<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.hostek.com/index.php?action=history&amp;feed=atom&amp;title=Visa_E-commerce_Security_Checklist_Questionaire</id>
		<title>Visa E-commerce Security Checklist Questionaire - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.hostek.com/index.php?action=history&amp;feed=atom&amp;title=Visa_E-commerce_Security_Checklist_Questionaire"/>
		<link rel="alternate" type="text/html" href="https://wiki.hostek.com/index.php?title=Visa_E-commerce_Security_Checklist_Questionaire&amp;action=history"/>
		<updated>2026-04-15T03:07:49Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.24.2</generator>

	<entry>
		<id>https://wiki.hostek.com/index.php?title=Visa_E-commerce_Security_Checklist_Questionaire&amp;diff=2774&amp;oldid=prev</id>
		<title>Briana at 20:06, 27 January 2016</title>
		<link rel="alternate" type="text/html" href="https://wiki.hostek.com/index.php?title=Visa_E-commerce_Security_Checklist_Questionaire&amp;diff=2774&amp;oldid=prev"/>
				<updated>2016-01-27T20:06:32Z</updated>
		
		<summary type="html">&lt;p&gt;&lt;/p&gt;
&lt;table class='diff diff-contentalign-left'&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;col class='diff-marker' /&gt;
				&lt;col class='diff-content' /&gt;
				&lt;tr style='vertical-align: top;'&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan='2' style=&quot;background-color: white; color:black; text-align: center;&quot;&gt;Revision as of 20:06, 27 January 2016&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 92:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 92:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; Q: How are backups done?&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; Q: How are backups done?&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; A: Nightly.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; A: &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;We utilize CDP Backup from R1Soft to perform &lt;/ins&gt;Nightly &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;Backups&lt;/ins&gt;. &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt; Nightly backups are processed for Shared and Reseller accounts.&amp;#160; Virtual Servers (VPS) are recommended to add the Nightly Backup option.&amp;#160; &lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; Q: What kind of logging is in place?&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; Q: What kind of logging is in place?&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 120:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 120:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; Q: What is the data retention policy?&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; Q: What is the data retention policy?&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;−&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; A: &lt;del class=&quot;diffchange diffchange-inline&quot;&gt;Backups &lt;/del&gt;are retained up to 14 days on shared database servers.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;color:black; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; A: &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;For Shared and Reseller accounts, backups &lt;/ins&gt;are retained up to 14 days on shared &lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;web and &lt;/ins&gt;database servers&lt;ins class=&quot;diffchange diffchange-inline&quot;&gt;.&amp;#160; For VPS customers choosing the Nightly Backup option, backups can be retained between 5 and 30 days depending on the option selected&lt;/ins&gt;.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; Q: How is the database backed-up?&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt;&amp;#160;&lt;/td&gt;&lt;td style=&quot;background-color: #f9f9f9; color: #333333; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #e6e6e6; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&amp;#160; Q: How is the database backed-up?&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Briana</name></author>	</entry>

