Disclaimer: All information provided in these pages is meant to be helpful for a typical Sign, Print, or Graphics company. If your business model differs significantly from these typical establishments, these recommendations may not apply. In all cases, you are responsible for providing the correct answer and Cyrious assumes no direct or indirect liability with the guidance below.
Once you are logged into TrustKeeper at https://elavonpci.trustkeeper.net/, one of the steps is to set up your Compliance Questionaire. The information below is meant to help you answer those questions. Please note that the answers provided only concern Cyrious' applications. Many of the questions concern Cyrious and other applications you have and must be answered in this context.
SAQ-D Questionaire
The SAQ Questionaire is the document where you must attest that you are following all of the best practices necessary to secure the card holder information you come into contact with.
For users of Cyrious SMS or Control, Cyrious recommends you complete SAQ-D. If you never place a single credit card number into Control or SMS, and no employe ever has, ever does, or ever will then you probably qualify to use SAQ-C. This does not just apply to processing credit card information, but storing any credit card number in the system also. SAQ-C is easier to complete, but if you find that your or an employee has, does, or will put this information into Control you will end up not being in compliance.
The information below assumes you are using Questionaire D. If you are using another form, then this information does not apply to you.
Security Questions
Unfortunately, Cyrious does not know the status of your network. Our support technicians are not authorized to answer any questions on your network security. You will need to have these questions verified by someone knowledgeable about your specific network configuration. In some cases, you may need to make changes or implement additional security measures.
Section 3: Stored Data Protection
Cyrious SMS 8.9 pci and later and Cyrious Control 4.4 and later satisfy the requirements required of our software in Section 3. Stored Data Protection, but you must confirm these for all systems you use.
Cyrious does not store any magnetic track data. (Question 4)
Cyrious does not store the card-validation code. (Question 5)
Cyrious does not store the PIN. (Question 6)
Cyrious does mask the PAN except when authorized employees need access to this information. (Question 7)
Cyrious does use strong cryptography (encryption) and key management for all stored sensitive information. (Question 8)
Cyrious does not rely on disk encryption. (Question 9 & 10)
Cyrious does use cryptographic keys for encryption against disclosure and misuse. (Question 11)
Cyrious does restrict its encryption keys automatically. Once you enter your key the system uses it automatically and there is no way to retrieve it! (Question 12)
Cyrious does store keys securely for you, in the fewest locations and forms possible. (Question 13)
Though Cyrious does not require key retention, you should have a policy to change the key if the person who created it leaves the company or you believe the key is compromised. (Question 14)
Cyrious does generate strong cryptographic keys. (Question 15)
Cyrious does secure cryptographic key distribution between its applications. (Question 16)
Cyrious does secure cryptographic key storage. (Question 17)
Cyrious does change its internal security keys at least annually. (Question 18) (Note: Users not on support may be required to purchase the product update to obtain the changed keys.)
Though Cyrious does not require key retention, you should have a policy to change the key if the person who created it leaves the company or you believe the key is compromised. (Question 19)
Cyrious does split the knowledge and control of the cryptographic keys by having some of those keys controlled by Cyrious and some controlled by you. (Question 20)
Cyrious' approach does automatically prevent substitution of cryptographic keys since different parties have different pieces. (Question 21)
Cyrious' approach does not require a key custodian since the key is only asked for once and can never be retrieved. (Question 22)
Section 4. Transmitted Data Protection
Cyrious SMS 8.9 pci and later and Cyrious Control 4.4 and later satisfy the requirements required of our software in Section 4. Transmitted Data Protection, but you must confirm these for all systems you use.
Cyrious does transmit all sensitive cardholder data using appropriate encryption on all networks. (Question 1)
If you are using a wireless network, you must attest to its security settings. (Question 2)
Cyrious does prevent the sending of any sensitive information through end-user messaging technologies when used correctly, but you need to make sure you have written and enforced policies that also prevent this. (Question 3)
Section 6. Application and System Security
Cyrious SMS 8.9 pci and later and Cyrious Control 4.4 and later satisfy the requirements required of our software in Section 6. Application and System Security, but you must confirm these for all systems you use.
