CFN III Fuel Management
System PA-DSS
Implementation Guide
Version 3.6
MDE-4870A
Computer Programs and Documentation
All Gasboy computer programs (including software on diskettes and within memory chips) and documentation are copyrighted by, and shall remain the property of, Gasboy. Such
computer programs and documents may also contain trade secret information. The duplication, disclosure, modification, or unauthorized use of computer programs or
documentation is strictly prohibited, unless otherwise licensed by Gasboy.
Federal Communications Commission (FCC) Warning
This equipment has been tested and found to comply with the limits for a Class A digital device pursuant to Part 15 of the FCC Rules. These limits are designed to provide
reasonable protection against harmful interference when the equipment is operated in a commercial environment. This equipment generates, uses, and can radiate radio frequency
energy, and if not installed and used in accordance with the instruction manual, may cause harmful interference to radio communications. Operation of this equipment in a
residential area is likely to cause harmful interference in which case the user will be required to correct the interference at his own expense. Changes or modifications not expressly
approved by the manufacturer could void the user’s authority to operate this equipment.
Approvals
Gasboy, Greensboro, is an ISO 9001:2000 registered facility.
Underwriters Laboratories (UL):
UL File#Products listed with UL
MH4314
MH10581Key con t r o l u n i t , M o d e l G K E - B S e r i e s
All dispensers and self-contained pumping
units
Card reader terminals, Models 1000, 1000P
Site Controller, Model 2000S CFN Series
Data entry terminals, Model TPK-900 Series
Fuel Point Reader System
National Conference of Weights and Measures (NCWM) - Certificate of Compliance (CoC):
Gasboy pumps and dispensers are evaluated by NCWM under the National Type Evaluation Program (NTEP). NCWM has issued the following CoC:
Page iiMDE-4870A CFN III Fuel Management System PA-DSS Implementation Guide Version 3.6 · June 2010
PurposeIntroduction
1 – Introduction
Purpose
This document provides information required to install and operate the CFN III in a manner
compliant with Payment Application - Data Security Standard (PA-DSS) version 1.2.
Failure to comply with the information in this document could put the merchant in violation of
PA-DSS and possibly Payment Card Industry (PCI-DSS) compliance.
Related Documents
Document
Number
PA-DSS – Requirements Version 1.2
MDE-4739 CFN III PCI Secure Controller Software Installation/Upgrade CFN Series Networks, Card
MDE-4871CFN III Manager’s Manual for Windows® XP Embedded
MDE-4872CFN III Configuration Manual for Windows XP Version 3.6CFN Series Controllers and POS
MDE-4873CFN Series Site Controller III Start-up Manual for CFN III
Document TitleGOLD Library
Version 3.6
Version 3.6 and Later
PA-DSS and PCI-DSS
PA-DSS is a series of requirements that apply to any payment application that stores,
processes, or transmits card holder data as part of the transaction process. CFN III falls under
this requirement and therefore must comply with PA-DSS. Many of the requirements under
PA-DSS are handled automatically by CFN III. However, there are certain requirements that
must be maintained by the merchant in order to run in a compliant manner. Each of the
merchant requirements will be covered in this document.
Handlers, and Pump Interface
CFN Series Controllers and POS
CFN Series Controllers and POS
PCI-DSS is a series of requirements that apply to the entire payment environment at a
merchant location. PA-DSS covers only a portion of that environment. It does not cover all
aspects of PCI-DSS. It is the responsibility of the merchant to ensure that their overall
payment environment is operated and maintained in a manner compliant with the PCI-DSS.
For more information on specific requirements of PCI-DSS or PA-DSS, refer to the PCI
Security Standards Council website http://www.pcisecuritystandards.org.
MDE-4870A CFN III Fuel Management System PA-DSS Implementation Guide Version 3.6 · June 2010Page 1
IntroductionCertification Status
Certification Status
CFN III version 3.6A was evaluated by K3DES in July 2009, and certified as compliant under
PA-DSS version 1.2.
Abbreviations and Acronyms
TermDescription
ASCAuthorized Service Contractor
CFNCash Flow Network
DESData Encryption Standard
PA-DSSPayment Application - Data Security Standard
PCI-DSSPayment Card Industry - Data Security Standard
PIN Personal Identification Number
POSPoint Of Sale
SCSite Controller
TIPTransaction In Process
USBUniversal Serial Bus
Page 2 MDE-4870A CFN III Fuel Management System PA-DSS Implementation Guide Version 3.6 · June 2010
Physical SecurityGetting Started
2 – Getting Started
Physical Security
The merchant is responsible for ensuring that the CFN III is physically secure.
System Security
Physical access to the Site Controller system must be limited to only those that use the Site
Controller. If modular Profit Point POS systems are used, then the Site Controller is best
controlled in a locked back room, with restricted access. If using Integral Profit Point POS
system, the system must only be accessible by those using the system. If it is not possible to
maintain the system in a secure area, the area must have adequate coverage by available
security cameras so that unauthorized access can be recorded and used to determine any cause
of physical security breaches.
System Report and Other Logs
Though the system log is secure from exposing any sensitive card information, it is a good
practice to keep the log printer in a secure area. It is possible that some bank host systems
require card account information to be listed on a report or log for back office purpo ses. When
the reports are used for holding account information it is the responsibility of the site manager
or store owner to secure the reports from unauthorized access.
Installations and Upgrades
To upgrade the CFN payment system from a non-compliant version of 3.4 or earlier, to a
secure PCI-compliant version, refer to MDE-4739 CFN III PCI Secure Controller Software
Installation/Upgrade Instructions.
The integrity of software upgrades is guaranteed because only software created by Gasboy®
will operate on the CFN III board set. Software created without the unique Gasboy
development system will typically fail checksum. However, in the event that the software
passes that test, the system will not boot or operate.
Purge Transaction Records
After the installation is complete, the embedded payment controller transaction table must be
purged of any information left in memory, which may retain previous card information. This is
a mandatory procedure in order to meet PCI requirements and cannot be skipped. This process
must be executed before the site is allowed to start processing card data. It would be best to
proceed with this process right after the table sizing is finalized.
MDE-4870A CFN III Fuel Management System PA-DSS Implementation Guide Version 3.6 · June 2010Page 3
Loading...
+ 15 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.