If the operator keys in a credit card card number then yes; your software both accepts & transmits cardholder data so it, the machine running it & any network(s) its attached to are all in scope of PCI and so must be compliant.
Q: To whom does PCI apply? A: PCI applies to ALL organizations or merchants, regardless of size or number of transactions, that accepts, transmits or stores any cardholder data. Said another way, if any customer of that organization ever pays the merchant directly using a credit card or debit card, then the PCI DSS requirements apply
Browsers are not in scope only when the person using one to enter card details is the owner of the card & not a 3rd party merchant. PCI only applies to merchants & other processing entities, not the customers of the issuing card schemes.
Your app handles card numbers and is involved in the authorisation and/or settlement of card transactions. If you are providing it as off the shelf software it is in scope for PA-DSS.
The organisation that installs your app and runs it in their environment is in scope for PCI-DSS.
发布评论
评论(2)
如果接线员输入信用卡卡号,则可以;您的软件既接受又接受传输持卡人数据,以便它、运行它的机器和其连接的任何网络都在 PCI 范围内,因此必须兼容。
仅当使用浏览器输入卡详细信息的人是卡和信用卡的所有者时,浏览器才不在范围内。不是第三方商家。 PCI 仅适用于商户和个人其他处理实体,而不是发卡计划的客户。
If the operator keys in a credit card card number then yes; your software both accepts & transmits cardholder data so it, the machine running it & any network(s) its attached to are all in scope of PCI and so must be compliant.
Browsers are not in scope only when the person using one to enter card details is the owner of the card & not a 3rd party merchant. PCI only applies to merchants & other processing entities, not the customers of the issuing card schemes.
您的应用程序处理卡号并参与卡交易的授权和/或结算。如果您将其作为现成软件提供,则它属于 PA-DSS 的范围。
安装您的应用程序并在其环境中运行该应用程序的组织属于 PCI-DSS 的范围。
Your app handles card numbers and is involved in the authorisation and/or settlement of card transactions. If you are providing it as off the shelf software it is in scope for PA-DSS.
The organisation that installs your app and runs it in their environment is in scope for PCI-DSS.