Announcement

Collapse
No announcement yet.

RBS / Streamline & PCI DSS

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    RBS / Streamline & PCI DSS

    OK i know theres hundreds of thread around but im hoping to get info to one place for each bank / card service provider.

    I use Streamline and AP

    now i have had my letters through requireing me to certify and RBS use arsenal. I have registered and am working my way through. But i have to submit documentation and certification about my compliance. Now i may have miss understood this but they are askign me to provide evidence that my PSP is compliant. Having browsed around the Actinic site i find no information - im using AP

    Now i believe im level 4 type C because i process cards via AP and sometimes use the moto form.

    My main question here is
    Has anyone completed the RBS/Streamline PCI compliance to this level using Arsenal.

    If so would they mind sharing how they actually did this and what documentation they actually submitted, i have registered and need to submit documentation. Do i have to have a security scan done of my network and is the RBS offer of around £80 per annum about the right market cost?

    hope someone can offer some advice
    Cheers
    Darren

    #2
    I use an identical combination and am also Level 4 and use the MOTO form so completed SAQ C.

    You will need to get a network scan if you use the MOTO form.

    I completed the SAQ C MS Word Document that I download from www.pcisecuritystandards.org and signed up for a free network scan from Comodo/Hackerguardian the free subscription is valid for 90 days so did an itital scan that passed and have just performed a second scan on day 89 which covers the frist two scans. When the next scan is due I will probably try the McAfee free 12 month scans offer before I start to look around for the paid for options.

    HackerGuardian provide a compliance report in pdf format that you can donwload.
    I then logged into the Arsenal site and uploaded both the SAQ-C Word Doc and the Scan compliance report and I am then covered for the next 3 months, when an email is sent reminding you that another scan report is due. I have not been asked to provide any additional documentation.

    I do not remember seeing anything requesting proof of compliance of the PSP, if you can state where you saw the request I will check it against the letters/forms I have.
    Darren Guppy
    Golf Tee Warehouse
    Golf Tees and Golf Accessories.

    Comment


      #3
      If you do need to upload a certificate Actinic have the Creditcall PCI certificate on their website for download
      Direct Link: http://www.actinic.co.uk/docs/produc...ertificate.pdf
      Darren Guppy
      Golf Tee Warehouse
      Golf Tees and Golf Accessories.

      Comment


        #4
        On the SAQ what is payment application in use / payment application version?


        PS: Arsenal in their wisdom changed me to level 3! I use AP and the MOTO form via a single PC...
        https://www.harrisontelescopes.co.uk/

        Ed Harrison - Menmuir Scotland

        Comment


          #5
          Originally posted by Golf Tee Warehouse View Post
          If you do need to upload a certificate Actinic have the Creditcall PCI certificate on their website for download
          Direct Link: http://www.actinic.co.uk/docs/produc...ertificate.pdf
          Thats what i was looking for, thank you i cant remember were i read it. It might actually have been in the SAQ C somewere but not required. I think this week i will sit down and file the forms.

          Cheers for the info
          Darren

          Comment


            #6
            Originally posted by EdHarrison View Post
            On the SAQ what is payment application in use / payment application version?


            PS: Arsenal in their wisdom changed me to level 3! I use AP and the MOTO form via a single PC...
            Are you still on level 3 or has this been changed?

            Comment


              #7
              I entered:
              Payment Application in use: Creditcall
              and
              Payment Application Version: eKashu

              I was unsure if this was the correct answers but he best I could come up with.

              Level 3 I though was for companies with over 20,000 transaction a year, does that apply to you.
              Darren Guppy
              Golf Tee Warehouse
              Golf Tees and Golf Accessories.

              Comment


                #8
                The actinic info on this page http://www.actinic.co.uk/ecommerce-s...ompliance.html has some useful information and worth a read through.
                Darren Guppy
                Golf Tee Warehouse
                Golf Tees and Golf Accessories.

                Comment


                  #9
                  I have read so much i think i confused myself. I have trawelled alot of links here and from other places and have a feeling im looking to deep into this.

                  A fresh look next week will probably be the best thing

                  Comment


                    #10
                    I passed as compliant at level 3 (they changed it not me) in February but I have requested it be corrected - I am lucky to do 5000 transactions not 20,000!

                    The support is useless at Arsenal and I think the whole PCI DSS thing is flawed and needs one body to control it properly not just companies using it as a form of income.
                    https://www.harrisontelescopes.co.uk/

                    Ed Harrison - Menmuir Scotland

                    Comment


                      #11
                      Update

                      If anyone is struggling with the scan results via Qualys / Arsenal (a quick google shows Im not alone) I signed up with Mcafee and passed the scan no problem!
                      https://www.harrisontelescopes.co.uk/

                      Ed Harrison - Menmuir Scotland

                      Comment

                      Working...
                      X