Key USP s. Multiple PCI level GRC tool



Similar documents
Protecting Your Customers' Card Data. Presented By: Oliver Pinson-Roxburgh

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program

PCI DSS. Payment Card Industry Data Security Standard.

WHITE PAPER. PCI Basics: What it Takes to Be Compliant

How To Ensure Account Information Security

What are the PCI DSS requirements? PCI DSS comprises twelve requirements, often referred to as the digital dozen. These define the need to:

How To Protect Your Business From A Hacker Attack

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program

Puzzled about PCI compliance? Proactive ways to navigate through the standard for compliance

Credit Cards and Oracle: How to Comply with PCI DSS. Stephen Kost Integrigy Corporation Session #600

PCI Compliance for Cloud Applications

PCI DSS. CollectorSolutions, Incorporated

University of Oregon Policy Statement Development Form

Comodo HackerGuardian. PCI Security Compliance The Facts. What PCI security means for your business

PCI Compliance Overview

MasterCard PCI & Site Data Protection (SDP) Program Update. Academy of Risk Management Innovate. Collaborate. Educate.

Appendix 1 Payment Card Industry Data Security Standards Program

PCI Compliance: How to ensure customer cardholder data is handled with care

A Compliance Overview for the Payment Card Industry (PCI)

Becoming PCI Compliant

PCI DSS Payment Card Industry Data Security Standard. Merchant compliance guidelines for level 4 merchants

Project Title slide Project: PCI. Are You At Risk?

Click&DECiDE s PCI DSS Version 1.2 Compliance Suite Nerys Grivolas The V ersatile BI S o l uti on!

PAYMENT CARD INDUSTRY (PCI) COMPLIANCE HISTORY & OVERVIEW

Payment Card Industry Data Security Standard

Payment Card Industry Data Security Standard

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008

Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS)

1/18/10. Walt Conway. PCI DSS in Context. Some History The Digital Dozen Key Players Cardholder Data Outsourcing Conclusions. PCI in Higher Education

ARE YOU REALLY PCI DSS COMPLIANT? Case Studies of PCI DSS Failure! Jeff Foresman, PCI-QSA, CISSP Partner PONDURANCE

E Pay. A Case Study in PCI Compliance. Illinois State Treasurer. Dan Rutherford

What a Processor Needs from a University to Validate Compliance

Continuous compliance through good governance

IT Security Compliance PCI DSS FOR MERCHANTS THE PAYMENT CARD INDUSTRY DATE SECURITY STANDARD WHITE PAPER

Spokane Airport Board (Spokane International Airport, Airport Business Park, Felts Field) Addendum #1 - Q&A

A PCI Journey with Wichita State University

Property of CampusGuard. Compliance With The PCI DSS

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer

Merchant guide to PCI DSS

Payment Card Industry Data Security Standard Training. Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc.

PCI Security Compliance

PCI DSS Overview and Solutions. Anwar McEntee

PCI Compliance. Top 10 Questions & Answers

Your guide to the Payment Card Industry Data Security Standard (PCI DSS) Merchant Business Solutions. Version 5.0 (April 2011)

PCI Compliance at The University of South Carolina. Failure is not an option. Rick Lambert PMP University of South Carolina

Josiah Wilkinson Internal Security Assessor. Nationwide

The PCI DSS Compliance Guide For Small Business

2015 PCI DSS Meeting. OSU Business Affairs Projects, Improvement, and Technology (PIT) Robin Whitlock

June 19, Bobbi McCracken, Associate Vice Chancellor Financial Services. Subject: Internal Audit of PCI Compliance.

Technical breakout session

An article on PCI Compliance for the Not-For-Profit Sector

PCI DSS Compliance Information Pack for Merchants

PCI DSS Gap Analysis Briefing

Introduction to PCI DSS Compliance. May 18, :15 p.m. 2:15 p.m.

PCI Compliance Top 10 Questions and Answers

Using Automated, Detailed Configuration and Change Reporting to Achieve and Maintain PCI Compliance Part 4

Data Security Standard (DSS) Compliance. SIFMA June 13, 2012

Maintaining PCI-DSS compliance. Daniele Bertolotti Antonio Ricci

Office of Finance and Treasury

PCI DSS & 3 RD PARTY SERVICE PROVIDERS

Bottom line you must be compliant. It s the law. If you aren t compliant, you are leaving yourself open to fines, lawsuits and potentially closure.

