background image

P2PE  Instruction Manual for PCI P2PE  v2.0 
© 2021 

Elavon Financial Services DAC

 

PIM Page  16

 

3.2 Guidance for selecting appropriate locations for deployed devices 

Devi ces must be deployed in appropriate locations where there is no ri sk of these being accessed by unauthorised 
us ers. Plan where to put your POI devices and how to keep them secure, you must perform checks on devices at regular 
i nterva l s  to ens ure thes e ha ve not been ta mpered wi th. 

Items  to be Cons i dered: 

 

Moni tor and control public access to POI devices so that only the applicable part of the device (such as the 
PIN Pa d) i s  a va i l a bl e to the cus tomer to compl ete the pa yment 

 

Pl a ce devices in a reas so they ca n be monitored by a uthorised personal to ensure that the regular checks can 
be performed a s  needed 

 

Loca te devices i n environments that reducing risk of unauthorised a ccess with considerations for ensuring 
there is adequate lighting, appropriate access paths to the devices to prevent unauthorised personnel from 
ta mperi ng wi th the devi ce  a nd there i s  vi s i bl e s ecuri ty mea s ures  s uch a s  CCTV 

 

Your devices are designed to only be used in attended environment and must never be used in an Unattended 
envi ronment 

 

Devi ces  mus t be moni tored a t a l l  ti mes  

 

Pos i tion the devi ce s o there i s  no method of recordi ng or vi ewi ng the cus tomer PIN bei ng entered 

 

Porta ble (Move/5000) or mobile devices  should be assigned to a member of staff who will be responsible for 
the device during their allocated time. This person will be responsible for ensuring the POI device(s) are kept 
s a fe whilst i n their custody and are not l eft where they ca n be ta mpered wi th by una uthori s ed us ers  

 

Devi ces must be placed i n a well ventilated a re on a flat surface and shoul d  be a wa y from di rect s unl i ght 

 

Where feasible, use locking devices to secure your POI devices i n place as well as using, separately purchased, 
pol es  to mount the cus tomer fa ci ng PIN pa d.  

o

 

Ha vi ng a  pol e  wi l l  a l l ow the cus tomer to s wi vel  the PIN pa d to prevent ri s k of s pyi ng  

o

 

PIN  Pa d pol es ca n be purchased from va ri ous provi ders,  please ensure a ny pol e purchased is  
compa ti bl e wi th your devi ce  

o

 

El a von customers have the option to purchase consumable related i tems from UKPR and can place 
orders vi a phone or email, UKPR details below: 

UK/IRE Sales: 

[email protected]

 or +44 (0) 1698 843866 

POLAND Sa les : 

[email protected]

 or +48 123953173 

 

Devi ces not in use should be stored in a secure l ocation with res tri cted a cces s  to a uthori s ed us ers  onl y 

For more information, please refer to, 

PCI Best Practise Guide V3.0

 found on th

www.pcisecuritystandards.org

 website

  

 

3.3 Guidance for physically securing deployed devices to prevent unauthorized removal or 

substitution 

You s hould physically s ecure your POI devices to prevent unauthorised removal or substitution whilst devices are i n 
us e.  

For countertop devices (Desk/5000 a nd La ne/3000); 

 

Mount a nd secure the POI devices a nd cables with l ocking stands, cable tra ys, and other securing mechanisms 
s uch as space poles.  

For the Move/5000 (with 3G/WiFi/BT) devices, which cannot be physically s ecured, you must consider: 

Содержание Secured P2PE

Страница 1: ...nOffice The liability of themember islimited United Kingdom branch registered inEngland andWalesunder the number BR022122 Elavon Financial ServicesDAC trading asElavon Merchant Services isauthorised a...

Страница 2: ...1 1 07 05 2019 Stephen McLaughlin Updated with Issue Date and Version History as per PCI Council AQM Request 1 12 19 08 2019 Stephen McLaughlin Updated with Changes to facilitate access to new and eme...

Страница 3: ...I DSS compliance and should be aware of their applicable PCI DSS requirements Merchants should contact their acquirer or payment brands to determine their PCI DSS validation requirements 2 Approved PO...

Страница 4: ...text account data must be reviewed according to Domain 2 and are included in the P2PE solutionlisting These applications may also be optionally included in the PCI P2PE list of Validated P2PE Applicat...

Страница 5: ...549v01 xx LAN30EA 820547v01 xx 820548v02 xx 820549v01 xx N N Ingenico Tax Free EN4 18 01a Ingenico Desk 5000 Move 5000 Lane 3000 DES50BB 820547v01 xx 820548v02 xx 820549v01 xx MOV50BB 820547v01 xx 820...

Страница 6: ...2 xx 820549v01 xx MOV50BB 820547v01 xx 820548v02 xx 820549v01 xx LAN30EA 820547v01 xx 820548v02 xx 820549v01 xx N N Ingenico EN9 17 01b Ingenico Desk 5000 Move 5000 Lane 3000 DES50BB 820547v01 xx 8205...

Страница 7: ...B 820547v01 xx 820548v02 xx 820549v01 xx LAN30EA 820547v01 xx 820548v02 xx 820549v01 xx N N Ingenico EV2 18 01a Ingenico Desk 5000 Move 5000 Lane 3000 DES50BB 820547v01 xx 820548v02 xx 820549v01 xx MO...

Страница 8: ...l PIM and any changes to your P2PE solution due to changes of P2PE requirements POI Inventory You must define suitable POI inventorycontrols andmonitoring procedures that fit withyour businessfor trac...

Страница 9: ...es Annual POI Inspection Full POI device inventories must be completed at least once per annum Duringthis process you must investigate all the POI devices checking for anyevidence of unauthorisedvaria...

