card or other financial information on clients Yes/No
if NO
Do you protect your terminal: supervise, protect access, train staff, cameras etc etc
Yes
OK thats fine.
I can sign up to there recommend Global Fortress from* £3.50 for there shop/service, which is fine if I needed a shop?!?
BUT what I find astonishing is, "the alternative" to use another provider or use the SAQ but this will incur an admin fee that starts* from £3 + Vat per month.
WHAT!!
Whilst only a small amount of money, what admin? why should have to pay not to have a service, especially if I have done a SAQ & I have said I am compliant do they have to analize the form & re-read every month.
I wanted to be a bit more informed before I phone, I suspect they are simply going to say you need compliance & subscribe to our service.
Sorry bit of a rant, the tone of the letter I got was not pleasant, "...non-compliance charge of 15p per transaction & min £50 per month until you are compliant....We are enforcing this on all merchants regardless of how transaction are processed"
I understand they need to make people aware & improve security but somehow I suspect it will always be the big companies that seem to have the security breeches and assume they have huge budgets & IT departments but the smaller companies get alarming letters & spend valuable time trying to work out what to do.
I might change merchant anyway, I know I will prob have to comply also but just don't like the way they go about things.
Any advise
