Agenda: A PCI DSS Deep Dive

Size: px
Start display at page:

Download "Agenda: A PCI DSS Deep Dive"

Transcription

1 Understanding and Managing PCI DSS Walt Conway, CPISM

2 Walt Conway PCI consultant, blogger, trainer, speaker, author Former Visa VP Help schools become PCI compliant Represent Higher Education at PCI Council Recently joined 403 Labs, a QSA firm 2

3 Agenda: A PCI DSS Deep Dive 1:00 to 2:15 PCI DSS in Context PCI DSS basics Security Outsourcing 2:30 to 3:30 Surviving compliance Recent PCI developments Pretty good practices 3

4 PCI DSS in Context Some History The Digital Dozen Key Players Merchant Levels Validating Compliance Cardholder Data 4

5 First, Some PCI Basics PCI DSS: Payment Card Industry Data Security Standard Goal is to protect Cardholder Data (CHD) Primary Account Number (PAN) Also addresses track data, security codes, PINs If you take plastic, PCI applies to you Store, process, or transmit cardholder data P-cards, travel cards may be in scope PCI Compliance is by institution Most schools use Self-Assessment Questionnaire (SAQ) 5

6 PCI DSS: 6 Goals, 12 Requirements 6

7 PCI DSS Scope The cardholder data environment can include: Network components (firewall, switches, routers ) Servers (web, database, mail ) Applications (purchased, custom, internal, external) Policies, procedures Anything that stores, transmits, or processes cardholder data is in scope If you don t need it, don t keep it 7

8 Key Players Global forum to enhance global payment security PCI DSS, PA DSS, PIN PED Approve assessors (QSAs) and scan vendors (ASVs) Develop Self-Assessment Questionnaires i (SAQ) Develop and publish PCI documentation Participating Organizations include NACUBO 8

9 Key Players Five Payment brands Track compliance and enforce standards (fines, sanctions) Determine event response (forensics) Define merchant levels Acquirers (Merchant Banks) Set merchant level Certify compliance Approve compensating controls 9

10 Merchant Levels Level Visa and MasterCard Amex 1 > 6 million Visa/MC trans/year Compromise in last year Assigned by Visa/MC > 2.5 million Amex trans/year Assigned by Amex 2 1 to 6 million Visa/MC trans/year 50,000 to 2 million Amex trans/year 3 20,000 to 1 million Visa/MC e-commerce trans/year All other Amex merchants 4 All other Visa/MasterCard merchants 10

11 Quiz: What s My Merchant Level? 5 million Visa, 3 million M/C, 1 million Amex (9 million total) transactions/year Level 2: levels are set by volume per brand 800,000 card-present trans/year, all Visa Level 4 50,000 e-commerce trans/year, all M/C Level 3 5,000 trans/year transmitted for another merchant Trick question - you may be a Service Provider 11

12 Cardholder Data 12

13 Cardholder Data Source: PCI SSC 13

14 Why Are You Keeping Those Data!?! Policy: Store no PANs on campus anywhere But what about? Recurring payments acquirer has alternatives Chargebacks, refunds let acquirer store PAN data Legal requirements these apply to banks, not you Paper receipts reprogram terminals or upgrade to truncate t both copies POS software stores PANs reconfigure or replace Limiting PCI scope makes your life easier 14

15 Compliance Validation Level Visa and MasterCard Amex 1 Annual on-site assessment (QSA or Internal Audit) Quarterly network scan (ASV) Report on Compliance (ROC) based on Security Audit Guidelines Annual on-site Security Audit (QSA or Internal Audit) Quarterly network scans (ASV) Security Audit to Trustwave 2 Annual Self-Assessment Quarterly network scan (ASV) Questionnaire (SAQ) Quarterly network scan (ASV) 3 Annual SAQ Quarterly network scan (ASV) 4 As set by acquirer: Annual SAQ Quarterly network scan (ASV) Recommend quarterly network scan (ASV) 15

16 Merchant Compliance 16

17 Validating Compliance Validation is by institution Don t confuse Merchant Level and Merchant ID Level is for compliance validation ID is for accounting Acquirer may combine IDs for PCI validation Simplified SAQs Four versions: depends on card environment Limiting PCI scope simplifies validation No electronic CHD stored 17

18 Self-Assessment Questionnaires (SAQ) For merchants who don t need an on-site security assessment (L2-4) Two parts Attestation of Compliance Requirements Simplified SAQs: you do not keep electronic cardholder data 18 Walter Conway Associates LLC 2009

19 Which is Right for You? SAQ Validation Type Description SAQ 1 Card-not-present merchants, all cardholder A data functions outsourced 2 Imprint-only merchants, no cardholder data storage 3 Stand-alone terminal merchants, no cardholder data storage 4 Merchants with POS systems connected to the C Internet, no cardholder data storage 5 All other merchants and service providers D B B 19 Walter Conway Associates LLC 2009

20 Simplified SAQs Your life may have gotten easier SAQ A and B bonus: no scans More incentive not to keep cardholder data Retaining cardholder data means SAQ D Time answering lots of questions If you don t need it, don t keep it 20 Walter Conway Associates LLC 2009

21 Compliance OMG But we outsourced our e-commerce Staff use PCs to enter MOTO transactions ti P-cards and travel cards don t count If you store the PANs, they can be in scope We didn t know we stored the data Non-compliant POS devices, PCs, servers, 21

22 Staying Compliant PCI is backward looking Compliance today says s nothing about tomorrow You are one change from being non-compliant Establish and follow policies Educate, train, communicate Get trained and/or get help 22 Walter Conway Associates LLC 2009

23 Implications of PCI Your costs will go up Cost to get and remain PCI compliant Non-compliance costs more You will change the way you do business Do you want to be in the payment business? Maybe fewer campus merchants take plastic Limiting access to cardholder data Conclusion: PCI is a business issue 23

24 Security The Bad Guys Dangerous Places: Pwned! Higher Ed top 10 Threats The Insider Threat 24

25 Security: It s About the Data Five emerging g threats Malware Botnets Cyber warfare VoIP and mobile devices Evolving cyber crime economy Data will continue to be the primary motive behind future cyber crime. 25

