====== ====== ---- ---- ** Cyrious SMS 8.6 is __NOT__ a PCI Certified Application. Cyrious SMS 8.9 is awaiting approval. If you are using Cyrious SMS 8.9pci, refer to the following page for assistance: ** [[pci_certification_-_trustkeeper_-_saq-d_compliance_questionaire_sms_8.9|PCI Certification - TrustKeeper - SAQ-D Compliance Questionaire SMS 8.9]] ---- ---- **Disclaimer:** All information provided in these pages is meant to be helpful for a typical Sign, Print, or Graphics company. If your business model differs significantly from these typical establishments, these recommendations may not apply. In all cases, you are responsible for providing the correct answer and Cyrious assumes no direct or indirect liability with the guidance below. ---- [[toc|toc]]Once you are logged into TrustKeeper at [[https://elavonpci.trustkeeper.net/]], one of the steps is to set up your **Compliance Questionaire**. The information below is meant to help you answer those questions. Please note that the answers provided only concern Cyrious' applications. Many of the questions concern Cyrious //and// other applications you have and must be answered in this context. ===== SAQ-D Questionaire ===== The SAQ Questionaire is the document where //you// must attest that you are following all of the best practices necessary to secure the card holder information you come into contact with. ---- For users of Cyrious SMS or Control, Cyrious recommends you complete SAQ-D. If you //never// place a single credit card number into Control or SMS, and no employe ever has, ever does, or ever will then you probably qualify to use SAQ-C. __This does not just apply to processing credit card information, but storing any credit card number in the system also.__ SAQ-C is easier to complete, but if you find that your or an employee has, does, or will put credit card information into SMS or Control you will end up not being in compliance. ---- The information below assumes you are using Questionaire D. If you are using another form, then this information does not apply to you. ==== Security Questions ==== Unfortunately, Cyrious does not know the status of your network. Our support technicians are not authorized to answer any questions on your network security. You will need to have these questions verified by someone knowledgeable about //your// specific network configuration. In some cases, you may need to make changes or implement additional security measures. ==== Section 3: Stored Data Protection ==== **Note:** This information only applies to SMS 8.6, it does not apply to any other version of Cyrious SMS and should not be utilized in the assistance of completing the questionnaire if you have any other version. The information provided here has been made available to assist you with answering the questions in required //of our software// in Section 3. Stored Data Protection, but you must confirm these for //all// systems you use. * Cyrious SMS 8.6 //does not// store any magnetic track data. (Question 4) * Cyrious SMS 8.6 //does not// store the card-validation code. (Question 5) * Cyrious SMS 8.6 //does not// store the PIN. (Question 6) * Cyrious SMS 8.6 //does// mask the PAN except when authorized employees need access to this information. (Question 7) * Cyrious SMS 8.6 does encrypt sensitive data but the encryption //**is not**// strong cryptography as required by PCI with key management for all stored information. (Question 8) * Cyrious SMS 8.6 //does not// rely on disk encryption. (Question 9 & 10) * Cyrious SMS 8.6 //**does not**// use cryptographic keys for encryption against disclosure and misuse. (Question 11) * Cyrious SMS 8.6 //**does not**// restrict its encryption keys automatically. Once you enter your key the system uses it automatically and there is no way to retrieve it! (Question 12) * Cyrious SMS 8.6 //**does not**// store keys securely for you, in the fewest locations and forms possible. (Question 13) * Though Cyrious SMS 8.6 //does// not require key retention, you should have a policy to change the key if the person who created it leaves the company or you believe the key is compromised. (Question 14) * Cyrious SMS 8.6 //**does not**// generate strong cryptographic keys. (Question 15) * Cyrious SMS 8.6 //**does not**// secure cryptographic key distribution between its applications. (Question 16) * Cyrious SMS 8.6 //**does not**// secure cryptographic key storage. (Question 17) * Cyrious SMS 8.6 //**does not**// change its internal security keys at least annually. (Question 18) * Though Cyrious SMS 8.6 //does// not require key retention, you should have a policy to change the key if the person who created it leaves the company or you believe the key is compromised. (Question 19) * Cyrious SMS 8.6 //**does not**// split the knowledge and control of the cryptographic keys by having some of those keys controlled by Cyrious and some controlled by you. (Question 20) * Cyrious' SMS 8.6 approach //**does not**// automatically prevent substitution of cryptographic keys since different parties have different pieces. (Question 21) * Cyrious' SMS 8.6 approach //does not// require a key custodian since their are not user managed keys. (Question 22) ==== Section 4. Transmitted Data Protection ==== Cyrious SMS 8.6 information for the requirements //of our software// in Section 4. Transmitted Data Protection, but you must confirm these for //all// systems you use. * Cyrious SMS 8.6 //does// transmit all sensitive cardholder data using appropriate encryption on //all// networks. (Question 1) * If you are using a wireless network, you must attest to its security settings. (Question 2) * Cyrious SMS 8.6 //does// prevent the sending of any sensitive information through end-user messaging technologies when used correctly, but you need to make sure you have written and enforced policies that also prevent this. (Question 3) ==== Section 6. Application and System Security ==== Cyrious SMS 8.6 information for the requirements //of our software// in Section 6. Application and System Security, but you must confirm these for //all// systems you use. * This requirement specifies that you must maintain the latest version of Cyrious SMS. (Questions 1,2) * Cyrious SMS 8.6 //is not// considered a custom application for purposes of PCI certification. (Question 5, 6) * Cyrious SMS 8.6 //does not// connect to a web system directly if you are not running WebView or Production Terminal. For these, you need to ensure that proper web security techniques are deployed. ==== Section 7. Access Restrictions ==== Cyrious SMS 8.6 information for the requirements //of our software// in Section 7. Access Restrictions, but you must confirm these for //all// systems you use. * This section requires you to set up your system and policies so that only users with a requirement for access to sensitive information actually //can// access that information. Remember to answer this not just as it applies to Cyrious but as it applies to all of your systems.