Security Basics mailing list archives
pci question
From: "marck e." <marck.ernest () gmail com>
Date: Mon, 11 Apr 2011 15:28:27 -0500
Due to avoiding being scoped in PCI-compliance, we are now searching for PSP (Payment Service Providers) Our processing volume is quite low (maybe 20 o 30 orders a month) We already selected a couple of PSP and one of their requirements is we must establish a VPN connection with them in order they send payment status of orders (not credit card numbers at all) Even when we only would get payment status of orders,is there any reason we should establish a VPN connection with them? I mean , if we only get status of paid or not-paid for payment processing done on their infrastructure, why is that vpn requirement? Also, What is extent we are scoped regarding PCI if we are outsourcing all of our payment processing? thank you marck ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------
Current thread:
- pci question marck e. (Apr 15)