Having issues accessing the video above? Watch the video here.
Using Your QSA as a Resource Year Round
In this webinar, SecurityMetrics QSA Winn Oakey covers:
- Achieving compliance with your QSA
- Time saving tips for your next audit
- Best practices to prepare for your audit
- One year audit plan
This webinar was hosted on November 4th, 2015.
Using Your QSA as a Resource Year Round Transcript
We wanna welcome everyone out to the webinar this morning. Thank you for joining us.
We're gonna go ahead and get started here now that it's noon eastern.
The webinar today is gonna be called using your QSA as a resource year round, and one of our QSA's here at Security Metrics, Wynn Oke, will be the presenter.
A little bit about Security Metrics before we get started.
We've been helping organizations comply with mandates, avoid security breaches, and prevent data theft since two thousand.
Our company is really one of the few companies that can do all things PCI, PCI audits, PADSS audits, approved scanning vendor, forensic investigations, presenter today, Winoki.
He has five years as a QSA or ISA, internal scanning or security assessor.
He has twenty five years of IT experience and five years of audit and compliance specific experience.
He holds the certifications QSA and CISSP and should be able to bring a lot of real world knowledge with his years of IT experiences as well as PCI compliance knowledge to today's content.
Just a little housekeeping item, because we do get this asked this often. We will send the recording of this webinar and the slide deck, in the next few days. So watch for that in your email. It'll be sent to anyone who registered for the webinar to that same email address that you registered with. Also, if you have any questions throughout the webinar, please chat them in using your GoToWebinar control panel. At the end, we'll try to have some time to address as many as we can. And if we don't get to your question, we'll reach out to you on an individual basis to be able to answer your question or get you to the right place.
So with that said, we're gonna go ahead and get into today's content. I'm gonna turn the time over to Win Oke to go on to today's agenda.
Great. Thank you, Colin. It's good to be with you today, spend a little bit of time talking about PCI and, what your QSA can do to help you reach your compliance.
We've broken the agenda down into four categories, achieving compliance with your QSA, time saving tips for your next audit, best practices to prepare for your audit, and a one year audit plan.
So let's dive right in. In in, working on your, your compliance, there's a few different hindrances you can have and difficulties.
One of the ones that I experienced over my career is oftentimes, there's a disconnect between the IT security personnel and management and, getting work done in the the PCI realm. I've been involved with some companies that, had a good understanding of PCI, what was required of them. They had a good list of things that they needed to do, but they had a disconnect in communicating that up to management and getting management's involvement and and buy off on it. Management obviously controls the budgetary, of the company and getting things approved.
Oftentimes, there's company culture and company procedures that get in the way of of compliance. And management needs to be the driver in making sure that those, concerns are met and things are moving along. So as you're going through your PCI, declaration and process, management needs to be involved and and the driver behind that. If you are breached, it could be very catastrophic to your company.
Nobody wants to be, the next Sony or the next Target, and, and have breaches.
According to the National Cybersecurity Alliance, one in five small businesses fall victim to cybercrime each year. And of those, some sixty percent go out of business.
So breach can be very, detrimental to a company. We want to, make sure that your companies are secure, and that's what the the goal behind PCI is, is the security of your company.
PCI, as I mentioned, is a top down approach. It has to be driven by management.
As an ISA, I've been on both sides of this, the table. I've been the person that's being audited, and I've been the person that's going in and doing the audits.
And, oftentimes, that disconnect between management is is a real problem in getting things approved and getting things done.
You need to know what's required of you, what changes need to happen, and why. Management's gonna ask the the tough questions, and they and they rightfully should. They're gonna look at it from a budgeting standpoint. What happens if I don't make these changes?
What happens if, we are hacked? Are there penalties and and what happens to the company? They're gonna be looking at it from a standpoint of, are there different ways to get things done?
And are there, different tools that we need to use? And does it have to be done the way that you're recommending?
Also, we need to look at and say, what are other companies doing?