26 PCI DSS Role The purpose of PCI DSS: To protect t cardholder dhld dt data To keep you and your institution out of the headlines PCI is a data protection standard Not a fraud prevention measure PCI does not make you secure 26

27 Gone Phishing 27

28 Some Links are Good 28

29 30 Seconds PWNED! 29

30 I m Im OK, I have a Mac 30

31 Are Users Listening? Is Anybody Listening? Source: Psychology Department, North Carolina State University 31

32 Higher Ed Top 10 Security Threats 1. Malware, botnets 6. Outsource partners 2. Thieves 3. Staff members 4. Professors 7. Social networks 8. Phishing 9. Cell Phones 5. Students 10. Spammers 32

33 The Insider Threat Well-intentioned staff Just trying to do their jobs Self-interested or malicious staff Intentionally download apps or visit prohibited sites Economy is affecting this group Trusted partners Third-parties with insider privileges 33

34 The Insider Threat 20% of users changed security settings to access unauthorized websites Over 80% of enterprises show Google application activity, and nearly all evidence peer-to-peer applications 35% of users consciously violate internal security policies (to expedite their work) Over 50% of employees who left their job in 2008 took some company confidential information with them 34

35 Your Staff and Laptops Managers: 52% have employer-supplied data encryption 56% disengage their laptop encryption 57% write down - and 61% share their passwords IT Security pros: 92% report their organization had lost/stolen laptops 71% resulted in a data breach Question: Would you let a stranger use your laptop to check their ? Source: Ponemon Institute and Absolute Software Corp.,

36 Your Staff and USB Drives Personal thumb drives pose risks Found devices a new attack vector Stick phishing, thumb sucking Honey Stick Project Train users or as mom said: Don t put that in your mouth! Question: Do you let staff copy data and work on their home computer? 36

37 Your Staff and the Web People under the age of 28 are engaging in online behavior that could expose their organizations to data leakage and theft. 60% of young staff "are either unaware of their companies' IT policies or are not inclined to follow them. 37

38 Security: Why Care? Expense: lawsuits, financial liability, fixing systems Lost productivity Reputation (brand) State laws requiring notification and and often more The number of Higher Ed breaches is too high 38

39 Security: Why Care? 39

40 Outsourcing Service Providers vs. Applications PA DSS A Strategy, Not a Panacea 40

41 Outsourcing Strategic question: Do you want to be in the payments business? Outsourcing some or all processing can simplify your path to PCI compliance Service Providers You use their systems, services Software Application Vendors You buy a software package to run on your system 41

42 Service Providers They store, transmit, or process cardholder data on your behalf You are still responsible Ensure service providers are PCI compliant Validate, and include PCI compliance in contract Control third-party connections Visa website lists PCI-compliant service providers 42

43 Software Applications Payment Application Data Security Standard (PA DSS) Compliant third-party applications for merchants, processors Includes payment modules of larger package systems (ERP) PA DSS is for third-party payment application software used in authorization or settlement Not for internally-developed or customized applications Not for back-office or database applications PA DSS does not address functionality Got an RFP coming? Use the list! 43

44 PA DSS is Mandated 44

45 Outsourcing To Do List Check all payment vendors for PCI/PA DSS compliance POS, ERP, e-commerce, payment application Confirm your versions are compliant Update contracts to reflect PCI Appendix A Check for vendor training opportunities Compare implementation with vendor implementation guide Schedule upgrades to minimize costs 45

46 Outsourcing and the Law of Unintended Consequences PCI scope creep You outsource e-commerce payments But mail, phone, fax orders persist (e.g., donations, other MOTO transactions) School staff enter transactions using outsourced system Result: staff PCs may now be in scope for PCI 46

47 Recent Developments in PCI DSS PCI DSS Version 1.2 The PCI Council s Quality Assurance Program Special Interest Groups 47

48 PCI DSS v1.2 PCI Version 1.2 effective October 1, 2008 Update lifecycle: 2 years Clarification more than changes Language, terms Eliminate redundancies in previous version Consolidate documentation 48

49 Build and Maintain a Secure Network Req 1: Firewalls Configuration requirements apply both to firewalls and routers Timing flexibility in reviewing firewall rules, from quarterly to every 6 months Req 2 No vendor default passwords Applies to wireless OK to broadcast SSIDs Replaced WEP references to emphasize strong encryption 49

50 Protect Cardholder Data Req 3: Protect CHD Terminology (PAN, strong cryptography ) Disk encryption emphasizes local user databases Req 4: Encrypt CHD over open networks No new WEP after March 31, 2009 No WEP at all after June 30,

51 Vulnerability Management Program Req 5: AV software Applies to all system types AV must address all known types of malware Req 6: Develop secure systems Flexibility to use a risk-based approach when installing gpatches 6.6 mandated (public-facing web apps) 51

52 Strong Access Control Req 7: Restrict access to CHD Clarified language g for testing Req 8: Unique ID to each person Verify passwords are unreadable in storage and communication Req 9: Restrict physical access Visit offsite storage sites at least annually Flexibility in access control mechanisms (e.g., cameras) Requirement to secure media includes paper Clarify media destruction requirements 52

53 Monitor and Test Networks Req 10: Track all access to CHD Logs must be copied to an internal server Audit trail history must be quickly accessible Req 11: Test systems and processes Guidance on wireless analyzers and wireless IDS/IPS Must use ASV for quarterly vulnerability scans Require internal and external penetration tests, but do not need to use a QSA or ASV for these 53

54 Security Policies Req 12: Information security policies More examples of technologies covered including remote access, wireless, removable electronic media, use, internet use, laptops, PDAs Employees acknowledge internal policies i at least annually Require policies to manage and monitor service providers 54

55 PCI Council Initiatives PA DSS Applies to third-party software Includes payment modules of larger systems Quality Assurance Program Need for consistency: Hashing with Excel, 20 Fence, change encryption algorithm annually List assessors In Remediation Revocation is an option Rely on Merchant feedback 55

