leorwald:
I'm confused by this setting. As far as I understand zencart does not store any cardholder data (the PAN). If so, why does the admin have to timeout every 15 minutes. I understood that it only has to do so, if it is storing cc information.
TIA,
Leo
I performed the following search (pad-ss when timeout required) and the first link provided was to a pdf (https://www.pcisecuritystandards.org/minisite/en/docs/PA-DSS_v3.pdf) related to the topic of PAD-SS to which ZC has been certified.
Looking at the 2nd paragraph under the second main section of the introduction, > All applications that store, process, or transmit cardholder data are in scope for an entity's PCI DSS assessment, including applications that have been validated to PA-DSS.
Further, looking through the requirements provided, the area in question is identified as 3.1.11. Now my read of all this is: not complying with these and the other identified attributes means that the software can not be considered/evaluated as PA-DSS certified and if not PA-DSS certified then also not PCI-DSS compliant. As to the need to be such: well, a cardholder's name is considered one part of cardholder data, ZC does at least two of the three actions (store and process) and in some cases it does transmit it as well (ie. When submitting data to getting from a payment processor.) So, by sustaining the requirements of PA-DSS, ZC is able to maintain that certification (at least for the version which obtained it).
All that said, I am no authority on the subject, I did my own independent search and read on the topic and provided the above from that. Do as you will, I personally appreciate what has been done to obtain this certification and to provide a product that supports secure sales. If not mistaken, it remains the only eCommerce platform verified to meet this level of requirement. I may have applied that statement too broadly, but wouldn't be the first nor last time I'm wrong if so.