How are they, solving these same, needs? And also, what do the experts say? As a QSA and as a security company, SecurityMetrics is uniquely positioned to be able to answer all these thing all these questions, as as Colin mentioned in the introduction.
We need to know, and be able to present a good business case to management why we need to do these things. And, ultimately, the as I mentioned earlier, the security is the ultimate goal here. So, management, will and should be involved in the whole process.
Anytime your environment changes, you should be talking to your QSA and letting them know that the changes are happening.
Use us as a, as an expert as I mentioned earlier. Your environment you are the expert in your environment.
You know your environment better than anybody.
And PCI, declaration is ultimately coming from you as a QSA.
We can assist in that process.
But we don't know your environment as well as you do. You have the insights into how your your environment is laid out. You need to understand the scoping of your environment.
You need to have the appropriate documentation in place and, train your employees on their security needs.
I was involved with one company that, was putting in a new data center. They had a new data center, that they were rolling out. And in that process, they were bringing in some new tech talent technology, new systems, new security systems, and they were pretty excited about this new new environment. Here was an opportunity that they could, bury all their old sins and and do things, the right way from the very beginning.
And, when we come on-site to work with them, we, started going through their systems and their scoping and realized that a lot of the scoping had changed due to bringing the new systems in, getting trying to get them to work. They had taken and and taken some of the security mechanisms out trying to get systems to work.
Their environment was different enough, and I don't think they totally understood the environment how the credit card data moved through their environment.
Documentation was not up to date. They didn't have the appropriate documentation, like they did in their own data center. They hadn't gone through those that process of developing that documentation.
And also with the new technology, the employees had been trained on the new environment.
So, when they're starting to do, this new environment, if you step back and think about, okay, how could this work differently? What could they have done differently?
If a lot of these questions had been asked early in the process in the development and early in the implementation stage, they could have saved a lot of heartache. If you can imagine that, how hard it is to go to management and say, well, this last the money we spent on this new technology and new environment, we have to add to it for some additional security parameters, borders, and tools, and we have to spend a lot more time in the documentation phase. And all that was not in the project, documentation. So, you gotta go back to management and ask for more money, more time, for PCI and security needs.
You need to understand your scope. Now scoping is not a scoping is not a requirement of PCI. You don't have to use scoping, but it's a tool and a resource to you to drastically reduce the amount of work needed, the number of systems that are in, need PCI assessment done on them. So you need to understand your scope and what you're if you're using scoping, what that what that does for you. You also may need to take into account for the new PCI rules. PCI is a living document, and it's changing, over time.
Just recently, we've had changes as we've moved from PCI two point o to three point o to three point one. And all those changes bring new requirements and new things you need to do to meet PCI compliance.
Some of the examples are the changes in SSL and TLS that have been introduced over the last year, year and a half. So those changes continue to happen and will continue to happen. So you need to understand what changes those have on your scoping and reassess your scoping on a continual basis.
One of the biggest problems we see is when organizations think they're PCI compliant, but they're not.
We've worked with companies as we go in and they haven't, done their own assessments and understand what's required of them. So when we go in and do an audit, we discover a lot of things that need to be fixed.
If we're discovering a lot of things, during the audit process, that drastically increases the amount of time it takes to do an audit audit and to finish on time. Usually, when somebody's doing an audit and we're on-site, it's generally because there's a looming date ahead of them. They have a date that's coming up that they need to either declare their own PCI compliance or get a, a rock set out to report on compliance.
And that date is looming, and we're there on-site. If we're doing the discovery and finding out all these things need to be fixed, oftentimes, those dates are not met, and the person can't declare their PCI compliance.
And we have to continue to work on getting things fixed before we can issue a, a report on compliance.
If the time has gone too long, oftentimes, we have to come back on-site and do a second assessment, because there's too much time that's lapped between the original on-site assessment. So, those can be hard to explain to management why that needs to be done, and you can avoid that by working with your QSA and getting things fixed on a timely manner.
