SlideShare ist ein Scribd-Unternehmen logo
1 von 3
Downloaden Sie, um offline zu lesen
Phone: 1.484.482.1600 Contact Us For More Information WWW.IMS-POS.COM
Topic: Retail Pro® and PCI Compliance – What You Need To Know
There has been much communication and confusion recently about Retail Pro® and PCI Compliance. IMS
customers have been receiving information from Retail Pro®, Merchant Warehouse (MW - Retail Pro’s
EFT exclusive provider) and Shift 4®.
IMS has prepared this Point of View (POV) to help our customers understand what is happening and to
help you make the most informed choice for meeting PCI-DSS compliance standards not just for today,
but for moving forward.
PCI SECURITY STANDARDS
It is YOUR responsibility as a merchant to understand what YOU need to do to be fully PCI Data Security
Standard (PCI-DSS) compliant. Your Payment Application Data Security Standard (PA-DSS) validated POS
software is only one of many PCI-DSS compliance requirements. PCI Security Standards are available at
WWW.PCISECURITYSTANDARDS.ORG. According to the PCI Security Council:
“Use of a Payment Application Data Security Standard (PA-DSS) compliant application by itself
does not make an entity PCI DSS compliant, since that application must be implemented into a
PCI DSS compliant environment and according to the PA-DSS Implementation Guide provided by
the payment application vendor.”
There are 12 primary requirements listed below:
Build and Maintain a Secure Network and Systems 1. Install and maintain a firewall configuration to
protect cardholder data
2. Do not use vendor-supplied defaults for system
passwords and other security parameters
Protect Cardholder Data 3. Protect stored cardholder data
4. Encrypt transmission of cardholder data across
open, public networks
Maintain a Vulnerability Management Program 5. Protect all systems against malware and regularly
update anti-virus software or programs
6. Develop and maintain secure systems and
applications
Implement Strong Access Control Measures 7. Restrict access to cardholder data by business
need to know
8. Identify and authenticate access to system
components
9. Restrict physical access to cardholder data
Regularly Monitor and Test Networks 10. Track and monitor all access to network
resources and cardholder data
11. Regularly test security systems and processes
Maintain an Information Security Policy 12. Maintain a policy that addresses information
security for all personnel
Phone: 1.484.482.1600 Contact Us For More Information WWW.IMS-POS.COM
There are numerous sub-requirements under each main area. To find out about these requirements,
there is a full complement of resources, including a Self Assessment Questionnaire (SAQ), on the
WWW.PCISECURITYSTANDARDS.ORG website.
RETAIL PRO®’S COMPLIANCE APPROACH
As part of Retail Pro’s PA-DSS compliance responsibilities, it must complete a yearly validation process
with an approved Payment Application Qualified Security Assessor (PA-QSA). This year’s validation date
is June 21, 2014.
This means that any software versions and associated EFT link-system partners that Retail Pro® wishes
to be PA-DSS compliant and acceptable for new deployments, must be included in this validation
renewal. Versions and systems included in the re-validation include:
1. Retail Pro® V9.2
2. Retail Pro® Prism
3. Merchant Warehouse gateway services
This means that Retail Pro® V8.6 is only acceptable for pre-existing deployments (validated according to
PA-DSS V1.2). That also means that your legacy Monetra based EFT Links to Mercury, First Data, and
WorldPay, as well as the Shift 4® EFT Link, will continue to function as they currently do (validated
according to PA-DSS V2.0) until they are moved to sunset status at some point in the future.
The Shift4® 4Go® product has not been tested nor certified by Retail Pro International (RPI) for
operation with Retail Pro® products, and RPI has not developed, tested or certified any interface
between Retail Pro® and 4Go®.
WHAT THIS MEANS FOR YOU
For those customers who currently use the legacy EFT links listed above, your pre-existing deployments
will continue to work and you will continue to be PA-DSS validated as stated above. Any legacy EFT links
will not be PA-DSS compliant for new deployments after the re-validation date. If you are planning on
new deployments of any kind, these must use the Merchant Warehouse EFT solution.
Phone: 1.484.482.1600 Contact Us For More Information WWW.IMS-POS.COM
WHY MERCHANT WAREHOUSE?
In making this strategic decision, Retail Pro® considered not only its current PA-DSS validation
requirements, but how it could best support its customers in the rapidly advancing world of EMV and
mobile-digital payments. As stated in previous Retail Pro® communications, as well as IMS’s own blog
post communication, “EMV. Chip and Pin. What You Need To Know”, Retail Pro® has selected Merchant
Warehouse as its sole EFT partner after a thorough due-diligence review. Some of the reasons for
selecting Merchant Warehouse include:
 MW can act as both a gateway and processor - using either MW processing or your processor
 Gateway services include fully PA-DSS compliant advanced data encryption technologies
tokenization and point-to-point encryption
 The Genius Customer Engagement Platform enabling:
o EMV ready payment acceptance
o Secure credit card payments
o Acceptance of yet-to be-determined mobile payments and various promotional
payments such as gift cards, coupons, loyalty payments, etc.
ARE YOU PCI-DSS COMPLIANT?
Again, being PA-DSS compliant does not mean you are fully PCI-DSS compliant, as being PCI-DSS
compliant includes more than just having a PA-DSS compliant POS system. And perhaps more
importantly, are you taking all the steps necessary to protect yourself against a large scale data breach?
IMS’s RECOMMENDATION
IMS wants its customers not only PCI-DSS compliant, but to be as protected as possible against a data
breach. To that end, we recommend an implementation roadmap that includes the following:
 Do a PCI Security Council SAQ and utilize a Qualified Security Assessor (QSA) if needed
o IMS can recommend a QSA if needed
 Take appropriate steps to be fully PCI-DSS compliant
 Upgrade to the newly validated Retail Pro®-EFT system including Retail Pro® V9.2 or Retail Pro®
Prism and Merchant Warehouse for gateway services
YOUR NEXT STEPS
IMS understands this is a business critical and emotional issue. Call us at 1-484-482-1600 to discuss your
options and how you should proceed.

