I’m getting nowhere fast with support on this issue. I placed a ticket asking JodoHost to fullfill the requirement in PCI Self Assessment Questionaire version A that states:
[INDENT]If cardholder data is shared with service providers, are policies and
procedures maintained and implemented to manage service providers,
and do the policies and procedures include the following?
12.8.1 A list of service providers is maintained.
12.8.2 A written agreement that includes an acknowledgement that
the service providers are responsible for the security of
cardholder data the service providers possess.
12.8.3 There is an established process for engaging service
providers, including proper due diligence prior to engagement.
12.8.4 A program is maintained to monitor service providers’ PCI
DSS compliance status.[/INDENT]
https://www.pcisecuritystandards.org/pdfs/pci_saq_a.pdf
I’m a reseller and as such JodoHost is a provider who has access to this information.
My initial inquiry was given the following response:
[INDENT]We are seeing many PCI Compliance requests. As this amounts to lot of paperwork. Our Information Security Policy team is working on providing unifrom compliance information to customers. We will not be considering any such requests until team completed their work.
[/INDENT]
Well, yeah! I expect you are. PCI just became a REQUIREMENT for everyone.
I then asked for and ETA or confirmation that the HSphere control panel is PCI compliant.
Which gave this response:
[INDENT]There is no known ETA or if we will make our current Hsphere plans to be PCI compliant[/INDENT]
To which I can only respond, you have to be kidding me! If Jodo is not PCI compliant, we are all in BIG trouble and should cancel our plans right now.
So, can someone who actually knows something address this issue? I need to become PCI compliant. All that is standing in the way right now is a few vendors who seem to think PCI doesn’t mean them.
PCI is now a requirement for EVERYONE that accepts credit cards or stores credit card information. That would include JodoHost. So, the response, “we aren’t even sure we are going to bother becoming PCI compliant” is the same as saying, “we plan on going out of business.”
All I need to know is that JodoHost acknowledges they are responsible for the data and that they are PCI compliant with proof of compliance. What’s so hard about that? They ARE responsible for the data anyhow and they’d better be PCI compliant or we are all in trouble.
Who’da thunk this would be such a hard thing to get from a vendor the size of JodoHost?