As a QSA and as a security, security metrics, we're we wanna be, your tool and resource to help you reach your compliance.
We have a a vast knowledge of the common issues and what people face as they're, working on their PCI compliance.
You need to understand we have we understand the PCI requirements. We can help you understand them as well. And we can offer best practices, things that you need to do to, make it easier. And we'll go through some of those here in a minute.
Working with your QSA, we can, create an ongoing relationship. We can work with you throughout the year.
One of the things you need to do is keep your documentation up to date.
A lot of the things that are need to be done on PCI have a calendar time to them, how often they have to be done. And all that documentation has to be kept up to date. And as you gather that documentation, you can send that to your QSA.
And as we're beginning a audit process or if we're doing some consulting, we'll go to that documentation and make sure that we have a good understanding of your environment and and your documentation, and we can help you, through the year and especially when when changes occur to your environment and changes occur to PCI and and they introduce new requirements.
Some of the common questions, to ask your QSA are, what are the new changes that are coming out, and what do I need to do with, uniquely with my environment?
When do I have to have the new changes implemented?
And how does it affect my environment? Will it change my scoping and and my systems?
So let's get into a little bit about the time saving.
You know, all of us have have the same amount of time in a day.
And you're busy, and we all have different things on our plate and things we have to address.
But, and PCI can be daunting, and there's a lot of things that we need to do. So we wanna talk a little bit about not finding more time, but maximizing the time that you have.
So what what can we do with at Security Metrics to help you?
If you're new to PCI, and you've not done a declaration, and you're just coming into PCI, PCI can be a big, big animal, big beast. And we can help you break it down into manageable pieces.
We can help you find the low hanging fruit, what you need to do first.
There may be items that you can do one activity, and it can fill ten different PCI requirements.
What do you need to do first? We can help you build a prioritized approach in addressing your PCI compliance.
We can help you build a process.
We have sample documentation and worksheets and tools to help you manage your PCI compliance.
If you've not been through a gap analysis, that's a great tool for those that are new to PCI.
That's where we come in and go through your systems, and we do a complete audit, and we build a report that is very detailed and lets you know where you're out of compliance, what it would take to get in compliance, and what needs to be done first, and a gap analysis is a great tool. So if you're new to PCI, talk to, your QSA about a gap analysis.
If you're already PCI compliant, how can we help? Well, PCI is a lot about keeping your documentation up to date, about finishing your requirements on time.
So talk to your QSA about new PCI requirements, the new things that are coming out, what do you need to be ready for.
And work on scoping. So I mentioned scoping is not a requirement of PCI, but you can drastically reduce the amount of time that you have to spend in doing compliance. So work on the on scoping and reducing your scope. Somebody should be put in charge of PCI. Somebody in your organization should be the go to person.
They know that they don't have to do all the activities, and they won't do all all the activities. But they should know what's happening and be the one individual to know where you stand on PCI.
That person should have the power to act and implement changes.
They should be work meeting with management on an ongoing basis and giving them reports of where they stand and what needs to change.
But, ultimately, ultimately, they have to act have the power to make and enact change in corporation.
PCI should be a declaration process, not and and and a continual process, not just a once a year activity.
I kinda liken it to a dental visit. You know, you go to the dentist, and when you're there, he does a full checkup. You may take x rays, do a cleaning, and fix any problems that you have. And when you're done, you leave the dentist office. Now you have two choices. Either you can, make sure that you get your brushing done, clean your teeth, do your flossing, and you're doing those daily activities, or you can, just wait and say, well, I'm I'm done with my dental visit till the next year or the next time I go in.
Excuse me.
If if that's the best that you take, I can I can probably promise you that, your dental visit, will probably be pretty costly and pretty painful process in the next year? So PCI is the same way. There's activities you need to be doing every day. There's activities you need to be doing every week and month and and so forth. And it should be a continual process.
As a QSA, we can help you in that process. Make sure that you're focusing on the right things.
