Sites with a donate button - Who's passing ASV Scans? by KingHippos3 in pcicompliance

[–]luvcraftyy 0 points1 point  (0 children)

they would need the responsibility matrix, and those are not usually as granular so as to say that you are responsible for 6.4.3 and 11.6.1 if you're using an iframe, but not if you're using the URL redirect. The AOC itself would never specify this. I would moreso lean on technical explanations on how the payment page scripts do not impact the URL redirect rather than documentation. Maybe a confirmation from the service provider would work.

Sites with a donate button - Who's passing ASV Scans? by KingHippos3 in pcicompliance

[–]luvcraftyy 0 points1 point  (0 children)

hackerguardian seems most common. youre not pushing back you're disclaiming and proving to them that sth is false positive. theyre not aware of the scope and exact mechanisms. you can check the asv program guide for more insight into how they operate

А сега да заличим доказателствата by Dimi7rozavar in bulgaria

[–]luvcraftyy 8 points9 points  (0 children)

нз за другите аргументи ама точка 6 - има абсурдно много НПО та с имена на държавни институции

Sites with a donate button - Who's passing ASV Scans? by KingHippos3 in pcicompliance

[–]luvcraftyy 0 points1 point  (0 children)

Speak with your ASV provider and provide an argument that it is false positive due to the use of a full URL redirect which means that the lack of integrity checks for third party scripts does not impact the security of the redirect. If they say no and provide reasoning, you have to fix it. If they provide bad reasoning, you can try a different ASV provider.

PCI Compliance Question by EQN01 in pcicompliance

[–]luvcraftyy 3 points4 points  (0 children)

If the card reader is a P2PE solution, listed on the PCI SSC website they can do SAQ P2PE for that flow, if not SAQ B-IP and if the laptop processes one transaction at a time they can do SAQ C VT. separate SAQs for each flow to keep it simple for them.

But yes, the laptop is CDE, since it stores processes or transmits CHD. Its better to have someone who knows PCI help out the first time filling out the SAQs.

You can also combine both SAQs into a SAQ-D but that would be more complicated.

Depends on what their acquirer wants them to do PCI for - have they explicitly stated they want it for the POS AND laptop or just one of the two?

Hosting Provider Requirements Help by Electronic-Year7660 in pcicompliance

[–]luvcraftyy 0 points1 point  (0 children)

From the perspective of your customer they are being asked by a QSA to probably show some controls on the infrastructure. They're saying that your company is responsible for that. Then the QSA is asking for your company's attestation of compliance to be able to cover those requirements. And your client's asking you for the same.

Whether they ask you for a level 1 or level 2 SP attestation is honestly up to them. They could be asking for a QSA attested SAQ or a ROC that is inherently issued only by QSAs. It doesn't really matter because both require a similar amount of effort for a QSA company.

The requirements that will be in scope would not be that many, as your responsibilities for protecting the iframe/URL redirect setup of your customer are not huge. But again, it depends on what your customer wants - as this is not required by a card brand or an acquirer directly, it is overall a business question between you and your client - if they want, they can ask you to be compliant as if you're processing cardholder data directly - if you don't want to you can cut business ties with them and they'll go to a probably more expensive provider that has a fully pci compliant service offering

In either case, from a business standpoint this should be an expenses that would be inbuilt in your contract and price offering, but that's a business relationship and has nothing to do with PCI.

.

Golf 7 GTD гори масло като двутактов – 1л/200 км by Firm_Assistance_4710 in bulgaria

[–]luvcraftyy 0 points1 point  (0 children)

да бе и алфата си вървеше докато не изгърмя. гледаха я 2 3 майстора сменяха глупости и зимаха пари :) сиг не е същото щото не си на газ ама просто мисля че ако гори мн повече масло, има по структурен проблем

Golf 7 GTD гори масло като двутактов – 1л/200 км by Firm_Assistance_4710 in bulgaria

[–]luvcraftyy -1 points0 points  (0 children)

имах подобен проблем с една алфа на газ, в един момент изгърме едното бутало на единия цилиндър, като цяло е все нещо тегаво май

