90 Minds Community

 View Only
Expand all | Collapse all

Sage 100 compliance with PCI DSS 3.2.1 - any documentation?

  • 1.  Sage 100 compliance with PCI DSS 3.2.1 - any documentation?

    Posted 06-22-2020 10:51
    Is there any documentation available on Sage 100 compliance with PCI DSS 3.2.1?
    My google/bing searches only show things from about 2010...

    ------------------------------
    Clark Walliser
    Senior Consultant
    Dataself Corporation
    San Jose CA
    Clark
    ------------------------------


  • 2.  RE: Sage 100 compliance with PCI DSS 3.2.1 - any documentation?

    Posted 06-22-2020 13:32
    Edited by Moira Goggin 06-22-2020 13:32
    Sage 100 credit card processors (APS, Paya, Century) would hold a PCI too. 

    You can search the PCI Security Standards organization for verification a product is compliant

    https://www.pcisecuritystandards.org/assessors_and_solutions/payment_applications?agree=true

    ------------------------------
    Moira Goggin
    Executive Director
    90 Minds, Inc.
    ------------------------------



  • 3.  RE: Sage 100 compliance with PCI DSS 3.2.1 - any documentation?

    Posted 06-22-2020 13:37

    Thanks Moira,

    That helps ��

     

    Clark

     






  • 4.  RE: Sage 100 compliance with PCI DSS 3.2.1 - any documentation?

    Posted 06-22-2020 13:46
    From memory ( perhaps faulty ) I thought Sage indicated that since they didn't retain any data subject to PCI rules that they weren't required to undergo any type of regular audit, This might be a good question for Sage City since I'm sure other larger company audit deparments may be asking this same question,

    ------------------------------
    Wayne Schulz - Schulz Consulting - 860-516-8990
    ------------------------------



  • 5.  RE: Sage 100 compliance with PCI DSS 3.2.1 - any documentation?

    Posted 06-22-2020 13:51

    Yeah, I checked Sage City. The only post I found on it was my own back on version 4.50.

    The other part I was looking for is the Sage 100 statement that credit card info is no longer stored in the ERP.

    I think that happened on the upgrade from 4.50 to Sage 100.

    I found some indirect statements referencing that, so I think that will do.

     

    Clark Walliser

    DataSelf Corp.

    cwalliser@dataself.com

    www.dataself.com

    408-641-9549

     






  • 6.  RE: Sage 100 compliance with PCI DSS 3.2.1 - any documentation?

    Posted 06-23-2020 11:04
    Clark,

    I found this on the APS site - they are pretty good at providing helpful info so even though they request an email to download it might be worthwhile.

    https://www.apspayments.com/pci-compliance

    ------------------------------
    Wayne Schulz - Schulz Consulting - 860-516-8990
    ------------------------------



  • 7.  RE: Sage 100 compliance with PCI DSS 3.2.1 - any documentation?

    Posted 06-23-2020 11:22

    Thanks Wayne,

    It's worth just another marketing email ��

     

    Clark Walliser

    DataSelf Corp.

    cwalliser@dataself.com

    www.dataself.com

    408-641-9549

     






  • 8.  RE: Sage 100 compliance with PCI DSS 3.2.1 - any documentation?

    Posted 06-24-2020 11:30

    Hi All,
    This is a request we got from a client about PCI compliance with DataSelf, which connects to Sage 100, which connects with Century Business Solutions credit card processing.

    Have any of you encountered PCI DSS compliance questions to this level? I'm not sure how to respond. I've used the logic that we only connect to the ERP and the ERP doesn't contain any credit card information, end of story. But looks like this is "the rest of the story"...

    ----------Client Request ----------
    Our Sage 100 uses Century Business Solutions to process credit cards ,(not Paya), and they are PCI compliant. Although I am required by the PCI Standards to make sure all access to the Sage server and all it's connections follow Policy and PCI-DSS compliant standards, below is a list of information I will need to verify compliance with this access we are granting to you.
    Note: You are under PCI-DSS compliance when- You have access to a Computer or System that has Credit Card processing ability.

    1. What transfer encryption is used to communicate with the Sage-Server integration?
    2. Has your system been through a penetration test (PEN Test) ? When?  Result ?
    3. What monitoring do you have to identify breaches with-in your system that could affect access to ours.
      What is your policy on informing us of a breach?
    4. Have you ever had a PCI-DSS validation Scan done on the system that accesses our credit card computer?
    5. What updates do you do to the DataSelf integration and are they automated or manually done by employees of DataSelf?
      What reporting policy do you have to notify us of any discovered vulnerabilities in the integration or one of it's updates.

     

    The PCI-DSS Vendor Question documentation outlines that even integrators that are NOT directly "Pluged-in" to the credit card processing process are considered potential breach points because they have:

    1. Access to the same network as the Credit Card processor computer
    2. Data transfer to or from the same network as the Credit Card processor computer
    3. Have Integrations on the Credit Card processor computer.
    Note: Most Integrators are not presented with this line of questioning because most "Customers" don't have a clue as what it takes to be PCI-DSS compliant. With that said, I am sorry this is a long conversation, I would love to not be having to jump through so many hoops myself. I greatly appreciate your help and patience on this matter as it is a daunting requirement in the small business world.

    ------------------------------
    Clark Walliser
    Senior Consultant
    Dataself Corporation
    San Jose CA
    Clark
    ------------------------------



  • 9.  RE: Sage 100 compliance with PCI DSS 3.2.1 - any documentation?

    Posted 06-25-2020 11:25
    Clark, Since no credit card information is held in Sage 100, there is no compliancy to testing there.  Century Business Systems would be the one to provide answers to how the credit card information is held, passed through Sage to their holding space, and other info - question #'s 1, 2, 3, and 4.​  For question #5, does DataSelf pull/hold any credit card information?  If not, there is no PCI compliancy to meet., correct?  While DataSelf does have access to pull data from Sage, does it also pull data from CBS?

    ------------------------------
    Michelle Taylor
    ERP Consulting Manager, CS3 Technology
    918-388-9772
    ------------------------------



  • 10.  RE: Sage 100 compliance with PCI DSS 3.2.1 - any documentation?

    Posted 06-25-2020 13:02
    When responding to this kind of question I like to mention looking for old copies / backups of pre-2013 MAS90 folders (which could have CC data in them).

    ------------------------------
    Kevin Moyes
    Technical Systems Analyst
    Munjal White Consulting Co.
    Toronto ON
    ------------------------------



  • 11.  RE: Sage 100 compliance with PCI DSS 3.2.1 - any documentation?

    Posted 06-25-2020 13:08

    Ooh, good insight!

    Who knows what lurks in the backup archives...

     

    Clark Walliser

    DataSelf Corp.

    cwalliser@dataself.com

    www.dataself.com

    408-641-9549