![]() |
|
#31
|
||||
|
||||
|
Quote:
This is an example of where we frequently see SAQ C go wrong. A lot of restaurant franchisees that operate three or more locations typically have very sophisticated systems that not only run the POS, but also the back office accounting and inventory management, employee time keeping, etc. The problem is that these integrated solutions (usually only two servers, a primary and a backup) not only connect to the card processor, but also connect to master servers back at the franchisee's headquarters. 9 times out of 10, these are the people that want to fill out the SAQ C under the mistaken belief that their integrated solution meets the qualifications for SAQ C. This is where the acquiring bank or the card processor need to step up and explain that this is not the intent of SAQ C. However, because the majority of the card processors and acquiring banks have limited, if any, knowledge regarding the SAQs, let alone the full PCI DSS, they just nod their heads in agreement and let the franchisee fill out whatever SAQ they ask to fill out. Then when a breach occurs, all hell breaks loose because the franchisee is being fined by the people that gave them the bad advice. The correct SAQ for our example above is to fill out SAQ D.
__________________
Jeff Hall, Director, Risk Advisory Services RSM McGladrey Inc 801 Nicollet Mall, 11th Floor, West Tower Minneapolis, MN 55402-2526 612 376 9280 - office 612 395 7280 - facsimile www.mcgladrey.com The views presented are those of the writer and are not necessarily those of RSM McGladrey Inc |
|
#32
|
|||
|
|||
|
Quote:
The amount of misinformation out there is amazing. Unfortunately, smaller merchants often go with the lowest cost solution and trust the vendor that they have adequately scoped the solution for their environment. Come breach time, they will be unpleasantly surprised.
__________________
--------------------------- Blake Huebner - CISSP, QSA (now former), CPISM Last edited by bhuebner; 08-26-2010 at 01:25 PM. |
![]() |
| Thread Tools | |
| Display Modes | |
|
|