56 Other PCI Council Efforts Unattended Payment Terminals Increasingly used for vending, ticketing Council adopting standards (like PED) Special Interest Group (SIG) efforts Two SIGs today (Pre-authorization Data; Wireless) More coming? (Virtualization, Scope, ) 56

57 Some PCI-DSS Pretty Good Practices 57

58 How Schools Address PCI Treasury Institute for Higher Education PCI workshop attendees, May responses, Higher Ed institutions nationwide 76% public institutions From <10 to 200+ campus merchants 58 Walter Conway Associates LLC 2009

59 How Schools Address PCI 50% said Finance leads PCI, rest shared with IT 68% fund PCI compliance centrally (changing?) Between 1 and 1.5 FTE dedicated to PCI 50% or less had key policies in place Schools somewhat satisfied with acquirer support Over 50% experienced a data breach (some fined) 59 Walter Conway Associates LLC 2009

60 From PCI Workshops Secure top management commitment Develop your pitch: PCI is a business not a security issue Budget adequately: PCI is a program not a project Build a dedicated, multidisciplinary team Inventory data, processes, vendors Ask, interpret, verify, explore where stuff is, where it goes Engage stakeholders, communicate Hold users accountable for behavior (consequences) 60

61 Have a Strategy Map transaction and data flow Payments Analysis Manage scope: don t retain cardholder data Find and eliminate i prohibited data IPOS, logs, databases, spreadsheets, Search for rogue databases Search for sensitive numbers Easiest path: don t keep cardholder data! 61

62 Some Pretty Good Practices Think before you act, or PCI Requirement 0 Understand d cardholder data and cardholder data environment Understand PCI before implementing solutions Eliminate storing cardholder data Then tell people about it! 62

63 Some Pretty Good Practices Get trained Visa has 2-day deep dive Treasury Institute PCI Workshops SPSP training for CPISM/A certification MasterCard website has on-line training Use the PCI SSC resources Audit Guidelines Technical FAQ 63

64 Some Pretty Good Practices Monitor card alerts and bulletins Monitor PCI and security blogs and forums Keep up to date Ask questions, get expert help Collaborate: share experiences, good and bad 64

65 Some Pretty Good Practices Raise security awareness on campus Identify repeat offenders who lose (stolen) devices, download malware, etc. Publicize names Consequences 65

66 Some Pretty Good Practices Develop and promote payment policies Train POS staff (then re-train!) Develop a user manual New merchants Guidelines Responsibilities Costs Merchant agreement 66

67 Some Pretty Good Practices Find and eliminate track data Reduce potential liability 90% Vendors may not be much help Sensitive number finder can locate rogue databases Upgrade POS terminals to truncate PANs on both paper copies Find rogue payment sites on your campus(es) Google news alert 67

68 Some Pretty Good Practices Make your acquirer your partner Sets merchant level, l validates compliance Approves compensating controls Some offer PCI training, newsletters, support Advice: Get the name of a Compliance Officer 68

69 Some Pretty Good Practices Use PA DSS list for all third-party applications Use Visa CISP list for all third-party service providers New service provider levels in 2009 Only Level 1 will be listed on Visa website 69

70 Some Pretty Good Practices Prepare an Incident Response Plan See PCI Blog (treasuryinstitute.com/blog) tit t March 25 for list of resources and sample plans SANS, NIST, Educause, Test the plan before you have to use it 70

71 Compliance Action Plan Start with a Payments Analysis Every merchant, application, departmental database, service provider, terminal, website, Expect surprises Adopt a risk-based approach Identify campus merchants posing greatest risk Address them first Plan to visit it each merchant, observe, question Document findings Train, communicate, empower 71

72 Staying Compliant PCI is backward looking Compliance today says s nothing about tomorrow You are one change from being non-compliant Establish and follow policies Educate, train, communicate ( rinse, lather, repeat ) Get trained and/or get help 72

73 PCI and Beyond PCI does not make you secure Map your payment data flow Monitor service providers and vendors Use strong passwords for technical support Log tech support and third-party access Upgrade POS equipment and payment apps Beware of rogue wireless networks Perform vulnerability scans monthly Go beyond: apply PCI to all your PII 73

74 50 Questions Every CFO Should Ask "The guide is revolutionary in its approach and extremely practical in its application. It will assist organizations in taking the necessary multi-dimensional approach to managing their cyber infrastructure by shifting the locus of control to the Chief Financial Officer. Larry Clinton, President, Internet Security Alliance Let the process, and the preparation, wait no longer. Gather the stakeholders. Let the questions begin. 74

75 Conclusions Take control You can t outsource responsibility PCI training has a very high ROI! Senior management commitment and multidisciplinary team are critical Outsourcing can help with compliance Network with other institutions If you don t need it, don t keep it 75

76 Higher Education Community Resources The Treasury Institute for Higher Education: PCI blog: NACUBO: 76

77 Additional PCI Resources Society of Payment Security Professionals: Blogs, PCI forum PCI SSC: pcisecuritystandards.org Standards, FAQ, PA DSS Visa: visa.com/cisp PCI-compliant service providers MasterCard: mastercard.com/us/sd 77

78 Understanding and Managing PCI DSS YOUR thoughts? Comments? Questions? 78

Understanding and Managing PCI DSS

Understanding and Managing PCI DSS Understanding and Managing PCI DSS PCI DSS in Context Some History Key Players Validating Compliance Cardholder Data 2! 5 Stages of PCI Grief Denial: It doesn t apply to me PCI compliance is mandatory

More information

1/18/10. Walt Conway. PCI DSS in Context. Some History The Digital Dozen Key Players Cardholder Data Outsourcing Conclusions. PCI in Higher Education

1/18/10. Walt Conway. PCI DSS in Context. Some History The Digital Dozen Key Players Cardholder Data Outsourcing Conclusions. PCI in Higher Education PCI in Higher Education Walter Conway, QSA 403 Labs, LLC Walt Conway PCI consultant, blogger, trainer, speaker, author Former Visa VP Help schools become PCI compliant Represent Higher Education at PCI

More information

PCI DSS Gap Analysis Briefing

PCI DSS Gap Analysis Briefing PCI DSS Gap Analysis Briefing The University of Chicago October 1, 2012 Walter Conway, QSA 403 Labs, LLC Agenda The PCI DSS ecosystem - Key players, roles - Cardholder data - Merchant levels and SAQs UofC

More information

PCI Compliance Overview

PCI Compliance Overview PCI Compliance Overview 1 PCI DSS Payment Card Industry Data Security Standard Standard that is applied to: Merchants Service Providers (Banks, Third party vendors, gateways) Systems (Hardware, software)

More information

Why Is Compliance with PCI DSS Important?

