Solved

FSM - PCI Compliance

  • 16 November 2022
  • 2 replies
  • 73 views

Userlevel 5
Badge +14

Hi,

I have been through the community and can see posts relating to IFS Apps, but nothing much around PCI Compliance and FSM.

I am being asked internally if FSM (current version is 5.7u11, and FSM6) is compliant with PCI v4.0 and if any assessments have been completed. If there has, is there a certificate that can be shared. If not then is that in the timeline to be completed?

As a company we do a small amount of transactions via the FSM UI which calls a direct integration api, and we store the response into database. Our internal security team are specifically looking at that transaction with regards to the scope of PCI.

 

Ady

icon

Best answer by Jon Reid 3 December 2022, 16:49

View original

2 replies

Userlevel 6
Badge +17

Hi Adrian - we don't certify FSM for this as we merely act as a gateway to the payment provider and we we no longer store the information in FSM except for the transaction confirmation received from the provider.  All information transmitted is encrypted.  Many of the requirements are not under our control as they are specific to the customer's installation such as on-premise firewalls, etc.

Userlevel 5
Badge +14

@Jon Reid thank you.

Reply