Preface. Author s Biography

Size: px
Start display at page:

Download "Preface. Author s Biography"

Transcription

1

2 Table of Contents Preface... 3 Author s Biography... 3 Executive Summary... 4 The Payment Card Industry Data Security Standard... 4 Applicability of the PCI DSS... 5 Compliance vs. Validation... 5 Defining Cardholder Data... 6 Understanding the Cardholder Data Environment (CDE)... 6 The Compliance Spectrum... 7 ProPay s ProtectPay and the Compliance Spectrum Summary About ProPay

3 Preface Whitepapers are often written from the third-person perspective. This projects objectivity and neutrality into the topic. The topic of this particular paper however, is so hotly debated that I felt it appropriate to deviate from the normal format and write from the first person perspective. I feel that the first person perspective will allow me to explain the concepts more clearly and provide more relevant examples for the readers. Before going too far into the content I feel it is important to establish my credibility on this subject. For this reason, I am going to describe my background first. If, after reading my biography, you are still not convinced of my expertise then you have not wasted time reading the rest of the document. Author s Biography My name is Chris Mark and I am ProPay s Executive Vice President; Data Security & Compliance. I am a Payment Card Industry Data Security Standard (PCI DSS) expert. In 2001 I became involved with the PCI DSS predecessor when I worked with Visa USA on the original development of the Cardholder Information Security Program (CISP) and the development of the PCI DSS s predecessor, the CISP requirements. I conducted one of the first (if not the first) CISP assessments before there were such things as Qualified Data Security Professionals (QSA predecessor) and QSAs. I founded one of the industry s first Qualified Security Assessment (QSA) firms and conducted over 100 onsite PCI DSS assessments for merchants, service providers, and banks. After my company was acquired I then took employment at MasterCard Worldwide. At MasterCard I served as a member of their Site Data Protection (SDP) team and was one of the founding members of the Payment Card Industry Security Standards Council (PCI SSC) where I was MasterCard s representative on the Technical Working Group. The TWG published the first PCI DSS standard in After departing MasterCard, I was contracted by Visa to conduct PCI DSS related training for their merchants, banks, and service providers. My company, The Aegenis Group, was selected as the sole worldwide trainer for Qualified Security Assessors (QSA). From I trained over 10,000 people on PCI DSS related topics and trained over 1,500 QSAs in numerous countries including Thailand, Japan, Australia, Argentina, and the UK. Finally, my company developed the industry s first and only payment card security certification programs the CPISM and CPISA and I have certified over 500 people on the topic of payment card security. 3

4 I am a frequent industry speaker and have presented at numerous events including the Electronic Transaction Association (ETA) annual convention (5 times), NACSTech, ACI Customer Event, PCIPortal South Africa, Utah Technology Counsel, Akamai s Customer Security Event, CSI Executive Meeting, and have published scores of articles on payment card security and risk. Executive Summary For many companies required to comply with the PCI DSS, the mere mention of the standard brings groans of frustration and angst. Companies are frustrated, angry, and (insert your own emotion here) at the idea of having to comply with the standard. These feelings are often exacerbated by well meaning, although occasionally misguided individuals within the industry that espouse incorrect or irrelevant information as being accurate and truthful. The end result is a confusing, misguided approach to PCI DSS compliance. When pursuing the PCI DSS, there are a few steps one can take to make the process easier. Understanding the component parts of the PCI DSS, the differences between compliance and validation, and the applicability of the Standard can make the process much easier to understand. Finally, applying these ideas to understand what this paper calls the Compliance Spectrum will help companies move through PCI DSS much more efficiently and cost effectively. More importantly it will enable organizations to make educated, informed decisions regarding the outsourcing of their payment card acceptance and processing. The Payment Card Industry Data Security Standard The Payment Card Industry Data Security Standard (PCI DSS) was developed originally as Visa s Cardholder Information Security Program (CISP) in 2001 and later adopted by all of the major card brands in 2006 as an international standard. The PCI DSS consists of 12 high-level requirements and approximately 220 sub-requirements. The stated objective of the PCI DSS is to...encourage and enhance cardholder data security... It is not, nor was it ever intended to provide, an absolute statement on security. As stated on page 2 of the Preface section of PCI DSS v1.2.1: The Payment Card Industry (PCI) Data Security Standard (DSS) was developed to encourage and enhance cardholder data security and facilitate the broad adoption of consistent data security measures globally. 1 1 PCI DSS; 4

5 Applicability of the PCI DSS The PCI DSS applies to any organization that stores, transmits or processes Cardholder Data. Version of the standard further clarified the statement to state specifically: PCI DSS requirements are applicable if a Primary Account Number (PAN) is stored, processed, or transmitted. If a PAN is not stored, processed, or transmitted, PCI DSS requirements do not apply. As can be seen from the language in the PCI DSS, the determining factor as to whether or not the requirements apply is whether Primary Account Numbers (PANs) are stored, transmitted or processed. It is unfortunate that this very apparent statement has been overlooked by a number of vendors and QSAs. Recently, I was listening to a webinar published by a major industry organization and a QSA stated something to the effect of: Just because you don t have any data does not mean you don t have to comply with the PCI DSS. As a former QSA, QSA trainer, and one of the original authors of the PCI DSS, I can state definitively that this statement is misleading at best, and incorrect at worst. Notice that the PCI DSS talks about the applicability of the requirements and not the applicability of the program. Any organization that possesses a merchant ID is defined as a merchant by the card brand regulations known as Operating Regulations. Any and all merchants must comply with all card brand operating regulations. One of the OpRegs states that: all members (banks) must comply and ensure their merchants comply with the PCI DSS. This operating regulation states that merchants must comply with the program. Whether or not the requirements apply is dictated by whether or not the merchant stores, transmits, or processes PANs. What does this mean in a practical sense? You may have to comply with the PCI DSS program and have few if any requirements to apply to your organization. We will discuss this in greater depth in the following sections. Compliance vs. Validation One of the other areas that creates some confusion is the difference between the need to comply with the PCI DSS requirements and the need to validate compliance. Compliance can be most easily defined as a state of being, while validation is proving to a third party that you are in a particular state of being. An example I use frequently to describe the difference is that of automobile insurance. In most states it is a law to have insurance if you own an automobile. 5

