<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SAQs for Authorize.net APIs in Integration and Testing</title>
    <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SAQs-for-Authorize-net-APIs/m-p/36001#M20064</link>
    <description>&lt;P&gt;I know that some of the Authorize.net APIs allow for reduced PCI compliance scope, however is there any guidance anywhere indicating to what level? The PCI DSS E-commerce Guidelines released by the PCI SSC would seem to indicate that the only merchants that are allowed to use an SAQ A would be ones that employ a “wholly-outsourced E-commerce Implementation” (page 17).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Link to PCI DSS E-commerce Guidelines:&lt;/P&gt;&lt;P&gt;&lt;A target="_blank" href="https://www.pcisecuritystandards.org/pdfs/PCI_DSS_v2_eCommerce_Guidelines.pdf"&gt;https://www.pcisecuritystandards.org/pdfs/PCI_DSS_v2_eCommerce_Guidelines.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since the various APIs offered by Authorize.net require some level of integration with the merchant, whether it is serving up the payment page/client side code or redirecting the customer to a hosted payment page, does that mean a SAQ D is required (wholly or sections). Would any of the APIs allow us to fill out a SAQ C?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 30 Sep 2013 21:05:47 GMT</pubDate>
    <dc:creator>ynermk</dc:creator>
    <dc:date>2013-09-30T21:05:47Z</dc:date>
    <item>
      <title>SAQs for Authorize.net APIs</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SAQs-for-Authorize-net-APIs/m-p/36001#M20064</link>
      <description>&lt;P&gt;I know that some of the Authorize.net APIs allow for reduced PCI compliance scope, however is there any guidance anywhere indicating to what level? The PCI DSS E-commerce Guidelines released by the PCI SSC would seem to indicate that the only merchants that are allowed to use an SAQ A would be ones that employ a “wholly-outsourced E-commerce Implementation” (page 17).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Link to PCI DSS E-commerce Guidelines:&lt;/P&gt;&lt;P&gt;&lt;A target="_blank" href="https://www.pcisecuritystandards.org/pdfs/PCI_DSS_v2_eCommerce_Guidelines.pdf"&gt;https://www.pcisecuritystandards.org/pdfs/PCI_DSS_v2_eCommerce_Guidelines.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Since the various APIs offered by Authorize.net require some level of integration with the merchant, whether it is serving up the payment page/client side code or redirecting the customer to a hosted payment page, does that mean a SAQ D is required (wholly or sections). Would any of the APIs allow us to fill out a SAQ C?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Sep 2013 21:05:47 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SAQs-for-Authorize-net-APIs/m-p/36001#M20064</guid>
      <dc:creator>ynermk</dc:creator>
      <dc:date>2013-09-30T21:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: SAQs for Authorize.net APIs</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SAQs-for-Authorize-net-APIs/m-p/36009#M20068</link>
      <description>Hmm, good question. DPM is definitely SAQ-C. AIM, ARB, and non-hosted CIM are -probably- SAQ-C, unless you store credit card data on your end, in which case SAQ-D. SIM and hosted CIM are probably SAQ-A. But an official word from Authorize.net would be nice. Compliance requirements also vary by volume of transactions, btw.</description>
      <pubDate>Tue, 01 Oct 2013 00:35:30 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SAQs-for-Authorize-net-APIs/m-p/36009#M20068</guid>
      <dc:creator>TJPride</dc:creator>
      <dc:date>2013-10-01T00:35:30Z</dc:date>
    </item>
    <item>
      <title>Re: SAQs for Authorize.net APIs</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SAQs-for-Authorize-net-APIs/m-p/36027#M20076</link>
      <description>&lt;P&gt;&lt;FONT face="Calibri"&gt;&lt;FONT size="3"&gt;&lt;FONT color="#000000"&gt;Based on the guidance provided I don't see how SIM and CIM could be SAQ A.&amp;nbsp; On page 17 of the e-commerce guidelines it clearly states that in a wholly outsourced e-commerce implementation &lt;FONT color="#ff0000"&gt;"the merchant may be able to complete a SAQ A.”&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri"&gt;&lt;FONT size="3"&gt;&lt;FONT color="#000000"&gt;A wholly outsourced implementation&lt;FONT color="#ff0000"&gt; "consists of e-commerce application, hosted servers, and hosted infrastructure, which are all provided and managed by the third party"&lt;/FONT&gt;.&amp;nbsp; The note on that page is particularly clear:&amp;nbsp; &lt;FONT color="#ff0000"&gt;"Note that if the merchant has to install an application or code on a server, configure a server file, etc. for their e-commerce implementation, they should refer to Section 3.4.3, “Shared-management E-commerce Implementations,” above.”&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri"&gt;&lt;FONT size="3"&gt;&lt;FONT color="#000000"&gt;Based on that statement I don’t see how any Authorize.net API or from any other vendor for that matter can qualify for an SAQ A.&amp;nbsp; I’d love to be wrong on this, but after reading and rereading this document several times I just don’t see any other way to interpret this.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Calibri"&gt;Without a doubt the API solutions provided by Authorize.net and others greatly reduces the scope of PCI, but I don’t think to the level that many people assume.&amp;nbsp; &lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri"&gt;&lt;FONT size="3"&gt;&lt;FONT color="#000000"&gt;Can you get away with a SAQ C?&amp;nbsp; I can’t say I’ve seen any definitive documentation to prove or disprove that assertion.&amp;nbsp; If someone has something more substantive than a blog post I’d love to see it.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3"&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Calibri"&gt;Also, transaction volume determines if you can fill out a SAQ or if you have to have a ROC completed by a QSA.&amp;nbsp; It has nothing to do with the type of SAQ you are required to fill out.&amp;nbsp; If you are dealing with less than 6 million transactions in a year then you can fill out a SAQ, otherwise it is a ROC.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2013 18:04:51 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SAQs-for-Authorize-net-APIs/m-p/36027#M20076</guid>
