Teleflora Point of Sales PA-DSS Implementation Guide
Encrypting over Public Networks
Addresses:
PA-DSS 12.1.b
PCI DSS 4.1
“Public Networks” Defined:
Note that, you should consider the following networks as being “public”:
• The Internet
• Any Wireless (Wi-Fi) network.
• Cellular telephone networks, such as “GSM” or “GPRS”.
• In the event that you are using a network whose security you are unsure of, you should assume that network to be “public”.
Dove POS Transactions with Public Networks:
In order to perform functions such as authorizations, settlement, and Dove, your Dove POS system does transmit cardholder information across the public internet. To protect this transmission, Dove POS uses the “https” (HTTP over SSL) protocol. To protect cardholder information, it is important that you not intentionally take measures to disable, or otherwise hinder, encryption in the Dove POS software.
Multi-Site Connectivity:
Some florists may have multiple, physical locations which all communicate to a single, Dove POS server. In such a case, it is critically important that hardware firewall devices be used at each site, and all network traffic between sites, be transmitted through a secure mechanism, such as an IPSEC VPN, or
SSL sockets.
3rd Party Software:
In the event that you use any 3rd party software which sends or receives cardholder information, to remain PCI compliant, you are responsible for ensuring that your third party software properly encrypts its cardholder traffic, again, by use of technologies such as SSL sockets or a VPN.
Dove_POS_PA-DSS_Implementation_Guide_v1.3.doc – 2011-11-11 Page 18