Weitere ähnliche Inhalte

Kürzlich hochgeladen

Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024The Digital Insurer
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfEnterprise Knowledge
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdfhans926745
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesSinan KOZAK
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024The Digital Insurer
 
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...gurkirankumar98700
 
Developing An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilDeveloping An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilV3cube
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024Results
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Igalia
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonetsnaman860154
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Enterprise Knowledge
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityPrincipled Technologies
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking MenDelhi Call girls
 

Kürzlich hochgeladen (20)

Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdfThe Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
The Role of Taxonomy and Ontology in Semantic Layers - Heather Hedden.pdf
 
[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf[2024]Digital Global Overview Report 2024 Meltwater.pdf
[2024]Digital Global Overview Report 2024 Meltwater.pdf
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Unblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen FramesUnblocking The Main Thread Solving ANRs and Frozen Frames
Unblocking The Main Thread Solving ANRs and Frozen Frames
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
Kalyanpur ) Call Girls in Lucknow Finest Escorts Service 🍸 8923113531 🎰 Avail...
 
Developing An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilDeveloping An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of Brazil
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024
 
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
Raspberry Pi 5: Challenges and Solutions in Bringing up an OpenGL/Vulkan Driv...
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
How to convert PDF to text with Nanonets
How to convert PDF to text with NanonetsHow to convert PDF to text with Nanonets
How to convert PDF to text with Nanonets
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men08448380779 Call Girls In Civil Lines Women Seeking Men
08448380779 Call Girls In Civil Lines Women Seeking Men
 

Empfohlen

Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTExpeed Software
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsPixeldarts
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthThinkNow
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfmarketingartwork
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024Neil Kimberley
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)contently
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024Albert Qian
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsKurio // The Social Media Age(ncy)
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Search Engine Journal
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summarySpeakerHub
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next Tessa Mero
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentLily Ray
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best PracticesVit Horky
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project managementMindGenius
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...RachelPearson36
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Applitools
 

Empfohlen (20)

Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPT
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 