6 Simply having the insurance means you are in compliance with the law. If you are pulled over by a police officer for speeding, they will ask you to provide proof of insurance. Providing this proof is validation of your compliance with the law. All companies that store, transmit, or process Cardholder Data (PANs) must comply with the PCI DSS. Some of those companies may be required to validate their compliance through an onsite assessment conducted by a Qualified Security Assessor (QSA), completion of a Self Assessment Questionnaire (SAQ) or completion of a network security scan. Some companies may not be required to validate compliance. This however does not excuse them from their obligation to comply with the PCI DSS. Defining Cardholder Data Cardholder Data is defined by the PCI DSS as the Primary Account Number (PAN) alone. Storing, transmitting or processing a single PAN obligates a company to comply with the PCI DSS requirements. Cardholder name, expiration date, and service code are also considered Cardholder Data IF they are stored, transmitted or processed in conjunction with the PAN. Consider the example of a spreadsheet. If in the first column you have the PAN and the second you have the Cardholder Name then both elements are considered Cardholder Data and thus subject to the PCI DSS. If however you only have a PAN in one spreadsheet and you maintain the Cardholder name on a CDRom locked in a safe, the PAN is considered Cardholder Data while the cardholder name is not because it is not stored with the PAN. Understanding the Cardholder Data Environment (CDE) It is paramount for anyone required to comply with the PCI DSS that they understand the definition of Cardholder Data Environment or what is commonly called the CDE. The Cardholder Data Environment is defined by the PCI DSS as: The cardholder data environment is that part of the network that possesses cardholder data or sensitive authentication data. The PCI DSS applies to the Cardholder Data Environment or CDE. Additionally, the PCI DSS applies to system components that are connected to the CDE. To summarize, the PCI DSS requirements apply only to the Cardholder Data Environment and connected systems. Systems in this case include applications, devices, and servers or other computers. 6

7 Understanding that the PCI DSS applies to the CDE, it is logical then to try to minimize the footprint of the CDE. If, for example, a company could consolidate all of their Cardholder Data onto a single system that is completely isolated from the rest of the corporate network, then the CDE would consist only of that single system. The company then would only need to ensure that the single system is compliant with the PCI DSS. This is supported in the PCI DSS where it states: Network segmentation of, or isolating (segmenting), the cardholder data environment from the remainder of the corporate network is not a PCI DSS requirement. However, it is recommended as a method that may reduce: The scope of the PCI DSS assessment The cost of the PCI DSS assessment The cost and difficulty of implementing and maintaining PCI DSS controls The risk to an organization (reduced by consolidating cardholder data into fewer, more controlled locations) Without adequate network segmentation (sometimes called a "flat network") the entire network is in scope of the PCI DSS assessment. Network segmentation can be achieved through internal network firewalls, routers with strong access control lists or other technology that restricts access to a particular segment of a network. Now that we have a clear understanding of which companies must comply with the PCI DSS (those that store, transmit, and process CHD), to what part of the environment the PCI DSS applies (Cardholder Data Environment) and that the PCI DSS requirements only apply of PAN is stored, transmitted or processed we can now delve into which requirements apply to a given environment. The Compliance Spectrum As seen in by the QSA s previously referenced comments it is apparent, though unfortunate, that many in the industry have a very binary view of the PCI DSS programs and its requirements. There is almost ubiquitous belief that if a company must comply with the PCI DSS requirements then they must implement all 240+ sub-requirements to comply. This is an incorrect assumption. Before I go too much further let me state that I was a part of the team that created the Self Assessment Questionnaires (SAQ) that are used by companies validating compliance. As evidenced in the design of the SAQs it is recognized by the PCI SSC that not every requirement applies to every company, in every circumstance. 7

8 This is why SAQ A asks Card Not Present merchants that meet the criteria to only comply with Requirements 9 and 12. It is understood that the other requirements are addressed by the third party used by the merchant. Specifically, SAQ A states that it applies to: Merchant does not store, process, or transmit any cardholder data on merchant premises but relies entirely on third party service provider(s) to handle these functions; The PCI DSS acknowledges that appropriate segmentation can reduce the scope of the environment to which the PCI DSS requirements apply. As stated, once the CDE has been properly defined and minimized, now the only real question left to answer is what requirements apply to my company s CDE? Anyone who has attended a training event that I taught has likely heard me repeat the following seemingly ridiculous, circuitous statement numerous times: The PCI DSS requirements are applicable to the extent they apply to your environment. While the statement may appear ridiculous at first blush, it is accurate and can help when evaluating which requirements apply. As can be seen in the PCI SSC s own documentation related to the Self Assessment Questionnaires, the Council does not consider every requirement to be applicable in every circumstance. In fact the applicability of requirements can most easily be viewed as a spectrum or sliding scale. Considering the following situation: Company X receives Cardholder Data from their merchant clients and transmits the data to a processor without storing or otherwise processing the data. In essence, Service Provider X acts as a basic switch that only transmits data. Would it be logical to expect Service Provider X to comply with requirement 3.4 of the PCI DSS that requires protection of stored data by encryption or other methods? The answer is a clear and definitive No. Why? There is no Cardholder Data being stored electronically therefore the requirement simply does not apply in this situation. It should be noted that this is a simple example used for demonstration purposes. 8

9 When considering the PCI DSS requirements to which your company must comply it is important to answer the following questions: 1. Does your organization store, transmit, or process Cardholder Data? If the answer is Yes then the PCI DSS requirements apply. Now it is important to understand which requirements. 2. Does your organization store Cardholder Data? No; then the requirements related to storage don t apply. This includes 3.4, 3.5 and 3.6 and other requirements. Yes; then the requirements related to storage do apply. This includes 3.4, 3.5 and 3.6 among others. 3. What technology is employed in your organization? As an example, if your company does not employ wireless technology then the requirement related to using WPA2 would not be applicable. If your company does not develop applications internally than Requirement 6.5, which applies to secure development, would not apply. While brevity prevents us from outlining every possible variable for the PCI DSS, it is enough to understand that all requirements do not apply at all times. It is more important to understand that the easiest method to comply is to not store, transmit, or process data. For merchants that outsource all aspects of their storage, processing, and transmission of Cardholder Data, an abbreviated set of requirements apply to that merchant. Consider the following example: Merchant X accepts transactions by use of an imprint machine. While the merchant certainly stores Cardholder Data on receipts, the data is never transmitted, stored, or processed electronically. In this scenario, the Cardholder Data Environment would consist of the imprint machine and the box used to store receipts. Why would anyone care whether Merchant X used WPA2 for wireless or deployed Anti-Virus on their systems? The answer is that while the PCI DSS applies, it is a limited subset of requirements that apply to a very limited CDE. It is this concept that we begin to define as the PCI DSS Compliance Spectrum. 9

