Self-Assessment Questionnaire (SAQ) Which one is

Published  . 0 views
↓ Download
Self-Assessment Questionnaire (SAQ) Which one is
1 / 1
Self-Assessment Questionnaire (SAQ) Which one is - slide 1 of 13 Self-Assessment Questionnaire (SAQ) Which one is - slide 2 of 13 Self-Assessment Questionnaire (SAQ) Which one is - slide 3 of 13 Self-Assessment Questionnaire (SAQ) Which one is - slide 4 of 13 Self-Assessment Questionnaire (SAQ) Which one is - slide 5 of 13 Self-Assessment Questionnaire (SAQ) Which one is - slide 6 of 13 Self-Assessment Questionnaire (SAQ) Which one is - slide 7 of 13 Self-Assessment Questionnaire (SAQ) Which one is - slide 8 of 13 Self-Assessment Questionnaire (SAQ) Which one is - slide 9 of 13 Self-Assessment Questionnaire (SAQ) Which one is - slide 10 of 13 Self-Assessment Questionnaire (SAQ) Which one is - slide 11 of 13 Self-Assessment Questionnaire (SAQ) Which one is - slide 12 of 13 Self-Assessment Questionnaire (SAQ) Which one is - slide 13 of 13
Description: Self-Assessment Questionnaire (SAQ) Which one is right for my environment? Which SAQ?? Point-to-Point Encrypted (P2PE) P2PE: Merchants using only hardware payment terminals that are included in and managed via a validated, PCI SSC-listed

Related Topics

Download Presentation

"Self-Assessment Questionnaire (SAQ) Which one is" is the property of its rightful owner. Permission is granted to download and print the materials on this website for personal, non-commercial use only, and to display it on your personal computer provided you do not modify the materials and that you retain all copyright notices contained in the materials. By downloading content from our website, you accept the terms of this agreement.

Presentation Transcript

slide1. Self-Assessment Questionnaire (SAQ) Which one is right for my environment?<br>
slide2. Which SAQ??<br>
slide3. Point-to-Point Encrypted (P2PE) P2PE: Merchants using only hardware payment terminals that are included in and managed via a validated, PCI SSC-listed P2PE solution, with no electronic cardholder data storage

Not applicable to e-commerce channels

Find PCI DSS validated Point-to-Point Encryption Solutions at www.pcisecuritystandards.org<br>
slide4. Card Present<br>
slide5. Card Present SAQ B: Standalone dial out terminals with no electronic cardholder data storage (NO INTERNET)
Not applicable to e-commerce channels

SAQ B-IP: Merchants using only standalone, PTS-approved payment terminals with an IP connection to the payment processor, with no electronic cardholder data storage
Not applicable to e-commerce channels<br>
slide6. Card Present SAQ C: Merchants with payment application systems connected to the Internet, no electronic cardholder data storage
Not applicable to e-commerce channels

SAQ C-VT: Merchants who manually enter a single transaction at a time via a keyboard into an Internet-based virtual terminal solution that is provided and hosted by a PCI-DSS validated third-party service provider, no electronic cardholder data storage
Not applicable to e-commerce channels<br>
slide7. Mail/Telephone Order (MOTO)<br>
slide8. Mail/Telephone Order (MOTO) SAQ A: Card-Not-Present merchants that have fully outsourced all cardholder data functions to PCI DSS validated third-party service providers, with no electronic storage, processing, or transmission of any cardholder data on the merchant’s systems or premises
Not applicable to face-to-face channels

SAQ B: Standalone dial out terminals with no electronic cardholder data storage (NO INTERNET)
Not applicable to e-commerce channels<br>
slide9. Mail/Telephone Order (MOTO) SAQ C: Merchants with payment application systems connected to the Internet, no electronic cardholder data storage
Not applicable to e-commerce channels

SAQ C-VT: Merchants who manually enter a single transaction at a time via a keyboard into an Internet-based virtual terminal solution that is provided and hosted by a PCI-DSS validated third-party service provider, no electronic cardholder data storage
Not applicable to e-commerce channels<br>
slide10. E-commerce<br>
slide11. E-commerce SAQ A: Card-Not-Present merchants that have fully outsourced all cardholder data functions to PCI DSS validated third-party service providers, with no electronic storage, processing, or transmission of any cardholder data on the merchant’s systems or premises
Not applicable to face-to-face channels<br>
slide12. E-commerce SAQ A-EP: E-commerce merchants who outsource all payment processing to PCI DSS validated third parties, and who have a website(s) that doesn’t directly receive cardholder data but that can impact the security of the payment transaction. No electronic storage, processing, or transmission of any cardholder data on the merchant’s systems or premises
Applicable only to e-commerce channels

SAQ D: All merchants not included in descriptions for the above SAQ types<br>
slide13. Questions If you have any questions or need assistance verifying the appropriate SAQ(s) for your payment card environment, please contact Cash and Credit Management Services (CCMS).

Phone: 806-742-3271
Email: cash.credit.services@ttu.edu

Information obtained from PCI DSS Self Assessment Questionnaire Instructions and Guidelines, v3.2 SAQ-InstrGuidelines-v3_2.pdf (pcisecuritystandards.org)<br>