<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic PCI DSS 3.2.1 Responsibility Matrix for SaaS Services in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pci-dss-3-2-1-responsibility-matrix-for-saas-services/m-p/517802#M107439</link>
    <description>&lt;P&gt;I've been looking for any details from Palo Alto regarding the responsibility of controls for PCI 3.2.1 when it comes to SaaS and PaaS offerings such as Prisma Access, Wildfire, XSOAR, XDR, etc.&amp;nbsp; Most service providers will publish a 'responsibility matrix' that will define what the service provider is responsible for and what the consumer is.&amp;nbsp; Has anyone come across anything similar to this document (&lt;A href="https://help.mypurecloud.com/articles/pci-dss-customer-responsibility-matrix/?" target="_blank"&gt;https://help.mypurecloud.com/articles/pci-dss-customer-responsibility-matrix/?&lt;/A&gt;) but for Palo Alto SaaS solutions?&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Many thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 13 Oct 2022 15:05:24 GMT</pubDate>
    <dc:creator>mslavens</dc:creator>
    <dc:date>2022-10-13T15:05:24Z</dc:date>
    <item>
      <title>PCI DSS 3.2.1 Responsibility Matrix for SaaS Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pci-dss-3-2-1-responsibility-matrix-for-saas-services/m-p/517802#M107439</link>
      <description>&lt;P&gt;I've been looking for any details from Palo Alto regarding the responsibility of controls for PCI 3.2.1 when it comes to SaaS and PaaS offerings such as Prisma Access, Wildfire, XSOAR, XDR, etc.&amp;nbsp; Most service providers will publish a 'responsibility matrix' that will define what the service provider is responsible for and what the consumer is.&amp;nbsp; Has anyone come across anything similar to this document (&lt;A href="https://help.mypurecloud.com/articles/pci-dss-customer-responsibility-matrix/?" target="_blank"&gt;https://help.mypurecloud.com/articles/pci-dss-customer-responsibility-matrix/?&lt;/A&gt;) but for Palo Alto SaaS solutions?&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Many thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2022 15:05:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pci-dss-3-2-1-responsibility-matrix-for-saas-services/m-p/517802#M107439</guid>
      <dc:creator>mslavens</dc:creator>
      <dc:date>2022-10-13T15:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: PCI DSS 3.2.1 Responsibility Matrix for SaaS Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pci-dss-3-2-1-responsibility-matrix-for-saas-services/m-p/518186#M107508</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/60650"&gt;@mslavens&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does this work for you?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;XDR -&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/apps/pan/public/downloadResource?pagePath=/content/pan/en_US/resources/whitepapers/pci-compliance-wth-cortex-xdr" target="_blank" rel="noopener"&gt;https://www.paloaltonetworks.com/apps/pan/public/downloadResource?pagePath=/content/pan/en_US/resources/whitepapers/pci-compliance-wth-cortex-xdr&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Strata -&amp;nbsp;&lt;A href="https://www.paloaltonetworks.com/apps/pan/public/downloadResource?pagePath=/content/pan/en_US/resources/whitepapers/pci-compliance" target="_blank"&gt;https://www.paloaltonetworks.com/apps/pan/public/downloadResource?pagePath=/content/pan/en_US/resources/whitepapers/pci-compliance&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2022 02:28:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pci-dss-3-2-1-responsibility-matrix-for-saas-services/m-p/518186#M107508</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2022-10-18T02:28:38Z</dc:date>
    </item>
    <item>
      <title>Re: PCI DSS 3.2.1 Responsibility Matrix for SaaS Services</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pci-dss-3-2-1-responsibility-matrix-for-saas-services/m-p/518230#M107523</link>
      <description>Hi there,&lt;BR /&gt;&lt;BR /&gt;Unfortunately not.  We are specifically looking for a document that details what aspects of the SaaS solution Palo Alto is responsible for when it comes to meeting PCI guidelines and what parts are the responsibility of the consumer.  For example – the infrastructure running the SaaS/PaaS offering is fully managed by Palo Alto so they would be responsible for securing it (OS, buildings etc), having a hardened standard, enforcing password policies, training the Palo Alto staff on security best practice etc.  Whereas the consumer would be responsible for thing such as configuring the password policy within the consumer facing part of the solution, applying best practices, configuring and documenting integrations that consumed the SaaS/PaaS etc.  Most vendors who offer SaaS and PaaS services that promote their products to help meet PCI compliance will also provide a ‘responsibility matrix’ to their consumer.  Here is an example from a VOIP provider Genesys: &lt;A href="https://help.mypurecloud.com/articles/pci-dss-customer-responsibility-matrix/" target="_blank"&gt;https://help.mypurecloud.com/articles/pci-dss-customer-responsibility-matrix/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Thank you,&lt;BR /&gt;&lt;BR /&gt;Michael&lt;BR /&gt;</description>
      <pubDate>Tue, 18 Oct 2022 15:22:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pci-dss-3-2-1-responsibility-matrix-for-saas-services/m-p/518230#M107523</guid>
      <dc:creator>mslavens</dc:creator>
      <dc:date>2022-10-18T15:22:01Z</dc:date>
    </item>
  </channel>
</rss>