Make sure the changes in PCI are are, how it fits into your environment. So we wanna work with you.
Many of the PCI timelines, need to be done, as I mentioned, on a on a schedule. You need to remember to have them completed.
You need to make sure that the the it's documented, what you found, and be ready to demonstrate that to an auditor and and show, what was done and when it was done and who did it.
As I mentioned earlier, you understand your environment better than anybody, and you need to understand where you what your PCI requirements are. Are you a level one merchant? Are you a level two merchant?
Or what is your level?
Are you a service provider?
Do you, do ecommerce, or are you taking credit cards in person?
Will you be filling out a self assessment questionnaire?
And if so, what which version of the questionnaire do you need to fill out? Are you are you changing? Are you reaching a a level of credit card transactions that you're gonna be changing your merchant level?
Or are the way you do is the way you do business going to change which self assessment questionnaire you fill out?
And so as you're deciding new technology and so forth, is that gonna change what you need to do for PCI?
How's your data flow through your systems? Do you understand it, and is it documented? And will changes, affect that flow? You're the expert in that and and need to understand Hopefully, it's not a time when we're doing a lot of discovery.
If that's the case, then the audit process can take a lot longer. Generally, we like to come on and do an on-site audit, and we have the report generated in forty five to sixty days after the on-site audit.
If we're doing a lot of discovery in that audit process, that time can grow dramatically.
And then we wanna be transparent. You wanna you you know your systems. You want to send all the necessary documentation to the QSA. You wanna be completely open with your QSA. Don't try to hide weaknesses or avoid things you know you're out of compliance.
Ultimately, that will extend the auditing process, and, ultimately, it's your your security that's at risk.
You know, I was working on with one vendor, and we were on-site doing a, audit. And when I was in we're asking the questions, we're right in the middle of the audit process, and there was three of us in the office. And just adjacent to the office, there was a big open area. There was five or six people out there working. And as I was sitting there, I heard the receptionist taking and repeating a credit card over the phone and writing it down.
And I stopped for a minute, and I said, well, you know, what what is she doing?
He said, well, she's just taking a credit card. Sometimes people have trouble entering credit cards on our website or they don't feel comfortable in it on the website. They just call and give it to us. We write it down, and then we have an interface where we put it into the database and then do the processing of it.
I asked, well, what does she do with that paper when she's done writing it down? And he said, well, she puts it in that stack right there, and then once in a while, there's an individual in the office that comes by and takes those and crosses them out with a magic marker and then makes a photocopy of them and and destroys the original shreds the original.
And I thought, well, there's nowhere in this documentation that that process is documented.
And, when I asked him about it, he said, well, we only do a few of those a day. We we don't do it. He says, I have many thousands of credit cards in my database, and those are the things that I'm worried about. So I'm not worried about that. So let's get back to the real audit.
And, I thought, well, that is part of the the real audit. So it doesn't do any good. You know that they had thought through the process. Because they were trying to do the right things by by marking out the credit cards and doing the copying and stuff. So they were well aware of the situation, but it was not in the documentation. It was not, something they opened openly talked about, and we only found out about it by overhearing the process happening. So wanna make sure that you're open with your QSA and that you're not trying to hide things and and sweep things under the carpet.
So what do you need to do in preparing for your audit?
As, some activities, for a pre on-site audit, you need to go through your systems. Understand your systems and your scoping. You gotta go through your evidence of compliance and make sure that you're collecting all the evidence you need to demonstrate you're doing the right things. You need to make sure you have a good understanding of your business model. How are credit cards coming into your environment?
You need to come up with questions.
Ask your your QSA any questions you have. Send them questions, and they can make sure that they have the answers to you before they come in on-site or when they come on-site.
You should talk with your QSA at least quarterly, if not more. Keep them up to date on, changes in your environment and, obviously, what changes are coming in PCI.
Some of the questions you should ask.
What changes are you seeing?
How do secure organization address those changes?
