Schellman Adds PCI Point-to-Point Encryption (P2PE) Assessment Services
Via MarketWired
TAMPA, FL— May 21, 2015- Schellman & Company, Inc., a leading provider of compliance services, is now a Point to Point Encryption (P2PE) QSA company. The new service builds upon Schellman’s deep security expertise making it the only firm in the world that can offer a comprehensive suite of PCI , SOC 2, FedRAMP, and ISO 27001 assessments.
The PCI P2PE standard allows solution providers to offer merchants a secure payment acceptance channel. The P2PE solutions utilize secure and validated cryptographic hardware devices along with rigorous security practices to encrypt data from the point of interaction (POI), usually a card swipe or read, until the data reaches the its secure decryption environment. As these solutions have the potential to keep unencrypted credit card numbers out of merchant and service provider environment, it may allow for reducing scope to the physical and operational security controls of those encryption devices.
A PCI P2PE assessment includes a thorough assessment of the device management practices for the POIs and other cryptographic devices, the use of hardware security modules (HSMs) for key management and decryption, and the security controls for key management, key injection, and security operations for the decryption environment. A validated solution demonstrates to merchants that the solution provider has implemented effective controls and that the merchant may reduce their scope with confidence in the defenses to prevent device tampering or substitution or attacks against the Solution Provider itself. The PCI Security Standards Council (SSC) only recognizes validated P2PE solutions for scope reduction.
Jacob Ansari, Schellman’s PA-DSS and P2PE practice lead:
“PCI P2PE represents the most stringent set of controls while offering the potential for significant scope reduction for merchants... Schellman is pleased to be able to complement our existing PCI DSS, PA-DSS, and other security and compliance offerings with P2PE validation.”
Inquiries for P2PE services can be made with Schellman at 1-866-254-0000, or by submitting a request for a professional consultation at www.schellmanco.com/contact-us
About Schellman
Schellman is a leading provider of attestation and compliance services. We are the only company in the world that is a CPA firm, a globally licensed PCI Qualified Security Assessor, an ISO Certification Body, HITRUST CSF Assessor, a FedRAMP 3PAO, and most recently, an APEC Accountability Agent. Renowned for expertise tempered by practical experience, Schellman's professionals provide superior client service balanced by steadfast independence. Our approach builds successful, long-term relationships and allows our clients to achieve multiple compliance objectives through a single third-party assessor.