PCI DSS & 3 RD PARTY SERVICE PROVIDERS



Similar documents
PCI & the Contact Centre The Acquirer Perspective

Key USP s. Multiple PCI level GRC tool

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance

A Compliance Overview for the Payment Card Industry (PCI)

PCI 3.0 Making Payment Security Business As Usual

Internal Audit Activity Update

Registration and PCI DSS compliance validation

Payment Card Industry (PCI) Data Security Standard

Third-Party Security Assurance

Payment Card Industry (PCI) Data Security Standard

PCI DSS Compliance What Texas BUC$ Need to Know! Ron King CampusGuard

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard

IT TECHNICAL SECURITY REVIEW CHECKLISTS FOR E-COMMERCE WEBSITES

Payment Card Industry (PCI) Data Security Standard

What are the PCI DSS requirements? PCI DSS comprises twelve requirements, often referred to as the digital dozen. These define the need to:

How To Protect Your Business From A Hacker Attack

Payment Card Industry (PCI) Data Security Standard

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program

PCI on Amazon Web Services (AWS) What You Need To Know Understanding the regulatory roadmap for PCI on AWS

PCI DSS. Payment Card Industry Data Security Standard.

Payment Card Industry (PCI) Data Security Standard

Merchant guide to PCI DSS

Third Party Agent Registration and PCI DSS Compliance Validation Guide

Attestation of Compliance, SAQ A

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program

Payment Card Industry Data Security Standard

How To Ensure Account Information Security

Payment Card Industry (PCI) Data Security Standard

PDQ Guide for the PCI Data Security Standard Self-Assessment Questionnaire C (Version 1.1)

Payment Card Industry (PCI) Data Security Standard

PCI DSS Gap Analysis Briefing

Payment Card Industry (PCI) Data Security Standard. Attestation of Compliance for Self-Assessment Questionnaire C-VT. Version 2.0

AISA Sydney 15 th April 2009

Section 1: Assessment Information

Property of CampusGuard. Compliance With The PCI DSS

State of Oregon Office of the State Treasurer 3 rd Party Service Provider Application

PCI Compliance at The University of South Carolina. Failure is not an option. Rick Lambert PMP University of South Carolina

Data Security Standard (DSS) Compliance. SIFMA June 13, 2012

Vendor 1 QUESTION CCSF RESPONSE

UO Third Party Credit Card Processing Request

Attestation of Compliance for Onsite Assessments Service Providers

Registry of Service Providers

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard

Platform as a Service and PCI

1/18/10. Walt Conway. PCI DSS in Context. Some History The Digital Dozen Key Players Cardholder Data Outsourcing Conclusions. PCI in Higher Education

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard

UTAH VALLEY UNIVERSITY Policies and Procedures

THIRD PARTY AGENT REGISTRATION PROGRAM

Self Assessment Questionnaire A Short course for online merchants

Protecting Your Customers' Card Data. Presented By: Oliver Pinson-Roxburgh

Your Compliance Classification Level and What it Means

PCI DSS Overview. By Kishor Vaswani CEO, ControlCase

Achieving PCI Compliance for Your Site in Acquia Cloud

2.1.2 CARDHOLDER DATA SECURITY

Point-to-Point Encryption (P2PE)

PCI DSS 3.0 Overview. OSU Business Affairs Business Affairs PIT Crew - Project, Improvement, & Technology Robin Whitlock

Payment Card Industry (PCI) Data Security Standard

Attestation of Compliance for Onsite Assessments Service Providers

Payment Card Industry (PCI) Data Security Standard

Introduction to PCI DSS

Annual Trustwave PCI Self Assessment Questionnaire (SAQ) Educational Presentation. Understanding the Merchants Responsibilities for PCI Compliance

Mobile Device Payment Card Processing: How Secure is It? Richard Poworski CISSP, ISP, ITCP, SCF, PCI QSA, PCIP Managing Consultant

Credit Card Risks: Update on PCI Compliance Monday, May 23 2:40pm 3:55 CPE: 2

Third Party Agent Registration Program Frequently Asked Questions

PCI DSS 3.0 and You Are You Ready?

Reliable, Low-Cost Credit Card Processing Since 1998

<COMPANY> P07 - Third Parties Policy

PCI DSS. CollectorSolutions, Incorporated

A MERCHANTS GUIDE TO THE PAYMENT APPLICATION DATA SECURITY STANDARD (PA-DSS)

Three Critical Success Factors for PCI Assessment. Seth Peter NetSPI April 21, 2010

RFQ Section 1. What is your highest known merchant level (1, 2, 3, or 4) as assigned by your acquirer?

PCI DSS Compliance Information Pack for Merchants

Payment Card Industry Data Security Standards

PCI Compliance. How to Meet Payment Card Industry Compliance Standards. May cliftonlarsonallen.com CliftonLarsonAllen LLP

Comodo HackerGuardian. PCI Security Compliance The Facts. What PCI security means for your business

Payment Card Industry (PCI) Data Security Standard

MasterCard PCI & Site Data Protection (SDP) Program Update. Academy of Risk Management Innovate. Collaborate. Educate.

