<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PCI and VOIP - Suggestions to limit scope? in Integration and Testing</title>
    <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/PCI-and-VOIP-Suggestions-to-limit-scope/m-p/90041#M56692</link>
    <description>&lt;P&gt;You're considering securing your phone system, especially for those handling credit card data. Isolating the 10-15 phones to a cloud solution or POTS line is a practical way to limit your scope while ensuring compliance. By firewalling these phones and providing the PCI-compliant cloud provider, you could reduce the scope to just those phones, the firewall, and the provider.&lt;/P&gt;</description>
    <pubDate>Wed, 28 Aug 2024 07:58:37 GMT</pubDate>
    <dc:creator>leneolivarezu</dc:creator>
    <dc:date>2024-08-28T07:58:37Z</dc:date>
    <item>
      <title>PCI and VOIP - Suggestions to limit scope?</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/PCI-and-VOIP-Suggestions-to-limit-scope/m-p/69287#M42341</link>
      <description>&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;We just replaced our digital phone system with a Cisco VOIP phone system.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;My company has about 1000 phones across the organization. Only about 10-15 phones/users take down credit cards over the phone. We do NO phone recording.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Our computers/physical areas are already fully secured and compliant. However, the phones were a bit of an afterthought.&lt;/P&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Do you guys have any suggestions on limiting scope? Based on the pdf: "Protecting Telephone-Based Payments Special Interest Group", the ideas that pop-out are:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Convert 10-15 phones to a Cloud solution or Analog/POTS line. These phones would be in a firewalled network that can only talk to the cloud provider. The Cloud solution would need to be "PCI compliant". In this scenario, would the scope just be the 10-15 phones, the firewall, and the Cloud provider?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Bring in the entire existing phone system into the CDE and harden everything.&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Spin up a new internal phone system just for these 10-15 phones that would be considered a part of the CDE&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;DIV class="_3xX726aBn29LDbsDtzr_6E _1Ap4F5maDtT1E1YuCiaO0r D3IL3FD0RFy_mkKLPwL4"&gt;&lt;DIV class="_292iotee39Lmt0MkQZ2hPV RichTextJSON-root"&gt;&lt;P class="_1qeIAgB0cPwnLhDF9XSiJM"&gt;Thanks in advance!&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class="_1hwEKkB_38tIoal6fcdrt9 "&gt;&lt;DIV class="_3-miAEojrCvx_4FQ8x3P-s"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 03 Oct 2019 17:29:02 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/PCI-and-VOIP-Suggestions-to-limit-scope/m-p/69287#M42341</guid>
      <dc:creator>AjubaGomes</dc:creator>
      <dc:date>2019-10-03T17:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: PCI and VOIP - Suggestions to limit scope?</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/PCI-and-VOIP-Suggestions-to-limit-scope/m-p/69289#M42343</link>
      <description>&lt;a href="https://community.developer.cybersource.com/t5/user/viewprofilepage/user-id/33184"&gt;@AjubaGomes&lt;/a&gt;&lt;BR /&gt;&lt;BR /&gt;That’s an interesting question. Just an FYI, auth.net has very little to say about PCI compliance other than that they are PCI compliant, accept Hosted is SAQ A, etc. You can search the website.&lt;BR /&gt;&lt;BR /&gt;With that said, this is a good question. I take it you are a SAQ D scope merchant? And my next question is how is it that you have determined your VOIP systems are within the CDE? To me it sounds a little 50 yard line ish and I am leaning towards your VOIP are not in the CDE at all.</description>
      <pubDate>Fri, 04 Oct 2019 00:47:27 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/PCI-and-VOIP-Suggestions-to-limit-scope/m-p/69289#M42343</guid>
      <dc:creator>Renaissance</dc:creator>
      <dc:date>2019-10-04T00:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: PCI and VOIP - Suggestions to limit scope?</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/PCI-and-VOIP-Suggestions-to-limit-scope/m-p/90041#M56692</link>
      <description>&lt;P&gt;You're considering securing your phone system, especially for those handling credit card data. Isolating the 10-15 phones to a cloud solution or POTS line is a practical way to limit your scope while ensuring compliance. By firewalling these phones and providing the PCI-compliant cloud provider, you could reduce the scope to just those phones, the firewall, and the provider.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Aug 2024 07:58:37 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/PCI-and-VOIP-Suggestions-to-limit-scope/m-p/90041#M56692</guid>
      <dc:creator>leneolivarezu</dc:creator>
      <dc:date>2024-08-28T07:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: PCI and VOIP - Suggestions to limit scope?</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/PCI-and-VOIP-Suggestions-to-limit-scope/m-p/94261#M58302</link>
      <description>&lt;P&gt;I ran into something similar and ended up avoiding VoIP altogether for any card data paths. For other communication, I switched to using &lt;A href="https://sms.to" target="_self"&gt;sms.to&lt;/A&gt; for sending out payment links, which kept everything out of scope and way easier to manage. Took a load off the compliance side too since nothing sensitive goes through the phone lines anymore.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Oct 2025 14:32:58 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/PCI-and-VOIP-Suggestions-to-limit-scope/m-p/94261#M58302</guid>
      <dc:creator>Atmosgek</dc:creator>
      <dc:date>2025-10-09T14:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: PCI and VOIP - Suggestions to limit scope?</title>
      <link>https://community.developer.cybersource.com/t5/Integration-and-Testing/PCI-and-VOIP-Suggestions-to-limit-scope/m-p/94276#M58312</link>
      <description>&lt;P&gt;We had a similar setup at work where only a small group handled payments. We ended up isolating those phones onto a separate network with strict firewall rules. It made scope much smaller and easier to manage. The rest of the phones stayed on the normal system. Also, using solid &lt;FONT color="#000000"&gt;&lt;A href="https://activecalls.com" target="_self"&gt;call center software&lt;/A&gt;&lt;/FONT&gt; helped track who’s taking payments without overcomplicating things.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Oct 2025 14:12:54 GMT</pubDate>
      <guid>https://community.developer.cybersource.com/t5/Integration-and-Testing/PCI-and-VOIP-Suggestions-to-limit-scope/m-p/94276#M58312</guid>
      <dc:creator>Duncantr</dc:creator>
      <dc:date>2025-10-13T14:12:54Z</dc:date>
    </item>
  </channel>
</rss>

