PCI DSS v4.0 æ€èšŒããã¥ã¡ã³ãã®äž»ãªå€æŽç¹ã¯ïŒ
PCI DSS v4.0.1æ€èšŒããã¥ã¡ã³ãã®å€æŽç¹
ãªã³ã©ã€ã³æ±ºæžçµ±åã察é¢æ±ºæžçµ±åãªã©ã®Adyenã®æå·åãœãªã¥ãŒã·ã§ã³ããå©çšã®å Žåãææ°ããŒãžã§ã³ã®PCI DSSã«ãããäž»ãªå€æŽç¹ã¯ä»¥äžã®ãšããã§ãããããã®èŠä»¶ã¯ãã¯ã¬ãžããã«ãŒã決æžãåãå ¥ããPCI DSSããŒãžã§ã³4.0.1ã§è©äŸ¡ããããŒãã£ã³ãã察象ãšããŠããŸãã
SAQ A
- æ°ãããã¹ã¯ãŒããšæ¡åŒµãããå€èŠçŽ èªèšŒïŒMFAïŒèŠä»¶ïŒèŠä»¶8ïŒïŒã¢ã«ãŠã³ãããŒã¿ã®äŸµå®³ãé²ãããããã¹ãŠã®ã·ã¹ãã ã³ã³ããŒãã³ããžã®å€èŠçŽ èªèšŒã®å°å ¥ã匷ãæšå¥šãããŸãããã ããMFAãå®è£ ãããŠãããããã¹ã¯ãŒã/ãã¹ãã¬ãŒãºãå¯äžã®ãµã€ã³ã€ã³æ¹æ³ãšããŠäœ¿çšãããŠããå Žåããã¹ãã¬ãŒãº/ãã¹ãã¬ãŒãºã¯å°ãªããšã90æ¥ããšã«å€æŽããå¿ èŠããããŸãããŸããããŒãã£ã³ãã¯ããããã®ã¢ã«ãŠã³ãã®ã»ãã¥ãªãã£èšå®ã«åºã¥ããŠãã±ãŒã¹ãã€ã±ãŒã¹ã§ã·ã¹ãã ã³ã³ããŒãã³ããžã®ã¢ã¯ã»ã¹ãèš±å¯ããã«ã¹ã¿ã ã¢ãããŒããå®è£ ããããšãã§ããŸãã
- ã»ãã¥ãªãã£æèïŒèŠä»¶6ïŒïŒããŒãã£ã³ãã«ã¯ãåœéããã³å°åã®ã³ã³ãã¥ãŒã¿ç·æ¥å¯Ÿå¿ããŒã ïŒCERTïŒããã®æ°ããã»ãã¥ãªãã£è匱æ§ã«é¢ããèŠåãæ å ±ãåžžã«å ¥æããããšãæ±ããããŸãã
- ååæããšã®å€éšè匱æ§ã¹ãã£ã³ïŒèŠä»¶11ïŒïŒEã³ããŒã¹ã«ãã決æžãåãå ¥ããããŒãã£ã³ãã¯ãPCI SSCãæ¿èªããã¹ãã£ãã³ã°ãã³ããŒã«ããå€éšè匱æ§ã¹ãã£ãã³ã°ãå°ãªããšã3ãæã«1åãããã³æ±ºæžç°å¢ã«é倧ãªå€æŽããã£ãå Žåã¯ãã®åŸã«å®æœããããããªã·ãŒããã³æé ãææžåããå¿ èŠããããŸããåœåã¯12ãæ以å ã«4åã®ã¹ãã£ã³ã«åæ Œããããšã¯æ±ããããŸãããããã®åŸã®æ°å¹Žéã¯ãå°ãªããšã3ãæããšã®ã¹ãã£ã³ãžã®åæ Œã矩åä»ããããŠããŸãããã®èŠä»¶ã¯çŽã¡ã«çºå¹ããŸãã
SAQ BIPïŒå¯Ÿé¢æ±ºæžïŒIPPïŒïŒ
-
IPPããã€ã¹ã®ã»ãã¥ãªãã£ã¢ããããŒãïŒèŠä»¶6ïŒïŒã€ã³ã¹ããŒã«ããããã€ã¹ã¢ããããŒããããŒãã£ã³ãã管çããŠããå Žåãç¹å®ãããè匱æ§ã®æ·±å»åºŠãšåœ±é¿åºŠã«åŸã£ãŠãã»ãã¥ãªãã£ãããã管çãã決æžç«¯æ«ã«ã€ã³ã¹ããŒã«ããããšãæ±ããããŸãã
SAQ B-IPïŒIPPããã€ã¹äžã®MOTOïŒ
