Security Basics mailing list archives

pci question


From: "marck e." <marck.ernest () gmail com>
Date: Mon, 11 Apr 2011 15:28:27 -0500

Due to avoiding being scoped in PCI-compliance, we are now searching
for PSP (Payment Service Providers)
Our processing volume is quite low (maybe 20 o 30 orders a month)
We already selected a couple of PSP  and one of their requirements is
we must establish a VPN connection with them in order they send
payment status of orders (not credit card numbers at all)
Even when we only would get payment status of orders,is there any
reason we should establish a VPN connection with them?
I mean , if we only get status of paid or not-paid for payment
processing done on their infrastructure, why is that vpn requirement?
Also, What is extent we are scoped regarding PCI if we are outsourcing
all of our payment processing?

thank you

marck

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: