are you pci dss compliant? - cnsgare you pci dss compliant? we can help you get there. step-by-step...

2
Are You PCI DSS Compliant? We Can Help You Get There. Step-by-Step Process With Results No matter how great your payment process and devices are, it can be extremely challenging for you to ensure your current architecture is PCI DSS secure. TruShield is your trusted ally that will help plan, build, and implement the necessary elements that will not only comply with the requirements but also save you time and money on additional resources. Our skilled team has PCI Security Standards Council QSA Certification and a cybersecurity background that will give you the competitive advantage of a one-stop solution. Steps to Compliance How do you determine compliance? There are three main steps in the process that you need to follow to ensure you become PCI compliant, they are as follows: STEP 1: ASSESS Figure out what PCI DSS level you are. You can view the different levels on PCI SSC’s website (https://www.pcicomplianceguide. org/pci-faqs-2/#4), and your acquirer should be able to confirm what level you organization is currently categorized as. This will enable you to confirm the scope of the PCI-DSS Assessment. Know what is required of your organization. Some PCI levels have slightly different requirements in terms of deliverables and who is qualified to generate the deliverables. Scope your PCI environment. Identifying all the areas in which PCI data is located in, otherwise known as the cardholder data environment (CDE), will better prepare you for taking steps to implement the PCI controls in the correct areas rather than system-wide. STEP 2: REMEDIATE Review and implement the requirements. Assess each requirement for completion and tackle each in the CDE that is not currently complete. Remediation. If required, perform remediation to address requirements that are not in place. STEP 3: REPORT Complete the applicable report. This should include the documentation of all compensating controls, according to the applicable PCI DSS guidance and instructions. Complete the attestation of compliance (AOC). AOCs are available on the PCI SSC website. Submit compliance Package. SAQ or ROC, AOC, Certified ASV scan reports, and other documentations requested to the acquirer (for merchant) or other requestor (for service providers) should be included in the package. PCI COMPLIANCE trushieldinc.com Let TruShield help put together the pieces of the PCI puzzle for you and provide the clarity you need.

Upload: others

Post on 04-Jul-2020

9 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Are You PCI DSS Compliant? - CNSGAre You PCI DSS Compliant? We Can Help You Get There. Step-by-Step Process With Results No matter how great your payment process and devices are, it

Are You PCI DSS Compliant?We Can Help You Get There.

Step-by-Step Process With ResultsNo matter how great your payment process and devices are, it can be extremely challenging for you to ensure your current architecture is PCI DSS secure. TruShield is your trusted ally that will help plan, build, and implement the necessary elements that will not only comply with the requirements but also save you time and money on additional resources. Our skilled team has PCI Security Standards Council QSA Certification and a cybersecurity background that will give you the competitive advantage of a one-stop solution.

Steps to ComplianceHow do you determine compliance? There are three main steps in the process that you need to follow to ensure you become PCI compliant, they are as follows:

STEP 1:

ASSESSFigure out what PCI DSS level you are. You can view the different levels on PCI SSC’s website (https://www.pcicomplianceguide.org/pci-faqs-2/#4), and your acquirer should be able to confirm what level you organization is currently categorized as. This will enable you to confirm the scope of the PCI-DSS Assessment.

Know what is required of your organization. Some PCI levels have slightly different requirements in terms of deliverables and who is qualified to generate the deliverables.

Scope your PCI environment. Identifying all the areas in which PCI data is located in, otherwise known as the cardholder data environment (CDE), will better prepare you for taking steps to implement the PCI controls in the correct areas rather than system-wide.

STEP 2: REMEDIATEReview and implement the requirements. Assess each requirement for completion and tackle each in the CDE that is not currently complete.

Remediation. If required, perform remediation to address requirements that are not in place.

STEP 3: REPORTComplete the applicable report. This should include the documentation of all compensating controls, according to the applicable PCI DSS guidance and instructions.

Complete the attestation of compliance (AOC). AOCs are available on the PCI SSC website.

Submit compliance Package. SAQ or ROC, AOC, Certified ASV scan reports, and other documentations requested to the acquirer (for merchant) or other requestor (for service providers) should be included in the package.

PCI COMPLIANCE trushieldinc.com

Let TruShield help put together the pieces of the PCI puzzle for you and provide the clarity you need.

Page 2: Are You PCI DSS Compliant? - CNSGAre You PCI DSS Compliant? We Can Help You Get There. Step-by-Step Process With Results No matter how great your payment process and devices are, it

Is your organization struggling to understand which PCI DSS controls are required and when your critical systems need to be protected?

Look, there is no easy way to tackle it. Complicated legal information from an acquirer, notices of potential fees for violations, and credit card theft headlines in the news can make the whole PCI DSS project seem daunting and downright terrifying. Searching for answers online only leaves you with confusing jargon, conflicting information, and fuzzy advice that doesn’t help. You need real solutions by real people.

White-Glove ServiceIf your team is concerned about anything, such as having gaps in its security program, we are here to help. TruShield takes a white-glove concierge approach to our customer service. To ensure the absolute best support is provided, each of our customers is given an assigned project team. You will have ongoing communication and bi-weekly meetings with these helpful and experienced security professionals, where they will guide you through every step of the process while you work with TruShield.

Get Expert Guidance When and Where You Need it MostEvery organization is unique, and criminals are targeting different information sources to get what they want.

At TruShield, we are always a step ahead, learning everything we can about current and potential threats, and the latest approach criminals are using to access payment card data. We understand that there are a lot of moving parts and various configurations for how any organization can structure their payment system. A one-size-fits-all solution isn’t going to work. To help alleviate the pain points associated with compliance, TruShield offers a variety of services to help you on your way, including:

Sensible PricingPCI Compliance is a growing concern for most organizations as the number of credit card breaches continue to rise. With the increasing complexity of the payment process, ensuring that your organization stays compliant can be difficult and resource-intensive at a staggering cost. But don’t worry, TruShield can provide guidance and assistance at a comfortable price point.

Contact Us

• PCI DSS Self-Assessment Questionnaire Assistance

• PCI DSS Audit Readiness

• PCI DSS Scoping Evaluation

• PCI DSS Technical Evaluation

• PCI DSS QSA Assessment (for Level 1 merchants)

• PCI DSS Policy Development

• PCI DSS Policy Reviews

Take the first step towards compliance with an easier solution. Mitigate risks and strengthen your organization’s security posture by getting in touch with us. Let TruShield help put together the

pieces of the PCI puzzle so you can focus on what you do best, your business.

Interested in learning how TruShield can give you the peace of mind that your information is safe from cybercriminals? Reach out to the TruShield Sales staff now to get started using our innovative cybersecurity approach.

22375 Broderick Drive Suite 100, Dulles, VA 20166877-583-2841