Extreme POS ExtremePOS® Payment Payment System Implementation guide

Below you will find brief information for Payment System ExtremePOS® Payment. Payment System ExtremePOS® Payment designed to work on an internal network, and has no need to be in a DMZ for any component of it, but should there be a web server on the network, it must be in a DMZ as per PCI-DSS 1.3.4.

PDF
Document
Payment System ExtremePOS® Payment Implementation Guide | Manualzz

Advertisement

Advertisement

/

Advertisement

Key features

  • PCI-DSS compliant

  • Secure payment processing

  • AES 256-bit encryption

  • Data purging after expiration

  • Strong password policies

  • Detailed logging and auditing

  • Key management features

  • No remote access by default

  • Secure updates and installations

  • User friendly interface

Frequently asked questions

ExtremePOS® Payment encrypts all PAN data using AES with a 256-bit key. The key itself is then encrypted using another key, referred to as the KEK. PAN data is not accessible outside of ExtremePOS® Payment.

Passwords must be at least seven characters, contain at least both letters and numbers, and cannot be reused within the last four passwords used. Users must not reuse any of the last four passwords used.

Encryption keys must be changed at least annually, and additionally may be changed at any time, for instance if there is concern that there is a breach.

The audit logs can be viewed by an administrative level user from within ExtremePOS® Payment, in the ‘audit’ section of the reports. This information is logged in the audit table about each event that is logged: The action, the date and time, the user name, the workstation the action was taken from, and the windows user name of the account making the action.

The document has a section called 'Configuring Windows for PCI-DSS Compliance' which outlines the necessary steps for password policies, account lockout policy, Windows logging, Windows restore points, and screensaver configuration.

If a merchant wants to use a remote access tool, they are required to use security features that include two-factor authentication, such as requiring both a username and password and a token, per PCI-DSS requirement 8.3.

Preparing document for printing…
0%