      <dc:creator>ynermk</dc:creator>
      <dc:date>2013-10-01T18:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: SAQs for Authorize.net APIs</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SAQs-for-Authorize-net-APIs/m-p/36033#M20079</link>
      <description>SIM forwards to Authorize.net. None of the e-commerce part has anything to do with you. Similarly, hosted CIM loads a page from Authorize.net, and uses cross-domain Javascript to trigger the callback. You have zero interaction with the credit card part. I'm still betting SAQ-A for those. And SAQ-D is for instances where you store, rather than just transmit, credit card data.&lt;BR /&gt;&lt;BR /&gt;You can pay with a credit card through Paypal, and you can submit your shopping cart to Paypal externally, yet somehow nobody is required to fill out a SAQ for that. A shopping cart does not equate to an ecommerce solution.</description>
      <pubDate>Wed, 02 Oct 2013 08:10:20 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SAQs-for-Authorize-net-APIs/m-p/36033#M20079</guid>
      <dc:creator>TJPride</dc:creator>
      <dc:date>2013-10-02T08:10:20Z</dc:date>
    </item>
    <item>
      <title>Re: SAQs for Authorize.net APIs</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SAQs-for-Authorize-net-APIs/m-p/36039#M20082</link>
      <description>&lt;P&gt;Agreed with both solutions the merchant has zero visibility of the cardholder data.&amp;nbsp; However, the merchant plays a role in ensuring that data is securely transmitted to Authorize.net.&amp;nbsp; For example:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;a merchant is utilizing SIM ,&lt;/LI&gt;&lt;LI&gt;their systems are compromised&lt;/LI&gt;&lt;LI&gt;the code used to perform the redirect to Authorize.net is modified&lt;/LI&gt;&lt;LI&gt;instead the customer and/or their data is sent to a nefarious site&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;In my mind that equates to a breach caused by some weakness in the merchant’s e-commerce infrastructure.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3" face="Times New Roman"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;Based on how I’m reading the e-commerce guidelines, if you manage code or systems involved in the transmission of credit card data it is under scope for PCI, and you cannot &amp;nbsp;get by with a SAQ A.&amp;nbsp; I agree with the statement above that a shopping cart does not equate to an e-commerce solution, but I think it is clear that is a component of that solution and therefore whoever is managing it is responsible for addressing PCI requirements.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2013 17:34:22 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SAQs-for-Authorize-net-APIs/m-p/36039#M20082</guid>
      <dc:creator>ynermk</dc:creator>
      <dc:date>2013-10-02T17:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: SAQs for Authorize.net APIs</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SAQs-for-Authorize-net-APIs/m-p/36057#M20090</link>
      <description>Any site can be compromised to redirect to a hacker's site. In the Paypal example I gave, it would be quite simple to change the post location to a simulation of Paypal instead of to the real Paypal. Not sure what would qualify as SAQ-A if you are correct - would you have to offload your entire catalog to a third-party service? If you do that, why bother with SAQ at all? What is the purpose of SAQ-A?&lt;BR /&gt;&lt;BR /&gt;Need someone who's an expert on SAQ to post on this, I guess.</description>
      <pubDate>Thu, 03 Oct 2013 01:45:14 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SAQs-for-Authorize-net-APIs/m-p/36057#M20090</guid>
      <dc:creator>TJPride</dc:creator>
      <dc:date>2013-10-03T01:45:14Z</dc:date>
    </item>
    <item>
      <title>Re: SAQs for Authorize.net APIs</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SAQs-for-Authorize-net-APIs/m-p/36073#M20098</link>