What are some of the best practices?
You know, as a security organization, we work with a lot of companies, and you can be assured that we do not give out your information.
We keep that private, and we're not going to tell other companies what you do. But we do have an opportunity to gather a lot of information.
We're not going to recommend any one type of technology, but we will give you best practices in what other companies are doing to address their security needs and their PCI needs.
So one year before coming on audit. So if you're just new to PCI and and you know that you're gonna need to, declare in a year or if you've just finished an audit. What are those things you need to be doing to, be ready for an on-site audit?
You need to understand what new requirements there are and what requirements you need to meet.
You need to understand where you where you are on those those topics.
You need to know who's responsible for PCI. Who's gonna do the declaration? Who's going to, be responsible?
And how do you capture the results and and provide evidence?
And then the reporting plans. What are your reporting plans?
Also, one year before. You need to know, as I mentioned, the changes. Some of the changes that have come out recently are the new EMV technology. It's been out for a while now.
Are you taking advantage of that? What you what changes do you need to make for the EMV?
And how do you plan to meet any new timelines or guidelines?
What are the things you need to do six months before the audit?
You should start your own internal audit. You should be going through your systems and looking for credit cards in the wild. Credit cards have a way of, finding you have you find credit cards in unique places each time. So you need to be looking through spreadsheets and accounting files and log files, and you need to be going through all your processes to determine if things are as you were last year when you when you register.
You need to work more closely with your QSA.
Pass out information and documentation so we're ready for an on-site audit.
Oftentimes, as you go through your audit, you're gonna find things that need to be fixed.
You may have to purchase tools. You may have to change systems.
That is gonna take time to go through and get approved, get developed, implemented, and put in place.
So you should be doing that months before an on-site audit.
What do you need to do three months before an audit?
Well, at that time, you should have a good understanding of your PCI requirements.
You should have reviewed all your compliance.
You should implement any changes that need that may happen that you found in your audit.
And if possible, start another internal audit.
Go through your systems again and, be ready for the on-site.
One month before an on-site. You should work with key individuals.
When we come on-site, we're going to ask to interview different personnel.
They shouldn't be surprised by it.
They should know what questions we're gonna ask, have information and documentation ready, and and they should be well aware of what's the process is gonna be.
You should be putting together your documentation and your plan. Make sure you have all your policies and procedures ready to demonstrate to the auditor.
You should make assignments, gather logs, and everything you need to do to be ready for the audit.
You should also review your systems and check-in with your QSA one month before an on-site audit.
As part of the audit process, we're gonna we built in time to go through those questions and make sure that you're ready. And so take advantage of that and and work with your QSA.
So the takeaways here, understand what requirements you have, schedule, and do all the requirements on time.
Take time to understand PCI requirements and and develop your knowledge of PCI.
Tell your QSA when your environment changes.
Document all your, your processes and procedures and send that on to your QSA.
Talk to your QSA at least quarterly.
Ultimately, security is the goal. It's important to be compliant, but it's my belief that you can be compliant and not secure. But if you're not compliant, it's pretty tough to be secure. So security is the main goal here. We wanna make sure your company is secure, and that's our goal here at Security Metrics.
K.
So I'm gonna turn things back to Colin. He's gonna work with us on getting your questions and ask questions.
So, Colin?
Okay. Thank you, everyone, for your participation today. We're gonna go ahead and look through some of the questions and see how many we can address. So just one moment.
Okay. So thank you for so many questions. We're just sorting through some of them. So one here off the bat, someone asked, when do health care covered entities, business associates, you know, people in the health care space that probably have to comply with a lot of different mandates. Do they also need to comply with PCI?
Yeah.
That has to do with PCI is obviously dealing with credit card data. If the health care entities are, storing, processing, or transmitting credit card data, they're also gonna have PCI requirements as well. And they will be handled separately. You may have your HIPAA requirements, but you'll also have PCI requirements.