Страница 10: ...06 03 16 option 1 Sample Inventory Table We have providedyou a Sample Inventory Table Appendix A whichcovers the minimumrequirement that you could use for monitoring purposes if you do not chose to cr...

Страница 11: ...of Unique Identifier This is the serial number ofeachdevice deployedfor SecuredP2PE You can find the serial number of the device in a number of ways o Serial number can be found on the underside of t...

Страница 12: ...P2PE Instruction Manual for PCI P2PE v2 0 2021 Elavon Financial Services DAC PIM Page 12 Lane 3000 Serial Numbers Move 5000 Desk 5000 Lane 3000...

Страница 13: ...ch mechanisms to collectPCIpayment card data could mean thatmore PCIDSS requirements are now applicable for the merchant Only P2PE approved capture mechanisms as designated on PCI s listofValidated P2...

Страница 14: ...y set up by our chosen fulfilment house before being delivered to your chosen location When the devices have been delivered Elavon s technical helpdeskwillcontact youwithin24 hours ofdeliveryand will...

Страница 15: ...sk 5000 Move 5000 Lane 3000 Note Only PCI approved POI devices listed in the PIM are allowed for use in the P2PE solution for account data capture Physically secure POI devicesin your possession inclu...

Страница 16: ...he device during their allocatedtime This personwill be responsible for ensuringthe POI device s are kept safe whilst intheir custody andare not left where they can be tampered with by unauthorised us...

Страница 17: ...nge for POI devicesto be dispatchedto your chosenlocation s ina secured manner byour chosen fulfilment house see below Elavonwill alsoarrange for the collectionof any POI devices that needto be return...

Страница 18: ...s and POI device model s Details ofthe tamper evident packagingandwhat to check toensure the device hasnot beentamperedwith during transit The email will come from the below addresses where applicabl...

Страница 19: ...es not show anysigns oftampering suchas unexpected cabling exposedpanels Check for broken security seals and cracks around the device as well as inspecting for any other type of damage or tampering Wh...

Страница 20: ...any signs of tampering If the serial numbers of the devices do not match that the ones listed in the deployment email or if you identify any signs of tampering donot acceptthe device andinformthe cour...

Страница 21: ...d with the installation of your new device to enable you to start taking payments Kind regards Please note some of the elements of the email will verifydepending onthe delivery method of your P2PE dev...

Страница 22: ...uctions for physically inspecting POI devicesand preventing skimming including instructionsand contact detailsfor reporting any suspiciousactivity Additional guidancefor skimmingprevention on POI devi...

Страница 23: ...ne to measure against when the POI devices are weighed again Post Deployment Once deployed you must perform regular checks onall devicesas per below Perform visual inspections weeklyin high traffic ar...

Страница 24: ...erial number in our emailandthe serialnumber on the box If the device is displayingthe full card numbers on the customer receipts Please alsoconsider anyunauthorisedaccess to the POI devices including...

Страница 25: ...Contact Elavon on the numbers below to report the issue Elavonwillworkwith youto reviewthe issue and where needed will arrange for a replacement device STOP USING THE DEVICE IMMEDIATELY DISCONNECT THE...

Страница 26: ...r packaging whichhas tamper evident safeguards please be aware that the outer box will have alreadybeenopened byour secured engineer and the device will be placedwithina sealedTamper Evident Envelope...

Страница 27: ...r of the device beingreplacedas part ofyour Inventoryprocesses Courier Delivery If you identifya faultydevice please report this to the helpdeskonthe number listedbelow If the packaginghas been tamper...

Страница 28: ...site installation If the box or sealhas been tamperedwithor anyof the numbers donotmatch immediatelyinform Elavon on a IRL 1850202120 Option1 b UK 0345 850 0195 Option1 c POL 22 306 03 16 Option1 If...

Страница 29: ...attendsthe site please ensure youconfirm their identityvia their appropriate Identificationbadge before allowingthem access to your POI devices If you are not certainof the identityof the engineer pl...

Страница 30: ...edP2PE agreement please liaise withyour Account Manager Please note that in this instance your devices willneedto be returned to Elavon which we will arrange collection You will also need to work with...

Страница 31: ...P2PE Instruction Manual for PCI P2PE v2 0 2021 Elavon Financial Services DAC PIM Page 31 8 Additional Solution Provider Information Move 5000 Left View Front View Right View Move 5000 on Base...

Страница 32: ...P2PE Instruction Manual for PCI P2PE v2 0 2021 Elavon Financial Services DAC PIM Page 32...

Страница 33: ...P2PE Instruction Manual for PCI P2PE v2 0 2021 Elavon Financial Services DAC PIM Page 33 MBASE 004 IELV Base with Cover Base without Cover...

Страница 34: ...P2PE Instruction Manual for PCI P2PE v2 0 2021 Elavon Financial Services DAC PIM Page 34 Desk 5000 Left View Front View RightView...

Страница 35: ...P2PE Instruction Manual for PCI P2PE v2 0 2021 Elavon Financial Services DAC PIM Page 35 Rear View Casing Closed Rear View Casing Open...

Страница 36: ...P2PE Instruction Manual for PCI P2PE v2 0 2021 Elavon Financial Services DAC PIM Page 36 Lane 3000 Left View Front View Left View...

Страница 37: ...P2PE Instruction Manual for PCI P2PE v2 0 2021 Elavon Financial Services DAC PIM Page 37...

Страница 38: ...ual for PCI P2PE v2 0 2021 Elavon Financial Services DAC PIM Page 38 9 Appendix A Sample Inventory Table Device vendor Device model name s and number Device Location Device Status Serial Number or oth...

Отзывы: