<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PCI-DSS SAQ question 12.8.2.  Where does Authorize supply the written acknowledgement? in Integration and Testing</title>
    <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/PCI-DSS-SAQ-question-12-8-2-Where-does-Authorize-supply-the/m-p/55956#M30778</link>
    <description>&lt;P&gt;I'm filling out our PCI-DSS SAQ, and question 12.8.2 states:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Is a written agreement maintained that includes an&lt;BR /&gt;acknowledgement that the service providers are&lt;BR /&gt;responsible for the security of cardholder data the&lt;BR /&gt;service providers possess or otherwise store, process,&lt;BR /&gt;or transmit on behalf of the customer, or to the extent&lt;BR /&gt;that they could impact the security of the customer’s&lt;BR /&gt;cardholder data environment?&lt;BR /&gt;Note: The exact wording of an acknowledgement will&lt;BR /&gt;depend on the agreement between the two parties, the&lt;BR /&gt;details of the service being provided, and the&lt;BR /&gt;responsibilities assigned to each party. The&lt;BR /&gt;acknowledgement does not have to include the exact&lt;BR /&gt;wording provided in this requirement."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've not been able to find where it states in writing that Authorize.net assumes responsibility for the cardholder data they are handling on our behalf.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I contact customer support, they refuse to acknowledge that Authorize.net assumes that responsibility, much less point me to where that assumption of responsbility is outlined in writing. &amp;nbsp;Their stance is that Authorize.net is certified as PCI-DSS compliant, and by implication that means I can check the yes box to the above quoted question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't understand how that is possible. &amp;nbsp;The SAQ has a yes or no question about the existence of a written agreement. &amp;nbsp;Can someone explain it to me or point me to where the written acknowledgement actually is?&lt;/P&gt;</description>
    <pubDate>Thu, 13 Oct 2016 19:04:46 GMT</pubDate>
    <dc:creator>noahs</dc:creator>
    <dc:date>2016-10-13T19:04:46Z</dc:date>
    <item>
      <title>PCI-DSS SAQ question 12.8.2.  Where does Authorize supply the written acknowledgement?</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/PCI-DSS-SAQ-question-12-8-2-Where-does-Authorize-supply-the/m-p/55956#M30778</link>
      <description>&lt;P&gt;I'm filling out our PCI-DSS SAQ, and question 12.8.2 states:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Is a written agreement maintained that includes an&lt;BR /&gt;acknowledgement that the service providers are&lt;BR /&gt;responsible for the security of cardholder data the&lt;BR /&gt;service providers possess or otherwise store, process,&lt;BR /&gt;or transmit on behalf of the customer, or to the extent&lt;BR /&gt;that they could impact the security of the customer’s&lt;BR /&gt;cardholder data environment?&lt;BR /&gt;Note: The exact wording of an acknowledgement will&lt;BR /&gt;depend on the agreement between the two parties, the&lt;BR /&gt;details of the service being provided, and the&lt;BR /&gt;responsibilities assigned to each party. The&lt;BR /&gt;acknowledgement does not have to include the exact&lt;BR /&gt;wording provided in this requirement."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've not been able to find where it states in writing that Authorize.net assumes responsibility for the cardholder data they are handling on our behalf.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I contact customer support, they refuse to acknowledge that Authorize.net assumes that responsibility, much less point me to where that assumption of responsbility is outlined in writing. &amp;nbsp;Their stance is that Authorize.net is certified as PCI-DSS compliant, and by implication that means I can check the yes box to the above quoted question.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I don't understand how that is possible. &amp;nbsp;The SAQ has a yes or no question about the existence of a written agreement. &amp;nbsp;Can someone explain it to me or point me to where the written acknowledgement actually is?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2016 19:04:46 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/PCI-DSS-SAQ-question-12-8-2-Where-does-Authorize-supply-the/m-p/55956#M30778</guid>
      <dc:creator>noahs</dc:creator>
      <dc:date>2016-10-13T19:04:46Z</dc:date>
    </item>
  </channel>
</rss>

