PCI DSS non compliance

PCI DSS non compliance

Author
Discussion

4xTrader

Original Poster:

156 posts

147 months

Friday 7th March 2014
quotequote all
Hi,

A little help please! We are being charged a PCI DSS non compliance charge of £10 every month, we are a small(ish) shop where we take card payments over the counter and every so often over the phone. I have looked at the PCI website which does not make much sense and seems to be yet another why extract more cash out of people.

Does anyone know of a company that I can become compliant though as there seems to be many……or any other advice? or a way to get round this, do I need to be compliant??

Cheers

Big E 118

2,410 posts

169 months

Friday 7th March 2014
quotequote all
I used Trustwave https://www3.trustwave.com/pci-dss-compliance/ 10 minutes to complete the questions and then pay up and it's done.




Mr Overheads

2,440 posts

176 months

Friday 7th March 2014
quotequote all
www.securitymetrics.com

Do it online, rather than call them. Their helpline is US based and seems to be full of sales agents trying to upgrade you to the next level of compliance i.e. more expensive.

slippery

14,093 posts

239 months

Friday 7th March 2014
quotequote all
Big E 118 said:
I used Trustwave https://www3.trustwave.com/pci-dss-compliance/ 10 minutes to complete the questions and then pay up and it's done.
+1

4xTrader

Original Poster:

156 posts

147 months

Friday 7th March 2014
quotequote all
Ah, Trustwave, that rings a bell! I think I must have used them before.

Thanks smile

Brother D

3,720 posts

176 months

Wednesday 23rd July 2014
quotequote all
I'm just going through this minor nightmare myself for a single terminal used at my parents place. I kind of get where they are coming from.

The Part 12 of PCI compliance talks about staff responsibilities etc, does anyone have a template they have used etc that I could look at or a link?

(I'm moving them back to dial-up once this contract is up)...

Thanks in advance

CharlieCrocodile

1,193 posts

153 months

Wednesday 23rd July 2014
quotequote all
Trustwave have a very simple questionnaire, took me about 5 mins to go through it and be compliant.

madmover

1,725 posts

184 months

Wednesday 23rd July 2014
quotequote all
YHM smile


Edited by madmover on Wednesday 23 July 20:30

cuneus

5,963 posts

242 months

Wednesday 23rd July 2014
quotequote all
Brother D said:
The Part 12 of PCI compliance talks about staff responsibilities etc, does anyone have a template they have used etc that I could look at or a link?

Thanks in advance
Trustwave themselves have template policies

Brother D

3,720 posts

176 months

Thursday 24th July 2014
quotequote all
Guys thanks very much for the info - (persevered with the supplier processes, including a scan and it passed). I've sent the procedural docs over to my parents place for them to ignore : )


Dave_ST220

10,294 posts

205 months

Friday 25th July 2014
quotequote all
£10 a month for non compliance is actually cheaper than being compliant!! Although I assume should a data breech happen & it's down to your company you would get royally bum raped?!

If this is for a shop it's easy, it's when you take card payments on your website the fun & games begin. If doing that a good host is vital, we've not had a failed scan for years now thanks to the hosts smile (Vidahost & use Security Metrics for PCI)