Why Is Compliance with PCI DSS Important? Why Is Compliance with PCI DSS Important? The members of PCI Security Standards Council (American Express, Discover, JCB, MasterCard, and Visa) continually monitor cases of account data compromise. These

More information

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer Complying with the PCI DSS All the Moving Parts Don Roeber Vice President, PCI Compliance Manager Lisa Tedeschi Assistant Vice President, Compliance Officer Types of Risk Operational Risk Normal fraud

More information

PCI Data Security Standards

PCI Data Security Standards PCI Data Security Standards An Introduction to Bankcard Data Security Why should we worry? Since 2005, over 500 million customer records have been reported as lost or stolen 1 In 2010 alone, over 134 million

More information

PCI DSS Compliance What Texas BUC$ Need to Know! Ron King CampusGuard [email protected]

PCI DSS Compliance What Texas BUC$ Need to Know! Ron King CampusGuard rking@campusguard.com PCI DSS Compliance What Texas BUC$ Need to Know! Ron King CampusGuard [email protected] Whoops!...3.1 Changes 3.1 PCI DSS Responsibility Information Technology Business Office PCI DSS Work Information

More information

Becoming PCI Compliant

Becoming PCI Compliant Becoming PCI Compliant Jason Brown - [email protected] Enterprise Security Architect Enterprise Architecture Department of Technology, Management and Budget State of Michigan @jasonbrown17 History

More information

Payment Card Industry Data Security Standard Training. Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc.

Payment Card Industry Data Security Standard Training. Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc. Payment Card Industry Data Security Standard Training Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc. March 27, 2012 Agenda Check-In 9:00-9:30 PCI Intro and History

More information

PCI Compliance. Top 10 Questions & Answers

PCI Compliance. Top 10 Questions & Answers PCI Compliance Top 10 Questions & Answers 1. What is PCI Compliance and PCI DSS? 2. Who needs to follow the PCI Data Security Standard? 3. What happens if I don t comply? 4. What are the basic requirements

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire Instructions and Guidelines Version 1.1 February 2008 Table of Contents About this Document... 1 PCI Data Security Standard

More information

Puzzled about PCI compliance? Proactive ways to navigate through the standard for compliance

Puzzled about PCI compliance? Proactive ways to navigate through the standard for compliance Puzzled about PCI compliance? Proactive ways to navigate through the standard for compliance March 29, 2012 1:00 p.m. ET If you experience any technical difficulties, please contact 888.228.0988 or [email protected]

More information

PCI Compliance Top 10 Questions and Answers

PCI Compliance Top 10 Questions and Answers Where every interaction matters. PCI Compliance Top 10 Questions and Answers White Paper October 2013 By: Peer 1 Hosting Product Team www.peer1.com Contents What is PCI Compliance and PCI DSS? 3 Who needs

More information

Project Title slide Project: PCI. Are You At Risk?

Project Title slide Project: PCI. Are You At Risk? Blank slide Project Title slide Project: PCI Are You At Risk? Agenda Are You At Risk? Video What is the PCI SSC? Agenda What are the requirements of the PCI DSS? What Steps Can You Take? Available Services

More information

Are You Ready For PCI v 3.0. Speaker: Corbin DelCarlo Institution: McGladrey LLP Date: October 6, 2014

Are You Ready For PCI v 3.0. Speaker: Corbin DelCarlo Institution: McGladrey LLP Date: October 6, 2014 Are You Ready For PCI v 3.0 Speaker: Corbin DelCarlo Institution: McGladrey LLP Date: October 6, 2014 Today s Presenter Corbin Del Carlo QSA, PA QSA Director, National Leader PCI Services Practice 847.413.6319

More information

Property of CampusGuard. Compliance With The PCI DSS

Property of CampusGuard. Compliance With The PCI DSS Compliance With The PCI DSS Today s Agenda PCI DSS Introduction How are Colleges and Universities Affected? How Do You Validate Compliance? Best Practices Q&A CampusGuard Full-Service QSA/ASV Firm We Know

More information

Josiah Wilkinson Internal Security Assessor. Nationwide

Josiah Wilkinson Internal Security Assessor. Nationwide Josiah Wilkinson Internal Security Assessor Nationwide Payment Card Industry Overview PCI Governance/Enforcement Agenda PCI Data Security Standard Penalties for Non-Compliance Keys to Compliance Challenges

More information

Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance

Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance A Non-Technical Guide Essential for Business Managers Office Managers Operations Managers Compliant? Bank Name

More information

SecurityMetrics Introduction to PCI Compliance

SecurityMetrics Introduction to PCI Compliance SecurityMetrics Introduction to PCI Compliance Card Data Compromise What is a card data compromise? A card data compromise occurs when payment card information is stolen from a merchant. Some examples

More information

PCI Compliance. What is New in Payment Card Industry Compliance Standards. October 2015. cliftonlarsonallen.com. 2015 CliftonLarsonAllen LLP

PCI Compliance. What is New in Payment Card Industry Compliance Standards. October 2015. cliftonlarsonallen.com. 2015 CliftonLarsonAllen LLP cliftonlarsonallen.com PCI Compliance What is New in Payment Card Industry Compliance Standards October 2015 Overview PCI DSS In the beginning Each major card brand had its own separate criteria for implementing

More information

How To Protect Your Business From A Hacker Attack

How To Protect Your Business From A Hacker Attack Payment Card Industry Data Security Standards The payment card industry data security standard PCI DSS Visa and MasterCard have developed the Payment Card Industry Data Security Standard or PCI DSS as

More information

Two Approaches to PCI-DSS Compliance

Two Approaches to PCI-DSS Compliance Disclaimer Copyright Michael Chapple and Jane Drews, 2006. This work is the intellectual property of the authors. Permission is granted for this material to be shared for non-commercial, educational purposes,

More information

This appendix is a supplement to the Local Government Information Security: Getting Started Guide, a non-technical reference essential for elected

This appendix is a supplement to the Local Government Information Security: Getting Started Guide, a non-technical reference essential for elected This appendix is a supplement to the Local Government Information Security: Getting Started Guide, a non-technical reference essential for elected officials, administrative officials and business managers.

