PCI DSS Compliance & Security Awareness Program at UST



Similar documents
PCI DSS. CollectorSolutions, Incorporated

PCI Compliance: How to ensure customer cardholder data is handled with care

What are the PCI DSS requirements? PCI DSS comprises twelve requirements, often referred to as the digital dozen. These define the need to:

PCI Compliance Top 10 Questions and Answers

John B. Dickson, CISSP October 11, 2007

PCI Compliance. Top 10 Questions & Answers

WHITE PAPER. PCI Basics: What it Takes to Be Compliant

Payment Card Industry Data Security Standard Training. Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc.

Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS)

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008

SecurityMetrics Introduction to PCI Compliance

MasterCard PCI & Site Data Protection (SDP) Program Update. Academy of Risk Management Innovate. Collaborate. Educate.

An article on PCI Compliance for the Not-For-Profit Sector

TNHFMA 2011 Fall Institute October 12, 2011 TAKING OUR CUSTOMERS BUSINESS FORWARD. The Cost of Payment Card Data Theft and Your Business

PCI Overview. PCI-DSS: Payment Card Industry Data Security Standard

P R O G R E S S I V E S O L U T I O N S

PCI Compliance Overview

PC-DSS Compliance Strategies NDUS CIO Retreat July 27, 2011 Theresa Semmens, CISA

Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015

TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No MERCHANT DEBIT AND CREDIT CARD RECEIPTS

Josiah Wilkinson Internal Security Assessor. Nationwide

PCI Security Compliance

Adyen PCI DSS 3.0 Compliance Guide

The Cost of Payment Card Data Theft and Your Business. Aaron Lego Director of Business Development

Merchant guide to PCI DSS

FORT HAYS STATE UNIVERSITY CREDIT CARD SECURITY POLICY

White Paper September 2013 By Peer1 and CompliancePoint PCI DSS Compliance Clarity Out of Complexity

PCI Compliance. How to Meet Payment Card Industry Compliance Standards. May cliftonlarsonallen.com CliftonLarsonAllen LLP

PCI DSS Payment Card Industry Data Security Standard. Merchant compliance guidelines for level 4 merchants

PCI DSS. Payment Card Industry Data Security Standard.

Payment Card Industry Data Security Standards.

Project Title slide Project: PCI. Are You At Risk?

PCI Compliance at The University of South Carolina. Failure is not an option. Rick Lambert PMP University of South Carolina

IT Security Compliance PCI DSS FOR MERCHANTS THE PAYMENT CARD INDUSTRY DATE SECURITY STANDARD WHITE PAPER

PCI-DSS: A Step-by-Step Payment Card Security Approach. Amy Mushahwar & Mason Weisz

Comodo HackerGuardian. PCI Security Compliance The Facts. What PCI security means for your business

Introduction to PCI DSS

PCI DSS Compliance Services January 2016

How To Protect Your Business From A Hacker Attack

PCI DSS Presentation University of Cincinnati

Why Is Compliance with PCI DSS Important?

Becoming PCI Compliant

Payment Card Industry Data Security Standards Compliance

Understanding Payment Card Industry (PCI) Data Security

PAI Secure Program Guide

La règlementation VisaCard, MasterCard PCI-DSS

How To Protect Your Credit Card Information From Being Stolen

A PCI Journey with Wichita State University

PCI DSS Overview. By Kishor Vaswani CEO, ControlCase

Payment Card Industry Data Security Standard

How To Become A Pca Compliant Organization

Credit Cards and Oracle: How to Comply with PCI DSS. Stephen Kost Integrigy Corporation Session #600

Achieving PCI Compliance for Your Site in Acquia Cloud

What Every Business Should Know About PCI Compliance

Payment Card Industry - Achieving PCI Compliance Steps Steps

Whitepaper. PCI Compliance: Protect Your Business from Data Breach

PCI DSS 3.0 Changes & Challenges P R E S I D E N T/ C O - F O U N D E R F R S EC U R E

1/18/10. Walt Conway. PCI DSS in Context. Some History The Digital Dozen Key Players Cardholder Data Outsourcing Conclusions. PCI in Higher Education

Varonis Systems & The Payment Card Industry Data Security Standard (PCI DSS)

Strategies To Effective PCI Scoping ISACA Columbus Chapter Presentation October 2008

Frequently Asked Questions

PAYMENT CARD INDUSTRY (PCI) COMPLIANCE HISTORY & OVERVIEW

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer

Payment Card Industry Data Security Standard

Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions

PCI Compliance. What is New in Payment Card Industry Compliance Standards. October cliftonlarsonallen.com CliftonLarsonAllen LLP

PCI Standards: A Banking Perspective

Key Steps to Meeting PCI DSS 2.0 Requirements Using Sensitive Data Discovery and Masking

