Due Diligence and Ongoing Monitoring

 View Only
  • 1.  PCI Vendors

    This message was posted by a user wishing to remain anonymous
    Posted 02-09-2022 05:08 PM
    This message was posted by a user wishing to remain anonymous

    Good afternoon all, 

    What due diligence do you obtain from a new potential PCI solution? 

    We are getting real kick back on our request.  We have a potential provider who is not willing to provide any control documentation for our review, not even their SOC or AOC until we sign the merchant agreement.  

    I would appreciate insight into how you all review new PCI solutions or how you have handled a similar situation.


  • 2.  RE: PCI Vendors

    Posted 02-10-2022 10:08 AM

    As someone without any skin in the game, this would be a flag for me.

     

    Due diligence is something that we need to do prior to signing a contract. It's policy, and it's reasonable. They are in essence asking you to sign on the dotted line before you know anything about them.

     

    That said, I understand their desire to protect their information. That's what an NDA would be for, to allow you to do a legitimate review of controls and processes so that you can make a good decision.

     

    It does surprise me how often companies make this rather standard request into such a roadblock.

     

    Thanks,

          Dave

     

    David Howe, CCUFC

    Chief Information Officer

     

     

     






  • 3.  RE: PCI Vendors

    This message was posted by a user wishing to remain anonymous
    Posted 02-10-2022 01:03 PM
    This message was posted by a user wishing to remain anonymous

    My two cents as a TPRM manager who has been preparing audit evidence for PCI DSS controls 12.8.1-12.8.5 for quite some time:

    I agree with Dave that the NDA is meant to ensure privacy of information between both parties. So there shouldn't be a holdup in their ability to provide this type of information...it's standard practice across our industry. 

    Depending on the type of service provider and how they handle PCI data (access, store, process, transmit, or can affect the security of it) the PCI DSS AOC is generally the optimal evidence material to acquire, but typically for merchants you'll expect them to provide a PCI DSS SAQ A, PCI DSS SAQ-E or PCI DSS SAQ-D. If none of these then have them sign a Data Protection Agreement as an addendum to the service agreement. Your Legal counsel should be involved in the development of that material. 

    Last ditch effort I'd recommend is checking the VISA global registry of validated PCI providers, and using that as evidence if no other means help you achieve your desired outcome here: https://www.visa.com/splisting/searchGrsp.do


  • 4.  RE: PCI Vendors

    This message was posted by a user wishing to remain anonymous
    Posted 02-10-2022 01:03 PM
    This message was posted by a user wishing to remain anonymous

    Thank you Dave, 

    Yes, we have an NDA in place.  It is certainly worth pushing back yet again.  

    Does anyone have any similar situations with a PCI payment processing vendor not willing to comply with your initial or ongoing assessment requirements?


  • 5.  RE: PCI Vendors

    Posted 02-10-2022 01:03 PM

    We require, even prospective vendors to update both our questionnaire and send their SOC2 and AOC.  The only pushback I have seen is if they want an NDA signed before giving us their whole docs.  I would consider it concerning if they will not give anything until the agreement is signed as a whole.

     

    Jamie Sumter

    IT Risk Management Lead

    Clarios

    www.clarios.com

     

    Upcoming Out of Office: NA

      

    Questions on IT Risk Intake Form, IT Policies, IT SOX Matrix, Reporting a Security Incident, IT Risk Assessment Management?  Visit our Cybersecurity site