PCI Compliance : What does this mean for the Australian Market Place? Nov 2007



Similar documents
AISA Sydney 15 th April 2009

Payment Card Industry Data Security Standards.

How To Protect Your Business From A Hacker Attack

What are the PCI DSS requirements? PCI DSS comprises twelve requirements, often referred to as the digital dozen. These define the need to:

PCI DSS Payment Card Industry Data Security Standard. Merchant compliance guidelines for level 4 merchants

How To Protect Your Credit Card Information From Being Stolen

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008

PCI Security Compliance

Project Title slide Project: PCI. Are You At Risk?

An article on PCI Compliance for the Not-For-Profit Sector

PCI Compliance Overview

Josiah Wilkinson Internal Security Assessor. Nationwide

MasterCard PCI & Site Data Protection (SDP) Program Update. Academy of Risk Management Innovate. Collaborate. Educate.

How To Protect Visa Account Information

Frequently Asked Questions

Varonis Systems & The Payment Card Industry Data Security Standard (PCI DSS)

PCI Standards: A Banking Perspective

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard

Adyen PCI DSS 3.0 Compliance Guide

PCI DSS Compliance Information Pack for Merchants

Comodo HackerGuardian. PCI Security Compliance The Facts. What PCI security means for your business

Payment Card Industry - Achieving PCI Compliance Steps Steps

Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS)

WHITE PAPER. PCI Basics: What it Takes to Be Compliant

Payment Card Industry Data Security Standard

Important Info for Youth Sports Associations

Payment Card Industry (PCI) Data Security Standard

Attestation of Compliance for Onsite Assessments Service Providers

2015 PCI DSS Meeting. OSU Business Affairs Projects, Improvement, and Technology (PIT) Robin Whitlock

PCI Compliance: How to ensure customer cardholder data is handled with care

Property of CampusGuard. Compliance With The PCI DSS

Your guide to the Payment Card Industry Data Security Standard (PCI DSS) Merchant Business Solutions. Version 5.0 (April 2011)

PCI DSS Presentation University of Cincinnati

Credit Card Processing Overview

Payment Card Industry Data Security Standard Training. Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc.

Payment Card Industry Data Security Standard (PCI DSS) v1.2

DATA SECURITY. Payment Card Industry (PCI) Compliance Steps for Organizations May 26, Merit Member Conference

Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer

PCI DSS. CollectorSolutions, Incorporated

Payment Card Industry (PCI) Data Security Standard. Attestation of Compliance for Self-Assessment Questionnaire C-VT. Version 2.0

P R O G R E S S I V E S O L U T I O N S

CardControl. Credit Card Processing 101. Overview. Contents

TNHFMA 2011 Fall Institute October 12, 2011 TAKING OUR CUSTOMERS BUSINESS FORWARD. The Cost of Payment Card Data Theft and Your Business

Protecting Your Customers' Card Data. Presented By: Oliver Pinson-Roxburgh

Becoming PCI Compliant

La règlementation VisaCard, MasterCard PCI-DSS

Payment Card Industry Data Security Standards Compliance

PAYMENT CARD INDUSTRY (PCI) COMPLIANCE HISTORY & OVERVIEW

Introduction to PCI DSS

PC-DSS Compliance Strategies NDUS CIO Retreat July 27, 2011 Theresa Semmens, CISA

PCI Compliance Top 10 Questions and Answers

Merchant guide to PCI DSS

Payment Card Industry (PCI) Data Security Standard

worldpay.com Understanding the 12 requirements of PCI DSS SaferPayments Be smart. Be compliant. Be protected.

