PCI: It Never Ends. Why?



Similar documents
PCI It Never Ends! Shekar Swamy, President Omega ATC. Denise Lewis, Pinnacle POS Product Manager. omegasecure.com

What does it mean to be secure?

Why Is Compliance with PCI DSS Important?

Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008

Payment Card Industry Data Security Standard Training. Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc.

PCI Compliance Overview

PAI Secure Program Guide

Frequently Asked Questions

Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015

AISA Sydney 15 th April 2009

Becoming PCI Compliant

PCI Compliance Top 10 Questions and Answers

TNHFMA 2011 Fall Institute October 12, 2011 TAKING OUR CUSTOMERS BUSINESS FORWARD. The Cost of Payment Card Data Theft and Your Business

Project Title slide Project: PCI. Are You At Risk?

PCI-DSS Compliance. Ron Dinwiddie Chief Technology Officer J. Spargo & Associates

Whitepaper. PCI Compliance: Protect Your Business from Data Breach

PCI Compliance. Top 10 Questions & Answers

SecurityMetrics Introduction to PCI Compliance

Josiah Wilkinson Internal Security Assessor. Nationwide

Achieving Compliance with the PCI Data Security Standard

Payment Card Industry - Achieving PCI Compliance Steps Steps

NACS/PCATS WeCare Data Security Program Overview

PCI Compliance: How to ensure customer cardholder data is handled with care

Target Security Breach

Your Compliance Classification Level and What it Means

Whitepaper. PCI Compliance: Protect Your Business from Data Breach

Credit Card Acceptance Policy. Vice Chancellor of Business Affairs. History: Effective July 1, 2011 Updated February 2013

Your guide to the Payment Card Industry Data Security Standard (PCI DSS) Merchant Business Solutions. Version 5.0 (April 2011)

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire

Data Security Basics for Small Merchants

DATA SECURITY. Payment Card Industry (PCI) Compliance Steps for Organizations May 26, Merit Member Conference

A PCI Journey with Wichita State University

PCI Compliance. How to Meet Payment Card Industry Compliance Standards. May cliftonlarsonallen.com CliftonLarsonAllen LLP

PCI DSS Compliance Information Pack for Merchants

Recent Developments in PCI DSS. PCI in the Headlines Risks to Higher Education PCI DSS Version 1.2

PCI DSS. CollectorSolutions, Incorporated

PCI Data Security Standards

PDQ Guide for the PCI Data Security Standard Self-Assessment Questionnaire C (Version 1.1)

The Cost of Payment Card Data Theft and Your Business. Aaron Lego Director of Business Development

1/18/10. Walt Conway. PCI DSS in Context. Some History The Digital Dozen Key Players Cardholder Data Outsourcing Conclusions. PCI in Higher Education

North Carolina Office of the State Controller Technology Meeting

Data Security for the Hospitality

Are You Ready For PCI v 3.0. Speaker: Corbin DelCarlo Institution: McGladrey LLP Date: October 6, 2014

Introduction to PCI DSS

Payment Card Industry Data Security Standard

PCI Compliance : What does this mean for the Australian Market Place? Nov 2007

Payment Card Industry Data Security Standard (PCI DSS) v1.2

PCI DSS Compliance White Paper

Cyber - Security and Investigations. Ingrid Beierly August 18, 2008

Payment Card Industry Data Security Standards

HOW TO PREPARE FOR A PCI DSS AUDIT

Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS)

PCI Compliance in Multi-Site Retail Environments

PCI Compliance. What is New in Payment Card Industry Compliance Standards. October cliftonlarsonallen.com CliftonLarsonAllen LLP

MasterCard PCI & Site Data Protection (SDP) Program Update. Academy of Risk Management Innovate. Collaborate. Educate.

Technical breakout session

PCI Risks and Compliance Considerations

Data Security Standard (DSS) Compliance. SIFMA June 13, 2012

PCI DSS Presentation University of Cincinnati

PCI-DSS: A Step-by-Step Payment Card Security Approach. Amy Mushahwar & Mason Weisz

Payment Card Industry Data Security Standard

HOW SECURE IS YOUR PAYMENT CARD DATA?

What are the PCI DSS requirements? PCI DSS comprises twelve requirements, often referred to as the digital dozen. These define the need to:

SecurityMetrics. PCI Starter Kit

PAYMENT CARD INDUSTRY (PCI) COMPLIANCE HISTORY & OVERVIEW

Payment Card Industry Security Standards PCI DSS, PCI-PTS and PA-DSS

P R O G R E S S I V E S O L U T I O N S

How To Protect Your Credit Card Information From Being Stolen

Important Info for Youth Sports Associations

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer

Comodo HackerGuardian. PCI Security Compliance The Facts. What PCI security means for your business

Credit Cards and Oracle: How to Comply with PCI DSS. Stephen Kost Integrigy Corporation Session #600

Franchise Data Compromise Trends and Cardholder. December, 2010

PCI DSS. Payment Card Industry Data Security Standard.

