5 things to consider when engaging with a third-party service provider

11

Upload: brightline-cpas-and-associates

Post on 03-Aug-2015

322 views

Category:

Business


2 download

TRANSCRIPT

Page 1: 5 Things to Consider When Engaging With a Third-Party Service Provider
Page 2: 5 Things to Consider When Engaging With a Third-Party Service Provider

What is a TPSP? An organization that has the responsibility to protect card data and may leverage a TPSP to support them in card-processing activities

or to secure card data

Page 3: 5 Things to Consider When Engaging With a Third-Party Service Provider

Industries relevant to cardholder data

• Payment gateways • Payment processors • Colocation services • Cloud infrastructure • Managed security

services

• Encryption or tokenization services

• Application hosting • Managed

firewall/router service providers

Page 4: 5 Things to Consider When Engaging With a Third-Party Service Provider

What to consider when engaging with a TPSP:

Page 5: 5 Things to Consider When Engaging With a Third-Party Service Provider

Set Expectations

Define, agree upon, and document expectations, at least annually and after a

change in services.

Page 6: 5 Things to Consider When Engaging With a Third-Party Service Provider

Gain Transparency Scope

Take reasonable steps to determine that the scope of what is provided by a service

provider is appropriate and aligned.

Page 7: 5 Things to Consider When Engaging With a Third-Party Service Provider

Establish Communications

Consider establishing a communications schedule.

Page 8: 5 Things to Consider When Engaging With a Third-Party Service Provider

Request Evidence

To verify that appropriate procedures were followed and controls deployed to

support changes.

Page 9: 5 Things to Consider When Engaging With a Third-Party Service Provider

Obtain Information about PCI DSS Compliance

Validation documentation should be provided at least annually as evidence of

PCI DSS compliance.

Page 10: 5 Things to Consider When Engaging With a Third-Party Service Provider

PCI DSS compliance is a continuous process, not just

a point in time exercise