PCI DSS. Payment Card Industry Data Security Standard. www.tuv.com/id



Similar documents
Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS)

Comodo HackerGuardian. PCI Security Compliance The Facts. What PCI security means for your business

PCI Compliance. Top 10 Questions & Answers

PCI Compliance Top 10 Questions and Answers

PCI Security Compliance

Merchant guide to PCI DSS

What are the PCI DSS requirements? PCI DSS comprises twelve requirements, often referred to as the digital dozen. These define the need to:

Adyen PCI DSS 3.0 Compliance Guide

Josiah Wilkinson Internal Security Assessor. Nationwide

PCI DSS. CollectorSolutions, Incorporated

A Compliance Overview for the Payment Card Industry (PCI)

How To Protect Your Business From A Hacker Attack

Two Approaches to PCI-DSS Compliance

SecurityMetrics Introduction to PCI Compliance

PCI Compliance at The University of South Carolina. Failure is not an option. Rick Lambert PMP University of South Carolina

Payment Card Industry Data Security Standards.

E Pay. A Case Study in PCI Compliance. Illinois State Treasurer. Dan Rutherford

Credit Cards and Oracle: How to Comply with PCI DSS. Stephen Kost Integrigy Corporation Session #600

MasterCard PCI & Site Data Protection (SDP) Program Update. Academy of Risk Management Innovate. Collaborate. Educate.

Payment Card Industry Data Security Standards

PCI DSS Overview. By Kishor Vaswani CEO, ControlCase

Your guide to the Payment Card Industry Data Security Standard (PCI DSS) Merchant Business Solutions. Version 5.0 (April 2011)

PAYMENT CARD INDUSTRY (PCI) COMPLIANCE HISTORY & OVERVIEW

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program

WHITE PAPER. PCI Basics: What it Takes to Be Compliant

Data Security Standard (DSS) Compliance. SIFMA June 13, 2012

An article on PCI Compliance for the Not-For-Profit Sector

PCI Compliance Overview

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program

Information Security Services. Achieving PCI compliance with Dell SecureWorks security services

Are You Ready For PCI v 3.0. Speaker: Corbin DelCarlo Institution: McGladrey LLP Date: October 6, 2014

Payment Card Industry Data Security Standard Training. Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc.

Kim Decarolis Compliance and Security Specialist (248) Mark Wayne Vice President Compliance and Security Specialist

Registration and PCI DSS compliance validation

IT Security Compliance PCI DSS FOR MERCHANTS THE PAYMENT CARD INDUSTRY DATE SECURITY STANDARD WHITE PAPER

PCI DSS Compliance Information Pack for Merchants

The PCI DSS Compliance Guide For Small Business

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008

Varonis Systems & The Payment Card Industry Data Security Standard (PCI DSS)

Project Title slide Project: PCI. Are You At Risk?

Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions

PCI DSS Overview and Solutions. Anwar McEntee

A PCI Journey with Wichita State University

Protecting Your Customers' Card Data. Presented By: Oliver Pinson-Roxburgh

PCI Compliance: How to ensure customer cardholder data is handled with care

PCI on Amazon Web Services (AWS) What You Need To Know Understanding the regulatory roadmap for PCI on AWS

Tokenization Amplified XiIntercept. The ultimate PCI DSS cost & scope reduction mechanism

Achieving PCI Compliance for Your Site in Acquia Cloud

PCI Compliance. How to Meet Payment Card Industry Compliance Standards. May cliftonlarsonallen.com CliftonLarsonAllen LLP

Third Party Agent Registration and PCI DSS Compliance Validation Guide

PCI Compliance: Protection Against Data Breaches

FORT HAYS STATE UNIVERSITY CREDIT CARD SECURITY POLICY

Puzzled about PCI compliance? Proactive ways to navigate through the standard for compliance

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer

Becoming PCI Compliant

CHEAT SHEET: PCI DSS 3.1 COMPLIANCE

Retour d'expérience PCI DSS

PCI Compliance. What is New in Payment Card Industry Compliance Standards. October cliftonlarsonallen.com CliftonLarsonAllen LLP

Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015

Are You Prepared to Successfully Pass a PCI-DSS and/or a FISMA Certification Assessment? Fiona Pattinson, SHARE: Seattle 2010

Strategies To Effective PCI Scoping ISACA Columbus Chapter Presentation October 2008

Frequently Asked Questions

PCI COMPLIANCE TO BUILD HIGHER CONFIDENCE FOR CARD HOLDER AND BOOST CASHLESS TRANSACTION. Suresh Dadlani, ControlCase

Payment Card Industry Data Security Standard

SecurityMetrics. PCI Starter Kit

PCI Data Security Standards

Third-Party Access and Management Policy

2015 PCI DSS Meeting. OSU Business Affairs Projects, Improvement, and Technology (PIT) Robin Whitlock

How To Ensure Account Information Security

How To Comply With The Pci Ds.S.A.S

Payment Card Industry Data Security Standard

How To Protect Visa Account Information

Payment Card Industry Compliance Overview

PCI DSS Compliance Guide

Validation of PCI Compliance Requirements NC Office of the State Controller June 23, 2015

How To Protect Your Credit Card Information From Being Stolen

PCI DSS v2.0. Compliance Guide

Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance

Data Security & PCI Compliance & PCI Compliance Securing Your Contact Center Securing Your Contact Session Name :

La règlementation VisaCard, MasterCard PCI-DSS

Security Breaches and Vulnerability Experiences Overview of PCI DSS Initiative and CISP Payment Application Best Practices Questions and Comments

PAI Secure Program Guide

White Paper September 2013 By Peer1 and CompliancePoint PCI DSS Compliance Clarity Out of Complexity

Network Test Labs Inc Security Assessment Service Description Complementary Service Offering for New Clients

Version 7.4 & higher is Critical for all Customers Processing Credit Cards!

Transcription:

PCI DSS Payment Card Industry Data Security Standard www.tuv.com/id

What Is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is the common security standard of all major credit cards brands.the standard designed to enhance cardholder data security. Regardless of their size, organizations that process payment card information must be PCI DSS compliant. To secure business and increase customer confidence, achieving PCI DSS compliance is a clear indicator of protection when handling sensitive customer data. American Express, Discover Financial Services, JCB International, MasterCard Worldwide and Visa Inc. formed PCI SSC (PCI Security Standard Council) in 2006, responsible for administering, revising, managing, and promoting adoption of PCI DSS. Risk Management $80K 210 70% 1in6 98% Is the average direct cost of a data breach Average days between intrusion and detection Breached Business are out of business within one year of the attack Small businesses will suffer a credit card breach in the next 24 months Breaches originate from organized criminal groups Risk has many interpretations, and is often used to describe dangers or threats to a particular person, environment, or business. Understanding risk includes understanding of the different elements and how they fit together. For example, considerations from a business perspective may include: What are the different types of threats to the organization? What are the organization s assets that need protecting from the threats? How vulnerable is the organization to different threats? What is the likelihood that a threat will be realized? What would be the impact if a threat was realized? How can the organization reduce the likelihood of a threat being realized, or reduce the impact if it does occur? Who Has to Comply? PCI DSS applies to: + Merchants + Service Providers (TPPs, gateways) + Systems (Hardware, software) That: + Stores cardholder data + Transmits cardholder data + Processes cardholder data Non-Compliant and Suffer a Breach? Acquirers may ask merchants to cease credit cards transactions Forensic audit QSA team on-site to determine cause of breach Can take 90-120 days to complete remediation actions Merchant is responsible for all costs. $80-100K average Breaches are public knowledge; brand image tarnished PCI DSS is mandatory for entities processing, transmitting or storing cardholder data. This could include acquirers, banks, service providers such as payment gateway, data centers & merchants.

