Move/3500 PCI PTS Security Policy
Ingenico document - Please check document validity before using
4_4 Periodic Inspection and Maintenance
Information about periodic inspection is specified in the installation guide [8].
The merchant or acquirer should daily check that the keypad is firmly in place. Such checks would
provide warning of any unauthorized modification to the terminal, or suspicious behavior of the
terminal.
In the tampered state, the device displays a warning flashing message and further use of the device is
not possible. If such a message is observed, the merchant or acquirer must contact the device
helpdesk immediately, remove it from service and keep it available for potential forensics investigation.
The merchant or acquirer should also check that the installation/maintenance operations are
performed by a trusted person and log the maintenance operations, including name of the operator.
The merchant or acquirer should check if the ICC reader slot is damaged, such as abrasion, painting
and other machining marks or if there is any suspicious object like lead wire or any unknown object
inside ICC reader.
If such suspicious circumstances are observed, the merchant or acquirer shall stop using the device
immediately and contact the customer service to confirm the device has been tampered.
Figure 3: ICC reader slot
4_5 Product Service Removal
Sensitive data must be erased before refurbishing the device or removing it permanently from service.
The device shall go to tampered status, a state in which sensitive data are erased.
For example, disassembly of the device will lead to a tampered status.