More information

PCI DSS Compliance. 2015 Information Pack for Merchants

PCI DSS Compliance. 2015 Information Pack for Merchants PCI DSS Compliance 2015 Information Pack for Merchants This pack contains general information regarding PCI DSS compliance and does not take into account your business' particular requirements. ANZ recommends

More information

PCI DSS Presentation University of Cincinnati

PCI DSS Presentation University of Cincinnati PCI DSS Presentation University of Cincinnati Quick PCI Level Set Higher Ed Challenges Getting Compliant Application w/ customers Q& A PCI DSS Payment Card Industry Data Security Standard What is the PCI

More information

North Carolina Office of the State Controller Technology Meeting

North Carolina Office of the State Controller Technology Meeting PCI DSS Security Awareness Training North Carolina Office of the State Controller Technology Meeting April 30, 2014 agio.com A Note on Our New Name Secure Enterprise Computing was acquired as the Security

More information

MasterCard PCI & Site Data Protection (SDP) Program Update. Academy of Risk Management Innovate. Collaborate. Educate.

MasterCard PCI & Site Data Protection (SDP) Program Update. Academy of Risk Management Innovate. Collaborate. Educate. MasterCard PCI & Site Data Protection (SDP) Program Update Academy of Risk Management Innovate. Collaborate. Educate. The Payment Card Industry Security Standards Council (PCI SSC) Open, Global Forum Founded

More information

PCI Compliance. How to Meet Payment Card Industry Compliance Standards. May 2015. cliftonlarsonallen.com. 2015 CliftonLarsonAllen LLP

PCI Compliance. How to Meet Payment Card Industry Compliance Standards. May 2015. cliftonlarsonallen.com. 2015 CliftonLarsonAllen LLP 2015 CliftonLarsonAllen LLP PCI Compliance How to Meet Payment Card Industry Compliance Standards May 2015 cliftonlarsonallen.com Overview PCI DSS In the beginning Each major card brand had its own separate

More information

Complying with Payment Card Industry Data Security Standards (PCI DSS) Requirements. Approaches in Higher Education

Complying with Payment Card Industry Data Security Standards (PCI DSS) Requirements. Approaches in Higher Education September 28, 2010 Complying with Payment Card Industry Data Security Standards (PCI DSS) Requirements Approaches in Higher Education Dennis W. Reedy Managing Director, Treasury Operations Indiana University

More information

WHITE PAPER. PCI Basics: What it Takes to Be Compliant

WHITE PAPER. PCI Basics: What it Takes to Be Compliant WHITE PAPER PCI Basics: What it Takes to Be Compliant Introduction A long-running worldwide advertising campaign by Visa states that the card is accepted everywhere you want to be. Unfortunately, and through

More information

Frequently Asked Questions

Frequently Asked Questions PCI Compliance Frequently Asked Questions Table of Content GENERAL INFORMATION... 2 PAYMENT CARD INDUSTRY DATA SECURITY STANDARD (PCI DSS)...2 Are all merchants and service providers required to comply

More information

PCI Compliance: How to ensure customer cardholder data is handled with care

PCI Compliance: How to ensure customer cardholder data is handled with care PCI Compliance: How to ensure customer cardholder data is handled with care Choosing a safe payment process for your business Contents Contents 2 Executive Summary 3 PCI compliance and accreditation 4

More information

PCI Compliance at The University of South Carolina. Failure is not an option. Rick Lambert PMP University of South Carolina ricklambert@sc.

PCI Compliance at The University of South Carolina. Failure is not an option. Rick Lambert PMP University of South Carolina ricklambert@sc. PCI Compliance at The University of South Carolina Failure is not an option Rick Lambert PMP University of South Carolina [email protected] Payment Card Industry Data Security Standard (PCI DSS) Who Must

More information

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008 Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008 What is the PCI DSS? And what do the acronyms CISP, SDP, DSOP and DISC stand for? The PCI DSS is a set of comprehensive requirements

More information

Adyen PCI DSS 3.0 Compliance Guide

Adyen PCI DSS 3.0 Compliance Guide Adyen PCI DSS 3.0 Compliance Guide February 2015 Page 1 2015 Adyen BV www.adyen.com Disclaimer: This document is for guidance purposes only. Adyen does not accept responsibility for any inaccuracies. Merchants

More information

Data Security & PCI Compliance & PCI Compliance Securing Your Contact Center Securing Your Contact Session Name :

Data Security & PCI Compliance & PCI Compliance Securing Your Contact Center Securing Your Contact Session Name : Data Security & PCI Compliance Securing Your Contact Center Session Name : Title Introducing Trevor Horwitz Pi Principal, i TrustNet t [email protected] John Simpson CIO, Noble Systems Corporation

More information

Your guide to the Payment Card Industry Data Security Standard (PCI DSS) Merchant Business Solutions. Version 5.0 (April 2011)

Your guide to the Payment Card Industry Data Security Standard (PCI DSS) Merchant Business Solutions. Version 5.0 (April 2011) Your guide to the Payment Card Industry Data Security Standard (PCI DSS) Merchant Business Solutions Version 5.0 (April 2011) Contents Contents...2 Introduction...3 What are the 12 key requirements of

More information

HOW SECURE IS YOUR PAYMENT CARD DATA?