Standards & Requirements The consolidation of individual payment card brand s security programs offers the best available framework to guide better protection of cardholder data resulting a comprehensive security baseline of 6 Control Objective 12 Core Requirements ~375 ~375 Audit Procedures Compliance requirements apply to the entire cardholder data environment comprised of people, processes and technology that store, process, or transmit payment card data. Build and maintain a Secure Network Protect Cardholder Data Maintain Vulnerability Management Program Implement Strong Access Control Measures Regularly Monitor and Test Networks Maintain information Security Policy Requirements Firewall Management Vendor Default Controls Data Protection Data Transmission Encryption Anti-virus Control System & Application Security Data Access Control Personal Access Control Physical Access Control Data & Network Access Controls Security testing Information Security Policy How to Comply? PCI DSS provides a baseline of technical and operational controls that work together to provide a defense-indepth approach to the protection of cardholder data. Risk assessments provide valuable information to help organizations determine whether additional controls are necessary to protect their sensitive data and other assets. In order to achieve compliance with the PCI DSS, an organization must meet all applicable PCI DSS requirements. Merchants Level & Validation PCI compliance categorized compliance level depends on the number of annually. Understanding which PCI compliance level applies to your business is the first step in assuring that your PCI compliance audits will be as simple as possible. Transac"on Volume Onsite QSA Audit Self Assessment Questionnaire (SAQ) Authorized Scanning Vendor (ASV) scan Security Awareness training Policy Review and Acceptance >6mio 1 6 Mio 20K 1 Mio All other merchant Level 1 2 3 4 By a QSA/ISA Compliance Roadmap The PCI Security Standards Council recognizes the TÜV Rheinland Group as a QSAC (Qualified Security Assessors Company). To fully leverage cardholder data security through PCI DSS compliance, ask our experts. We will be glad to help your organization reach full compliance the standards and regulations for safe and secure credit card transactions. Collect Review Improve Measures Renew

Compliance Management PCI DSS version 3 intends to make compliance to be a continuous process, a business-as-usual approach. Maintaining compliance throughout the year is a demanding task involving oversight over hundreds of documents and approvals. In order to simplify this process, a GRC tool has been developed, which reduces time and complexity to review, process and inform compliance status. PCM is a one-stop portal to manage documentation, role assignment, workflow alerts, escalation, audit readiness on a continuous basis. Vulnerability Assessment and Penetration Test Vulnerability Assessment focuses on IT Infrastructure, Network and Application: Whitebox Penetration Test done by involving your IT Staff to monitor and evaluate the work and results of the audit. The audit is done from within the agency or evaluated institution. Blackbox Penetration Test not involved your IT Staff. The Audit is done from outside agencies or evaluated institution, the test is generally done with published web application for the enterprise, vendor and client. Test Target: Network components Servers incl. database. Applications Segmentation interface Results of Audit: Executive Summary Technical Report Solution and Remedial Methodology Reference Quarterly & Annual Schedules OSSTMM (Open Source Security Testing Methodology Manual ISSAF (Information System Security Assessments Framework) NIST SP800-115 (National Institute of Standards and Technology) OWASP Testing Guide (Open Web Application Security Project). PCI DSS (PCI Data Security Standard) Internal and External Vulnerability Assessments needs to be performed quarterly A clean ASV scan report is mandatory every quarter to comply with PCI DSS. Workflow would be set up to perform quarterly schedule the scans. Internal and External Penetration Tests need to be performed annually

Services Gap Analysis Identify non-compliance issues Discover vulnerabilities Explore segmentation potential Draw up a detailed compliance plan Training Holding trainings/workshops on PCI compliance, attack vectors, Policies/ SOPs/Forms, vendor management, Risk assessment, Incident Response, Business Continuity Remediation & Consulting Minimizing CHDE footprint Documentation development On-site/Off-site support Mitigating risks All requirements covered Compliance Audit PCI DSS compliance assessment, real time dashboard. Report on Compliance (RoC), Attestation of Compliance (AOC), Testmark, Certificate or validation of Self Assessment Questionnaire (SAQ). Vulnerability Assessment Internal and external vulnerability assessment and penetration testing; and ASV scan Compliance Management GRC tool with PCI DSS workflow alert, documentation, role assignments, review and dashboard. Deployed on-site with migration support. Test Mark Information Security Service Portfolio