Error » Security Error » Security News » Qualys Supports New Self Assessment Questionnaire for PCI Compliance

Security News The Latest Computer Security News

Post New Thread Reply
  Qualys Supports New Self Assessment Questionnaire for PCI Compliance
LinkBack Thread Tools Display Modes
Old 01-Apr-2008, 04:53 AM   #1 (permalink)
Fixed Error!
 
newsprovider's Avatar

Posts: 140
Join Date: Mar 2008
Rep Power: 1 newsprovider is on a distinguished road

IM:
Default Qualys Supports New Self Assessment Questionnaire for PCI Compliance

QualysGuard PCI Compliance Solution Provides Full Support for All Types of New Self-Assessment Questionnaire (SAQ) Version 1.1 for Both Merchants and Service Providers
Qualys, Inc. today announced an upgrade to its QualysGuard® PCI on demand compliance solution with the new Self-Assessment Questionnaire (SAQ) Version 1.1, issued by the Payment Card Industry (PCI) Security Standards Council (PCI SSC) in February 2008. The QualysGuard PCI implementation of the new SAQ allows customers to complete all versions of the questionnaire online and e-file it securely with their acquiring banks.
The SAQ is a validation tool used primarily by Level 2, 3 and 4 merchants (and some smaller service providers), as defined by the major credit-card brands—Visa Inc., MasterCard Worldwide, Discover Financial Services, American Express and JCB International — to validate compliance with the PCI Data Security Standards (PCI DSS). The PCI SSC updated SAQ version 1.0 to better align with PCI DSS version 1.1 and created four variants to ensure merchants only answer questions relevant to their environment. Each of the four variants, labeled A, B, C and D have qualifying questions used to determine which of the four questionnaires a merchant is required to complete.
“Issuing the latest self assessment questionnaire is another step the PCI Security Standards Council is taking to ensure that all merchants and service providers have options in determining their compliance strategy,” said Bob Russo, general manager, PCI Security Standards Council. “Having multiple SAQs available will streamline the process and make it easier for stakeholders to determine their compliance gaps and take action to ensure full compliance with the Standard.”
The SAQ, version 1.1 is now available at https://www.pcisecuritystandards.org/tech/saq.htm and consists of four unique forms to meet various business scenarios. Each merchant completing the SAQ version 1.1 selects the questionnaire that best represents their environment, based on the descriptions below:
SAQ Validation Description SAQ Number of Questions
Type
1 Card-not-present A 11
(e-commerce or mail/
telephone-order)
merchants, all
cardholder data
functions outsourced.
This would never apply
to face-to-face merchants.
2 Imprint-only or B 21
stand-alone terminal
merchants with no
electronic cardholder
data storage.

3 Merchants with POS C 38
systems connected to
the Internet, no
electronic cardholder
data storage.
4 All other merchants D 226
(not included in Types
1-3 above) and all
service providers defined
by a payment brand as
eligible to complete an SAQ.


QualysGuard fully supports all four types of questionnaires, labeled A-D, including the ability to enter online comments for compensating controls, provide remediation action plan for non-compliant sections, complete attestation of the assessment and electronically sign the SAQ online. More details on the QualysGuard PCI implantation or SAQ 1.1 are available at: http://www.qualys.com/docs/QG_PCI_GSG.pdf within the PCI Questionnaires chapter.
In this upgrade, QualysGuard PCI now supports both the previous SAQ version 1.0, as well as the four forms of the new SAQ version 1.1, allowing merchants to choose which version they wish to complete. According to the PCI SSC, after April 30, 2008, the older SAQ version 1.0 will no longer be accepted for compliance validation. From that date forward, all merchants will be required to use the new SAQ version 1.1.
newsprovider is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit!
Reply With Quote
   


   
Post New Thread Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT -8. The time now is 09:04 PM.

Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0

DMCA Policy

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227