This requirement specifies that you must maintain the latest version of Cyrious Control or Cyrious SMS. (Questions 1,2)
Cyrious is not considered a custom application for purposes of PCI certification. (Question 5, 6)
Cyrious does not connect to a web system directly if you are not running WebView or Production Terminal. For these, you need to ensure that proper web security techniques are deployed.
Section 7. Access Restrictions
Cyrious SMS 8.9 pci and later and Cyrious Control 4.4 and later satisfy the requirements required of our software in Section 7. Access Restrictions, but you must confirm these for all systems you use.
Both SMS and Control have security policies that can restrict this keep this information from individuals. This section requires you to attest that you are using these security features and that you have certain policies in place to control this access.
Section 8. Account Security
Cyrious Control 4.4 and later satisfy the requirements required of our software in Section 8. Account Security, but you must confirm these for all systems you use.
This section requires you to set up your system and policies so that only users accounts are established and tracked.
Cyrious does allow you to create unique logins per employee. Your policy must ensure each employee uses their own account. (Question 1)
Cyrious does use password authentication. (Question 2)
Cyrious does not use two-factor authentication. (Question 3)
Cyrious does secure passwords at all times using strong cryptography. (Question 4)
Cyrious does control access to the user setup areas. (Question 5)
Cyrious does require you to reenter your password before resetting yours or another password. (Question 6)
Cyrious does require you to enter a unique password for a new user and can force that to password to be reset on first login. You must ensure your policy specifies the password must be changed on first login. (Question 7)
Cyrious does automatically disable access for any employee that is no longer active. You must ensure your policy sets the employee inactive in Cyrious upon termination. (Question 8)
You must ensure your policy is to remove the Cyrious login when they are no longer using the system. (Question 9)
Cyrious does not provide access for vendors. (Question 10)
You must not use any shared logins. Your policy must ensure each employee uses their own account. (Question 12)
Cyrious does force users to change their passwords every 90 days. (Question 13)
Cyrious does require a minimum of seven characters in the password. (Question 14)
Cyrious does require passwords to contain both a number and letter. (Question 15)
Cyrious does track the last 4 passwords used and prevent reuse of any of these passwords. (Question 16)
Cyrious does automatically lock out a user for 30 minutes after 6 invalid attempts. (Question 17, 18)
Cyrious Control does have an option to automatically lock the screen and require a password to resume. You need to make sure this option is turned on for all users with a time of 15 minutes or less. Cyrious SMS users must make sure they enable the Windows screen saver to lock the screen after 15 minutes or less of inactivity and then require a password to log back in. (Question 19)
Cyrious does automatically require authentication for any database access. (Question 20)
Section 10. Access Tracking
Cyrious SMS 8.9 pci and later and Cyrious Control 4.4 and later satisfy the requirements required of our software in Section 8. Account Security, but you must confirm these for all systems you use.
These answers are only as the question relates to Cyrious. Each of these questions is broader than just Cyrious and you must answer them in the context of the entire business operations.
Cyrious does log activity for users throughout the system, particularly any access to sensitive information. This information provide audit trails for all users, administrative or otherwise, that can be used to recreate access to sensitive information. (Question 1, 2, 3, 4, 5, 6)
Cyrious does maintain system audit logs. These questions also apply to Windows logging. (Question 7, 8)
Cyrious does log the following information: User ID, Date and Time, Result, Computer Name,and Type of Event. These questions also apply to Windows logging. (Question 9-14)
Cyrious does require all computers running Cyrious to be synchronized in time . (Question 15)
Cyrious does not allow any alteration of the audit trails. Cyrious does store an encrypted checksum to detect any external alteration in the data. (Question 16, 18)
Cyrious does have provisions to restrict access to view any activities (audit logs) to users with a need for that information. It is up to you to establish a policy that implements this plan. (Question 17)
Audit trails are backed up when user data is backed up. You should make sure your policy conforms to PCI requirements for backup. (Question 19)
Cyrious
does not use “external facing” technologies unless you are using WebView or Production Terminal. If you are using these, you must ensure that the database logs are not on an external facing server or are copied onto a
LAN server. (Question 20)
Cyrious does detect external changes in the log files and will notify the user of any such detections. (Question 21)
Cyrious does maintain log files indefinitely. (Question 23)
Confirmation
If you are running Cyrious SMS 8.9pci and Control 4.4, those versions are PCI certified to not store sensitive authentication data after authorization.
Next Step