Data Security & PCI Compliance & PCI Compliance Securing Your Contact Center Securing Your Contact Session Name :



Similar documents
PCI-DSS: A Step-by-Step Payment Card Security Approach. Amy Mushahwar & Mason Weisz

Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions

Property of CampusGuard. Compliance With The PCI DSS

Data Security Standard (DSS) Compliance. SIFMA June 13, 2012

Frequently Asked Questions

PCI Compliance at The University of South Carolina. Failure is not an option. Rick Lambert PMP University of South Carolina

Are You Ready For PCI v 3.0. Speaker: Corbin DelCarlo Institution: McGladrey LLP Date: October 6, 2014

Payment Card Industry Data Security Standards

PCI: The Dark Side. May 2012 Roanoke, VA

What are the PCI DSS requirements? PCI DSS comprises twelve requirements, often referred to as the digital dozen. These define the need to:

PCI Compliance. How to Meet Payment Card Industry Compliance Standards. May cliftonlarsonallen.com CliftonLarsonAllen LLP

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry Data Security Standards.

How To Protect Your Business From A Hacker Attack

Becoming PCI Compliant

PCI Compliance Overview

Payment Card Industry Data Security Standard

An article on PCI Compliance for the Not-For-Profit Sector

PCI DSS. Payment Card Industry Data Security Standard.

worldpay.com Understanding the 12 requirements of PCI DSS SaferPayments Be smart. Be compliant. Be protected.

PCI Compliance 3.1. About Us

PCI Compliance: How to ensure customer cardholder data is handled with care

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer

Payment Card Industry - Achieving PCI Compliance Steps Steps

Your Compliance Classification Level and What it Means

Payment Card Industry (PCI) Data Security Standard

PCI Requirements Coverage Summary Table

PCI DSS Overview. By Kishor Vaswani CEO, ControlCase

PCI Compliance for Cloud Applications

PCI Requirements Coverage Summary Table

Introduction to PCI DSS

Josiah Wilkinson Internal Security Assessor. Nationwide

Cyber - Security and Investigations. Ingrid Beierly August 18, 2008

Project Title slide Project: PCI. Are You At Risk?

A Compliance Overview for the Payment Card Industry (PCI)

How To Protect Your Data From Being Stolen

E Pay. A Case Study in PCI Compliance. Illinois State Treasurer. Dan Rutherford

Varonis Systems & The Payment Card Industry Data Security Standard (PCI DSS)

PCI Compliance. Top 10 Questions & Answers

Credit Card Acceptance Policy. Vice Chancellor of Business Affairs. History: Effective July 1, 2011 Updated February 2013

How To Protect Your Credit Card Information From Being Stolen

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance

How To Ensure Account Information Security

Accepting Payment Cards and ecommerce Payments

PCI DSS Compliance What Texas BUC$ Need to Know! Ron King CampusGuard

FORT HAYS STATE UNIVERSITY CREDIT CARD SECURITY POLICY

Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS)

PCI Compliance: Protection Against Data Breaches

Data Security Basics for Small Merchants

Understanding and Managing PCI DSS

So you want to take Credit Cards!

CHEAT SHEET: PCI DSS 3.1 COMPLIANCE

TNHFMA 2011 Fall Institute October 12, 2011 TAKING OUR CUSTOMERS BUSINESS FORWARD. The Cost of Payment Card Data Theft and Your Business

Payment Card Industry Compliance Overview

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008

PCI DSS. CollectorSolutions, Incorporated

Protecting Your Customers' Card Data. Presented By: Oliver Pinson-Roxburgh

Comodo HackerGuardian. PCI Security Compliance The Facts. What PCI security means for your business

2015 PCI DSS Meeting. OSU Business Affairs Projects, Improvement, and Technology (PIT) Robin Whitlock

PCI Compliance Top 10 Questions and Answers

IT Security Compliance PCI DSS FOR MERCHANTS THE PAYMENT CARD INDUSTRY DATE SECURITY STANDARD WHITE PAPER

Credit Cards and Oracle: How to Comply with PCI DSS. Stephen Kost Integrigy Corporation Session #600

HOW SECURE IS YOUR PAYMENT CARD DATA?