- IPPããã€ã¹ã®ã»ãã¥ãªãã£ã¢ããããŒãïŒèŠä»¶6ïŒïŒã€ã³ã¹ããŒã«ããããã€ã¹ã¢ããããŒããããŒãã£ã³ãã管çããŠããå Žåãç¹å®ãããè匱æ§ã®æ·±å»åºŠãšåœ±é¿åºŠã«åŸã£ãŠãã»ãã¥ãªãã£ãããã管çãã決æžç«¯æ«ã«ã€ã³ã¹ããŒã«ããããšãæ±ããããŸãã
- ã¢ã¯ã»ã¹å¶åŸ¡ïŒèŠä»¶7ïŒïŒãã®èŠä»¶ã¯ãåŸæ¥å¡ã®è·ååé¡ãšæ©èœã«ãã£ãŠãMOTO決æžãããŒã®ã«ãŒãææè ããŒã¿ãžã®äžæçãªã¢ã¯ã»ã¹ãå¶éããŠããŸããéèŠãªã®ã¯ãå人ãèªåã®è·åãéè¡ããããã«å¿ èŠãªå Žåã«ã®ã¿ããŠãŒã¶ãŒæš©éãå²ãåœãŠãããšã§ãã
SAQ C-VTïŒããŒãã£ã«ã¿ãŒããã«äžã®MOTOïŒ
-
ã¢ã¯ã»ã¹å¶åŸ¡ïŒèŠä»¶7ïŒïŒIPPããã€ã¹äžã®MOTOãšåæ§ã«ãä»®æ³ç«¯æ«ãä»ããŠå®äºããMOTOã®ãã®èŠä»¶ã¯ãåŸæ¥å¡ã®è·ååé¡ãšæ©èœã«ãã£ãŠãMOTO決æžãããŒã®ã«ãŒãææè ããŒã¿ãžã®äžæçãªã¢ã¯ã»ã¹ãå¶éããŠããŸããéèŠãªã®ã¯ãå人ãèªåã®è·åãéè¡ããããã«å¿ èŠãªå Žåã«ã®ã¿ããŠãŒã¶ãŒæš©éãå²ãåœãŠãããšã§ãã
å æ¥ä»ã®å€æŽ
以äžã®èŠä»¶ã¯ã2025幎3æ31æ¥ä»¥éã«è¡ãããè©äŸ¡ã®ç¯å²å ã§ãã
SAQ A: æ°ãããã¹ã¯ãŒãèŠä»¶
ããŒãžã§ã³ 3.2.1ã®æå°èŠä»¶ã§ãã7æåãšã¯ç°ãªããã·ã¹ãã ã³ã³ããŒãã³ãã«æ°åãšè±åã®äž¡æ¹ãå«ã12æåïŒã·ã¹ãã ã12æåã«å¯Ÿå¿ããŠããªãå Žåã¯8æå以äžïŒãå¿ èŠãšãªããŸãã
SAQ D: æ¯æãããŒãžã®ã³ã³ãã³ãã®æŽåæ§ãç£èŠããïŒèŠä»¶ 6.4.3 ããã³ 11.6.1ïŒ:
äžéè æ»æã®ãªã¹ã¯ã軜æžããããã«ãããŒãã£ã³ãã¯ãããŒãã£ã³ãã®ãŠã§ããµã€ã/ãŠã§ãã¢ããªã±ãŒã·ã§ã³ã§å®è¡ãããTPSPã®ã€ã³ã©ã€ã³ãã¬ãŒã /iFrameãå«ããŠã§ããå«ãã決æžããŒãžã®HTTPããããŒãšã¹ã¯ãªããã®æŽåæ§ãç£èŠ/確èªããããã®æé ïŒå€æŽ/æ¹ããæ€åºã¡ã«ããºã /ãã¯ãããžãŒãªã©ïŒãæŽåããå¿ èŠããããŸãã
èŠä»¶ 6.4.3 ããã³ 11.6.1 㯠SAQ A ã®å¯Ÿè±¡ç¯å²ããé€å€ãããŸãããæ°ãã SAQ A ã®é©æ Œåºæº ã確èªãããèªèº«ãé©æ Œã§ãããã確èªãã ãããææ°ã® PCI DSS èŠä»¶ã«ã€ããŠã®è©³çŽ°ã¯ãAdyen ã® PCI DSSã³ã³ãã©ã€ã¢ã³ã¹ã¬ã€ããã芧ãã ããã
ãã®èšäºã¯åœ¹ã«ç«ã¡ãŸãããïŒ
PCI DSS ã³ã³ãã©ã€ã¢ã³ã¹ã¬ã€ã
䟿å©ãªçšèªéãšãã¹ãŠã®PCI DSSã«ãŒã«ãAdyen Docã§èŠã€ããŠãã ããã
ã³ã³ãã©ã€ã¢ã³ã¹ã¬ã€ããèŠã