r/pcicompliance

How to deal with phone payments?

We are SAQ D and currently take payments over the phone. We do not have pause/resume functionality currently, and the phone system cannot encrypt the recordings on its own. Current phone system is planned to be replaced with Intermedia. My understanding is that the pause/resume option is becoming less acceptable recently as well.

To make things worse, we have a department that legally cannot modify, pause, or delete their call recordings. For now I have gotten them to stop taking phone payments until a proper solution is implemented. I still need to determine what to do with the recordings that we cannot delete. I am thinking file level encryption and storing them on our BCDR device.

The company does not have online payments for everything yet, that is a work in progress.

What solutions would be best for us in this situation? How are phone payments dealt with at all these days, DTMF masking? Telling customers to kick rocks and pay online?

reddit.com
u/Positive-Cloud-1923 — 2 days ago

Our payment page has 23 third party scripts on it. how do people manage 6.4.3 at this scale?

Audit found 23 scripts running on our payment page, many we didn't know about. 6.4.3 needs integrity monitoring on all of them. Feels impossible manually. Any method or tools to handle this?

reddit.com
u/Dull_Appearance_1828 — 4 days ago

PCI on Employee Laptops

Hey guys. I sit on my company's CAB where I recently flagged a project as a potential expansion to our compliance scope due to what I feel like is a CHD-on-device situation (EUC devices are currently scoped out of our CDE). This project would require a small handful of users run an automation that would read CHD from the CDE, truncate the CHD, and then print the truncated string to a file to be shared with other employees.

If the CHD is being truncated at runtime, would that be an adequate control for the employee's laptop to be excluded from the CDE? My initial reaction is maybe? But only if we're able to baseline the automation and implement change monitoring over it (the risk being that someone may remove the truncation from the automation).

reddit.com
u/hiddenpowerlevel — 7 days ago

McDonald's store using Not Activated POS

I'm just curious about PCI DSS compliance at McDonald's store, I believe it should be level 1 of merchant? I found it this morning at Union Station, you can see Windows not activated. Any issues?

u/2268236155 — 8 days ago

Date Format is yyyy-mm-dd Get It Right

Nothing frustrates me more than seeing the front page of the AOC or ROC as mm-dd-yyyy or dd-mm-yyyy.

The format is yyyy-mm-dd, it is listed in multiple places in the document. If you are a fellow QSA, act like it.

reddit.com
u/bdiddlediddles — 10 days ago

How are you monitoring checkout scripts after adding a tag manager?

We’re looking at PCI DSS requirements around the scripts running on our checkout page after adding a tag manager.

The issue is that marketing wants to keep adding pixels and analytics scripts, while security wants to know exactly what’s executing on the payment page and when it changes.

For anyone who’s dealt with this, do you review every new script manually or restrict the tag manager to an allowlist, or have automated monitoring in place?

reddit.com
u/BasePerfect2865 — 14 days ago