Example: biology

Payment Card Industry (PCI) Qualification Requirements

Payment card Industry (PCI) Qualification Requirements For Qualified Security Assessors (QSA) Version March 2021 PCI DSS Qualification Requirements for Qualified Security Assessors March 2021 2021 PCI Security Standards Council, LLC, All rights reserved. Page ii Document Changes Date Version Description October 2008 To align version number with PCI DSS ; no other changes made. May 2015 Made various grammar improvements; aligned terminology with PCI DSS Increased Violation period to three (3) years Clarified QSA Company and Employee Qualification Requirements Enhanced Business Legitimacy Requirements Enhanced separation of duties, independence, and conflict of interest Requirements Clarified regional Requirements Clarified subcontra

PCI DSS The then-current version of the Payment Card Industry (PCI) Data Security Standard and Security Assessment Procedures as from time to time amended and made available on the Website. PCI DSS Assessment The review of an entity by a QSA Company to determine the entity’s compliance with the PCI DSS for QSA Program purposes.

Tags:

  Requirements, Qualification, Industry, Payments, Card, Payment card industry, Qualification requirements

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of Payment Card Industry (PCI) Qualification Requirements

1 Payment card Industry (PCI) Qualification Requirements For Qualified Security Assessors (QSA) Version March 2021 PCI DSS Qualification Requirements for Qualified Security Assessors March 2021 2021 PCI Security Standards Council, LLC, All rights reserved. Page ii Document Changes Date Version Description October 2008 To align version number with PCI DSS ; no other changes made. May 2015 Made various grammar improvements; aligned terminology with PCI DSS Increased Violation period to three (3) years Clarified QSA Company and Employee Qualification Requirements Enhanced Business Legitimacy Requirements Enhanced separation of duties, independence, and conflict of interest Requirements Clarified regional Requirements Clarified subcontracting vs.

2 Partnership with active QSA Company Enhanced QSA Employee skills and experience Requirements Added PCI SSC Code of Professional Responsibility Enhanced background check Requirements Enhanced QSA Company internal quality assurance Requirements Enhanced Evidence (Assessment workpaper) retention Requirements Added Security Incident Response Enhanced annual requalification Requirements Enhanced Assessor Quality Management process: QSA Audit, Quality Remediation and Revocation process Updated the QSA Agreement (Appendix A) Updated insurance Requirements (Appendix B) Added QSA Company application (Appendix C) Added QSA Employee application (Appendix D) February 2016 Updated Section to clarify professional certification Requirements .

3 December 2017 Added Associate QSA Program Updated requirement for QSA Employees to include two Industry Certifications Clarified in process certifications February 2020 Updated Section adding RISS professional certification to List A March 2021 Added requirement for annual QA questionnaire Added requirement for QA staff at QSA Company has PCI credential Added requirement for periodic checks on QA process Added requirement for QSA Company to have conflict of interest policy Added requirement for QSAs to have appropriate skills for assessments Added requirement that QSAs must be training on the version of standard they are using Removed requirement that QSAs must submit CPEs to PCI SSC Removed requirement that customer information not be stored on Internet accessible systems Performed minor clarifications in language throughout PCI DSS Qualification Requirements for Qualified Security Assessors March 2021 2021 PCI Security Standards Council, LLC, All rights reserved.

4 Page 1 Table of Contents 1 Introduction .. 3 Terminology .. 3 Goal .. 5 Qualification Process Overview .. 5 Document Structure .. 5 Related Publications .. 6 QSA Company Application Process .. 6 Additional Information Requests .. 7 2 QSA Company Business Requirements .. 8 Business Legitimacy .. 8 Requirement .. 8 Provisions .. 8 Independence .. 8 Requirement .. 8 Provisions .. 10 Insurance Coverage .. 10 Requirement .. 10 Provisions .. 10 QSA Company Fees .. 11 Requirement .. 11 QSA Agreement.

5 11 Requirement .. 11 3 QSA Capability Requirements .. 12 QSA Company Services and Experience .. 12 Requirement .. 12 Provisions .. 12 QSA Employee Skills and 13 Requirement .. 13 Provisions .. 15 Associate QSA Employee Skills and Experience .. 15 Requirement .. 15 Provisions .. 16 Mentor Requirement .. 16 Code of Professional Responsibility .. 17 Requirement .. 17 4 QSA Administrative Requirements .. 18 Contact Person .. 18 Requirement .. 18 Provisions .. 18 Background 18 Requirement.

6 18 Provisions .. 18 Internal Quality Assurance .. 19 Requirement .. 19 Provisions .. 20 Protection of Confidential and Sensitive Information .. 21 Requirement .. 21 PCI DSS Qualification Requirements for Qualified Security Assessors March 2021 2021 PCI Security Standards Council, LLC, All rights reserved. Page 2 Provisions .. 21 Evidence (Assessment Workpaper) Retention .. 21 Requirement .. 21 Provisions .. 22 Security Incident Response .. 23 Requirement .. 23 Provisions .. 23 5 QSA List and Annual Re- Qualification .

7 24 QSA List .. 24 Annual Re- Qualification .. 24 Requirements .. 24 Provisions .. 25 6 Assessor Quality Management Program .. 26 QSA Audit Process .. 26 QSA Annual QA Questionnaire Process .. 26 QSA Quality Remediation Process .. 26 QSA Revocation Process .. 27 Appendix A. Qualified Security Assessor (QSA) Agreement .. A1 Appendix B. Insurance Coverage .. B1 Appendix C. QSA Company Application .. C1 Appendix D. QSA Employee Application .. D1 Appendix E. Associate QSA Employee Application .. E1 PCI DSS Qualification Requirements for Qualified Security Assessors March 2021 2021 PCI Security Standards Council, LLC, All rights reserved.

8 Page 3 1 Introduction In response to requests from members of the Payment card Industry ( PCI ) for a unified set of Payment account data security Requirements , PCI Security Standards Council, LLC ( PCI SSC ) adopted and maintains the PCI Data Security Standard or PCI DSS, a set of Requirements for cardholder data protection across the Industry . When implemented properly, PCI DSS Requirements provide a well-aimed defense for merchants and service providers against data exposure and compromise. As a result, assessment of merchants and service providers for compliance with PCI DSS Requirements has become increasingly critical in today s environment and is key to the success of the PCI DSS.

9 Independent security organizations qualified by PCI SSC to validate an entity s adherence to PCI DSS Requirements are referred to as Qualified Security Assessor Companies or QSA Companies. Validation of PCI DSS Requirements by QSA Companies is important to the effectiveness of the PCI DSS; and the quality, reliability, and consistency of a QSA Company s work provides confidence that cardholder data is adequately protected. The proficiency with which a QSA Company conducts a PCI DSS Assessment can therefore have a tremendous impact on data protection and the consistent and proper application of PCI DSS measures and controls.

10 This document the QSA Qualification Requirements describes the necessary qualifications for security companies and their employees to be qualified by PCI SSC to perform PCI DSS Assessments. Terminology Capitalized terms used but not otherwise defined in this document have the meanings set forth in this Section , or in the QSA Agreement, as applicable. Term Definition Assessor-Employee A QSA Employee or Associate QSA Employee. Associate QSA Employee ( AQSA ) An individual who is employed by a QSA Company and has satisfied and continues to satisfy all QSA Requirements applicable to Associate QSA Employees.


Related search queries