Bryce
10/10/2020, 12:36 PMwbermudo
10/10/2020, 10:07 PMSteve Goldberg
10/12/2020, 9:57 AMMitch
10/12/2020, 5:44 PMIf a session has been idle for
more than 15 minutes, require the user
to re-authenticate to re-activate the
terminal or session.
However, after taking a further look, it does not appear that 8.1.8 is required for customer facing accounts given the following text from that document:
Note: These requirements are applicable for all accounts, including point-of-sale accounts, with administrative capabilities and all accounts used
to view or access cardholder data or to access systems with cardholder data. This includes accounts used by vendors and other third parties (for
example, for support or maintenance).
However, Requirements 8.1.1, 8.2, 8.5, 8.2.3 through 8.2.5, and 8.1.6 through 8.1.8 are not intended to apply to user accounts within a point-ofsale payment application that only have access to one card number at a time in order to facilitate a single transaction (such as cashier accounts).
Is it possible that we could extend the user session without breaking PCI compliance, or is there a different section of the document that I should be looking at?Steve Goldberg
10/12/2020, 7:54 PMMitch
10/12/2020, 8:08 PMSteve Goldberg
10/12/2020, 8:11 PMSteve Goldberg
10/12/2020, 8:12 PMMitch
10/12/2020, 9:23 PMNote: These requirements are applicable for all accounts, including point-of-sale accounts, with administrative capabilities and all accounts used
to view or access cardholder data or to access systems with cardholder data. This includes accounts used by vendors and other third parties (for
example, for support or maintenance). These requirements do not apply to accounts used by consumers (e.g., cardholders).
However, Requirements 8.1.1, 8.2, 8.5, 8.2.3 through 8.2.5, and 8.1.6 through 8.1.8 are not intended to apply to user accounts within a point-ofsale payment application that only have access to one card number at a time in order to facilitate a single transaction (such as cashier accounts).
I think the statement *"These requirements do not apply to accounts used by consumers (e.g., cardholders).*" is specifically what we are looking at when making this argument. We are hoping to be able to utilize a longer session time with that text in mind. Given this updated text and document, would you agree with our conclusion that we can provide a user session longer than 30 minutes, or do you think we are missing something here? I appreciate you taking the time to work through this with me!Mark
10/14/2020, 7:31 PMSteve Goldberg
10/15/2020, 10:15 AMSteve Goldberg
10/15/2020, 12:06 PMSteve Goldberg
10/15/2020, 12:08 PMMark
10/15/2020, 12:34 PMMitch
10/15/2020, 12:39 PM