<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Sample PCI-DSS Policy Part 3: Handling of Cardholder Data</title>
	<atom:link href="http://www.pcidssguru.com/policy/handling-cardholder-data/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pcidssguru.com/policy/handling-cardholder-data/</link>
	<description>Practical Implementation Guidance on the Payment Card Industry Data Security Standard</description>
	<lastBuildDate>Tue, 31 Jan 2012 16:19:53 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Warren</title>
		<link>http://www.pcidssguru.com/policy/handling-cardholder-data/comment-page-1/#comment-1492</link>
		<dc:creator>Warren</dc:creator>
		<pubDate>Mon, 01 Nov 2010 14:46:17 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=68#comment-1492</guid>
		<description>Hello.  I manage a records management facility.  We store data and back up media for a call center.  They are requesting our compliance with PCI DSS, however there are only a few sections that deal with offsite storage.  The self assessments don&#039;t seem to be helping because we only store paper or back ups and not any of that information is on a computer or database of any kind.  

I guess my question is how does one get &quot;official&quot; compliance for the applicable portions of the document?
Thanks a bunch.</description>
		<content:encoded><![CDATA[<p>Hello.  I manage a records management facility.  We store data and back up media for a call center.  They are requesting our compliance with PCI DSS, however there are only a few sections that deal with offsite storage.  The self assessments don&#8217;t seem to be helping because we only store paper or back ups and not any of that information is on a computer or database of any kind.  </p>
<p>I guess my question is how does one get &#8220;official&#8221; compliance for the applicable portions of the document?<br />
Thanks a bunch.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Lisa</title>
		<link>http://www.pcidssguru.com/policy/handling-cardholder-data/comment-page-1/#comment-1470</link>
		<dc:creator>Lisa</dc:creator>
		<pubDate>Tue, 26 Oct 2010 16:30:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=68#comment-1470</guid>
		<description>I have more of a question than a comment.  
Does our shredding vendor need to be PCI COMPLIANT OR PCI CERTIFIED? 
Thanks all.</description>
		<content:encoded><![CDATA[<p>I have more of a question than a comment.<br />
Does our shredding vendor need to be PCI COMPLIANT OR PCI CERTIFIED?<br />
Thanks all.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tippy</title>
		<link>http://www.pcidssguru.com/policy/handling-cardholder-data/comment-page-1/#comment-1368</link>
		<dc:creator>Tippy</dc:creator>
		<pubDate>Sun, 03 Oct 2010 09:06:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=68#comment-1368</guid>
		<description>Chris: If your company only deals with truncated cardholder data, then it should be noted that truncated cardholder data is not classified as cardholder data in the first place. This if proven as you say is truncated data.</description>
		<content:encoded><![CDATA[<p>Chris: If your company only deals with truncated cardholder data, then it should be noted that truncated cardholder data is not classified as cardholder data in the first place. This if proven as you say is truncated data.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Emily</title>
		<link>http://www.pcidssguru.com/policy/handling-cardholder-data/comment-page-1/#comment-1324</link>
		<dc:creator>Emily</dc:creator>
		<pubDate>Thu, 16 Sep 2010 16:30:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=68#comment-1324</guid>
		<description>One of you bullet points reads: &quot;coverage for all storage of cardholder data, including database servers, mainframes, transfer directories, and bulk data copy directories used to transfer data between servers, and directories used to&quot;.  What is the end to this sentence?  &quot;Used to&quot; what?

Thanks!</description>
		<content:encoded><![CDATA[<p>One of you bullet points reads: &#8220;coverage for all storage of cardholder data, including database servers, mainframes, transfer directories, and bulk data copy directories used to transfer data between servers, and directories used to&#8221;.  What is the end to this sentence?  &#8220;Used to&#8221; what?</p>
<p>Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jewel</title>
		<link>http://www.pcidssguru.com/policy/handling-cardholder-data/comment-page-1/#comment-983</link>
		<dc:creator>Jewel</dc:creator>
		<pubDate>Tue, 16 Mar 2010 23:08:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=68#comment-983</guid>
		<description>@Chris: Page six of the DSS says &quot;PCI DSS, however, does not apply if PANs are not stored, processed, or transmitted.&quot;  Whenever &quot;cardholder data&quot; is mentioned in the standard it is only as defined on that page.</description>
		<content:encoded><![CDATA[<p>@Chris: Page six of the DSS says &#8220;PCI DSS, however, does not apply if PANs are not stored, processed, or transmitted.&#8221;  Whenever &#8220;cardholder data&#8221; is mentioned in the standard it is only as defined on that page.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://www.pcidssguru.com/policy/handling-cardholder-data/comment-page-1/#comment-815</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Tue, 15 Dec 2009 17:54:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.pcidssguru.com/?p=68#comment-815</guid>
		<description>My company only has truncated cardholder data to begin with. Does this still count as cardholder data that must be destroyed from all our old backups and servers? It&#039;s useless without the full number anyway, so I don&#039;t understand why it would be necessary, but from my interpretation of the requirement, that is what they are asking.</description>
		<content:encoded><![CDATA[<p>My company only has truncated cardholder data to begin with. Does this still count as cardholder data that must be destroyed from all our old backups and servers? It&#8217;s useless without the full number anyway, so I don&#8217;t understand why it would be necessary, but from my interpretation of the requirement, that is what they are asking.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

