====== ====== ---- **Disclaimer:** All information provided in these pages is meant to be helpful for a typical Sign, Print, or Graphics company. If your business model differs significantly from these typical establishments, these recommendations may not apply. In all cases, you are responsible for providing the correct answer and Cyrious assumes no direct or indirect liability with the guidance below. ---- Once you are logged into TrustKeeper at [[https://elavonpci.trustkeeper.net/]], one of the steps is to set up your **Compliance Questionaire**. The information below is meant to help you answer those questions. Please note that the answers provided only concern Cyrious' applications. Many of the questions concern Cyrious //and// other applications you have and must be answered in this context. ===== SAQ-D Questionaire ===== The SAQ Questionaire is the document where //you// must attest that you are following all of the best practices necessary to secure the card holder information you come into contact with. ---- For users of Cyrious SMS or Control, Cyrious recommends you complete SAQ-D. If you //never// place a single credit card number into Control or SMS, and no employe ever has, ever does, or ever will then you probably qualify to use SAQ-C. __This does not just apply to processing credit card information, but storing any credit card number in the system also.__ SAQ-C is easier to complete, but if you find that your or an employee has, does, or will put this information into Control you will end up not being in compliance. ---- The information below assumes you are using Questionaire D. If you are using another form, then this information does not apply to you. ==== Security Questions ==== Unfortunately, Cyrious does not know the status of your network. Our support technicians are not authorized to answer any questions on your network security. You will need to have these questions verified by someone knowledgeable about //your// specific network configuration. In some cases, you may need to make changes or implement additional security measures. ==== Section 3: Stored Data Protection ==== Cyrious SMS 8.9 pci and later and Cyrious Control 4.4 and later satisfy the requirements required //of our software// in Section 3. Stored Data Protection, but you must confirm these for //all// systems you use. * Cyrious //does not// store any magnetic track data. (Question 4) * Cyrious //does not// store the card-validation code. (Question 5) * Cyrious //does not// store the PIN. (Question 6) * Cyrious //does// mask the PAN except when authorized employees need access to this information. (Question 7) * Cyrious //does// use strong cryptography (encryption) and key management for all stored sensitive information. (Question 8) * Cyrious //does not// rely on disk encryption. (Question 9 & 10) * Cyrious //does// use cryptographic keys for encryption against disclosure and misuse. (Question 11) * Cyrious //does// restrict its encryption keys automatically. Once you enter your key the system uses it automatically and there is no way to retrieve it! (Question 12) * Cyrious //does// store keys securely for you, in the fewest locations and forms possible. (Question 13) * Though Cyrious //does// not require key retention, you should have a policy to change the key if the person who created it leaves the company or you believe the key is compromised. (Question 14) * Cyrious //does// generate strong cryptographic keys. (Question 15) * Cyrious //does// secure cryptographic key distribution between its applications. (Question 16) * Cyrious //does// secure cryptographic key storage. (Question 17) * Cyrious //does// change its internal security keys at least annually. (Question 18) (Note: Users not on support may be required to purchase the product update to obtain the changed keys.) * Though Cyrious //does// not require key retention, you should have a policy to change the key if the person who created it leaves the company or you believe the key is compromised. (Question 19) * Cyrious //does// split the knowledge and control of the cryptographic keys by having some of those keys controlled by Cyrious and some controlled by you. (Question 20) * Cyrious' approach //does// automatically prevent substitution of cryptographic keys since different parties have different pieces. (Question 21) * Cyrious' approach //does not// require a key custodian since the key is only asked for once and can never be retrieved. (Question 22) ==== Section 4. Transmitted Data Protection ==== Cyrious SMS 8.9 pci and later and Cyrious Control 4.4 and later satisfy the requirements required //of our software// in Section 4. Transmitted Data Protection, but you must confirm these for //all// systems you use. * Cyrious //does// transmit all sensitive cardholder data using appropriate encryption on //all// networks. (Question 1) * If you are using a wireless network, you must attest to its security settings. (Question 2) * Cyrious //does// prevent the sending of any sensitive information through end-user messaging technologies when used correctly, but you need to make sure you have written and enforced policies that also prevent this. (Question 3) ==== Section 6. Application and System Security ==== Cyrious SMS 8.9 pci and later and Cyrious Control 4.4 and later satisfy the requirements required //of our software// in Section 6. Application and System Security, but you must confirm these for //all// systems you use. * This requirement specifies that you must maintain the latest version of Cyrious Control or Cyrious SMS. (Questions 1,2) * Cyrious //is not// considered a custom application for purposes of PCI certification. (Question 5, 6) * Cyrious //does not// connect to a web system directly if you are not running WebView or Production Terminal. For these, you need to ensure that proper web security techniques are deployed. ==== Section 7. Access Restrictions ==== Cyrious SMS 8.9 pci and later and Cyrious Control 4.4 and later satisfy the requirements required //of our software// in Section 7. Access Restrictions, but you must confirm these for //all// systems you use. * This section requires you to set up your system and policies so that only users with a requirement for access to sensitive information actually //can// access that information. Remember to answer this not just as it applies to Cyrious but as it applies to all of your systems.