And that is up to the assessor. That's your relationship with the the bank that you're taking credit cards with. They'll determine whether you need PCI requirements and what PCI requirements you have, what level of merchant you are, and etcetera. So that's a relationship between you and your acquirer.
Perfect.
And how do you protect PCI scope systems or in scope systems from non PCI systems? You know, there's a lot of defined set controls for PCI systems or in scope systems, but what do you recommend as far as, you know, protecting your in scope systems from from non PCI systems?
So as I mentioned in the presentation, scoping is one of those things. It's not a mandate from PCI. You don't have to do it. But as I mentioned, it's a it's a good tool and resource you have to control it. And how you control that, there's not a a set recipe. There's not set things you need to do.
But, obviously, those boundaries need to be protected through some type of security device. That can be a firewall. That can be a managed switch.
That can be, different systems.
The important thing is to understand where those boundaries are and make sure that your security system, is set up to configure so that you can have a clear delineation between in scope and out of scope. And PCI is getting a little more some of the changes in PCI as the most recent, used to talk about just transmit process or store credit card data. Now it's, some systems that can influence that. So that boundary gets a little, less defined, and you need to understand where the boundaries are and make sure that you have the appropriate security systems in place. But there's not a set which ones you have to use.
Awesome. Thank you. So, you know, someone else asked and it very applicable to this presentation. What are some of the key processes that must be documented during the PCI audit?
As you go through the PCI documentation, there's a lot of things that say you need to do certain things.
Some of them that come right to mind right off the bat is you need to be looking at, alerting, from your security systems, your IDS, your IPS on a a daily basis.
And you need to be deleting user accounts every ninety days and document that. So your user accounts that that, have access to your systems need to be, any of them that are are deleted need to be, handled in a timely manner.
You need to be having your pen test, your vulnerability scanning. Your vulnerability scanning internal and external need to be done on a quarterly basis. Your pen test needs to be done on an annual basis.
And there's a number of other things that need to be done on a calendar. So as you go through the PCI requirements, those are pretty spelled out.
But oftentimes, that's where companies fall down, and they don't stay up to date on doing those things on a timely matter. And then also being able to demonstrate here doing those things.
Great. Thank you. So we've had a lot of a lot of the similar questions, so we're gonna tackle a few of those. Hopefully, they answer, you know, everyone that asked similar questions.
So first off, for those who joined a little late, we will be sending out the recording of this webinar as well as the slide deck in the next few days. So be watching for that in your email. It'll just be sent to all registrants with the email address they registered with. So, we've gotten a few questions about, you know, who is my QSA?
How do I know who my QSA is? Is it the person that performed last year's audit?
So, Wen, if you can just kind of talk about, you know, what the process is of working with your QSA and what questions you can ask to know who your resources at the firm and and even if you need a QSA or not.
Right.
Your QSA, is not a set person or individual. And and it may be. Some some companies, like, get a relationship with their QSA, and they wanna keep that same QSA.
But when you work with Security Metrics, we will we will let you know who your QSA is assigned to you. If you some corporations want to change and and get a different view on it. And so that option is available to you as well. But we'll let you know who the QSA is gonna be, and you can work directly with the QSA, and, they'll be your contact with the company. But, it's kind of on a case to case basis.
We we treat you as a, as as a customer of Security Metrics. Your account, information is kept private.
But if someone needs to get to it and and your QSA is reassigned, they'll have access to your doc your documentation and be up to speed and be able to assist you, when you need.
Great. And not not all, companies need a QSA. Is that right, Wynn? Depending on their PCI requirements?
Correct.
Depending on your level, what level of the, you are what level of the merchant you are, PCI some levels can self assess.
You get to a level two merchant, you can still self assess, but you have to have somebody that's trained and and registered with the council to be able to do an internal audit. And those are called ISAs. That's I've spent some some of my time as as an ISA.
But level one merchants, will require a third party and a QSA to be involved. So, yeah, that depends on what level merchant you are, and that is decide between you and your merchant and your acquirer. Your acquirer will let you know what level of merchant you are.