HOW SECURE IS YOUR PAYMENT CARD DATA? HOW SECURE IS YOUR PAYMENT CARD DATA? October 27, 2011 MOSS ADAMS LLP 1 TODAY S PRESENTERS Francis Tam, CPA, CISA, CISM, CITP, CRISC, PCI QSA Managing Director PCI Practice Leader Kevin Villanueva,, CISSP,

More information

Strategies To Effective PCI Scoping ISACA Columbus Chapter Presentation October 2008

Strategies To Effective PCI Scoping ISACA Columbus Chapter Presentation October 2008 Strategies To Effective PCI Scoping ISACA Columbus Chapter Presentation October 2008 Matthew T. Davis SecureState, LLC [email protected] SecureState Founded in 2001, Based on Cleveland Specialized

More information

PCI: The Dark Side. May 2012 Roanoke, VA

PCI: The Dark Side. May 2012 Roanoke, VA PCI: The Dark Side May 2012 Roanoke, VA Agenda The problem Who are they? Why? What do they steal? How do they do it? What can they do with it? How can you stop it? Ron King, Ed Ko, CampusGuard CampusGuard

More information

Technical breakout session

Technical breakout session Technical breakout session Small leaks sink great ships Managing data security, fraud and privacy risks Tarlok Birdi, Deloitte Ron Borsholm, WTS May 27, 2009 Agenda 1. PCI overview: the technical intent

More information

HOW SECURE IS YOUR PAYMENT CARD DATA? COMPLYING WITH PCI DSS

HOW SECURE IS YOUR PAYMENT CARD DATA? COMPLYING WITH PCI DSS HOW SECURE IS YOUR PAYMENT CARD DATA? COMPLYING WITH PCI DSS August 23, 2011 MOSS ADAMS LLP 1 TODAY S PRESENTERS Presenters Francis Tam, CPA, CISA, CISM, CITP, CRISC, PCI QSA Managing Director, IT Security

More information

What s New in PCI DSS 2.0. 2010 Cisco and/or its affiliates. All rights reserved. Cisco Systems, Inc 1

What s New in PCI DSS 2.0. 2010 Cisco and/or its affiliates. All rights reserved. Cisco Systems, Inc 1 What s New in PCI DSS 2.0 2010 Cisco and/or its affiliates. All rights reserved. Cisco Systems, Inc 1 Agenda PCI Overview PCI 2.0 Changes PCI Advanced Technology Update PCI Solutions 2010 Cisco and/or

More information

Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions

Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions PCI/PA-DSS FAQs Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions What is PCI DSS? The Payment Card Industry Data

More information

Payment Card Industry - Achieving PCI Compliance Steps Steps

Payment Card Industry - Achieving PCI Compliance Steps Steps CUR RITY SE Data Security Requirements for K-12 January 28, 2010 Payment Card Industry (PCI) SE CUR RITY 1 Welcome To Join The Voice Conference Dial 866-939-3921 Technical issues press 0 Q & A We ll leave

More information

TNHFMA 2011 Fall Institute October 12, 2011 TAKING OUR CUSTOMERS BUSINESS FORWARD. The Cost of Payment Card Data Theft and Your Business

TNHFMA 2011 Fall Institute October 12, 2011 TAKING OUR CUSTOMERS BUSINESS FORWARD. The Cost of Payment Card Data Theft and Your Business TAKING OUR CUSTOMERS BUSINESS FORWARD The Cost of Payment Card Data Theft and Your Business Aaron Lego Director of Business Development Presentation Agenda Items we will cover: 1. Background on Payment

More information

PCI DSS. CollectorSolutions, Incorporated

PCI DSS. CollectorSolutions, Incorporated PCI DSS Robert Cothran President CollectorSolutions www.collectorsolutions.com CollectorSolutions, Incorporated Founded as Florida C corporation in 1999 Approximately 235 clients in 35 states Targeted

More information

Understanding Payment Card Industry (PCI) Data Security

Understanding Payment Card Industry (PCI) Data Security Understanding Payment Card Industry (PCI) Data Security Office of the State Controller November 2010 State of North Carolina The Enemy Major Security Breaches TJ-Max Heartland Hannaford Foods BJ s Wholesale

More information

PAI Secure Program Guide

PAI Secure Program Guide PAI Secure Program Guide A complete guide to understanding the Payment Card Industry Data Security Requirements and utilizing the PAI Secure Program. Letter From the CEO Welcome to PAI Secure. As you

More information

CREDIT CARD MERCHANT PROCEDURES MANUAL. Effective Date: 5/25/2011

CREDIT CARD MERCHANT PROCEDURES MANUAL. Effective Date: 5/25/2011 CREDIT CARD MERCHANT PROCEDURES MANUAL Effective Date: 5/25/2011 Updated: May 25, 2011 TABLE OF CONTENTS Introduction... 1 Third-Party Vendors... 1 Merchant Account Set-up... 2 Personnel Requirements...

More information

Payment Card Industry Data Security Standard

Payment Card Industry Data Security Standard Payment Card Industry Data Security Standard Abhinav Goyal, B.E.(Computer Science) MBA Finance Final Trimester Welingkar Institute of Management ISACA Bangalore chapter 13 th February 2010 Credit Card

More information

How To Protect Your Credit Card Information From Being Stolen

How To Protect Your Credit Card Information From Being Stolen Visa Account Information Security Tool Kit Welcome to the Visa Account Information Security Program 2 Contents 1. Securing cardholder data is everyone s concern 4 2. Visa Account Information Security (AIS)

More information

Your Compliance Classification Level and What it Means

Your Compliance Classification Level and What it Means General Information What are the Payment Card Industry (PCI) Data Security Standards? The PCI Data Security Standards represents a common set of industry tools and measurements to help ensure the safe

More information

SECTION: SUBJECT: PCI-DSS General Guidelines and Procedures

SECTION: SUBJECT: PCI-DSS General Guidelines and Procedures 1. Introduction 1.1. Purpose and Background 1.2. Central Coordinator Contact 1.3. Payment Card Industry Data Security Standards (PCI-DSS) High Level Overview 2. PCI-DSS Guidelines - Division of Responsibilities

