Skip to main content

Notifications

Announcements

No record found.

Microsoft Dynamics RMS (Archived)

Manager PC in PCI scope - mitigating risk

Posted on by Microsoft Employee

Each of our stores has a manager's PC, where they run SO Manager to settle batches, check inventory, perform transfers etc. But they also use many other functions on those PCs outside of RMS, such as checking email, managing employee time cards, even surfing the web. Since the PC is used to settle credit card batches, it should be considered within the scope of PCI-DSS. However, does that mean that all of the systems they connect to should also be considered in scope, such as our email server? Obviously there is some risk here as they are able to surf the web and handle credit card batches on the same PC. 

We are trying to find a way to isolate the manager functions to a separate PC or thin client to eliminate this risk. We have gone down a few paths - running Manager from the register, connecting remotely to a register to run manager, or connecting to a store server. But they all come up a bit short and a bit difficult to implement. For example. our registers do not have mice or keyboards attached - they do all PoS functions with the on screen keyboard and taskpad, which would be cumbersome or impossible for some manager functions. It would also take a register out of sales for the duration of the manager functions, on busy days this could affect sales. If they connect to the server, then we are giving end users control over our server, which could result in a server going down and putting all registers in offline mode. Do you have any suggestions? 

*This post is locked for comments

  • Suggested answer
    Community Member Profile Picture
    Community Member Microsoft Employee on at
    RE: Manager PC in PCI scope - mitigating risk

    Hello Jesse,

    Thank you for your question.

    I would recommend reviewing the PCI Implementation guide available here:

    go.microsoft.com/fwlink

    Please let me know if you have any additional questions.

    Thank you,

    Scott Wardzinski

    Microsoft Dynamics RMS & POS Support Engineer

  • Community Member Profile Picture
    Community Member Microsoft Employee on at
    RE: Manager PC in PCI scope - mitigating risk

    We are using the built-in Tsys processing. We have looked at Shift4 recently which moves all of the scope to network and pinpad hardware. However, we have a pretty big RMS environment, with around 350 registers across 60+ stores. Our top brass gets concerned about budget when we talk about rolling out that many pinpads, software licenses, etc. It's been a tough fight.

  • Community Member Profile Picture
    Community Member Microsoft Employee on at
    RE: Manager PC in PCI scope - mitigating risk

    What processing method are you using? There are methods where your entire POS system can pretty much be taken out of scope, leaving only the network in scope.

  • Suggested answer
    Jeff @ Check Point Software Profile Picture
    Jeff @ Check Point ... 13,380 on at
    RE: Manager PC in PCI scope - mitigating risk

    Officially, any machine connected to the same network (wired or wireless) as a POS machine needs to be PCI compliant.

    Have you tried the on-screen keyboard built into Windows?

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

December Spotlight Star - Muhammad Affan

Congratulations to a top community star!

Top 10 leaders for November!

Congratulations to our November super stars!

Tips for Writing Effective Suggested Answers

Best practices for providing successful forum answers ✍️

Leaderboard

#1
André Arnaud de Calavon Profile Picture

André Arnaud de Cal... 291,269 Super User 2024 Season 2

#2
Martin Dráb Profile Picture

Martin Dráb 230,198 Most Valuable Professional

#3
nmaenpaa Profile Picture

nmaenpaa 101,156

Leaderboard

Featured topics

Product updates

Dynamics 365 release plans