All Top Banking

PCI's QSA's/ASV's Must Participate in Quality Assurance Program

Posted by John B. Frank Monday, November 17, 2008

PCI SSC launches quality assurance programs for QSAs and ASVs


Wakefield, Mass., Nov. 17, 2008 -- The PCI Security Standards Council (PCI SSC), a global, open industry standards body providing management of the Payment Card Industry Data Security Standard (PCI DSS), PIN Entry Device (PED) Security Requirements and the Payment Application Data Security Standard (PA-DSS), announces that it has launched a quality assurance program for Qualified Security Assessors (QSAs) and Approved Scanning Vendors (ASVs).

The new program was designed to provide QSAs and ASVs with a set of requirements that helps ensure they provide consistent, quality validation and assessment services to merchants and service providers.

The PCI SSC developed the quality assurance program as a direct result of feedback from the Council’s participating organizations and assessment community and is intended to promote consistent interpretation of the PCI standards and ensure quality is maintained among all vendors.

Participation in the program will be required for the Council’s registered QSAs and ASVs, in order for them to retain the ability to conduct PCI assessments.


“Feedback from the Council’s participating organizations and others made it clear that the assessment process for the PCI standards would benefit greatly from more rigorous guidelines,” said Bob Russo, general manager, PCI Security Standards Council. “As a result, we created a clear-cut program that will help ensure all those involved in this process are consistent, credible, competent and ethical.”

The new quality assurance program is based on eight guiding principles. Through the program, the Council and assessor community commit to:

Uphold the best interest of the assessor client

Adhere to validation requirements among the assessor company
Adhere to validation requirements among the assessor employee
Maintain consistent assessor procedures and reporting
Interpret the PCI standards appropriately as applicable to the client’s systems & environment
Remain current with industry trends and PCI SSC updates in the assessor community
Report all opinions as factual, documented and defendable, and
Maintain a positive relationship between the assessor and PCI SSC.

An expanded range of communications channels will allow the PCI SSC to interact with assessors, merchants and service providers on an ongoing basis through certification reviews, credit checks, training, educational webinars, newsletters, a dedicated e-mail service, question and answer documents, informational supplements and feedback forms. A team of dedicated staff will validate assessor application and renewals, ensure that training is relevant and accessible to organizations and maintain the integrity of the testing process. This team also will be responsible for assessor performance monitoring and overseeing any necessary disciplinary action, which could include probation or revocation.

The program will continue to be rolled out in a four-stage process throughout 2009.

For More Information:


More information on the PCI Security Standards Council and becoming a participating organization please visit www.pcisecuritystandards.org , or contact the PCI Security Standards Council at participation@pcisecuritystandards.org.

About the PCI Security Standards Council: The mission of the PCI Security Standards Council is to enhance payment account security by driving education and awareness of the PCI Data Security Standard and other standards that increase payment data security. The PCI Security Standards Council was formed by the major payment card brands American Express, Discover Financial Services, JCB International, MasterCard Worldwide and Visa Inc. to provide a transparent forum in which all stakeholders can provide input into the ongoing development, enhancement and dissemination of the PCI Data Security Standard (DSS), PIN Entry Device (PED) Security Requirements and the Payment Application Data Security Standard (PA-DSS). Merchants, banks, processors and other vendors are encouraged to join as participating organizations.

Reblog this post [with Zemanta]

1 Responses to PCI's QSA's/ASV's Must Participate in Quality Assurance Program

  1. pci Says:
  2. This information is very helpful. It really helps me understand more about PCI SSC. Keep posting. Will certainly try doing that myself. Your post/article really helped. Thanks a lot.

     

Post a Comment

Powered by Blogger.

Blog Archive

Search This Blog

Our Manufacturing Facility

Learn More About Us

Find out how our patented technology can empower your financial institution.

Our secure two-factor online banking authentication eliminates dangerous passwords and usernames and replicates the same trusted process used to access cash at ATM's. (Insert Bank Issued Card, Enter Bank Issued PIN)

There is an R.O.I. as FI's also earn recurring revenue from each transaction conducted using our PCI 2.0 Certified PIN Entry Device. Our technology also provides a unique real-time P2P "Instant-Transfer" which allows your online banking customer to transfer cash from ANY of their bankcards to ANY other bankcard...with the Swipe of a card.

Help your bank eliminate phishing and your customers avoid identity theft by providing them with the ability to stop typing and start swiping. There is no safer way to conduct financial transactions online than by 3DES DUKPT encrypting the cardholder details, which we do at the mag-head "inside the box/outside the browser."

Total Pageviews

SLIM for PC or SmartPhone

SLIM for PC or SmartPhone
Click to Inquire

Chip and PIN eCommerce and Mobile

Chip and PIN eCommerce and Mobile
Click to Inquire

Kapersky Calls for Mass Adoption of Card Readers

Kapersky Calls for Mass Adoption of Card Readers

Translate This Blog

BobCaps

Search ePayment News (example: NFC)

About Me

My photo
Named one of the best Payment Industry News Blogs 4 Years Running

Feedjit

My Zimbio