PCI COMPLIANCE TO BUILD HIGHER CONFIDENCE FOR CARD HOLDER AND BOOST CASHLESS TRANSACTION. Suresh Dadlani, ControlCase

IT Security Compliance PCI DSS FOR MERCHANTS THE PAYMENT CARD INDUSTRY DATE SECURITY STANDARD WHITE PAPER

The PCI DSS Compliance Guide For Small Business

This appendix is a supplement to the Local Government Information Security: Getting Started Guide, a non-technical reference essential for elected

Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry Security Standards PCI DSS, PCI-PTS and PA-DSS

PCI DSS Compliance Services January 2016

A Compliance Overview for the Payment Card Industry (PCI)

The Cost of Payment Card Data Theft and Your Business. Aaron Lego Director of Business Development

Two Approaches to PCI-DSS Compliance

How To Comply With The Pci Ds.S.A.S

Payment Card Industry (PCI) Data Security Standard

TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No MERCHANT DEBIT AND CREDIT CARD RECEIPTS

PCI Compliance. Top 10 Questions & Answers

Customer Card Data Security and You

Attestation of Compliance for Onsite Assessments Service Providers

PCI DSS Overview. By Kishor Vaswani CEO, ControlCase

PCI Compliance at The University of South Carolina. Failure is not an option. Rick Lambert PMP University of South Carolina

Your Compliance Classification Level and What it Means

Attestation of Compliance for Onsite Assessments Service Providers

PCI-DSS Compliance. Ron Dinwiddie Chief Technology Officer J. Spargo & Associates

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire

Attestation of Compliance for Onsite Assessments Service Providers

Introduction to PCI DSS Compliance. May 18, :15 p.m. 2:15 p.m.

PAI Secure Program Guide

Whitepaper. PCI Compliance: Protect Your Business from Data Breach

Payment Card Industry (PCI) Data Security Standard

Payment Cardholder Data Handling Procedures (required to accept any credit card payments)

SecurityMetrics Introduction to PCI Compliance

PCI DSS FAQ. The twelve requirements of the PCI DSS are defined as follows:

Data Security Basics for Small Merchants

Payment Card Industry (PCI) Data Security Standard

PCI Data Security Standards

1/18/10. Walt Conway. PCI DSS in Context. Some History The Digital Dozen Key Players Cardholder Data Outsourcing Conclusions. PCI in Higher Education

University of Sunderland Business Assurance PCI Security Policy

PCI Security Standards Council

PCI Data Security Standards. Presented by Pat Bergamo for the NJTC February 6, 2014

A MERCHANTS GUIDE TO THE PAYMENT APPLICATION DATA SECURITY STANDARD (PA-DSS)

Payment Card Industry (PCI) Data Security Standard

Key Steps to Meeting PCI DSS 2.0 Requirements Using Sensitive Data Discovery and Masking

Whitepaper. PCI Compliance: Protect Your Business from Data Breach

Information Technology

Transcription:

Sense of Security Pty Ltd (ABN 14 098 237 908) 306, 66 King St Sydney NSW 2000 Australia Tel: +61 (0)2 9290 4444 Fax: +61 (0)2 9290 4455 info@senseofsecurity.com.au PCI Compliance : What does this mean for the Australian Market Place? 1 www.senseofsecurity.com

Overview of PCI DSS Merchant Compliance Levels and Associated Compliance Requirements Risks and consequences of non-compliance Benefits of Compliance Current status of PCI in Australia Agenda 2 www.senseofsecurity.com

Payment Card transactions - on the increase 3 www.senseofsecurity.com

The big players in AU market 4 www.senseofsecurity.com

The PCI Security Standards Council Members 5 www.senseofsecurity.com

PCI Data Security Standard PCI DSS is: An open industry standard Tech requirements for data security PCI SSC maintains list of qualified PCI assessors (QSAs & ASVs) PCI DSS is not: A compliance program Card Schemes run their own programs 6 www.senseofsecurity.com

PCI DSS: Six Goals, Twelve Requirements The Payment Card Industry Data Security Standard (PCI DSS) Build and Maintain a Secure Network 1. Install and maintain a firewall configuration to protect cardholder data 2. Do not use vendor-supplied defaults for system passwords and other security parameters Protect Cardholder Data 3. Protect stored data 4. Encrypt transmission of cardholder data across open, public networks Maintain a Vulnerability Management Program 5. Use and regularly update anti-virus software 6. Develop and maintain secure systems and applications Implement Strong Access Control Measures 7. Restrict access to cardholder data by business need-to-know 8. Assign a unique ID to each person with computer access 9. Restrict physical access to cardholder data Regularly Monitor and Test Networks 10. Track and monitor all access to network resources and cardholder data 11. Regularly test security systems and processes Maintain an Information Security Policy 12. Maintain a policy that addresses information security 7 www.senseofsecurity.com