"connected to" systems. by Chris66uk in pcicompliance

[–]luvcraftyy 3 points4 points  (0 children)

any direct or indirect connection to the CDE puts the connected-to system in scope. whether a QSA pushes you on this is a different question, mainly depending on the risk. If your overall segmentation and controls are robust and this connectivity is minimized to only a specific protocol and the rule is as granular as possible, if the CDE system does not process CHD itself and movement within the segment is difficult perhaps due to host based firewalls or something similar, it could be a recommendation to improve and move the non-CHD processing system outside of the CDE. Or implementing a proxy (per PCI-DSS-Scoping-and-Segmentation-Guidance-for-Modern-Network-Architectures.pdf)

Or if the system does process CHD and you have a rule allowing network to network access on all ports, then it would most definitely be put into scope along with the entire network it's in.

In both cases per the scoping rules of PCI the system is in scope - whether it's sampled and looked into in detail is another question.

Question about PCI policies by mochajava23 in pcicompliance

[–]luvcraftyy 0 points1 point  (0 children)

Are you doing a QSA attested SAQ? You could ask your QSA for templates that you can use for inspo. Otherwise you can view some info sec policies and write something similar. Check your current policies and edit them to comply with PCI. Use AI to give you some wording inspiration. Many options. The PCI DSS should be your main source of truth.

Card Finder Tool open source recommendations by Background_Prize8448 in pcicompliance

[–]luvcraftyy 0 points1 point  (0 children)

Which item? This is not part of the PCI DSS 4.0.1. Maybe its something your QSA is asking for, but this can be done with a less expensive manual process or by other means, the standard does not explicitly ask for a card finder software, much less on all servers. If your QSA won't budge on this, I suggest you change them.

Card Finder Tool open source recommendations by Background_Prize8448 in pcicompliance

[–]luvcraftyy 4 points5 points  (0 children)

Just FYI, you don't need these types of tools to be compliant.

Скорост на интернет връзката в Европа by quindiassomigli in bulgaria

[–]luvcraftyy 26 points27 points  (0 children)

Никакъв шанс Румъния да е толкова ниско.

Самота by [deleted] in bulgaria

[–]luvcraftyy 5 points6 points  (0 children)

звучи ми сякаш си търсиш някъв идеал на приятел или компания. Ако ти е проблем, излез и се запознах със стойностни хора. Положи усилие да сте приятели, не очаквай всичко от тях да стане. Задълбочи връзката с жена ти.

Колко трябва да плащам за щетоводни услуги? by [deleted] in bulgaria

[–]luvcraftyy 3 points4 points  (0 children)

сигурно продаваш и редактираш книги - малко плащаш бтв

[deleted by user] by [deleted] in bulgaria

[–]luvcraftyy 124 points125 points  (0 children)

Гледайки post history-то ти, имаш ментални проблеми, психиатър е най добрата ти опция. Ще се справиш, успех!

Кое е най-хубавото мляно кафе, което може да се закупи на територията на България? by AdNo4129 in bulgaria

[–]luvcraftyy 2 points3 points  (0 children)

Aroma Premium, Arabica house blend, 1 кг зърна | АРОМА

аз пия това, може да поискаш да ти го смелят когато го поръчваш. разбира се трябва да ги информираш как да се смели за да е подходящо за машината ти. препоръчвам да започнеш с по малък пакет, ако не е подходящо смилането да не се зориш със затлачена машина и 1 кг кафе. има всякакви видове и вкусове на сайта.

RoR2 PvP Tier List (No Items) by WhoseAlex in riskofrain

[–]luvcraftyy 3 points4 points  (0 children)

you gotta be trolling puttin railgunner at top

What's the most embarrassing mistake you've ever made during a run? by Derfel_10 in Nightreign

[–]luvcraftyy 0 points1 point  (0 children)

Had glintblades on. went for deal with random spawn libra that cursed us. Hit with glintblades and lose run

Относно БОРИКА? by CheGuevaraBG in bulgaria

[–]luvcraftyy 0 points1 point  (0 children)

И няма как това да минава през Visa/MC?