Whitepaper. PCI Compliance: Protect Your Business from Data Breach

Your guide to the Payment Card Industry Data Security Standard (PCI DSS) Merchant Business Solutions. Version 5.0 (April 2011)

PCI Compliance: Protection Against Data Breaches

COLORADO STATE UNIVERSITY Financial Procedure Statements FPI 6-6

Cal Poly PCI DSS Compliance Training and Information. Information Security 1

Credit Card Acceptance Policy. Vice Chancellor of Business Affairs. History: Effective July 1, 2011 Updated February 2013

Payment Card Industry Data Security Standards

Customer Card Data Security and You

The PCI DSS Compliance Guide For Small Business

E Pay. A Case Study in PCI Compliance. Illinois State Treasurer. Dan Rutherford

CHEAT SHEET: PCI DSS 3.1 COMPLIANCE

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire C and Attestation of Compliance

Accounting and Administrative Manual Section 100: Accounting and Finance

Protecting Your Customers' Card Data. Presented By: Oliver Pinson-Roxburgh

SecurityMetrics. PCI Starter Kit

Payment Card Industry Security Standards PCI DSS, PCI-PTS and PA-DSS

DATA SECURITY. Payment Card Industry (PCI) Compliance Steps for Organizations May 26, Merit Member Conference

Data Security Basics for Small Merchants

PCI DSS in Essence Through practical examples. September, 2016 Septia Academy

Understanding and Managing PCI DSS

HOW SECURE IS YOUR PAYMENT CARD DATA?

Your Compliance Classification Level and What it Means

Introduction to PCI DSS Compliance. May 18, :15 p.m. 2:15 p.m.

So you want to take Credit Cards!

Data Security Standard (DSS) Compliance. SIFMA June 13, 2012

Important Info for Youth Sports Associations

Property of CampusGuard. Compliance With The PCI DSS

A Compliance Overview for the Payment Card Industry (PCI)

PCI DSS Compliance Information Pack for Merchants

Two Approaches to PCI-DSS Compliance

Clark University's PCI Compliance Policy

AISA Sydney 15 th April 2009

Transcription:

PCI DSS Compliance & Security Awareness Program at UST

PCI DSS in a Nutshell Who? What? Where? When? Applicable to all UST employees that are exposed to any cardholder data while performing their job responsibilities Regulations created by card associations for merchants to follow in order to minimize risk and maximize protection of cardholder data Everywhere UST is handling (transmitting, storing, or processing) credit/debit card data Supposed to be compliant a few years ago the day before yesterday Why? Criminals are sneaky. Anyway, it s our duty to think critically, act wisely, and work skillfully to advance the common good this qualifies!

Bad Boys, Bad Boys Criminals and Stephen Watt, 26, wrote a custom packetsniffing program dubbed blabla - the code was used to siphon more than 100 million credit- and debit-card numbers from TJX s corporate network. When he s released from jail, he ll have a $171.5 million restitution order waiting for him to repay financial losses claimed by TJX in the hack attack. Computers Albert Gonzalez is a computer hacker and convicted criminal for masterminding the combined credit card theft and subsequent reselling of more than 170 million card and ATM numbers from TJ Maxx, Dave and Busters, and Heartland.

Higher Ed Is In The Crosshairs Data Security Challenges in HE Commitment to open networks Payment processes spread over large geographical areas/ multiple campuses Multiple merchants on one campus Multiple third-party systems for merchant transactions House data such as names, social security numbers, addresses, phone, etc http://datalossdb.org/statistics Taking into consideration that: There are vastly fewer education institutions than there are businesses (over 14 million) in the U.S. The share of total payment card transactions processed in the U.S. attributable to Higher Ed is relatively small Conclusion - Higher Ed has a disproportionately high percentage of data security incidents it s not a matter of if, but rather when.

Categorizing Incidents Security breach an incident where an attacker is able to circumvent the security of a system but does not imply a violation of the data Data compromise an incident where an attacker breaches a security system and gains access to data Exposed data Halfway between a breach and a compromise, when a known breach has occurred, but uncertain when and what data may have been compromised For example - You arrive home from work and find your front door broken down (breach). After entering your home, you realize your computer is gone (compromised). You keep track of your finances on that computer without any password protection (exposed data).