10 The Compliance Spectrum can be best understood by looking at a graphic like the one below. On the left hand side of the spectrum a company would not have to comply with any PCI DSS requirements. This situation likely exists in theory only, but for the sake of argument it provides a good starting point. For a company that had a merchant account but did not use it at all to accept transactions, it could be argued that while they have an obligation to comply with the PCI DSS under the card brand operating regulations (see first section), in practice no actual requirements would apply as they would not be storing, transmitting, and/or processing Cardholder Data. For a company that outsources all aspects of storage, transmission, and processing of Cardholder Data still has a requirement to comply with the PCI DSS and the requirements do apply. At a minimum the company would need to ensure that they have contracts in place with their outsourced service provider verifying their security controls and that any physical receipts are protected appropriately. This particular company would need to ensure that they comply with PCI DSS requirement 12.8 and possibly sections of PCI DSS requirement 9. As the company begins to handle more data in more ways and employs more technology, the number of requirements that would be applicable to their particular environment would increase thereby moving the merchant toward the right hand side of the spectrum. It is possible that, in some instances, the merchant would need to comply with all of the PCI DSS requirements within their Cardholder Data Environment. By ensuring that there is a firm understanding of the nuances of the PCI DSS and the applicability of the standard before embarking on a PCI DSS compliance project, companies can save time and money on their projects while simultaneously reducing the risk to their data. ProPay s ProtectPay and the Compliance Spectrum ProPay s ProtectPay solution allows merchants to accept payments without storing, transmitting, or processing Cardholder Data within the merchant s own environment. As discussed in this and other documents, without storing, transmitting, or processing Cardholder Data the PCI DSS requirements don t apply. 10

11 It is important to understand that compliance with the PCI DSS program is required under the card brand rules however. By offloading the data to a third party and ensuring that the merchant never stores, transmits or processes their own data they have met compliance through the use of a PCI validated third party. In this case that third party is ProPay. I have heard the one argument a number of times and feel it is important to address in this document. Question: My company has a business need to access our client s cardholder data and as you have told us the PCI DSS now applies to my company. If this is the case what value would a solution like Protect Pay provide? This is an interesting question and certainly is important to discuss. As this document explains, there may very well be requirements that apply to your organization. If your organization has a need to view data, this can be accomplished securely through terminal services, a Citrix session, or similar technologies. Would this potentially result in the organization needing to comply with additional requirements? Certainly it would. Looking at the compliance spectrum it is possible that additional requirements around system configurations and other aspects may apply. Even if it increased the need to comply with an additional 24 requirements (10% of the total number of sub-requirements) and the company had requirement to comply with all of Requirement 12.8 and some of Requirement 9 already (another 10%) reducing the compliance burden by 80% appears to be a very solid investment. More importantly, removing the data from the merchant environment reduces the risk associated with compromise of payment data significantly. Summary PCI DSS compliance can be a complex and confusing project for companies to undertake. Further confusing the process are well-intentioned yet misinformed individuals that either mistakenly or less frequently intentionally confuse the issues. Companies that are required to comply with the PCI DSS should invest in understanding the specific language and requirements of both the card brand security programs such as the CISP, SDP or DSOP as well as the PCI DSS standard. With this understanding companies can begin to approach PCI DSS using the Compliance Spectrum approach. This approach allows companies to address fewer requirements by outsourcing the storage and/or processing of their cardholder data. 11

12 Companies such as ProPay and their ProtectPay solution can not only alleviate a number of PCI DSS challenges for organizations but can also significantly reduce the risk to which companies are exposed by removing and housing their data in a secure environment. About ProPay ProPay leads the market in providing simple, safe and affordable credit card processing and electronic payment services for businesses ranging from the small, home-based entrepreneur to multi-billiondollar corporations and enterprises. Whether you re a small business or a large corporation, ProPay provides simple, safe and affordable merchant services and can help secure your payment data through robust encryption and tokenization. Call us today at (888) or us at sales@propay.com. Corporate Headquarters: 3400 Ashton Boulevard, Suite 200 Lehi, UT (888) sales@propay.com ProPay, Inc. All rights reserved. The information contained in this document represents the current view of ProPay, Inc. on the issues discussed herein as of the date of publication. It should not be interpreted as a commitment on the part of ProPay, Inc. and ProPay, Inc. cannot guarantee the accuracy of the information presented after the date of publication. Specifications and content are subject to change without notice. This document is for informational purposes only. PROPAY, INC. MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS DOCUMENT. ProPay is a trademark of ProPay, Inc. Other product or company names mentioned herein may be the trademarks of their respective owners. 12

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire Instructions and Guidelines Version 1.1 February 2008 Table of Contents About this Document... 1 PCI Data Security Standard

More information

Josiah Wilkinson Internal Security Assessor. Nationwide

Josiah Wilkinson Internal Security Assessor. Nationwide Josiah Wilkinson Internal Security Assessor Nationwide Payment Card Industry Overview PCI Governance/Enforcement Agenda PCI Data Security Standard Penalties for Non-Compliance Keys to Compliance Challenges

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire Instructions and Guidelines Version 3.2 May 2016 Document Changes Date Version Description October 1, 2008 1.2 October 28,

More information

PCI Compliance Overview

PCI Compliance Overview PCI Compliance Overview 1 PCI DSS Payment Card Industry Data Security Standard Standard that is applied to: Merchants Service Providers (Banks, Third party vendors, gateways) Systems (Hardware, software)

More information

1/18/10. Walt Conway. PCI DSS in Context. Some History The Digital Dozen Key Players Cardholder Data Outsourcing Conclusions. PCI in Higher Education

1/18/10. Walt Conway. PCI DSS in Context. Some History The Digital Dozen Key Players Cardholder Data Outsourcing Conclusions. PCI in Higher Education PCI in Higher Education Walter Conway, QSA 403 Labs, LLC Walt Conway PCI consultant, blogger, trainer, speaker, author Former Visa VP Help schools become PCI compliant Represent Higher Education at PCI

More information

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer Complying with the PCI DSS All the Moving Parts Don Roeber Vice President, PCI Compliance Manager Lisa Tedeschi Assistant Vice President, Compliance Officer Types of Risk Operational Risk Normal fraud

More information

Why Is Compliance with PCI DSS Important?