IMS Point of View: Retail Pro and PCI-DSS Compliance

  • 1. Phone: 1.484.482.1600 Contact Us For More Information WWW.IMS-POS.COM Topic: Retail Pro® and PCI Compliance – What You Need To Know There has been much communication and confusion recently about Retail Pro® and PCI Compliance. IMS customers have been receiving information from Retail Pro®, Merchant Warehouse (MW - Retail Pro’s EFT exclusive provider) and Shift 4®. IMS has prepared this Point of View (POV) to help our customers understand what is happening and to help you make the most informed choice for meeting PCI-DSS compliance standards not just for today, but for moving forward. PCI SECURITY STANDARDS It is YOUR responsibility as a merchant to understand what YOU need to do to be fully PCI Data Security Standard (PCI-DSS) compliant. Your Payment Application Data Security Standard (PA-DSS) validated POS software is only one of many PCI-DSS compliance requirements. PCI Security Standards are available at WWW.PCISECURITYSTANDARDS.ORG. According to the PCI Security Council: “Use of a Payment Application Data Security Standard (PA-DSS) compliant application by itself does not make an entity PCI DSS compliant, since that application must be implemented into a PCI DSS compliant environment and according to the PA-DSS Implementation Guide provided by the payment application vendor.” There are 12 primary requirements listed below: Build and Maintain a Secure Network and Systems 1. Install and maintain a firewall configuration to protect cardholder data 2. Do not use vendor-supplied defaults for system passwords and other security parameters Protect Cardholder Data 3. Protect stored cardholder data 4. Encrypt transmission of cardholder data across open, public networks Maintain a Vulnerability Management Program 5. Protect all systems against malware and regularly update anti-virus software or programs 6. Develop and maintain secure systems and applications Implement Strong Access Control Measures 7. Restrict access to cardholder data by business need to know 8. Identify and authenticate access to system components 9. Restrict physical access to cardholder data Regularly Monitor and Test Networks 10. Track and monitor all access to network resources and cardholder data 11. Regularly test security systems and processes Maintain an Information Security Policy 12. Maintain a policy that addresses information security for all personnel
  • 2. Phone: 1.484.482.1600 Contact Us For More Information WWW.IMS-POS.COM There are numerous sub-requirements under each main area. To find out about these requirements, there is a full complement of resources, including a Self Assessment Questionnaire (SAQ), on the WWW.PCISECURITYSTANDARDS.ORG website. RETAIL PRO®’S COMPLIANCE APPROACH As part of Retail Pro’s PA-DSS compliance responsibilities, it must complete a yearly validation process with an approved Payment Application Qualified Security Assessor (PA-QSA). This year’s validation date is June 21, 2014. This means that any software versions and associated EFT link-system partners that Retail Pro® wishes to be PA-DSS compliant and acceptable for new deployments, must be included in this validation renewal. Versions and systems included in the re-validation include: 1. Retail Pro® V9.2 2. Retail Pro® Prism 3. Merchant Warehouse gateway services This means that Retail Pro® V8.6 is only acceptable for pre-existing deployments (validated according to PA-DSS V1.2). That also means that your legacy Monetra based EFT Links to Mercury, First Data, and WorldPay, as well as the Shift 4® EFT Link, will continue to function as they currently do (validated according to PA-DSS V2.0) until they are moved to sunset status at some point in the future. The Shift4® 4Go® product has not been tested nor certified by Retail Pro International (RPI) for operation with Retail Pro® products, and RPI has not developed, tested or certified any interface between Retail Pro® and 4Go®. WHAT THIS MEANS FOR YOU For those customers who currently use the legacy EFT links listed above, your pre-existing deployments will continue to work and you will continue to be PA-DSS validated as stated above. Any legacy EFT links will not be PA-DSS compliant for new deployments after the re-validation date. If you are planning on new deployments of any kind, these must use the Merchant Warehouse EFT solution.
  • 3. Phone: 1.484.482.1600 Contact Us For More Information WWW.IMS-POS.COM WHY MERCHANT WAREHOUSE? In making this strategic decision, Retail Pro® considered not only its current PA-DSS validation requirements, but how it could best support its customers in the rapidly advancing world of EMV and mobile-digital payments. As stated in previous Retail Pro® communications, as well as IMS’s own blog post communication, “EMV. Chip and Pin. What You Need To Know”, Retail Pro® has selected Merchant Warehouse as its sole EFT partner after a thorough due-diligence review. Some of the reasons for selecting Merchant Warehouse include:  MW can act as both a gateway and processor - using either MW processing or your processor  Gateway services include fully PA-DSS compliant advanced data encryption technologies tokenization and point-to-point encryption  The Genius Customer Engagement Platform enabling: o EMV ready payment acceptance o Secure credit card payments o Acceptance of yet-to be-determined mobile payments and various promotional payments such as gift cards, coupons, loyalty payments, etc. ARE YOU PCI-DSS COMPLIANT? Again, being PA-DSS compliant does not mean you are fully PCI-DSS compliant, as being PCI-DSS compliant includes more than just having a PA-DSS compliant POS system. And perhaps more importantly, are you taking all the steps necessary to protect yourself against a large scale data breach? IMS’s RECOMMENDATION IMS wants its customers not only PCI-DSS compliant, but to be as protected as possible against a data breach. To that end, we recommend an implementation roadmap that includes the following:  Do a PCI Security Council SAQ and utilize a Qualified Security Assessor (QSA) if needed o IMS can recommend a QSA if needed  Take appropriate steps to be fully PCI-DSS compliant  Upgrade to the newly validated Retail Pro®-EFT system including Retail Pro® V9.2 or Retail Pro® Prism and Merchant Warehouse for gateway services YOUR NEXT STEPS IMS understands this is a business critical and emotional issue. Call us at 1-484-482-1600 to discuss your options and how you should proceed.