Accepting Payment Cards and ecommerce Payments

Sales Rep Frequently Asked Questions

PCI DSS READINESS AND RESPONSE

How To Protect Your Credit Card Information From Being Stolen

Adyen PCI DSS 3.0 Compliance Guide

Mobile Device Payment Card Processing: How Secure is It? Richard Poworski CISSP, ISP, ITCP, SCF, PCI QSA, PCIP Managing Consultant

Understanding and Managing PCI DSS

Payment Card Industry Data Security Standard (PCI DSS) v1.2

TOP 10 WAYS TO ADDRESS PCI DSS COMPLIANCE. ebook Series

Your Compliance Classification Level and What it Means

IT TECHNICAL SECURITY REVIEW CHECKLISTS FOR E-COMMERCE WEBSITES

Brown Smith Wallace, LLC

Payment Card Industry Data Security Standard Explained

Are You Ready For PCI v 3.0. Speaker: Corbin DelCarlo Institution: McGladrey LLP Date: October 6, 2014

PCI DSS Reporting WHITEPAPER

Vanderbilt University

Payment Card Industry Data Security Standards Compliance

Third-Party Access and Management Policy

PCI Standards: A Banking Perspective

PCI COMPLIANCE FOR HIGHER EDUCATION BEST PRACTICES CHECKLIST. Presented By: The Treasury Institute for Higher Education.

WHITE PAPER. How to simplify and control the cardholder security environment

PCI DSS Compliance What Texas BUC$ Need to Know! Ron King CampusGuard

Payment Card Industry Compliance Overview

University Policy Accepting Credit Cards to Conduct University Business

Transcription:

PCI GRC tool

Introduction GP history Visa level 1 approved hosting facility Niche product for a specific problem Reduce BAU cost and cost of PCI compliance Reduce cost in managing 3rd parties PCI stakeholder engagement Metering PCI compliance all year long Less dependency on QSA as the baseline is set and agreed

Key USP s Multiple PCI level GRC tool Based on the compliance reporting as expected by the QSA and the Acquiring Banks Every item included in the solution is based on key audit points that will be required to show their activities over a period of time Integration and Management of 3 rd Parties Complete visibility into 3 rd parties risks, assets, policies and projects Online registration and data entry Merchant has complete control over 3 rd party PCI compliance Complete System of Record for PCI DSS 3.1 Backbone to PCI DSS 3.1 Governance, Reporting and Compliance Continuously evolves as PCI requirement changes Complete audit trail across many periods Fully hosted and accessible from anywhere Perfect tool for operations to use on an ongoing basis to ensure compliance

Target audience Level 1 processing over 6M Visa transactions per year. Level 2 processing 1M to 6M Visa transactions per year. Level 3 QSA required No QSA required 20,000 to 1M Visa e-commerce transactions per year Level 4 20,000 Visa e-commerce transactions per year, and all other merchants

What is PCI GRC? A new concept to the PCI sector Allows merchants to be organised and structured in the management on their PCI obligations Puts the merchant in control of its PCI estate Reduces OPEX on PCI compliance Breaks down all the PCI reporting compliance into manageable task distributed across your organisation with consolidated reporting Online based self reporting that can be expanded nationwide Reduces the need to have multiple Auditors with the self assessment capabilities PCI GRC Acquiring Banks PCI scope PCI stakeholders PCI non compliance PCI compliance status Policy management Policy change management PCI 3 rd parties Merchant ID Payment channels Business units Notification & escalation Compliance dashboard Policy owners & review dates Business demand for MIDs Payment systems Project managers Risk assessment of changes Compliance assessment SAQs Incident reporting Remediation & approval Incident notification Online Self reporting Policy enforcement Non compliance reporting Service catalogue

A consolidated system of records for PCI PCI Locations Centralised self reporting PCI Policies PCI service catalogue PCI GRC PCI Projects PCI non tech risks PCI 3 rd parties Merchant IDs