Why Is Compliance with PCI DSS Important? Why Is Compliance with PCI DSS Important? The members of PCI Security Standards Council (American Express, Discover, JCB, MasterCard, and Visa) continually monitor cases of account data compromise. These

More information

Introduction to PCI DSS

Introduction to PCI DSS Month-Year Introduction to PCI DSS March 2015 Agenda PCI DSS History What is PCI DSS? / PCI DSS Requirements What is Cardholder Data? What does PCI DSS apply to? Payment Ecosystem How is PCI DSS Enforced?

More information

The PCI DSS Compliance Guide For Small Business

The PCI DSS Compliance Guide For Small Business PCI DSS Compliance in a hosted infrastructure A Rackspace White Paper Spring 2010 Summary The Payment Card Industry Data Security Standard (PCI DSS) is a global information security standard defined by

More information

TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No. 08-01 MERCHANT DEBIT AND CREDIT CARD RECEIPTS

TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No. 08-01 MERCHANT DEBIT AND CREDIT CARD RECEIPTS TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No. 08-01 MERCHANT DEBIT AND CREDIT CARD RECEIPTS 1. Introduction Debit and Credit Card Receipt Standards apply to the administration

More information

La règlementation VisaCard, MasterCard PCI-DSS

La règlementation VisaCard, MasterCard PCI-DSS La règlementation VisaCard, MasterCard PCI-DSS Conférence CLUSIF "LES RSSI FACE À L ÉVOLUTION DE LA RÉGLEMENTATION" 7 novembre 07 Serge Saghroune Overview of PCI DSS Payment Card Industry Data Security

More information

PCI DSS. CollectorSolutions, Incorporated

PCI DSS. CollectorSolutions, Incorporated PCI DSS Robert Cothran President CollectorSolutions www.collectorsolutions.com CollectorSolutions, Incorporated Founded as Florida C corporation in 1999 Approximately 235 clients in 35 states Targeted

More information

PCI Compliance. Top 10 Questions & Answers

PCI Compliance. Top 10 Questions & Answers PCI Compliance Top 10 Questions & Answers 1. What is PCI Compliance and PCI DSS? 2. Who needs to follow the PCI Data Security Standard? 3. What happens if I don t comply? 4. What are the basic requirements

More information

PCI Compliance Top 10 Questions and Answers

PCI Compliance Top 10 Questions and Answers Where every interaction matters. PCI Compliance Top 10 Questions and Answers White Paper October 2013 By: Peer 1 Hosting Product Team www.peer1.com Contents What is PCI Compliance and PCI DSS? 3 Who needs

More information

Tokenization Amplified XiIntercept. The ultimate PCI DSS cost & scope reduction mechanism

Tokenization Amplified XiIntercept. The ultimate PCI DSS cost & scope reduction mechanism Tokenization Amplified XiIntercept The ultimate PCI DSS cost & scope reduction mechanism Paymetric White Paper Tokenization Amplified XiIntercept 2 Table of Contents Executive Summary 3 PCI DSS 3 The PCI

More information

What are the PCI DSS requirements? PCI DSS comprises twelve requirements, often referred to as the digital dozen. These define the need to:

What are the PCI DSS requirements? PCI DSS comprises twelve requirements, often referred to as the digital dozen. These define the need to: What is the PCI standards council? The Payment Card Industry Standards Council is an institution set-up by American Express, Discover Financial Services, JCB, MasterCard Worldwide and Visa International

More information

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008 Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008 What is the PCI DSS? And what do the acronyms CISP, SDP, DSOP and DISC stand for? The PCI DSS is a set of comprehensive requirements

More information

PCI Compliance. How to Meet Payment Card Industry Compliance Standards. May 2015. cliftonlarsonallen.com. 2015 CliftonLarsonAllen LLP

PCI Compliance. How to Meet Payment Card Industry Compliance Standards. May 2015. cliftonlarsonallen.com. 2015 CliftonLarsonAllen LLP 2015 CliftonLarsonAllen LLP PCI Compliance How to Meet Payment Card Industry Compliance Standards May 2015 cliftonlarsonallen.com Overview PCI DSS In the beginning Each major card brand had its own separate

More information

Adyen PCI DSS 3.0 Compliance Guide

Adyen PCI DSS 3.0 Compliance Guide Adyen PCI DSS 3.0 Compliance Guide February 2015 Page 1 2015 Adyen BV www.adyen.com Disclaimer: This document is for guidance purposes only. Adyen does not accept responsibility for any inaccuracies. Merchants

More information

P R O G R E S S I V E S O L U T I O N S

P R O G R E S S I V E S O L U T I O N S PCI DSS: PCI DSS is a set of technical and operational mandates designed to ensure that all organizations that process, store or transmit credit card information maintain a secure environment and safeguard

More information

A Compliance Overview for the Payment Card Industry (PCI)

A Compliance Overview for the Payment Card Industry (PCI) A Compliance Overview for the Payment Card Industry (PCI) Many organizations are aware of the Payment Card Industry (PCI) and PCI compliance but are unsure if they are doing everything necessary. This

More information

An article on PCI Compliance for the Not-For-Profit Sector

An article on PCI Compliance for the Not-For-Profit Sector Level 8, 66 King Street Sydney NSW 2000 Australia Telephone +61 2 9290 4444 or 1300 922 923 An article on PCI Compliance for the Not-For-Profit Sector Page No.1 PCI Compliance for the Not-For-Profit Sector

More information

Becoming PCI Compliant

Becoming PCI Compliant Becoming PCI Compliant Jason Brown - brownj52@michigan.gov Enterprise Security Architect Enterprise Architecture Department of Technology, Management and Budget State of Michigan @jasonbrown17 History

More information

PCI Compliance. What is New in Payment Card Industry Compliance Standards. October 2015. cliftonlarsonallen.com. 2015 CliftonLarsonAllen LLP

