Payment Card Industry (PCI) Qualified Security Assessor (QSA) Services
Support and pragmatic advice on every element of PCI compliance to all merchants using cloud-based services to handle payments:
* PCI workshops to provide guidance on compliance requirements
* Gap analysis and roadmaps to PCI compliance
* QSA audits and Report On Compliance and Attestation On Compliance documents
Features
- Assurance of cloud payments
- Audit of cloud-based paymet deployments
- Architecture analysis
- PCI Compliance
- Risk analysis of cloud payment deployments
- Risk assessment
- Risk management
Benefits
- Assurance of payment handling
- Assurance of ongoing cloud payment security
- PCI Compliance
- Avoiding PCI fines
- Risk assessment reports
- Risk management
Pricing
£918.00 to £1,260.00 a unit a day
Service documents
Request an accessible format
Framework
G-Cloud 14
Service ID
5 2 9 7 4 8 7 8 5 0 7 3 9 6 3
Contact
Prism Infosec
Robin Mulligan
Telephone: 01242652100
Email: contact@prisminfosec.com
Planning
- Planning service
- No
Training
- Training service provided
- No
Setup and migration
- Setup or migration service available
- Yes
- How the setup or migration service works
- Prism Infosec can provide expert consultancy on the secure setup and migration of payment services into the cloud. Using best practice guidelines from the PCI SSC, NCSC and the Cloud Security Alliance, as well as our own experience on conducting many assessment of infrastructure and application payment services in the cloud, Prism Infosec will be able to provide guidance on correct architecture and configuration to manage cyber security of cloud payments.
- Setup or migration service is for specific cloud services
- No
Quality assurance and performance testing
- Quality assurance and performance testing service
- No
Security testing
- Security services
- Yes
- Security services type
-
- Security strategy
- Security risk management
- Security design
- Cyber security consultancy
- Security testing
- Security audit services
- Other
- Other security services
-
- Risk assessment
- Risk management
- Cyber security review
- Certified security testers
- Yes
- Security testing certifications
-
- CHECK
- CREST
- Cyber Scheme
- Other
- Other security testing certifications
-
- QSA
- ISO27001 Lead Auditor
- IASME
Ongoing support
- Ongoing support service
- No
Service scope
- Service constraints
- None
User support
- Email or online ticketing support
- Email or online ticketing
- Support response times
- We will respond within 2 working days.
- User can manage status and priority of support tickets
- No
- Phone support
- Yes
- Phone support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support
- No
- Support levels
- We typically provide support during office hours with regard to the delivery of ongoing penetration testing services or reports delivered within the last 3 months with a 6 hour response window. This is included in the cost of delivery of a penetration test. The principal consultant responsible for the delivery of a penetration test shall be responsible for customer's technical account.
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Conforms to BS7858:2019
- Government security clearance
- Up to Developed Vetting (DV)
Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- Alcumus ISOQAR
- ISO/IEC 27001 accreditation date
- 10/03/2020
- What the ISO/IEC 27001 doesn’t cover
- TBC
- ISO 28000:2007 certification
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- Yes
- Cyber essentials plus
- Yes
- Other security certifications
- No
Social Value
- Social Value
-
Social Value
- Fighting climate change
- Covid-19 recovery
- Tackling economic inequality
- Equal opportunity
- Wellbeing
Fighting climate change
The Company is committed to keeping the environmental impact of its activities to a minimum and has established an Environmental Policy in order help achieve this aim. As an absolute minimum, the Company will ensure that it meets all applicable environmental laws in whichever jurisdiction it may be operating.Covid-19 recovery
Covid 19 has forced the world to re-evaluate it’s approach in all aspects of business and life. We at Prism Infosec pride ourselves at being agile in our approach and very quickly adjusted our approach to be more flexible and have put measures in place to be able to provide our services safely and securely from a remote location if needed. We have adjusted very well to the pandemic and have adopted a similar approach coming out of the pandemic. This gives us also the opportunity to provide a more sustainable service that is less impact on the environment as well as the cost to the client.Tackling economic inequality
Additionally, Prism Infosec are supporting the DWP and IASME ‘Kickstart’ Scheme, which is a government initiative which provides funding to employers to create jobs for 16 to 24 year olds on Universal Credit. We currently have a ‘Kickstart’ vacancy pending and are in the process of conducting interviews to fill this position and add a Kickstart based resource into our team. We align with the philosophy of this programme as it seeks to encourage individuals into our industry who may well have missed out as they have not progressed through into the further education environments that traditionally fuel our industry Other initiatives have included the sponsorship of industry related events, to the extent that we have been the major sponsor of the previous Liverpool ‘BSides’ event. BSides Liverpool is a cyber security industry driven, community event, that relies on sponsorship to happen. The event itself has strong social values as it looks to inform and provide workshops relating to our industry and to attract individuals into it . BSides believe that these are inclusive events and places where all people should feel safe and respected and welcome diversity in age, race, ethnicity, national origin, range of abilities, sexual orientation, gender identity, financial means, education, and political perspective.Equal opportunity
1.1 Policy Statement Prism Infosec Ltd (“the Company”) is committed to achieving a working environment which provides equality of opportunity and freedom from unlawful discrimination on the grounds of race, sex, pregnancy and maternity, marital or civil partnership status, gender reassignment, disability, religion or beliefs, age or sexual orientation. This Policy aims to remove unfair and discriminatory practices within the Company and to encourage full contribution from its diverse community. The Company is committed to actively opposing all forms of discrimination. The Company also aims to provide a service that does not discriminate against its clients and customers in the means by which they can access the services and goods supplied by the Company. The Company believes that all employees and clients are entitled to be treated with respect and dignity.Wellbeing
In 2022 Prism implemented a private medical scheme to its employees, that provides them with therapies like mental health included in the cover. We have also provided channels for employees to talk about their mental health or any other related wellbeing issues.
Pricing
- Price
- £918.00 to £1,260.00 a unit a day
- Discount for educational organisations
- No