Who must comply? Everyone who stores, processes or transmits cardholder data PCI compliance is mandatory PCI applies to all parties in the payment process You cannot be partially compliant: Compliance is PASS/FAIL 8 www.senseofsecurity.com

How is PCI DSS Regulated? Regulated by the respective Card Scheme Compliance Programs. PCI is a technical standard of due care. PCI DSS is not law. The Payments System Board (PSB) of the Reserve Bank oversees the payments system in Australia. 9 www.senseofsecurity.com

Card Present Merchant swipes the card, enters the dollar amount. Merchant receives authorisation response and completes the transaction. Merchant bank forwards authorisation response Customer to merchant. bank sends funds to merchant bank. Authorisation request is sent to acquiring merchant bank. Customer bank verifies credit card and clears request. Customer Bank Merchant bank sends transaction information to customer (issuing) bank through Card Scheme Network Merchant Bank 10 www.senseofsecurity.com

Merchant Levels MasterCard & Visa from Jan08 *Annually Level 1 Level 2 Level 3 Level 4 Quarterly Annually More than 6M transactions Between 1M and 6M transactions Between 20K and 1M e- Commerce transactions All Others Self Assessment * Not Reqd Mandate Mandate Mandate Vulnerability Scan Mandate Mandate Mandate Mandate / Rec VISA Onsite Review Mandate Not Reqd Not Reqd Not Reqd 11 www.senseofsecurity.com

Merchant Levels Amex Quarterly Level 1 Level 2 Level 3 Annually More than 2.5M transactions Between 50K and 2.5M transactions Less than 50K transactions Vulnerability Scan Mandate Mandate Highly Recommend Onsite Review Mandate N/A N/A ref: http://www10.americanexpress.com/sif/cda/page/0,1641,17457,00.asp 12 www.senseofsecurity.com

What can and can t be stored What must not be stored (after authorisation): Full magnetic stripe Card verification values (CVV2, CVC2, CID) PIN verification value PIN and PIN block What can be stored (must be protected): Primary account number Cardholder name Service code Expiration date 13 www.senseofsecurity.com

Most Common PCI Requirements Not Met *Percentage of Compromised Merchants That Failed To Meet Each PCI DSS Requirement *Data gathered from more than 250 card compromise investigations conducted by ATW. This Slide is Copyright PCI Security Council Requirement 1: Install and maintain a firewall to protect cardholder data Requirement 3: Protect stored data Requirement 6: Develop and maintain secure systems and applications Requirement 8: Assign a unique ID to each person with computer access Requirement 10: Track and monitor access to network and card data Requirement 11: Regularly test security systems and processes 14 www.senseofsecurity.com

Risks and consequences of non-compliance Card Schemes may levy fines to the Acquiring Bank of a Merchant if Merchant is not compliant. Acquiring Bank may pass on fines to the Merchant in line with Merchant Contract or Bank s discretion. 15 www.senseofsecurity.com

Fines - MasterCard MasterCard has issued fines in AU. US$25K for non compliant Level 1 s & Level 1 and 2 Service Providers US$5K for Level 2 and 3 Merchants. Penalty applied if Merchant/Gateway: did not complete PCI DSS did not take steps to mitigate the risks of an account data compromise. Operational Risks to consider: Up to US$100K for each incident + Up to US$25K each day until member achieves compliance + Investigation and other related costs incurred. Compensation: Up to US$25 per card re-issued + Up to US$5 per card monitored (without card reissue) 16 www.senseofsecurity.com

Fines - Visa Visa AP has not yet levied any fines in AU. Crunch time will come in Jan 2008. Visa AP can fine up to US$500K if a threshold level is triggered. This threshold probably has been reached in AU (recent breach). $500K comprised of $100K in card replacement fees & $400K if more than $1M fraud reported. 17 www.senseofsecurity.com