PCI Compliance. What is New in Payment Card Industry Compliance Standards. October 2015. cliftonlarsonallen.com. 2015 CliftonLarsonAllen LLP cliftonlarsonallen.com PCI Compliance What is New in Payment Card Industry Compliance Standards October 2015 Overview PCI DSS In the beginning Each major card brand had its own separate criteria for implementing

More information

Payment Card Industry - Achieving PCI Compliance Steps Steps

Payment Card Industry - Achieving PCI Compliance Steps Steps CUR RITY SE Data Security Requirements for K-12 January 28, 2010 Payment Card Industry (PCI) SE CUR RITY 1 Welcome To Join The Voice Conference Dial 866-939-3921 Technical issues press 0 Q & A We ll leave

More information

Puzzled about PCI compliance? Proactive ways to navigate through the standard for compliance

Puzzled about PCI compliance? Proactive ways to navigate through the standard for compliance Puzzled about PCI compliance? Proactive ways to navigate through the standard for compliance March 29, 2012 1:00 p.m. ET If you experience any technical difficulties, please contact 888.228.0988 or support@learnlive.com

More information

How To Protect Your Business From A Hacker Attack

How To Protect Your Business From A Hacker Attack Payment Card Industry Data Security Standards The payment card industry data security standard PCI DSS Visa and MasterCard have developed the Payment Card Industry Data Security Standard or PCI DSS as

More information

What Every Business Should Know About PCI Compliance

What Every Business Should Know About PCI Compliance What Every Business Should Know About PCI Compliance www.bullseyetelecom.com As technology advances, identity thieves are also finding easier ways to steal vital information such as credit card data. Businesses

More information

PDQ Guide for the PCI Data Security Standard Self-Assessment Questionnaire C (Version 1.1)

PDQ Guide for the PCI Data Security Standard Self-Assessment Questionnaire C (Version 1.1) PDQ has created an Answer Guide for the Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire C to help wash operators complete questionnaires. Part of the Access Customer Management

More information

PCI DSS 101 FOR CTOs AND BUSINESS EXECUTIVES

PCI DSS 101 FOR CTOs AND BUSINESS EXECUTIVES PCI DSS 101 FOR CTOs AND BUSINESS EXECUTIVES CUTTING THROUGH THE COMPLEXITY AND CONFUSION Over the years, South African retailers have come under increased pressure to gain PCI DSS (Payment Card Industry

More information

PCI Overview. PCI-DSS: Payment Card Industry Data Security Standard

PCI Overview. PCI-DSS: Payment Card Industry Data Security Standard PCI-DSS: Payment Card Industry Data Security Standard Why is this important? Cardholder data and personally identifying information are easy money That we work with this information makes us a target That

More information

Project Title slide Project: PCI. Are You At Risk?

Project Title slide Project: PCI. Are You At Risk? Blank slide Project Title slide Project: PCI Are You At Risk? Agenda Are You At Risk? Video What is the PCI SSC? Agenda What are the requirements of the PCI DSS? What Steps Can You Take? Available Services

More information

Strategies To Effective PCI Scoping ISACA Columbus Chapter Presentation October 2008

Strategies To Effective PCI Scoping ISACA Columbus Chapter Presentation October 2008 Strategies To Effective PCI Scoping ISACA Columbus Chapter Presentation October 2008 Matthew T. Davis SecureState, LLC mdavis@securestate.com SecureState Founded in 2001, Based on Cleveland Specialized

More information

PCI DSS Compliance & Security Awareness Program at UST

PCI DSS Compliance & Security Awareness Program at UST PCI DSS Compliance & Security Awareness Program at UST PCI DSS in a Nutshell Who? What? Where? When? Applicable to all UST employees that are exposed to any cardholder data while performing their job responsibilities

More information

Payment Card Industry Data Security Standard Explained

Payment Card Industry Data Security Standard Explained Payment Card Industry Data Security Standard Explained Agenda Overview of PCI DSS Compliance Levels and Requirements PCI DSS in More Detail Discussion, Questions and Clarifications Overview of PCI-DSS

More information

PCI DATA SECURITY STANDARD OVERVIEW

PCI DATA SECURITY STANDARD OVERVIEW PCI DATA SECURITY STANDARD OVERVIEW According to Visa, All members, merchants and service providers must adhere to the Payment Card Industry (PCI) Data Security Standard. In order to be PCI compliant,

More information

Initial Roadmap: Point-to-Point Encryption Technology and PCI DSS Compliance

Initial Roadmap: Point-to-Point Encryption Technology and PCI DSS Compliance Emerging Technology Whitepaper Initial Roadmap: Point-to-Point Encryption Technology and PCI DSS Compliance For Transmissions of Cardholder Data and Sensitive Authentication Data Program Guide Version

More information

A PCI Journey with Wichita State University

A PCI Journey with Wichita State University A PCI Journey with Wichita State University Blaine Linehan System Software Analyst III Financial Operations & Business Technology Division of Administration & Finance 1 Question #1 How many of you know

More information

John B. Dickson, CISSP October 11, 2007

John B. Dickson, CISSP October 11, 2007 PCI Compliance for Your Organization PCI Compliance for Your Organization John B. Dickson, CISSP October 11, 2007 Learning objectives for today s session Overview of PCI who, what, why Overview of PCI

More information

Achieving PCI Compliance for Your Site in Acquia Cloud

Achieving PCI Compliance for Your Site in Acquia Cloud Achieving PCI Compliance for Your Site in Acquia Cloud Introduction PCI Compliance applies to any organization that stores, transmits, or transacts credit card data. PCI Compliance is important; failure

More information

E Pay. A Case Study in PCI Compliance. Illinois State Treasurer. Dan Rutherford

E Pay. A Case Study in PCI Compliance. Illinois State Treasurer. Dan Rutherford E Pay A Case Study in PCI Compliance Illinois State Treasurer Dan Rutherford What is PCI? The Payment Card Industry s Data Security Standard states: PCI Data Security Requirements applies to all members,

More information

DATA SECURITY. Payment Card Industry (PCI) Compliance Steps for Organizations May 26, 2010. 2010 Merit Member Conference

DATA SECURITY. Payment Card Industry (PCI) Compliance Steps for Organizations May 26, 2010. 2010 Merit Member Conference 2010 Merit Member Conference Compliance Steps for Organizations May 26, 2010 Payment Card Industry (PCI) 1 Welcome 2 Welcome Q & A We ll leave time to address questions during the last 15 minutes of the