More information

Payment Card Industry Compliance Overview

Payment Card Industry Compliance Overview January 31, 2014 11:30am 12:30pm Central Hosted by: Texas.gov Presented by: Jayne Holland Barbara Brinson Payment Card Industry Compliance Overview Securing Government Payments Audio Dial In: 866-740-1260

More information

PCI DSS Overview. By Kishor Vaswani CEO, ControlCase

PCI DSS Overview. By Kishor Vaswani CEO, ControlCase PCI DSS Overview By Kishor Vaswani CEO, ControlCase Agenda About PCI DSS PCI DSS Applicability to Banks, Merchants and Service Providers PCI DSS Technical Requirements Overview of PCI DSS 3.0 Changes Key

More information

How To Protect Visa Account Information

How To Protect Visa Account Information Account Information Security Merchant Guide At Visa, protecting our cardholders is at the core of everything we do. One of the many reasons people trust our brand is that we make buying and selling safer

More information

An article on PCI Compliance for the Not-For-Profit Sector

An article on PCI Compliance for the Not-For-Profit Sector Level 8, 66 King Street Sydney NSW 2000 Australia Telephone +61 2 9290 4444 or 1300 922 923 An article on PCI Compliance for the Not-For-Profit Sector Page No.1 PCI Compliance for the Not-For-Profit Sector

More information

05.118 Credit Card Acceptance Policy. Vice Chancellor of Business Affairs. History: Effective July 1, 2011 Updated February 2013

05.118 Credit Card Acceptance Policy. Vice Chancellor of Business Affairs. History: Effective July 1, 2011 Updated February 2013 05.118 Credit Card Acceptance Policy Authority: Vice Chancellor of Business Affairs History: Effective July 1, 2011 Updated February 2013 Source of Authority: Office of State Controller (OSC); Office of

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance All other SAQ-Eligible Merchants and Service Providers Version 2.0 October 2010 Document

More information

Cyber - Security and Investigations. Ingrid Beierly August 18, 2008

Cyber - Security and Investigations. Ingrid Beierly August 18, 2008 Cyber - Security and Investigations Ingrid Beierly August 18, 2008 Agenda Visa Cyber - Security and Investigations Today s Targets Recent Attack Patterns Hacking Statistics (removed) Top Merchant Vulnerabilities

More information

Protecting Your Customers' Card Data. Presented By: Oliver Pinson-Roxburgh

Protecting Your Customers' Card Data. Presented By: Oliver Pinson-Roxburgh Protecting Your Customers' Card Data Presented By: Oliver Pinson-Roxburgh Agenda Trustwave Overview PCI Scope Compromise Statistics PCI Makes Business Sense Registration Process TrustKeeper Features Support

More information

Credit Cards and Oracle: How to Comply with PCI DSS. Stephen Kost Integrigy Corporation Session #600

Credit Cards and Oracle: How to Comply with PCI DSS. Stephen Kost Integrigy Corporation Session #600 Credit Cards and Oracle: How to Comply with PCI DSS Stephen Kost Integrigy Corporation Session #600 Background Speaker Stephen Kost CTO and Founder 16 years working with Oracle 12 years focused on Oracle

More information

Presented By: Bryan Miller CCIE, CISSP

Presented By: Bryan Miller CCIE, CISSP Presented By: Bryan Miller CCIE, CISSP Introduction Why the Need History of PCI Terminology The Current Standard Who Must Be Compliant and When What Makes this Standard Different Roadmap to Compliance

More information

The Cost of Payment Card Data Theft and Your Business. Aaron Lego Director of Business Development

The Cost of Payment Card Data Theft and Your Business. Aaron Lego Director of Business Development The Cost of Payment Card Data Theft and Your Business Aaron Lego Director of Business Development Presentation Agenda Items we will cover: 1. Background on Payment Card Industry Data Security Standards

More information

PCI DSS 3.0 : THE CHANGES AND HOW THEY WILL EFFECT YOUR BUSINESS

PCI DSS 3.0 : THE CHANGES AND HOW THEY WILL EFFECT YOUR BUSINESS PCI DSS 3.0 : THE CHANGES AND HOW THEY WILL EFFECT YOUR BUSINESS CIVICA Conference 22 January 2015 WELCOME AND AGENDA Change is here! PCI-DSS 3.0 is mandatory starting January 1, 2015 Goals of the session

More information

Merchant guide to PCI DSS

Merchant guide to PCI DSS Merchant guide to PCI DSS Contents What is PCI DSS and why was it introduced?... 3 Who needs to become PCI DSS compliant?... 3 BOIPA Simple PCI DSS - 3 step approach to helping businesses... 3 What does

More information

Tokenization Amplified XiIntercept. The ultimate PCI DSS cost & scope reduction mechanism

Tokenization Amplified XiIntercept. The ultimate PCI DSS cost & scope reduction mechanism Tokenization Amplified XiIntercept The ultimate PCI DSS cost & scope reduction mechanism Paymetric White Paper Tokenization Amplified XiIntercept 2 Table of Contents Executive Summary 3 PCI DSS 3 The PCI

More information

Vanderbilt University

Vanderbilt University Vanderbilt University Payment Card Processing and PCI Compliance Policy and Procedures Manual PCI Compliance Office Information Technology Treasury VUMC Finance Table of Contents Policy... 2 I. Purpose...