Safe Harbour Safe harbor provides members protection from Visa fines in the event its merchant or service provider experiences a data compromise. To attain safe harbor status: must maintain full compliance at all times, including at the time of breach. must demonstrate prior to the compromise merchant was fully compliant. Ref: http://usa.visa.com/merchants/risk_management/cisp_overview.html 18 www.senseofsecurity.com

Merchant Benefits of Compliance Protect customers personal data Boost customer confidence through a higher level of data security Lower exposure to financial losses and remediation costs Maintain customer trust and safeguard the reputation of their brand Provide a complete health check for any business that stores or transmits customer information. 19 www.senseofsecurity.com

Visa s focus Historically focused on large e-commerce & Level 1 Merchants. (Target Compliance 31Dec07) Visa looking for evidence of Merchant PCI Cert intent & Road Maps for 08 09. Visa requires validation of Level 1 but not yet Level 2 Merchants. 20 www.senseofsecurity.com

Visa s Focus cont Not enough focus on Level 2 s at present. At least 6 breaches on Level 2 and Level 3 ecom Merchants recently. Expect in 2008: Certificate of compliance for Level 2 s. Education campaign for L3 s but not looking for certificate of compliance yet. 21 www.senseofsecurity.com

Service Providers 30-90 Service Providers in the AU Market. Expect merchants to look for partnership with a Service Provider to reduce Merchant exposure. Complexity when there is a 3 rd Party involved. 22 www.senseofsecurity.com

How big is the AU Market? Level 1 Level 2 Level 3 Level 4 } 300 650,000-750,000 Per info from MasterCard 23 www.senseofsecurity.com

So how many Merchants are Compliant? According to VISA USA: Ref:http://corporate.visa.com/md/nr/press719.jsp (30 Jul 07) Level Compliant Working towards 1 2 40% 33% 50% 42% 3 52% 22% 24 www.senseofsecurity.com

And in Australia? This type of info is not readily available to the public. Conflicting information. Some Acquirers confident for their L1 s. Complexity of historical systems means that true compliance still requires significant effort. 25 www.senseofsecurity.com

Australia s Position Research indicates that AU and NZ regions compare favourably with other APAC regions. Higher level of collaboration. Good work between banks and schemes. Scheme PCI Road Shows had good results. Fewer barriers with brands. 26 www.senseofsecurity.com

Are we better off now than 12 and 24 months ago? Overwhelming answer YES from all schemes and acquiring banks interviewed. 27 www.senseofsecurity.com

So where to from now? Merchants will likely consider hosted solutions. Expect more focus on Verified by Visa (vbv) and MasterCard SecureCode for cardholder authentication. Called 3-D Secure if the Gateway offers both. Merchants are no longer liable for chargebacks where the cardholder claims fraud or non participation 28 www.senseofsecurity.com

PCI DSS Continual Development Clarity and Consistency: data definitions and cardholder data storage and protection. Flexibility: compensating controls for data encryption New Security Requirement: New application level requirement (6.6) web app code review or web app fw. 29 www.senseofsecurity.com

Simplified SAQ s "Today, it's a one-size fits all but going forward we'll have four different versions based on the merchant's business," says Russo. "For instance, if they're small and just doing dial-up, there's no need for them to answer 200 questions, we'll just have 30 or 40 questions." Ref: http://computerworld.co.nz/news.nsf/scrt/6277adb06ebbc57fcc2573870002c963 5 Nov 07 30 www.senseofsecurity.com

Card Scheme Focus in 2008 Visa and MasterCard concur more education required for smaller sized merchants. MasterCard also noted focus on recalcitrant merchants. Payment Application Best Practices. 31 www.senseofsecurity.com

What if you haven't started PCI Compliance Initiatives yet? There is plenty of help available. Speak to Merchant Services at your Acquiring Bank. Speak to your local Card Scheme office. Read the standards at www.pcisecuritystandards.org Find a local QSA. Join a PCI Forum, read whitepapers Prepare your managers for the work ahead. 32 www.senseofsecurity.com

Thank you for participating in this research 33 www.senseofsecurity.com

Thank you Questions? Murray Goldschmidt Sense of Security Pty Ltd info@senseofsecurity.com.au Tel: +61 2 9290 4442 34 www.senseofsecurity.com