The Dangers of Noncompliance with PCI DSS Compromised data negatively affects customers, merchants, and financial institutions Just one incident can severely damage the reputation of UST Fines of up to $500,000 per card association per incident Additional related expenses of a breach: Forensic investigation fees Lawsuits Insurance claims Cancelled accounts Government fines Replacement cards Credit monitoring fees Reimbursement of losses Immediate level 1 merchant status and corresponding security measures (UST is currently level 4; level 1 is much more costly and burdensome to maintain) Lose the ability all together to accept payment cards

Alphabet Soup Before delving too much farther into the wondrous world of PCI DSS compliance, note the following acronyms and what they stand for: PCI DSS Payment Card Industry Data Security Standards PCI SSC Payment Card Industry Security Standards Council PA-DSS Payment Application Data Security Standards QSA Qualified Security Assessor ASV Approved Scanning Vendor SAQ Self Assessment Questionnaire ROC Report On Compliance CHD Cardholder Data CDE Cardholder Data Environment PAN Primary Account Number

PCI Players PCI SSC Card Associations ASV/QSA ( auditors ) Approved Scanning Vendor/ Qualified Security Assessor Acquiring Bank Merchant

PCI Players PCI Security Standards Council aka the Council was founded in 2006 by the five major Card Associations (Visa, MasterCard, Discover, American Express, and JCB) in an effort to standardize regulatory compliance requirements for payment card processing The 12 fruits of their labor are the PCI DSS

PCI Players Merchant Point of initiation for a payment card transaction Accepts payment cards (debit/credit) via one of several acceptance channels (card present/card not present) Subject to PCI DSS if process, store, or transmit sensitive cardholder data You! (As an agent of St. Thomas)

PCI Players Approved Scanning Vendor (ASV) Organizations approved by the PCI SSC to perform quarterly Internet vulnerability scans as required by PCI DSS 11.2 Qualified Security Assessor (QSA) A company and employed individual that is trained and approved by the PCI SSC to perform PCI compliance assessments

PCI Players Acquiring Bank aka the merchant bank the organization that sponsors the merchant to the card associations and enables the merchant to accept payment cards via the use of a merchant ID Majority of PCI DSS enforcement is accomplished through fines, fees, and other requirements issued by the acquiring bank to the merchant

PCI DSS Compliance vs. Validation Compliance state of being 24/7/365 Continual maintenance of baseline security requirements Merchants must be compliant with PCI DSS requirements at ALL times Validation point in time Periodic Annual or quarterly verification of compliance with PCI DSS Even if compliance is validated at some point during the year it does not mean UST is safe from attack

Merchant Categorization PCI DSS compliance validation standards may vary for merchants depending upon the volume of transactions processed and the acceptance channels used to process them. Merchants are segregated into levels (1 4) by their acquiring bank. Level 1 has the most stringent validation requirements, while level 4 allows for more selfreporting. Generally speaking, UST merchants are level 4.

The Self Assessment Questionnaire (SAQ) is a report completed by the merchant to assist with validating their PCI DSS compliance. There are several versions of the SAQ; selection of the appropriate SAQ is based upon payment acceptance methods. Validation Tool The SAQ

PCI DSS The Digital Dozen Build and Maintain a Secure Network 1. Install and maintain a firewall configuration to protect cardholder data 2. Do not use vendor-supplied defaults for system passwords and other security parameters Protect Cardholder Data 3. Protect stored data 4. Encrypt transmission of cardholder data across open, public networks Maintain a Vulnerability Management Program Implement Strong Access Control Measures Regularly Monitor and Test Networks Maintain an Information Security Policy 5. Use and regularly update anti-virus software 6. Develop and maintain secure systems and applications 7. Restrict access to cardholder data by business need-to-know 8. Assign a unique ID to each person with computer access 9. Restrict physical access to cardholder data 10. Track and monitor all access to network resources and cardholder data 11. Regularly test security systems and processes 12. Maintain a policy that addresses information security

UST Compliance PCI Group Representatives from IRT and Finance have been working on PCI DSS compliance for years Much effort has been expended toward creating a PCI Island - segmenting connected systems to keep them out of the PCI scope Created campus wide policy regarding payment card processing Updated Web Apps to bring them into compliance Responsible for developing and maintaining PCI DSS compliance program

Things You Must Do To Help Maintain Never store, process, or transmit card data outside of the approved systems Never transmit payment card data via email, text, IM, etc Do not use Wi-Fi for processing payment cards Contact the Business Office if you have any questions/concerns about payment card processing Compliance

Things You Must Do To Help Maintain Compliance Limit access to and lock down machines used to process payment card transactions Use only PA-DSS certified vendors (Put it in the contract!) Adhere to all UST payment card and data security policies Contact the Business Office if you have any questions/concerns about payment card processing

Things You Must Do To Help Maintain Shred any paper with payment card data immediately after processing using a cross-cut shredder Contact the Business Office if you have any questions/concerns about payment card processing Compliance

For more information Visit the following websites to learn more about PCI DSS and related issues: https://www.pcisecuritystandards.org/ http://www.adamdodge.com/esi/ http://usa.visa.com/merchants/risk_management/cisp.html http://www.mastercard.com/us/merchant/pdf/merchantacce ptanceguide_manual.pdf http://www.treasuryinstitute.org/pages/pci%7b47%7ddss- Information.html http://www.youtube.com/watch?v=oceywri86ts