More information

AISA Sydney 15 th April 2009

AISA Sydney 15 th April 2009 AISA Sydney 15 th April 2009 Where PCI stands today: Who needs to do What, by When Presented by: David Light Sense of Security Pty Ltd Agenda Overview of PCI DSS Compliance requirements What & When Risks

More information

Are You Ready For PCI v 3.0. Speaker: Corbin DelCarlo Institution: McGladrey LLP Date: October 6, 2014

Are You Ready For PCI v 3.0. Speaker: Corbin DelCarlo Institution: McGladrey LLP Date: October 6, 2014 Are You Ready For PCI v 3.0 Speaker: Corbin DelCarlo Institution: McGladrey LLP Date: October 6, 2014 Today s Presenter Corbin Del Carlo QSA, PA QSA Director, National Leader PCI Services Practice 847.413.6319

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance Card-not-present Merchants, All Cardholder Data Functions Fully Outsourced Version 3.0 February

More information

Payment Card Industry Data Security Standard Training. Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc.

Payment Card Industry Data Security Standard Training. Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc. Payment Card Industry Data Security Standard Training Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc. March 27, 2012 Agenda Check-In 9:00-9:30 PCI Intro and History

More information

PCI DSS 3.0 Overview. OSU Business Affairs Business Affairs PIT Crew - Project, Improvement, & Technology Robin Whitlock

PCI DSS 3.0 Overview. OSU Business Affairs Business Affairs PIT Crew - Project, Improvement, & Technology Robin Whitlock PCI DSS 3.0 Overview OSU Business Affairs Business Affairs PIT Crew - Project, Improvement, & Technology Robin Whitlock 01/16/2015 Purpose of Today s Presentation To provide an overview of PCI 3.0 based

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Self-Assessment Questionnaire D Service Providers For use with PCI DSS Version 3.1 Revision 1.1 July 2015 Section 1: Assessment

More information

What a Processor Needs from a University to Validate Compliance

What a Processor Needs from a University to Validate Compliance What a Processor Needs from a University to Validate Compliance Lisa T. Conroy Merchant Compliance Manager Vantiv May 24, 2016 Disclosures The information included in this presentation is for information

More information

Data Security Standard (DSS) Compliance. SIFMA June 13, 2012

Data Security Standard (DSS) Compliance. SIFMA June 13, 2012 Payment Card Industry (PCI) Data Security Standard (DSS) Compliance SIFMA June 13, 2012 EisnerAmper Consulting Services Group Overview of EisnerAmper Fifth fhlargest accounting firm in the Metro New York

More information

The Relationship Between PCI, Encryption and Tokenization: What you need to know

The Relationship Between PCI, Encryption and Tokenization: What you need to know October 2014 The Relationship Between PCI, Encryption and Tokenization: What you need to know Mike English Executive Director, Product Development Heartland Payment Systems 2014 Heartland Payment Systems,

More information

PCI DSS Compliance for Cloud-Based Contact Centers Mitigating Liability through the Standardization of Processes for cloud-based contact centers.

PCI DSS Compliance for Cloud-Based Contact Centers Mitigating Liability through the Standardization of Processes for cloud-based contact centers. PCI DSS Compliance for Cloud-Based Contact Centers Mitigating Liability through the Standardization of Processes for cloud-based contact centers. White Paper January 2013 1 INTRODUCTION The PCI SSC (Payment

More information

Spokane Airport Board (Spokane International Airport, Airport Business Park, Felts Field) Addendum #1 - Q&A

Spokane Airport Board (Spokane International Airport, Airport Business Park, Felts Field) Addendum #1 - Q&A Spokane Airport Board (Spokane International Airport, Airport Business Park, Felts Field) Request for Proposals (RFP) for PCI DSS COMPLIANCE SERVICES Project # 15-49-9999-016 Addendum #1 - Q&A May 29,

More information

Understanding the SAQs for PCI DSS version 3

Understanding the SAQs for PCI DSS version 3 Understanding the SAQs for PCI DSS version 3 The PCI DSS self-assessment questionnaires (SAQs) are validation tools intended to assist merchants and service providers report the results of their PCI DSS

More information

WHITE PAPER. PCI Basics: What it Takes to Be Compliant

WHITE PAPER. PCI Basics: What it Takes to Be Compliant WHITE PAPER PCI Basics: What it Takes to Be Compliant Introduction A long-running worldwide advertising campaign by Visa states that the card is accepted everywhere you want to be. Unfortunately, and through

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Standard Attestation of Compliance for Self-Assessment Questionnaire D Service Providers Version 3.1 April 2015 Section 1: Assessment Information Instructions for Submission

More information

Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015

Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015 Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015 I. PURPOSE The purpose of this policy is to establish guidelines for processing charges on Payment Cards to protect

More information

How To Protect Your Credit Card Information From Being Stolen

How To Protect Your Credit Card Information From Being Stolen Visa Account Information Security Tool Kit Welcome to the Visa Account Information Security Program 2 Contents 1. Securing cardholder data is everyone s concern 4 2. Visa Account Information Security (AIS)

More information

Payment Card Industry Standard - Symantec Services

Payment Card Industry Standard - Symantec Services Payment Card Industry Standard - Symantec Services The Payment Card Industry Data Security Standard (PCI, or PCI DSS) was developed by the PCI Security Standards Council to assure cardholders that their

More information

University of Sunderland Business Assurance PCI Security Policy

University of Sunderland Business Assurance PCI Security Policy University of Sunderland Business Assurance PCI Security Policy Document Classification: Public Policy Reference Central Register IG008 Policy Reference Faculty / Service IG 008 Policy Owner Chief Financial

More information

Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions

Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions PCI/PA-DSS FAQs Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions What is PCI DSS? The Payment Card Industry Data

More information

PCI v2.0 Compliance for Wireless LAN

PCI v2.0 Compliance for Wireless LAN PCI v2.0 Compliance for Wireless LAN November 2011 This white paper describes how to build PCI v2.0 compliant wireless LAN using Meraki. Copyright 2011 Meraki, Inc. All rights reserved. Trademarks Meraki

More information

Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS)

Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS) Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS) What is PCI DSS? The 12 Requirements Becoming compliant with SaferPayments Understanding the jargon SaferPayments Be smart.

