Do you have a question about the Toast PCI and is the answer not in the manual?
Brand | Toast |
---|---|
Model | PCI |
Category | Touch terminals |
Language | English |
Explains the Payment Card Industry Data Security Standard (PCI DSS) and its scope.
Explains the Payment Application Data Security Standard (PA-DSS).
Maps PCI DSS v3.2.1 requirements to Toast's role and merchant actions.
Prohibits storing sensitive authentication data post-authorization.
Mandates strong cryptography for data transmission over networks.
Installing security patches to protect against vulnerabilities.
Restricting access based on job role and need-to-know.
Establishing access control systems based on need-to-know.
Policies for user identification management for all system components.
Multi-factor authentication for remote network access.
Using facility entry controls for physical access to cardholder data environment.
Protecting devices from tampering and substitution.
Periodic inspection of devices for tampering or substitution.
Implementing audit trails for user access to system components.
Reviewing logs to identify anomalies and suspicious activity.
Running network vulnerability scans quarterly and after changes.
Performing quarterly external vulnerability scans via ASV.
Performing annual external penetration testing.
Implementing an incident response plan.