      <description>&lt;P&gt;&lt;FONT color="#3366ff" face="Calibri"&gt;&lt;FONT size="3"&gt;Not sure what would qualify as SAQ-A if you are correct - would you have to offload your entire catalog to a third-party service?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri"&gt;&lt;FONT color="#000000"&gt;&lt;FONT size="3"&gt;Yes, that is exactly what the e-commerce guideline is saying.&amp;nbsp; From page 17 of the PCI DSS e-commerce guidlines:&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#ff0000" face="Calibri"&gt;&lt;FONT size="3"&gt;“Many merchants are interested in managing their PCI DSS responsibility by outsourcing all cardholder data storage, processing, and transmission to a third party hosting provider or e-commerce payment processor. In this case, merchants may elect to use a solution provided and hosted by a third party, which is wholly under the control and responsibility of the third party. This type of solution could consist of an e-commerce application, hosted servers, and hosted infrastructure, which are all provided and managed by the third party. A web interface is provided for the merchant to access the third-party site, and to manage the e-commerce store and customers.”&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#ff0000" face="Calibri"&gt;&lt;FONT size="3"&gt;“PCI DSS Scoping Guidance: In this scenario, the merchant may be eligible for the PCI DSS Self-Assessment Questionnaire (SAQ) A. SAQ A reduces the number of applicable PCI DSS requirements for merchants that outsource all storing, processing, and transmitting of cardholder data to an e-commerce payment processor. More information about SAQ A can be found below under “Outsourced e-commerce Implementations and SAQ A.”&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="3" face="Calibri"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#3366ff" face="Calibri"&gt;&lt;FONT size="3"&gt;If you do that, why bother with SAQ at all? What is the purpose of SAQ-A?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri"&gt;&lt;FONT size="3"&gt;&lt;FONT color="#000000"&gt;Actually if you look at the requirements the merchant is being asked to attest to in a SAQ A (for reference at the bottom of this post), it totally lines up with a “wholly outsourced implementation”.&amp;nbsp; Basically the merchant is validating &amp;nbsp;3 areas:&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT size="3" face="Calibri"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1.&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;FONT face="Calibri"&gt;&lt;FONT size="3"&gt;They are eligible to complete a SAQ A because wholly outsource the handling, storage,&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Calibri"&gt;&lt;FONT size="3"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;processing, and/or transmission of cardholder data.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT size="3" face="Calibri"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2.&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;FONT face="Calibri"&gt;&lt;FONT size="3"&gt;There are physical controls to protect credit card data that is on paper media received by &lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Calibri"&gt;&lt;FONT size="3"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the &lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Calibri"&gt;&lt;FONT size="3"&gt;merchant from the vendor.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT size="3" face="Calibri"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3.&lt;/FONT&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;FONT face="Calibri"&gt;&lt;FONT size="3"&gt;The merchant has the appropriate contractual and policy pieces in place to spell out the &lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Calibri"&gt;&lt;FONT size="3"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;vendor’s responsibility in protecting cardholder data and ensure the vendor’s adherence to&amp;nbsp; &lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Calibri"&gt;&lt;FONT size="3"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PCI DSS.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri"&gt;&lt;FONT size="3"&gt;&lt;FONT color="#000000"&gt;Nothing in SAQ A references technical controls on the merchant’s part.&amp;nbsp; It does not make sense that if you are using one of the APIs that you would not have to attest to some technical or process controls, because at a minimum it is your responsibility to ensure that the code that specifies where the cardholder data is posted is protected from unauthorized changes.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri"&gt;&lt;FONT size="3"&gt;&lt;FONT color="#000000"&gt;So we get back to my original question which SAQ or subsections of an SAQ make sense for a particular API?&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri"&gt;&lt;FONT size="3"&gt;&lt;FONT color="#000000"&gt;SAQ A Validation Questions :&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;FONT color="#000000" face="Arial"&gt;Requirement 9:&amp;nbsp; Restrict physical access to cardholder data&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;&lt;TABLE cellspacing="0" border="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="Calibri" color="#000000"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;Question&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Response:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;&lt;U&gt;Yes&lt;/U&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;&lt;U&gt;No&lt;/U&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;STRONG&gt;&lt;FONT color="#000000"&gt;&lt;U&gt;Special&lt;/U&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;A title="" href="https://community.developer.cybersource.com/t5/forums/replypage/board-id/Integration01/message-id/20090#_ftn1" target="_blank"&gt;&lt;STRONG&gt;&lt;U&gt;&lt;FONT color="#0066cc"&gt;*&lt;/FONT&gt;&lt;/U&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;9.6&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Are all paper and electronic media that contain cardholder data physically secure?&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;9.7&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;(a)&amp;nbsp;&amp;nbsp;&amp;nbsp; Is strict control maintained over the internal or external distribution of any kind of media that contains cardholder data?