pci compliance for very small biz using mac and ipad

I run a very SMALL business. We have one MacBook an iPad and an iPhone. We run everything through a second party merchant card processor/software (mindbody). However, according to the PCI compliance survey I just finished, I am supposed to run quarterly internal scans for vulnerabilities. Does antivirus software do this?


Also, what firewall settings do I need on my mac to be PCI compliant?


I know this may be a very simple question, but the PCI survey assumes everyone has an IT department with a ton of policies and procedures. Trying to figure out how to be compliant as a super small business without all that infrastructure.

Posted on Jun 27, 2014 3:43 PM

Reply
4 replies

Jun 28, 2014 12:11 PM in response to Lori Banducci1

For the iPad and iPhone, Apple checks out the software before putting it in the store.


Most of the so called anti-virus software checkers on the Mac are a scam and are worse than not using such software. The best only check for Windows problems in your email. The net is do not use an anti-virus software on the mac.


What to do? Stay current on your software updates. That is every quarter verify that you have the latest software update from Apple. Apple includes malware detection and malware removal software within Mac OS. By being up-to-date on the OS, you have run the latest malware detection software.


You have a Mac therefor you are are availing all the malware problems of Windows.

Jun 28, 2014 2:04 PM in response to Lori Banducci1

Anti-virus software would not do PCI vulnerability scanning. You need specialized software to do that. Unfortunately, I cannot recommend specific software. My wife's small business was wrestling with PCI issues some time ago, and they're currently not doing any kind of internal scans. I don't know why not. They do get scanned externally periodically, to look for vulnerabilities in their setup that could allow people outside their network to gain access.


PCI compliance is a scam anyway. It doesn't prevent the numerous breaches that so many high-profile companies have been facing lately, and you can bet they're dotting their i's and crossing their t's with respect to PCI compliance. They have the budget to do so.


Your Mac should not need the firewall on. That shouldn't affect PCI compliance, if the Mac is properly configured and does not have any services open in System Preferences -> Sharing.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

pci compliance for very small biz using mac and ipad

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.