0 Comments
WAKEFIELD, Mass. — The PCI Security Standards Council, a global, open industry-standards body providing management of the Payment Card Industry Data Security Standard, PIN Entry Device Security Requirements and the Payment Application Data Security Standard, announced that it has launched a quality-assurance program for Qualified Security Assessors and Approved Scanning Vendors. 
 
According to a news release, the new program was designed to provide QSAs and ASVs with a set of requirements that helps ensure they provide consistent, quality validation and assessment services to merchants and service providers. 
The PCI SSC developed the quality-assurance program as a direct result of feedback from the council's participating organizations and assessment community and is intended to promote consistent interpretation of the PCI standards and ensure quality is maintained among all vendors. Participation in the program will be required for the council's registered QSAs and ASVs in order for them to retain the ability to conduct PCI assessments.
 
"Feedback from the council's participating organizations and others made it clear that the assessment process for the PCI standards would benefit greatly from more rigorous guidelines," said Bob Russo, general manager of the PCI Security Standards Council. "As a result, we created a clear-cut program that will help ensure all those involved in this process are consistent, credible, competent and ethical."
The new quality-assurance program is based on eight guiding principles. Through the program, the Council and assessor community commit to: 
  • Uphold the best interest of the assessor client. 
  • Adhere to validation requirements among the assessor company. 
  • Adhere to validation requirements among the assessor employee. 
  • Maintain consistent assessor procedures and reporting.
  • Interpret the PCI standards appropriately as applicable to the client's systems & environment. 
  • Remain current with industry trends and PCI SSC updates in the assessor community. 
  • Report all opinions as factual, documented and defendable.
  • Maintain a positive relationship between the assessor and PCI SSC.
An expanded range of communications channels will allow the PCI SSC to interact with assessors, merchants and service providers on an ongoing basis through certification reviews, credit checks, training, educational webinars, newsletters, a dedicated e-mail service, question-and-answer documents, informational supplements and feedback forms. A team of dedicated staff will validate assessor applications and renewals, ensure that training is relevant and accessible to organizations and maintain the integrity of the testing process. This team also will be responsible for assessor performance monitoring and overseeing any necessary disciplinary action, which could include probation or revocation.
The program will continue to be rolled out in a four-stage process throughout 2009.

Related Content

Reader Comments

Add a Comment

We welcome your thoughtful comments. All comments will display your real name.

Want to participate in the discussion?

Or log in for complete access.

  • Clear
  • Post
Be the first to post a comment for this story.
Products & Services

Retail ATM - Tranax C4000

http://global.networldalliance.com/new/images/products/mb4k_view13_100.gif

1188/Retail-ATM-Tranax-C4000

ADA-Compliant ATM Surrounds, Toppers, and Wraps

http://global.networldalliance.com/new/images/products/4539.png

4539/ADA-Compliant-ATM-Surrounds-Toppers-and-Wraps

Serve versatile demands—Full-function TTW ATM H38N

http://global.networldalliance.com/new/images/products/H38N.jpg

3738/Serve-versatile-demands-Full-function-TTW-ATM-H38N

ATM Canopies & Buildings

http://global.networldalliance.com/new/images/products/1079.png

1079/ATM-Canopies-Buildings

Depositories

http://global.networldalliance.com/new/images/products/449.png

449/Depositories

Free Webinar

http://global.networldalliance.com/new/images/products/4079.png

4079/Free-Webinar

ATM Remote Monitoring, The DPL Group AC Disconnect Module

http://global.networldalliance.com/new/images/products/4051.png

4051/ATM-Remote-Monitoring-The-DPL-Group-AC-Disconnect-Module

Network Processing

http://global.networldalliance.com/new/images/products/4336.png

4336/Network-Processing

ATM Programs and Services

http://global.networldalliance.com/new/images/products/4648.png

4648/ATM-Programs-and-Services

Outdoor Encrypting Pin Pad - Cryptera EPP 1315

http://global.networldalliance.com/new/images/products/896.png

896/Outdoor-Encrypting-Pin-Pad-Cryptera-EPP-1315

Request Information From Suppliers
Save time looking for suppliers. Complete this form to submit a Request for Information to our entire network of partners.