More information

Important Info for Youth Sports Associations

Important Info for Youth Sports Associations Important Info for Youth Sports Associations What the Heck is PCI DSS and Why Should I Care? Joe Posey Terrapin Financial Services Your Club is an ecommerce Business You accept online registration over

More information

IT Security Compliance PCI DSS FOR MERCHANTS THE PAYMENT CARD INDUSTRY DATE SECURITY STANDARD WHITE PAPER

IT Security Compliance PCI DSS FOR MERCHANTS THE PAYMENT CARD INDUSTRY DATE SECURITY STANDARD WHITE PAPER July 9 th, 2012 Prepared By: Mark Akins PCI QSA, CISSP, CISA WHITE PAPER IT Security Compliance PCI DSS FOR MERCHANTS THE PAYMENT CARD INDUSTRY DATE SECURITY STANDARD PCI DSS for Merchants The Payment

More information

North Carolina Office of the State Controller Technology Meeting

North Carolina Office of the State Controller Technology Meeting PCI DSS Security Awareness Training North Carolina Office of the State Controller Technology Meeting April 30, 2014 agio.com A Note on Our New Name Secure Enterprise Computing was acquired as the Security

More information

PAYMENT CARD INDUSTRY (PCI) COMPLIANCE HISTORY & OVERVIEW

PAYMENT CARD INDUSTRY (PCI) COMPLIANCE HISTORY & OVERVIEW PAYMENT CARD INDUSTRY (PCI) COMPLIANCE HISTORY & OVERVIEW David Kittle Chief Information Officer Chris Ditmarsch Network & Security Administrator Smoker Friendly International / The Cigarette Store Corp

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire C and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire C and Attestation of Compliance Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire C and Attestation of Compliance Payment Application Connected to Internet, No Electronic Cardholder Data Storage Version

More information

Cal Poly PCI DSS Compliance Training and Information. Information Security http://security.calpoly.edu 1

Cal Poly PCI DSS Compliance Training and Information. Information Security http://security.calpoly.edu 1 Cal Poly PCI DSS Compliance Training and Information Information Security http://security.calpoly.edu 1 Training Objectives Understanding PCI DSS What is it? How to comply with requirements Appropriate

More information

Payment Card Industry Compliance Overview

Payment Card Industry Compliance Overview January 31, 2014 11:30am 12:30pm Central Hosted by: Texas.gov Presented by: Jayne Holland Barbara Brinson Payment Card Industry Compliance Overview Securing Government Payments Audio Dial In: 866-740-1260

More information

PC-DSS Compliance Strategies. 2011 NDUS CIO Retreat July 27, 2011 Theresa Semmens, CISA

PC-DSS Compliance Strategies. 2011 NDUS CIO Retreat July 27, 2011 Theresa Semmens, CISA PC-DSS Compliance Strategies 2011 NDUS CIO Retreat July 27, 2011 Theresa Semmens, CISA True or False Now that my institution has outsourced credit card processing, I don t have to worry about compliance?

More information

MasterCard PCI & Site Data Protection (SDP) Program Update. Academy of Risk Management Innovate. Collaborate. Educate.

MasterCard PCI & Site Data Protection (SDP) Program Update. Academy of Risk Management Innovate. Collaborate. Educate. MasterCard PCI & Site Data Protection (SDP) Program Update Academy of Risk Management Innovate. Collaborate. Educate. The Payment Card Industry Security Standards Council (PCI SSC) Open, Global Forum Founded

More information

PCI Compliance Training

PCI Compliance Training PCI Compliance Training 1 PCI Training Topics Applicable PCI Standards Compliance Requirements Compliance of Unitec products Requirements for compliant installation and use of products 2 PCI Standards

More information

PAYMENT CARD INDUSTRY (PCI) ANNUAL TRAINING DECEMBER 10, 2009 WESTERN ILLINOIS UNIVERSITY OFFICE OF THE CTSO & BUSINESS SERVICES

PAYMENT CARD INDUSTRY (PCI) ANNUAL TRAINING DECEMBER 10, 2009 WESTERN ILLINOIS UNIVERSITY OFFICE OF THE CTSO & BUSINESS SERVICES PAYMENT CARD INDUSTRY (PCI) ANNUAL TRAINING DECEMBER 10, 2009 WESTERN ILLINOIS UNIVERSITY OFFICE OF THE CTSO & BUSINESS SERVICES AGENDA PCI Players and Roles Merchant Requirements Keys To Successful PCI

More information

The State of Security and Compliance for E- Commerce and Retail

The State of Security and Compliance for E- Commerce and Retail The State of Security and Compliance for E- Commerce and Retail Current state of security PCI regulations and compliance Does the data you hold require PCI compliance Security and safeguarding against

More information

PCI DSS Overview. By Kishor Vaswani CEO, ControlCase

PCI DSS Overview. By Kishor Vaswani CEO, ControlCase PCI DSS Overview By Kishor Vaswani CEO, ControlCase Agenda About PCI DSS PCI DSS Applicability to Banks, Merchants and Service Providers PCI DSS Technical Requirements Overview of PCI DSS 3.0 Changes Key

More information

HOW SECURE IS YOUR PAYMENT CARD DATA? COMPLYING WITH PCI DSS

HOW SECURE IS YOUR PAYMENT CARD DATA? COMPLYING WITH PCI DSS HOW SECURE IS YOUR PAYMENT CARD DATA? COMPLYING WITH PCI DSS August 23, 2011 MOSS ADAMS LLP 1 TODAY S PRESENTERS Presenters Francis Tam, CPA, CISA, CISM, CITP, CRISC, PCI QSA Managing Director, IT Security

More information

PCI Standards: A Banking Perspective

PCI Standards: A Banking Perspective Slide 1 PCI Standards: A Banking Perspective Bob Brown, CISSP Wachovia Corporate Information Security Slide 2 Agenda 1. Payment Card Initiative History 2. Description of the Industry 3. PCI-DSS Control

More information

PCI DSS Presentation University of Cincinnati

PCI DSS Presentation University of Cincinnati PCI DSS Presentation University of Cincinnati Quick PCI Level Set Higher Ed Challenges Getting Compliant Application w/ customers Q& A PCI DSS Payment Card Industry Data Security Standard What is the PCI

