APPENDIX B--REFERENCES AND 16. SPSP Society of Payment Security Professionals. ADDITIONAL RESOURCES CPISM. CPISM/. Accessed April, 2010. REFERENCES 17. Magtek. Brochures--Magnetic Stripe Card Stan- 1. PCI Security Standards Council. Payment Applica- dards. tion Data Security Standard (PA-DSS) V1.2. https:// public/99800004-1.03.pdf. Accessed April, 2010. pci_pa_dss.shtml. Accessed April, 2010. ADDITIONAL RESOURCES 2. Visa. How It Works. new_acceptance/how_it_works.html. Accessed March, American Express (card brand) website: https://www209. 2010. 3. PCI Compliance Guide. PCI FAQS--What Is the American Express. American Express Data Security Definition of Merchant. http://www.pcicompliance Operating Policy for U.S. Merchants. https://www Accessed April, 2010. 4. PCI Compliance Guide. PCI FAQS--What Consti- en_US/DSOP_Merchant_US.pdf. tutes a Service Provider. http://www.pcicompliance American Express Data Security Home. Data Security for Accessed April, 2010. Merchants. 5. DED Limited. Magnetic Stripe Card Standards.http:// merchant/singlevoice/dsw/FrontServlet?request_type= / magnetic-stripe-card-standards /. dsw&pg_nm=home&ln=en&frm=US. Accessed April, 2010. ARINC. ARINC's PCI-DSS Adventure. Presented at ACI 6. PCI Security Standards Council. Navigating PCI DSS, BITCOM, Austin, Tex., Oct., 2009. http://www. Understanding the Intent of Requirements. https:// Barich, Inc. The Future of Airport Information Tech- dss_v1-1.pdf. Accessed March, 2010. nology. Presented at ACI-NA Airport Board Mem- 7. PCI Security Standards Council. Glossary, Abbre- bers and Commissioners Conference, Chicago, Ill., viations and Acronyms. https://www.pcisecurity April, 2009. 8-TheFutureOfAirportInformationTech-FBarich.pdf. Accessed March, 2010. Coalfire Systems. PCI Compliance: "Just the Facts." Pre- 8. Visa. Merchants. sented at ACI-NA Conference, Seattle, Wash., April, management/cisp_merchants.html. Accessed April, 2009. 2010. a8dd06be8dca0163245f9c 9. MasterCard. Merchant Levels Defined. http://www. The Compliance Authority website: http://www.thecom html. Accessed April, 2010. CompliancesForum website: http://www.compliances 10. NDB Advisory. Important PCI Compliance Informa- tion for Merchants. checklist merchants.php#bookmark-3. Accessed April, 2010. Discover (card brand) website: 11. Visa. Service Providers. merchants/risk_management/cisp_service_providers. Discover Information Security and Compliance. http:// html. Accessed April, 2010. 12. MasterCard. Service Provider Levels Defined. http:// Element website: pci-dss/compliance-level/. provider_levels.html. Accessed April, 2010. GFI. PCI DSS Made Easy. 13. NDB Advisory. Important PCI Compliance Informa- papers/pci-dss-made-easy.pdf. tion for Service Providers. http://www.pciassessment. Whitepapers: org/service-providers.php. Accessed April, 2010. pci-dss-made-easy.pdf. 14. PCI Security Standards Council. Security Audit Proce- IATA Payment Card Industry Data Security Standards. dures, Version 1.1. https://www.pcisecuritystandards. org/pdfs/pci_audit_procedures_v1-1.pdf. Accessed dss.htm. April, 2010. IT Compliance Institute (ITCi). IT Audit Checklist: Pay- 15. PCI Security Standards Council. Qualified Security ment Card Industry (PCI). http://download.101com. Assessors (QSAs)/Approved Scanning Vendors (ASVs). com/pub/itci/Files/ITCi_ITACL-PCI_0321-Lb.pdf. JCB Data Security Program. shtml. Accessed April, 2010. english/jdsp/index.html. 27