&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;(b)&amp;nbsp;&amp;nbsp;&amp;nbsp; Do controls include the following:&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;FONT face="Calibri" color="#000000"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;9.7.1&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Is the media classified so it can be identified as confidential?&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;9.7.2&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Is the media sent by secured courier or other delivery method that can be accurately tracked?&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;9.8&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Are processes and procedures in place to ensure management approval is obtained prior to moving any and all media containing cardholder data from a secured area (especially when media is distributed to individuals)?&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;9.9&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Is strict control maintained over the storage and accessibility of media that contains cardholder data?&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;9.10&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Is media containing cardholder data destroyed when it is no longer needed for business or legal reasons?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Destruction should be as follows:&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;9.10.1&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;Are hardcopy materials cross-cut shredded, incinerated, or pulped so that cardholder data cannot be reconstructed?&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;FONT face="Arial" color="#000000"&gt;Requirement 12:&amp;nbsp; Maintain a policy that addresses information security for employees and contractors&lt;/FONT&gt;&lt;/EM&gt;&lt;/P&gt;&lt;TABLE cellspacing="0" border="0" cellpadding="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;STRONG&gt;&lt;FONT face="Calibri" color="#000000"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;Question&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Response:&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;&lt;U&gt;Yes&lt;/U&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;&lt;U&gt;No&lt;/U&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;STRONG&gt;&lt;FONT color="#000000"&gt;&lt;U&gt;Special&lt;/U&gt;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;A title="" href="https://community.developer.cybersource.com/t5/forums/replypage/board-id/Integration01/message-id/20090#_ftn2" target="_blank"&gt;&lt;STRONG&gt;&lt;U&gt;&lt;FONT color="#0066cc"&gt;*&lt;/FONT&gt;&lt;/U&gt;&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;12.8&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;If cardholder data is shared with service providers, are policies and procedures maintained and implemented to manage service providers, and do the policies and procedures include the following?&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;12.8.1&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;A list of service providers is maintained.&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;12.8.2&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;A written agreement that includes an acknowledgement that the service providers are responsible for the security of cardholder data the service providers possess.&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;12.8.3&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;There is an established process for engaging service providers, including proper due diligence prior to engagement.&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;12.8.4&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;A program is maintained to monitor service providers’ PCI DSS compliance status.&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&lt;P align="center"&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;DIV&gt;&lt;DIV&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 03 Oct 2013 17:56:03 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SAQs-for-Authorize-net-APIs/m-p/36073#M20098</guid>
      <dc:creator>ynermk</dc:creator>
      <dc:date>2013-10-03T17:56:03Z</dc:date>
    </item>
    <item>
      <title>Re: SAQs for Authorize.net APIs</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SAQs-for-Authorize-net-APIs/m-p/36079#M20101</link>
      <description>Well, which API are you going to use? Assuming you are correct, in which case all of the API's fall under SAQ-C, unless you are storing credit card data locally for later use. SAQ-C covers all pass-through solutions.</description>
      <pubDate>Thu, 03 Oct 2013 23:58:32 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SAQs-for-Authorize-net-APIs/m-p/36079#M20101</guid>
      <dc:creator>TJPride</dc:creator>
      <dc:date>2013-10-03T23:58:32Z</dc:date>
    </item>
    <item>
      <title>Re: SAQs for Authorize.net APIs</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/SAQs-for-Authorize-net-APIs/m-p/36121#M20119</link>
      <description>I think it will be SIM where possible and DPM in cases where product owners are concerned about the user experience. I am hoping that PCI 3.0 provides a bit more clarity regarding API solutions and possibly some more relevant SAQs.</description>
      <pubDate>Tue, 08 Oct 2013 07:42:29 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/SAQs-for-Authorize-net-APIs/m-p/36121#M20119</guid>
      <dc:creator>ynermk</dc:creator>
      <dc:date>2013-10-08T07:42:29Z</dc:date>
    </item>
  </channel>
</rss>