Agent Registration. Program Guide. (For use in Asia Pacific, Central Europe, Middle East, Africa)

PCI Standards: A Banking Perspective

The PCI DSS Compliance Guide For Small Business

Attestation of Compliance for Onsite Assessments Service Providers

Payment Card Industry Data Security Standard (PCI DSS) v1.2

Payment Card Industry (PCI) Additional Security Requirements for Token Service Providers (EMV Payment Tokens)

UTAH VALLEY UNIVERSITY Policies and Procedures

Puzzled about PCI compliance? Proactive ways to navigate through the standard for compliance

PCI Compliance Instructions

FAQ s for Payment Card Processing at the University

This document contains 3 checklists for three different types of ecommerce websites permissible under University e commerce

Project Title slide Project: PCI. Are You At Risk?

Spokane Airport Board (Spokane International Airport, Airport Business Park, Felts Field) Addendum #1 - Q&A

PCI Compliance: How to ensure customer cardholder data is handled with care

Validation of PCI Compliance Requirements NC Office of the State Controller June 23, 2015

Understanding the SAQs for PCI DSS version 3

UCSB Credit Card Processing and PCI Compliance

John B. Dickson, CISSP October 11, 2007

Agent Registration. Program Guidelines. (For use in Asia Pacific, Central Europe, Middle East and Africa)

Transcription:

PCI DSS & 3 RD PARTY SERVICE PROVIDERS A PUSH-ME, PULL-ME RELATIONSHIP Katie Todd, CTP Asst. Director of PCI Compliance & Merchant Account Services Columbia University Global Treasury Operations Tuesday, May 24, 2016

AGENDA Defining Third Party Service Providers (TPSPs) How does CU Manage TPSPs Lessons Learned Best Practices for Managing TPSPs PCI Requirements Q & A

THINGS TPSP MAY SAY None of our other customers ask for this. You re the Merchant, you re the one that has to maintain PCI compliance, not us.

WHAT IS A TPSP? Any business entity that is not a payment brand, directly involved in the processing, storage, or transmission of cardholder data on behalf of another entity. This also includes companies that provide services that control or could impact the security of cardholder data. (Source:www.pcisecuritystandards.org)

TRADITIONAL TPSPs ACQUIRERS & PAYMENT PROCESSORS PAYMENT GATEWAY PROVIDERS

OTHER SERVICE PROVIDERS

COLUMBIA UNIVERSITY Approximately 350 Merchant Accounts Over 80 Departments Level 3 Merchant 16 Schools and Medical Center 16K Employees 30K Students

HOW MANAGING DOES CU MANAGE TPSPs TPSPs Who s Involved? PROCUREMENT SERVICES IT SECURITY TREASURY Morningside Manhattanville Medical Center Nevis Labs Lamont- Doherty Faculty Practice Offices

HOW MANAGING DOES CU MANAGE TPSPs TPSPs HOW DOES COLUMBIA DO IT? PROCUREMENT SERVICES Services Compliance Checklist

MANAGING TPSPs HOW DOES COLUMBIA DO IT? PCI if this section does not apply check here Does the project scope include integrating a method for accepting credit yes no card payments? If yes, provide a list of services that will be provided and attach documentation that demonstrates the Supplier has achieved PCI DSS compliance. Validation documentation may vary (You must contact Treasury to review specific documentation requirements)

HOW MANAGING DOES CU MANAGE TPSPs TPSPs HOW DOES COLUMBIA DO IT? PROCUREMENT SERVICES TREASURY SPECIFIC DOCUMENTATION Services Compliance Checklist If PCI is Checked IT SECURITY RISK ASSESSMENT SOW AoC ASV

LESSONS LEARNED THEN NOW

LESSONS LEARNED Bridging the communication gap. You MUST have a clear process in place. Be aware of modified or invalid PCI documentation.

NEW INITIATIVES OnBase Repository Documentation RSAM Registration Risk Assessment Collaboration

BEST PRACTICES (1): Have a clear policy & procedure in place for engaging service providers. (2): Identify specific services the service provider will provide. (3): Perform proper due diligence and risk assessment.

Here are 5 important questions you should ask upon hearing We re PCI compliant Did they self-attest to their compliance, or has their compliance been attested to by a third-party Qualified Security Assessor (QSA) in a Report on Compliance (RoC)? Does their PCI Compliance extend beyond physical security and their infrastructure? * If the service provider is a hosting provider, does their compliance extend into the customer environment? * Does the service provider maintain a written Responsibility Matrix to allow for easy identification of their customers responsibilities?

ADDITIONAL BEST PRACTICES Promote transparency Set expectations Responsibility matrix Develop a TPSP monitoring program

REVIEWING DOCUMENTATION

REVIEWING DOCUMENTATION

BEST PCI REQs PRACTICES FOR MERCHANTS continued 12.8 Maintain and implement policies and procedures to manage service providers with whom cardholder data is shared, or that could affect the security of cardholder data. 12.8.1 Maintain a list of service providers including a description of the service provided. 12.8.2 Maintain a written agreement. 12.8.5 Maintain information about which PCI DSS requirements are managed by each service provider, and which are managed by the entity.

PCI REQs THAT APPLY TO TPSPs Requirement 3: Protect stored cardholder data Requirement 10: Track and monitor all access to network resources and cardholder data. Requirement 11: Regularly test security systems and processes. Requirement 12: Maintain a policy that addresses information security for all personnel.

SUMMARY COLLABORATION HAVE A CLEAR PROCESS DOCUMENTATION DUE DILIGENCE MAINTAIN DOCUMENTATION

REFERENCES: https://www.pcisecuritystandards.org/documents/pci_dss_v3.0_third_party_security_assurance.pdf