More information

Information Sheet. PCI DSS Overview

Information Sheet. PCI DSS Overview The payment card industry (PCI) protects cardholder data through technical and operations standard set by its Council. Compliance with PCI standards is mandatory. It is enforced by the major payment card

More information

PCI DSS Compliance. 2015 Information Pack for Merchants

PCI DSS Compliance. 2015 Information Pack for Merchants PCI DSS Compliance 2015 Information Pack for Merchants This pack contains general information regarding PCI DSS compliance and does not take into account your business' particular requirements. ANZ recommends

More information

Achieving Compliance with the PCI Data Security Standard

Achieving Compliance with the PCI Data Security Standard Achieving Compliance with the PCI Data Security Standard June 2006 By Alex Woda, MBA, CISA, QDSP, QPASP This article describes the history of the Payment Card Industry (PCI) data security standards (DSS),

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance All other SAQ-Eligible Merchants and Service Providers Version 2.0 October 2010 Document

More information

Payment Card Industry Data Security Standard (PCI DSS)

Payment Card Industry Data Security Standard (PCI DSS) Payment Card Industry Data Security Standard (PCI DSS) What is PCI SSC? A 12 year old independent industry standards body providing oversight of the development and management of Payment Card Industry

More information

PCI DSS v3.0 SAQ Eligibility

PCI DSS v3.0 SAQ Eligibility http://www.ambersail.com Disclaimer: The information in this document is provided "as is" without warranties of any kind, either express or implied, including, without limitation, implied warranties of

More information

PCI Requirements Coverage Summary Table

PCI Requirements Coverage Summary Table StillSecure PCI Complete Managed PCI Compliance Solution PCI Requirements Coverage Summary Table January 2013 Table of Contents Introduction... 2 Coverage assumptions for PCI Complete deployments... 2

More information

PCI DSS Gap Analysis Briefing

PCI DSS Gap Analysis Briefing PCI DSS Gap Analysis Briefing The University of Chicago October 1, 2012 Walter Conway, QSA 403 Labs, LLC Agenda The PCI DSS ecosystem - Key players, roles - Cardholder data - Merchant levels and SAQs UofC

More information

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program MERCHANTS Can Level 1 merchants currently use internal auditors to perform an onsite assessment? Yes. However, after June 30,

More information

Payment Card Industry Data Security Standards

Payment Card Industry Data Security Standards Payment Card Industry Data Security Standards Discussion Objectives Agenda Introduction PCI Overview and History The Protiviti Difference Questions and Discussion 2 2014 Protiviti Inc. CONFIDENTIAL: This

More information

Version 7.4 & higher is Critical for all Customers Processing Credit Cards!

Version 7.4 & higher is Critical for all Customers Processing Credit Cards! Version 7.4 & higher is Critical for all Customers Processing Credit Cards! Data Pro Accounting Software has met the latest credit card processing requirements with its release of Version 7.4 due to the

More information

Merchant guide to PCI DSS

Merchant guide to PCI DSS Merchant guide to PCI DSS Contents What is PCI DSS and why was it introduced?... 3 Who needs to become PCI DSS compliant?... 3 BOIPA Simple PCI DSS - 3 step approach to helping businesses... 3 What does

More information

PCI DSS 3.0 Changes Bill Franklin Executive IT Auditor bfranklin@compassitc.com January 23, 2014

PCI DSS 3.0 Changes Bill Franklin Executive IT Auditor bfranklin@compassitc.com January 23, 2014 PCI DSS 3.0 Changes Bill Franklin Executive IT Auditor bfranklin@compassitc.com January 23, 2014 Agenda Introduction PCI DSS 3.0 Changes What Can I Do to Prepare? When Do I Need to be Compliant? Questions

More information

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program MERCHANTS Can Level 1 merchants currently use internal auditors to perform an onsite assessment? Yes. However, after June 30,

More information

SecurityMetrics Introduction to PCI Compliance

SecurityMetrics Introduction to PCI Compliance SecurityMetrics Introduction to PCI Compliance Card Data Compromise What is a card data compromise? A card data compromise occurs when payment card information is stolen from a merchant. Some examples

More information

The following are responsible for the accuracy of the information contained in this document:

The following are responsible for the accuracy of the information contained in this document: AskUGA 1 of 5 Credit/Debit Cards Responsible administrator: Senior Vice President for Finance and Administration Related Procedure: The Credit/Debit Card Processing Procedures Responsible department: Bursar's

More information

Payment Card Industry Data Security Standard

Payment Card Industry Data Security Standard Payment Card Industry Data Security Standard Abhinav Goyal, B.E.(Computer Science) MBA Finance Final Trimester Welingkar Institute of Management ISACA Bangalore chapter 13 th February 2010 Credit Card

More information

VISA EUROPE ACCOUNT INFORMATION SECURITY (AIS) PROGRAMME FREQUENTLY ASKED QUESTIONS (FAQS)

VISA EUROPE ACCOUNT INFORMATION SECURITY (AIS) PROGRAMME FREQUENTLY ASKED QUESTIONS (FAQS) VISA EUROPE ACCOUNT INFORMATION SECURITY (AIS) PROGRAMME FREQUENTLY ASKED QUESTIONS (FAQS) Q1: What is the purpose of the AIS programme? Q2: What exactly is the Payment Card Industry (PCI) Data Security

More information

Frequently Asked Questions

Frequently Asked Questions PCI Compliance Frequently Asked Questions Table of Content GENERAL INFORMATION... 2 PAYMENT CARD INDUSTRY DATA SECURITY STANDARD (PCI DSS)...2 Are all merchants and service providers required to comply

More information

Credit Card Processing, Point of Sale, ecommerce

Credit Card Processing, Point of Sale, ecommerce Credit Card Processing, Point of Sale, ecommerce Compliance, Self Auditing, and More John Benson Kurt Willey HACKS REGULATIONS Greater Risk for Merchants Topics Compliance Changes Scans Self Audits

More information

LESS IS MORE PCI DSS SCOPING DEMYSTIFIED

LESS IS MORE PCI DSS SCOPING DEMYSTIFIED LESS IS MORE PCI DSS SCOPING DEMYSTIFIED Lauren Holloway PCI Security Standards Council Emma Sutcliffe PCI Security Standards Council Session ID: Session Classification: DSP-W21 Intermediate Who s Here

More information