Great. So another really good question kinda based around today's title is what type of discussions would you have with a QSA quarterly? You mentioned, you know, discussing or being in contact with your QSA quarterly. What kind of discussions would you have or questions would you address?
As you as your environment changes, that's one of the things we find when we come on-site. Oftentimes, we'll come on-site, and there'll be changes in your environment that really you didn't think about changing your PCI scope and and your environment. So as those change, you should be letting your QSA know what changes are coming. And then as I mentioned, all the different changes in PCI, What new requirements do they have?
What do you what does that mean to you? So you should be having those discussions with your QSA. And and, possibly, they may have some insight into changes that are coming. So, they may know what's gonna happen in the next quarter, and that can have an impact on how you deploy your systems.
And so having that relationship with your QSA can save you a lot of time and money.
Great. So one one person has asked, do you need to meet all PCI requirements and sub requirements, or can you be compliant with ninety five percent compliancy rate?
You need to meet all PCI requirements. It's it's, all or nothing.
So when you report, if there are deficiencies, you have to spell those out, and and you're marked as noncompliant.
And you can have a remediation plan. And then what happens with that is up to the acquirer. The acquirer decides what happens if if you're out of compliance, but it's, hundred percent. You need to be a hundred percent compliant.
Great.
And so if someone was interested in becoming an internal security assessor, an ISA for, you know, a level two organization, where would they go to find some guidance, a checklist, or information about becoming or conducting an internal audit?
Go to the council. You can go to the PCISSSC website.
On there, they have a section that talks about, compliance. They have a section on ISA. It describes what is involved.
It's, to become an ISA, you'll need to take a test. There's a class that you need to go to, but that is all spelled out on the on the website. So go to the, PCI d SSC council's website, and there's a section in there that talks about the ISA program.
Great. Going back to, you know, being compliant, what someone has asked, if you're breached, if you experience a breach, does that mean that you were noncompliant?
No. That does not.
If you're breached, number one, if you're say you're a level four merchant and you're breached, you need to report that breach, and that breach will automatically make you a level one merchant.
But that does not mean that you are you were or are out of compliance.
The, there can be fines if you're you were found to be out of compliance. And, generally, when there's a breach, there'll be an investigation, and they'll look into your systems and stuff. So that's where I I mentioned that, you know, you shouldn't be hiding things, and you should be upfront with your QSA. Because if that is the case and then you find that there was a lot of stuff that was was known about or systems that weren't reported, there can be fines.
Great. And you've mentioned a few different times, you know, levels of merchants, level fours, level two. So how did how did merchants determine which level they are?
That depends on what kind of merchant you are. There's there's service providers and there's, regular merchants. And but the level your level is determined on the number of transactions you do, generally. And so depending on how many credit cards you take of a card brand, be it Visa, Mastercard, and so forth, your merchant will you'll work with your acquirer, and they will tell you what level of merchant you are based on how many card transactions you do annually.
Okay. Great. And many of the new with some of the new SAQs and some of the new requirements, penetration to have a third party penetration test?
A lot of the internal penetration test, can be done, with your corporation as long as the person is trained and qualified to be able to do that penetration test.
Okay. Great. So we did have a few other questions. A lot of our questions, as it often is, is a little more specific to your environment and is hard to address without having a little more information.
So at this point, we're gonna wrap up the q and a. All of you who asked questions that we didn't address, we will have someone reach out to you and address those, get to know your environment better and be able to give you, you know, a little better answer, and probably a little more satisfactory. And even those who we probably did address questions, we'll reach out and make sure that you don't have anything, you know, that you're still confused about with that topic. And we wanna thank Wyn for the presentation, and we especially wanna thank all of you for attending this morning and giving some of your time.
Once again, watch in your inbox for the recording and the slide deck. It should be getting to you in the next few days for sure by the end of this week. So thank you again, and have a wonderful rest of the day. Thank you.
