Visa and MasterCard have collaborated in creating payment card industry standard security requirements
and alignment of Visa USA Cardholder Information Security Program (CISP) and MasterCard Site Data
Protection (SDP) programs in the United States and alignment of SDP and Visa’s Accountholder Information
Security (AIS) Program outside of the United States. In December 2004, Visa US and MasterCard announced
the alignment of their programs re-branded as Payment Card Industry (PCI) Data Security Standards. The
MasterCard SDP, Visa USA CISP, and Visa Canada AIS Programs have the similar goal of protecting payment
card account data stored by merchants and service providers and include both a review of policies,
procedures, and safeguards in addition to network scans. These goals have been endorsed by Discover, JCB,
and Diners Club and are under review by American Express.
All third parties with internal systems that store, process, or transmit cardholder data on behalf of
merchants must comply with Payment Card Industry (PCI) Security Standards. Compliance validation is
required for all third parties that store, process, or transmit cardholder data on behalf of merchants
and member financial institutions. Validation requires regular network scans and annual validation of
policies and procedures. Level 1 and Level 2 Service Providers must engage a qualified independent security
assessor to prepare a Report on Compliance and Level 3 Service Providers may complete the self-assessment
or utilize self-assessment tools available through qualified independent security assessors.
Network scanning tools map the Web site’s configuration and check a database of more than 1,200 known
vulnerabilities. Network scan may also include intrusion detection services, firewall monitoring, and
additional web insurance. Network scans must be performed by a qualified independent scan vendor.
The Level 1 Service Provider group includes all processors that are connected to VisaNet and MasterCard
networks. Global Payments has met the PCI requirements for 2005. Level 1 Service Provider group includes
all payment gateways that operate between merchant and Global Payments or between merchant and other
processors. Level 1 Service Providers was expanded to include Data Storage Entities (DSEs) for Level 1
Merchants (more than 6 million MasterCard or Visa transactions regardless of acceptance channel) and
Level 2 Merchants (more than 150,000 and less than 6,000,000 electronic commerce transactions).
The Level 2 and Level 3 Service Provider group includes all third party service providers (example:
Third-Party Servicer (TPS), Independent Sales Organizations (ISO), merchant vendor, Web hosting company
or shopping cart, media back-up company, Loyalty program vendor, Risk management vendor, chargeback vendor,
and credit bureau) not in Level 1 that store, process, or transmit transactions. The number of transactions
will be determined based on the gross number of Visa transactions stored, processed, or transmitted—not
just for the merchant or Member supported but for all entities supported by a service provider. The Level 2
and Level 3 Service Provider group also includes third party Data Storage Entities storing data on behalf of
Level 3 Merchants (more than 20,000 and less than 150,000 electronic commerce transactions) or Level 4
Merchants (all other merchants, regardless of acceptance channels).
Visa requires service providers to provide compliance validation results directly to Visa. After a Level 1,
1, 2 , or 3 Service Provider has provided compliance documentation demonstrating full compliance to Visa USA,
they will be included on the list of Compliant Service Providers. To view current Visa list, click here.
Third parties that receive, pass, and store transaction data for merchants should have agreements with
merchants.
The following is a summary of the compliance validation steps required for third parties (including ISOs,
loyalty, etc.) that store cardholder data.
Level |
Description |
Compliance Validation Requirements |
Compliance Validation Tools Available at
https://www.pcisecuritystandards.org |
Level 1 |
Processors or any service provider that stores, processes and/or transmits over 300,000
transactions per year
Note: Eliminates payment gateway definition from several existing regional programs |
Complete an annual on-site assessment using the PCI DSS Requirements and Security Assessment
Procedures. On-site assessment must be performed by a Qualified Security Assessor.
Complete Quarterly Network Vulnerability Scans performed by an Approved Scanning Vendor (ASV)
|
PCI DSS Requirements and Security Assessment Procedures v1.2
List of PCI SSC Qualified Security Assessors (QSA)
https://www.pcisecuritystandards.org/approved_companies_providers/qsa_companies.php
NOTE: TrustWave is strongly recommended
https://www.trustwave.com/
List of PCI SSC Approved Scanning Vendors (ASV)
https://www.pcisecuritystandards.org/pdfs/approved_companies_providers/approved_scanning_vendors.php |
Level 2 |
Any service provider that stores, processes and/or transmits less than 300,000 transactions
per year
Note: Effective January 1, 2009, MasterCard will no longer list those Service Providers who
have only submitted an SAQ. The posting will contain only those entities who have successfully
completed an annual onsite review
Note: Effective February 1, 2009, Level 2 service providers will not longer be listed on
Visas’ List of PCI DSS Compliant Service Providers. Entities that wish to be on the
List of PCI DSS Compliant Service Providers must validate as a Level 1 provider |
Annual PCI Self-Assessment Questionnaire
Quarterly Network Scan |
|
American Express and Discover's Service Providers Regulations
-
American Express Data Security Operating Policy for U.S. Service Providers
Service Providers must adhere to American Express Data Security Policies.
Review this article for detailed information on Data Security Operating Policy for U.S.
Service Providers. Link
-
Discover Service Provider Compliance Validation and Reporting Requirements
All service providers that process, store or transmit cardholder data on the Discover network
are required to report their compliance status to Discover Network on an annual basis. In order
to validate and report their compliance status to Discover Network, service providers must
complete and submit one of the following:
On-site assessment
Service providers that completed an on-site assessment using PCI DSS v1.2 are required to submit
Appendix E of the PCI DSS Requirements and Security Assessment Procedures v1.2: Attestation of
Compliance - Service Providers, as well as the Executive Summary of the Report on Compliance (ROC).
Note: Discover requires service providers that are not fully compliant with
the PCI DSS to also complete the "Action Plan for Non-Compliant Status" section of the Attestation
of Compliance.1
Self-Assessment
Service Providers that completed an on-site assessment using PCI DSS v1.1 are required to submit
the Executive Summary from their Report on Compliance (ROC). Please note: all assessments that
commence after January 1, 2009 must use PCI DSS v1.2.
Service providers that perform a self-assessment are required to complete PCI DSS Self-Assessment
Questionnaire D and submit the Service Provider Version of the Attestation of Compliance.
Note: Discover requires service providers that are not fully compliant with the
PCI DSS to also complete the "Action Plan for Non-Compliant Status" Section of the Attestation of
Compliance.1
All compliance reports must be submitted by December 31 for the current year*.
For more information visit Discover's Information Security and Compliance (DISC) Web site.
Link
For more information on Service Providers, visit the card schemes' links.
Validation procedures and documentation
Effective February 1, 2009, Visa will only require submission of an executed Attestation of Compliance
Form
https://www.pcisecuritystandards.org/documents/pci_dss_aoc_service_providers.doc and the “Executive
Summary” section of the service provider’s Report on Compliance (ROC) to demonstrate PCI DSS
compliance as a Level 1 service provider. Level 2 service providers will submit version D of the
Self-Assessment Questionnaire (SAQ).