	<entry>
		<id>https://wiki.hostek.com/index.php?title=Visa_E-commerce_Security_Checklist_Questionaire&amp;diff=2047&amp;oldid=prev</id>
		<title>Briana: Created page with &quot;==Visa E-commerce Security Checklist Questionaire==  ===Physical Security===  Q: Where is the server physically located?  A: St. Louis, MO, USA (in most cases)   Q: Who has ac...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.hostek.com/index.php?title=Visa_E-commerce_Security_Checklist_Questionaire&amp;diff=2047&amp;oldid=prev"/>
				<updated>2014-04-05T15:47:05Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;==Visa E-commerce Security Checklist Questionaire==  ===Physical Security===  Q: Where is the server physically located?  A: St. Louis, MO, USA (in most cases)   Q: Who has ac...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==Visa E-commerce Security Checklist Questionaire==&lt;br /&gt;
&lt;br /&gt;
===Physical Security===&lt;br /&gt;
 Q: Where is the server physically located?&lt;br /&gt;
 A: St. Louis, MO, USA (in most cases)&lt;br /&gt;
&lt;br /&gt;
 Q: Who has access?&lt;br /&gt;
 A: Authorized personnel only.&lt;br /&gt;
&lt;br /&gt;
 Q: Who authorizes access?&lt;br /&gt;
 A: Data Center &lt;br /&gt;
&lt;br /&gt;
 Q: What is the access control mechanism?&lt;br /&gt;
 A: Multi-step: Security cards, manual ID inspection, manual access entry.&lt;br /&gt;
&lt;br /&gt;
 Q: Are there motion detectors, cameras, etc...?&lt;br /&gt;
 A: Several 24x7 recorded cameras/video throughout.&lt;br /&gt;
&lt;br /&gt;
 Q: Where are the backups stored?&lt;br /&gt;
 A: Generally offsite in Dallas, TX, USA&lt;br /&gt;
&lt;br /&gt;
===Network Security===&lt;br /&gt;
 Q: Are the appropriate contacts defined in DNS?&lt;br /&gt;
 A: Yes&lt;br /&gt;
&lt;br /&gt;
 Q: On what VLAN is the host? Where does this VLAN exist?&lt;br /&gt;
 A: Virtual VLAN via vmWare&lt;br /&gt;
&lt;br /&gt;
 Q: Is there a network firewall in place?&lt;br /&gt;
 A: Yes&lt;br /&gt;
&lt;br /&gt;
 Q: Is there a host-based firewall in place?&lt;br /&gt;
 A: Yes&lt;br /&gt;
&lt;br /&gt;
 Q: What are the firewall rules for remote administrative access?&lt;br /&gt;
 A: Internal only&lt;br /&gt;
&lt;br /&gt;
 Q: What kind of logging is in place?&lt;br /&gt;
 A: Standard logging (generic question)&lt;br /&gt;
&lt;br /&gt;
 Q: Are the logs periodically reviewed and acted on?&lt;br /&gt;
 A: Yes&lt;br /&gt;
&lt;br /&gt;
 Q: What services are available to the Internet?&lt;br /&gt;
 A: Only needed services to allow the site to function.  All others blocked.&lt;br /&gt;
&lt;br /&gt;
 Q: What network access controls are in place for the database server?&lt;br /&gt;
 A: Internal access only for admin access, requiring strong username/password authentication.&lt;br /&gt;
&lt;br /&gt;
===System Security===&lt;br /&gt;
 Q: What OS is running on the system?&lt;br /&gt;
 A: Depends.  If you have cPanel, it's Linux.  If you have MochaPanel/WCP, it's Windows.&lt;br /&gt;
&lt;br /&gt;
 Q: What is the OS version? Is it nearing end of life?&lt;br /&gt;
 A: Depends on the plan chosen.&lt;br /&gt;
&lt;br /&gt;
 Q: Is the OS patched? What is the process for applying security patches?&lt;br /&gt;
 A: Yes.  The servers are routinely patched as releases are made.&lt;br /&gt;