More information

Corbin Del Carlo Director, National Leader PCI Services. October 5, 2015

Corbin Del Carlo Director, National Leader PCI Services. October 5, 2015 PCI compliance: v3.1 Key Considerations Corbin Del Carlo Director, National Leader PCI Services October 5, 2015 Today s Presenter Corbin Del Carlo QSA, PA QSA Director, National Leader PCI Services Practice

More information

PCI DSS FAQ. The twelve requirements of the PCI DSS are defined as follows:

PCI DSS FAQ. The twelve requirements of the PCI DSS are defined as follows: What is PCI DSS? PCI DSS is an acronym for Payment Card Industry Data Security Standards. PCI DSS is a global initiative intent on securing credit and banking transactions by merchants & service providers

More information

PAYMENT CARD INDUSTRY (PCI) ANNUAL TRAINING DECEMBER 10, 2009 WESTERN ILLINOIS UNIVERSITY OFFICE OF THE CTSO & BUSINESS SERVICES

PAYMENT CARD INDUSTRY (PCI) ANNUAL TRAINING DECEMBER 10, 2009 WESTERN ILLINOIS UNIVERSITY OFFICE OF THE CTSO & BUSINESS SERVICES PAYMENT CARD INDUSTRY (PCI) ANNUAL TRAINING DECEMBER 10, 2009 WESTERN ILLINOIS UNIVERSITY OFFICE OF THE CTSO & BUSINESS SERVICES AGENDA PCI Players and Roles Merchant Requirements Keys To Successful PCI

More information

Payment Card Industry Data Security Standard Explained

Payment Card Industry Data Security Standard Explained Payment Card Industry Data Security Standard Explained Agenda Overview of PCI DSS Compliance Levels and Requirements PCI DSS in More Detail Discussion, Questions and Clarifications Overview of PCI-DSS

More information

CHEAT SHEET: PCI DSS 3.1 COMPLIANCE

CHEAT SHEET: PCI DSS 3.1 COMPLIANCE CHEAT SHEET: PCI DSS 3.1 COMPLIANCE WHAT IS PCI DSS? Payment Card Industry Data Security Standard Information security standard for organizations that handle data for debit, credit, prepaid, e-purse, ATM,

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Self-Assessment Questionnaire D Service Providers For use with PCI DSS Version 3.1 Revision 1.1 July 2015 Section 1: Assessment

More information

PCI Compliance for Cloud Applications

PCI Compliance for Cloud Applications What Is It? The Payment Card Industry Data Security Standard (PCIDSS), in particular v3.0, aims to reduce credit card fraud by minimizing the risks associated with the transmission, processing, and storage

More information

TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No. 08-01 MERCHANT DEBIT AND CREDIT CARD RECEIPTS

TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No. 08-01 MERCHANT DEBIT AND CREDIT CARD RECEIPTS TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No. 08-01 MERCHANT DEBIT AND CREDIT CARD RECEIPTS 1. Introduction Debit and Credit Card Receipt Standards apply to the administration

More information

CREDIT CARD MERCHANT POLICY. All campuses served by Louisiana State University (LSU) Office of Accounting Services

CREDIT CARD MERCHANT POLICY. All campuses served by Louisiana State University (LSU) Office of Accounting Services Louisiana State University Finance and Administrative Services Operating Procedure FASOP: AS-22 CREDIT CARD MERCHANT POLICY Scope: All campuses served by Louisiana State University (LSU) Office of Accounting

More information

PCI Standards: A Banking Perspective

PCI Standards: A Banking Perspective Slide 1 PCI Standards: A Banking Perspective Bob Brown, CISSP Wachovia Corporate Information Security Slide 2 Agenda 1. Payment Card Initiative History 2. Description of the Industry 3. PCI-DSS Control

More information

White Paper September 2013 By Peer1 and CompliancePoint www.peer1.com. PCI DSS Compliance Clarity Out of Complexity

White Paper September 2013 By Peer1 and CompliancePoint www.peer1.com. PCI DSS Compliance Clarity Out of Complexity White Paper September 2013 By Peer1 and CompliancePoint www.peer1.com PCI DSS Compliance Clarity Out of Complexity Table of Contents Introduction 1 Businesses are losing customer data 1 Customers are learning

More information

PCI DSS 3.0 Changes Bill Franklin Executive IT Auditor [email protected] January 23, 2014

PCI DSS 3.0 Changes Bill Franklin Executive IT Auditor bfranklin@compassitc.com January 23, 2014 PCI DSS 3.0 Changes Bill Franklin Executive IT Auditor [email protected] January 23, 2014 Agenda Introduction PCI DSS 3.0 Changes What Can I Do to Prepare? When Do I Need to be Compliant? Questions

More information

IT Security Compliance PCI DSS FOR MERCHANTS THE PAYMENT CARD INDUSTRY DATE SECURITY STANDARD WHITE PAPER

IT Security Compliance PCI DSS FOR MERCHANTS THE PAYMENT CARD INDUSTRY DATE SECURITY STANDARD WHITE PAPER July 9 th, 2012 Prepared By: Mark Akins PCI QSA, CISSP, CISA WHITE PAPER IT Security Compliance PCI DSS FOR MERCHANTS THE PAYMENT CARD INDUSTRY DATE SECURITY STANDARD PCI DSS for Merchants The Payment

More information

UNDERSTANDING PCI 3.0 AND HOW TO REDUCE YOUR SCOPE

UNDERSTANDING PCI 3.0 AND HOW TO REDUCE YOUR SCOPE UNDERSTANDING PCI 3.0 AND HOW TO REDUCE YOUR SCOPE April 30 th, 2014 Sean Mathena CISSP, CISA, QSA Trustwave Managing Consultant WELCOME AND AGENDA PCI-DSS 3.0 Review the high-level areas that have changed

More information

PCI Assessments 3.0 What Will the Future Bring? Matt Halbleib, SecurityMetrics

PCI Assessments 3.0 What Will the Future Bring? Matt Halbleib, SecurityMetrics PCI Assessments 3.0 What Will the Future Bring? Matt Halbleib, SecurityMetrics About Us Matt Halbleib CISSP, QSA, PA-QSA Manager PCI-DSS assessments With SecurityMetrics for 6+ years SecurityMetrics Security

More information

PCI DSS Security Awareness Training for University of Tennessee Credit Card Merchants. UT System Administration Information Security Office

PCI DSS Security Awareness Training for University of Tennessee Credit Card Merchants. UT System Administration Information Security Office PCI DSS Security Awareness Training for University of Tennessee Credit Card Merchants UT System Administration Information Security Office Agenda Overview of PCI DSS Compliance versus Non-Compliance PCI

More information

A Compliance Overview for the Payment Card Industry (PCI)

A Compliance Overview for the Payment Card Industry (PCI) A Compliance Overview for the Payment Card Industry (PCI) Many organizations are aware of the Payment Card Industry (PCI) and PCI compliance but are unsure if they are doing everything necessary. This

More information