Well I have been given written notice by PayQuake to be PCI-DSS within 60 days or loose my merchant account. I no have an obligatory service with TrustWave @ $11+ per month to certify me and the process is daunting. Some 200 + questions many of which are complete Greek to me ( or geek).
I feel very much like I am standing in a hornet's nest with three wolves standing around deciding what for dinner.........
To Start off it appears that Stone Edge order manager will not be certified compliant until fall. So no more using that software to process phone orders, credits or voids......uggg.
As for Hostasaurus, I went to them with one of the first questions:
Questions for PCI-DSS compliance :
ANSWER: (Read bottom up)
Does this make sence to anyone? So there is no firewall? What am I missing ?
I will have more questions on this but I thought I'd go one at a time.
Thanks!
I feel very much like I am standing in a hornet's nest with three wolves standing around deciding what for dinner.........
To Start off it appears that Stone Edge order manager will not be certified compliant until fall. So no more using that software to process phone orders, credits or voids......uggg.
As for Hostasaurus, I went to them with one of the first questions:
Questions for PCI-DSS compliance :
1. Do you have a firewall (or similar protective device) between your
e-commerce Web site and the internet?
2. Does this firewall restrict access between the Web site and the
Internet? (For example, does it allow only web-related traffic in?)
e-commerce Web site and the internet?
2. Does this firewall restrict access between the Web site and the
Internet? (For example, does it allow only web-related traffic in?)
David Hubbard
Posted On: Jun 22 2010 07:13 PM PCI doesn't require a firewall between the web server and the internet so they may be asking because they've misinterpreted the requirements. What it does require is the credit card data be stored on a physically separate server on an internal network and that server firewalled off from all traffic other than from the web server. Miva has not yet completed coding a way to accomplish that in existing Merchant 5.5 stores, only in new installs, so if that's the requirement they're really talking about there is no way to do it at this time.
David
[email protected]
Lee Sutherburg
Posted On: Jun 22 2010 07:09 PM ok I'll put that in but it does not sound like that passes muster for them?
David Hubbard
Posted On: Jun 22 2010 07:06 PM There is no firewall between the website and the internet Lee, the server has its own internal firewall software, but the server itself only listens for web traffic so basically nothing other than web traffic can get in anyway.
David
[email protected]



David
[email protected]





David Hubbard



David
[email protected]
I will have more questions on this but I thought I'd go one at a time.
Thanks!
Comment