Merchant ID

MID lifecycle MID request Business units complete online form They select options from the form PCI scope alignment Business units selects from a Service catalogue in the PCI scope PCI compliance PCI team assesses the request for PCI compliance Treasury approval Treasury receive a PCI compliant request ready for Acquiring Bank submission Acquiring Bank MID assignment PCI compliance reporting per MID

Integration with multiple payment processors

Linking Merchant IDs into your PCI scope

PCI request register/form 1. PCI request form completed 2. Request is sent to PCI POC for review and approval 3. Once POC approves, it is sent to Treasury for treasury approval 4. Request approver approves and it is sent to supplier 5. Supplier gets the form and enters confirmation number and confirmation is sent to all the parties 6. Request is archived and added to the PCI scope 7. Update to existing a. New role called Treasury b. PCI location linked to business departments c. MID to be associated to each payment channel d. Business units to reflect payment scope e. Business department to include address, f. Acquiring bank to include user accounts 8. Permission can be set

MID Request - General

MID Request Card Readers

MID Request ecommerce

Managing multiple PCI locations & Business units

PCI merchant ID System of record from Merchant ID to risks The foundation of the PCI compliance starts from your Merchant ID. Every activity you carry is based on the decision of whether or not the activity is in scope (within the Merchant ID or out of scope (not within the Merchant ID.

PCI Asset register

PCI GRC approach to Asset management Projects Assets PCI projects PCI changes PCI systems PCI devices (Telephone) Technical Assets PCI firewalls PCI routers PCI devices PCI GRC 3 rd party Assets 3 rd PCI systems 3 rd PCI devices 3 rd PCI locations PCI physical locations Merchant owned locations 3 rd party owned locations

System of record PCI reporting range Merchant ID Acquiring Bank Business units Business projects Risk assessment Payment channels E-commerce Cardholder present Cardholder not present Payment apps Risk assessment PCI 3 rd party suppliers E-commerce redirect PCI products & services 3 rd party procurement PCI service catalogue Risk assessment PCI change management Software development lifecycle Business acquisitions New sales projects New suppliers Due diligence PCI BAU activities PCI policies & procedures PCI QSA & ASV reports PCI risk management Prioritized approach reporting PCI SAQs PCI Assets & network elements Network monitoring solutions

PCI Asset management PCI Assets linked to risks, Policies and projects Automated PCI Asset network monitoring Integration with PCI Asset monitoring tools

PCI 3 rd parties

What is the contractual expectation of Acquiring Banks in relation to 3 rd parties The Merchant must notify Acquiring Banks of all third parties who have access to Cardholder data on behalf of the Merchant (i.e., store, process or otherwise transmit Cardholder data). The Merchant acknowledges such third parties are required by the Card Schemes to be registered, and the Merchant shall cooperate with Acquiring Banks in completing such registration and be responsible for all fees imposed by the Card Schemes in connection therewith. The Merchant shall notify Acquiring Bank immediately if it becomes aware of or suspects any security breach relating to Transaction Data and shall also (and without prejudice to any other remedy Acquiring Bank have in respect thereof) immediately identify and resolve the cause of such security breach and take any steps that Acquiring Bank may require of the Merchant to do so, including as reasonably necessary the procurement (at the Merchant s cost) of forensic reports from third parties recommended by Acquiring Bank.

The MasterCard service provider compliance list

PCI compliant PCI service providers are maintained with automatic notification

Your PCI service providers: Products and services

Visa & MasterCard approved suppliers Validation date

Managing external providers and their obligations

QSAs and their deliverables QSA

PCI prioritized approach

PCI service catalogue PCI products and service view

PCI products and services placed with merchants

PCI risks with resolution links to suppliers

PCI risk reporting

Records kept to show PCI risk mitigation efforts lesson learnt can be shared group wide PCI Risk reporting PCI risk register PCI Asset register Business units Suspicious activities PCI policy register PCI 3 rd parties Customer complaints Anomaly reporting PCI BAU team notification PCI policy register PCI project register Contact centres Banned cards PCI risk assessment Online tool available to Manager level or regional level contact

PCI Risk reporting from business units

PCI reporting

PCI prioritized approach

PCI prioritized approach summary

The End info@pci-selfassessment.com