&lt;br /&gt;
 Q: What is the server used for, other than this application?&lt;br /&gt;
 A: Our shared web servers are only used as web servers.  &lt;br /&gt;
&lt;br /&gt;
 Q: What software is installed?&lt;br /&gt;
 A: Depends on the OS type.&lt;br /&gt;
&lt;br /&gt;
 Q: What services are running?&lt;br /&gt;
 A: Only those services needed by a web server.&lt;br /&gt;
&lt;br /&gt;
 Q: Is the clock synchronized via NTP?&lt;br /&gt;
 A: Yes&lt;br /&gt;
&lt;br /&gt;
 Q: What are the login accounts on the system?&lt;br /&gt;
 A: N/A&lt;br /&gt;
&lt;br /&gt;
 Q: What authentication methods does the system support?&lt;br /&gt;
 A: Depends on the OS.&lt;br /&gt;
&lt;br /&gt;
 Q: Does the system authenticate against a domain/realm/external database?&lt;br /&gt;
 A: No&lt;br /&gt;
&lt;br /&gt;
 Q: How does one get root/Administrator privilege?&lt;br /&gt;
 A: You don't on a shared server.&lt;br /&gt;
&lt;br /&gt;
 Q: Are strong passwords used? Is usage enforced?&lt;br /&gt;
 A: Yes&lt;br /&gt;
&lt;br /&gt;
 Q: Are there shared accounts?&lt;br /&gt;
 A: Users are not shared.  The web server is a shared server.&lt;br /&gt;
&lt;br /&gt;
 Q: What is the state of the file system security? (world writable files, suid root)&lt;br /&gt;
 A: Files have restricted access to the account owner.&lt;br /&gt;
&lt;br /&gt;
 Q: How are backups done?&lt;br /&gt;
 A: Nightly.&lt;br /&gt;
&lt;br /&gt;
 Q: What kind of logging is in place?&lt;br /&gt;
 A: Standard logging.&lt;br /&gt;
&lt;br /&gt;
 Q: Are the logs periodically reviewed and acted on?&lt;br /&gt;
 A: Yes&lt;br /&gt;
&lt;br /&gt;
===Database Security===&lt;br /&gt;
 Q: Where does the database server run?&lt;br /&gt;
 A: On a separate database server.&lt;br /&gt;
&lt;br /&gt;
 Q: With what privileges on the system does the database server run?&lt;br /&gt;
 A: Depends on the type of database server.  The user account privileges are restricted to that specific database.&lt;br /&gt;
&lt;br /&gt;
 Q: What access controls are in place for the application's data?&lt;br /&gt;
 A: (Customer needs to answer)&lt;br /&gt;
&lt;br /&gt;
 Q: What database privileges does the application have?&lt;br /&gt;
 A: (Customer needs to answer)&lt;br /&gt;
&lt;br /&gt;
 Q: What information is stored in the database?&lt;br /&gt;
 A: (Customer needs to answer)&lt;br /&gt;
&lt;br /&gt;
 Q: What database users/roles are defined, and what privileges do they have?&lt;br /&gt;
 A: (Customer needs to answer)&lt;br /&gt;
&lt;br /&gt;
 Q: What is the data retention policy?&lt;br /&gt;
 A: Backups are retained up to 14 days on shared database servers.&lt;br /&gt;
&lt;br /&gt;
 Q: How is the database backed-up?&lt;br /&gt;
 A: Nightly&lt;br /&gt;
&lt;br /&gt;
 Q: What kind of logging is in place?&lt;br /&gt;
 A: Standard logging&lt;br /&gt;
&lt;br /&gt;
 Q: Are the logs periodically reviewed and acted on?&lt;br /&gt;
 A: Yes&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Web Server Security===&lt;br /&gt;
 Q: Does the server force SSL/TLS to the application?&lt;br /&gt;
 A: (Customer needs to answer)&lt;br /&gt;
&lt;br /&gt;
 Q: Is the SSL/TLS keypair adequately secured?&lt;br /&gt;
 A: Yes&lt;br /&gt;
&lt;br /&gt;
 Q: Are weak ciphers disabled?&lt;br /&gt;
 A: Yes&lt;br /&gt;
&lt;br /&gt;
 Q: Is SSLv2 disabled?&lt;br /&gt;
 A: Yes&lt;br /&gt;
&lt;br /&gt;
 Q: Are unnessesary modules/plugins disabled?&lt;br /&gt;
 A: Yes&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Application Security===&lt;br /&gt;
Customer needs to answer those questions as they are application specific.&lt;/div&gt;</summary>
		<author><name>Briana</name></author>	</entry>

	</feed>