The Cost of Payment Card Data Theft and Your Business. Aaron Lego Director of Business Development

A PCI Journey with Wichita State University

Mobile Device Payment Card Processing: How Secure is It? Richard Poworski CISSP, ISP, ITCP, SCF, PCI QSA, PCIP Managing Consultant

Payment Card Industry (PCI) Data Security Standard

PCI DSS 3.0 Overview. OSU Business Affairs Business Affairs PIT Crew - Project, Improvement, & Technology Robin Whitlock

Two Approaches to PCI-DSS Compliance

Validation of PCI Compliance Requirements NC Office of the State Controller June 23, 2015

PCI Compliance. What is New in Payment Card Industry Compliance Standards. October cliftonlarsonallen.com CliftonLarsonAllen LLP

PCI PA - DSS. Point XSA Implementation Guide. Atos Worldline Banksys XENTA SA. Version 1.00

How To Protect Visa Account Information

Your guide to the Payment Card Industry Data Security Standard (PCI DSS) Merchant Business Solutions. Version 5.0 (April 2011)

PCI Standards: A Banking Perspective

Adyen PCI DSS 3.0 Compliance Guide

Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015

SecurityMetrics Introduction to PCI Compliance

AIS Webinar. Payment Application Security. Hap Huynh Business Leader Visa Inc. 1 April 2009

PDQ Guide for the PCI Data Security Standard Self-Assessment Questionnaire C (Version 1.1)

Understanding Payment Card Industry (PCI) Data Security

COLORADO STATE UNIVERSITY Financial Procedure Statements FPI 6-6

PCI DSS Compliance Information Pack for Merchants

Transcription:

Data Security & PCI Compliance Securing Your Contact Center Session Name : Title

Introducing Trevor Horwitz Pi Principal, i TrustNet t trevor.horwitz@trustnetinc.com John Simpson CIO, Noble Systems Corporation Carolynn Horrell-Chamoun CIO, Penncro

Objectives Learn about PCI Discuss Emerging Security Threats Specific Issues for Contact Centers Your PCI Project Plan Q&A

Payment Card Industry Compliance Payment Card Industry (DSS and PA-DSS) DSS: Data Security Standard PA-DSS: Payment Application DSS PED: PIN Entry Device Created by PCI Security Standards Council Security standard designed to protect payment account data Applies to any business that accepts, stores, manages, processes or transmits payment card information. There are no exceptions.

PCI Requirements 1. Install firewalls to protect CHD 2. Do not use default passwords and parameters 3. Protect stored cardholder data 4. Encrypt data transmission across public networks 5. Use up-to-date anti-virus software 6. Develop secure systems and applications 7. Restrict access to CHD 8. Assign unique ID s 9. Restrict physical access to CHD 10. Track and monitor access to network and CHD 11. Regularly l test t security systems and processes 12. Maintain information security policy

PCI Requirements - Examples 3.2 Encryption of sensitive cardholder data 11.2 Quarterly vulnerability scans 11.3 Annual penetration test 12.6 Security awareness training (all employees) 12.1 Establish, publish, maintain and disseminate an information security policy

Why Should We comply? Non compliance may result in: Loss of ability to accept payment cards, card brand and processor fines and fees, cost of reissuing new payment cards, liability for fraudulent charges, legal settlements or judgments, loss of customers and customer confidence Its the LAW Minnesota - Plastic Card Security Act - 2009 Nevada SB 227 Effective 1/1/2010 Washington - HB 1149 Passed 3/22/10, effective 7/1/10 Massachusetts MA 201 CMR 17 Data Privacy Act

PCI Resources PCI Security Standards Council - https://www.pcisecuritystandards.org/ pcisecuritystandards PCI Solution Vendors www.pcitoolbox.com PCI Blog http://www.pcianswers.com/

Emerging Security Threats Windows 7 Large scale worm attacks Malware - polymorphic threats Mac attack Phishing, Spear Phishing, & Social Engineering Social Networking third-party apps Rogue security software Botnets Mobile Malware Attacks leverage the cloud

Contact Center PCI Trends Voice recordings Storage of sensitive authentication data is prohibited subsequent to authorization Contact Centers Guidance from the PCI Council to QSA s Clearly in scope for PCI VoIP VoIP infrastructure connected to the CDE must be PCI compliant

Contact Center IT Security Trends Virtualization Cloud Computing Breach Notification 45 US States State and Federal Data Privacy Laws MAS 201 CMR 17 HIPAA and HITECH Act Other states to follow

PCI Compliance Project Plan Project Scope Assessment and Planning Determine validation level Merchant or Service Provider What level? Determine the in-scope business operations, IT infrastructure, applications, information, and people Gap Analysis Risk assessment Assess documentation and identify control gaps and deficiencies

PCI Compliance Project Plan PCI DSS Compliance Assessment Assess compliance as defined by the PCI DSS v1.2. Review applications for PA-DSS compliance Remediate Deficiencies Evaluate deficiencies Identify and assess any compensating controls Reporting Debrief management and other stakeholders as required Complete the relevant Self Assessment Questionnaire and Attestation of Compliance

Q & A