PCI DSS SAQ A Request

I’m getting nowhere fast with support on this issue. I placed a ticket asking JodoHost to fullfill the requirement in PCI Self Assessment Questionaire version A that states:

[INDENT]If cardholder data is shared with service providers, are policies and
procedures maintained and implemented to manage service providers,
and do the policies and procedures include the following?
12.8.1 A list of service providers is maintained.
12.8.2 A written agreement that includes an acknowledgement that
the service providers are responsible for the security of
cardholder data the service providers possess.
12.8.3 There is an established process for engaging service
providers, including proper due diligence prior to engagement.
12.8.4 A program is maintained to monitor service providers’ PCI
DSS compliance status.[/INDENT]
https://www.pcisecuritystandards.org/pdfs/pci_saq_a.pdf

I’m a reseller and as such JodoHost is a provider who has access to this information.

My initial inquiry was given the following response:
[INDENT]We are seeing many PCI Compliance requests. As this amounts to lot of paperwork. Our Information Security Policy team is working on providing unifrom compliance information to customers. We will not be considering any such requests until team completed their work.
[/INDENT]

Well, yeah! I expect you are. PCI just became a REQUIREMENT for everyone.

I then asked for and ETA or confirmation that the HSphere control panel is PCI compliant.

Which gave this response:

[INDENT]There is no known ETA or if we will make our current Hsphere plans to be PCI compliant[/INDENT]

To which I can only respond, you have to be kidding me! If Jodo is not PCI compliant, we are all in BIG trouble and should cancel our plans right now.

So, can someone who actually knows something address this issue? I need to become PCI compliant. All that is standing in the way right now is a few vendors who seem to think PCI doesn’t mean them.

PCI is now a requirement for EVERYONE that accepts credit cards or stores credit card information. That would include JodoHost. So, the response, “we aren’t even sure we are going to bother becoming PCI compliant” is the same as saying, “we plan on going out of business.”

All I need to know is that JodoHost acknowledges they are responsible for the data and that they are PCI compliant with proof of compliance. What’s so hard about that? They ARE responsible for the data anyhow and they’d better be PCI compliant or we are all in trouble.

Who’da thunk this would be such a hard thing to get from a vendor the size of JodoHost?

We can make our service PCI compliant but web servers and sites will not be able to be PCI compliant if you are in a shared environment without huge sacrifices.

We are working on it but basically in PCI environment there won’t be any FTP, SQL access, etc it will be VERY locked down and many of the clients have no desire for this.
Our DB itself is PCI compliant but we are working on the certifications and all, but again that won’t mean every web server under it is PCI Compliant, it just means there will be (and are already) very segmented networks and plans in the backend.

I understand about shared environment etc. All I REALLY care about right now is that the hsphere control panel payment process is secure since 1) I have no control over it and 2) I can’t run a PCI scan against it and 3) even if I could run a PCI scan against it, I couldn’t fix any problem the scan might find.

Therefore I need a statement that JodoHost realizes they are responsible for the security of the data stored by hsphere and some sort of proof that the hsphere environment is PCI compliant. This must be true since JodoHost is using it and certainly must fall under Level 1 requirements in order to accept credit cards under the same hsphere control panel that I am using.

I also realize that I’m responsible for the SSL certificate for my CP domain which means I’m responsible for the secure transmition of the data into the control panel. But since the control panel is storing the information, then whoever “owns” the control panel is responsible for the security of it’s data.

Selling my own products on a shared environment is a completely different issue which can most likely be addressed by “compensating controls” which are also in the SAQ if and when I ever need to address that issue. Right now it isn’t on my radar.

WE are working on the full answers to this, in short Hsphere itself is not PCI Compliant but we’ve already made many changes over the last months and we are but getting all the documentation and ‘certification’ in place.

As you probably know we’ve got many of the control panel services split up more than other hosts, which actually makes it easier for PCI compliance, I’d hate to have the one server wonder install, it would never come close to passing.

Can we even assert that the network hsphere is on is PCI compliant? I don’t think the software HAS to be for another year. But, the network it is on (physical box it is on and physical box the database is on) should be able to pass the security scan.

The network itself but there are servers on it that are not :smiley:

There is no open wifi, there are firewalls, etc.