Top Five Data Security Trends Impacting Franchise Operators. Payment System Risk September 29, 2009

CHEAT SHEET: PCI DSS 3.1 COMPLIANCE

PCI PA - DSS. Point XSA Implementation Guide. Atos Worldline Banksys XENTA SA. Version 1.00

PCI DSS Overview. By Kishor Vaswani CEO, ControlCase

Protect Data. Secure Business.

PCI Assessments 3.0 What Will the Future Bring? Matt Halbleib, SecurityMetrics

2015 PCI DSS Meeting. OSU Business Affairs Projects, Improvement, and Technology (PIT) Robin Whitlock

A MERCHANTS GUIDE TO THE PAYMENT APPLICATION DATA SECURITY STANDARD (PA-DSS)

Payment Card Industry (PCI) Data Security Standard

SellWise User Group. Thursday, February 19, 2015

Security Breaches and Vulnerability Experiences Overview of PCI DSS Initiative and CISP Payment Application Best Practices Questions and Comments

Property of CampusGuard. Compliance With The PCI DSS

And Take a Step on the IG Career Path

White Paper September 2013 By Peer1 and CompliancePoint PCI DSS Compliance Clarity Out of Complexity

Payment Card Industry Data Security Standards.

PCI DSS Payment Card Industry Data Security Standard. Merchant compliance guidelines for level 4 merchants

PCI Compliance for Healthcare

Validation of PCI Compliance Requirements NC Office of the State Controller June 23, 2015

Payment Card Industry (PCI) Compliance A QSA Perspective

Net Report s PCI DSS Version 1.1 Compliance Suite

PCI DSS 3.0 and You Are You Ready?

The State of Security and Compliance for E- Commerce and Retail

Westpac Merchant. A guide to meeting the new Payment Card Industry Security Standards

Cal Poly PCI DSS Compliance Training and Information. Information Security 1

Transcription:

PCI: It Never Ends. Why? How to stay prepared? Shekar Swamy American Technology Corporation St. Louis, MO January 13, 2011

PCI compliance basics It s all about Data Security 12 major areas of compliance requirements it s the minimum not the maximum Essentially 286 specific controls for compliance new PCI 2.0 Self Assessment Questionnaire (SAQ) can be daunting

Merchant levels What are the merchant levels MasterCard or Visa Level 1 over 6 million Level 2-1 million 6 million Level 3 20,000 1 million Level 4 Less than 20,000

Who is liable for a breach? At the very minimum the entity that owns the merchant ID Major Oil Companies are not responsible for marketers and dealers Multi-store operators need to pay attention to their own compliance and breach risk Don t wait for MOC to tell you what to do New guidelines for Franchisors and franchisees Liability starts at the point of breach

State of PCI facts from the field Good security leads to compliance and keeps it that way 60% of breaches are external, 0ver 40% started inside 90% of insider breaches are deliberate malicious activity 94% is malware Backdoor 38% of all breaches, 85% of all records Going after memory resident data, moments before it gets encrypted Malware pre-tested against 30 plus engines created just for you! Remote access 34% - that s where it starts Please monitor your logs and create alerts based on policies Retailers freeze patching during busy season hackers know this Most breaches go unreported Majority of breaches discovered through 3 rd party notifications 86% of forensic audits everything about the breach was in the logs

What are the fines and Who levies them? Visa PCI Non-compliance fines begin at $5000 per month and can be significantly higher A data compromise could result in further fines by Visa and MasterCard to recover monetary losses suffered by credit card issuers affected by the breach American Express has posted fines beginning at $50,000 for PCI Non-compliance A data compromise could result in Visa fines for Account Data Compromise Recovery (ADCR), which pertains to domestic issued cards Data Compromise Recovery Solution (DCRS), which pertains to international issued cards The merchant where the breach occurred is held responsible, and ADCR/ DCRS fines represent a partial recovery of those losses suffered by the issuers

What are the fines and who levies them? (cont d) MasterCard fines are usually lump sum MasterCard levies fines for wrongful storage of magnetic stripe data and wrongful disclosure of account data These fines are typically one-time fines substituted for Visa's PCI Noncompliance fines MasterCard does not have a program similar to Visa's ADCR or DCRS MasterCard issuers utilize the chargeback system to recoup losses resulting from fraudulent transactions and the reissuance of credit cards Some issuers (e.g. Citibank) are very aggressive in pursuing monies via chargebacks while other issuers are less active

What should be your goal? Avoid getting breached folks it s not worth it It s painful, expensive and never ending Get the processes in place for becoming and staying compliant

A Burger King Franchise chain story Located in Illinois and Missouri 21 restaurants One location breached over a year ago 2 forensic audits just with Visa so far 5,000 dollars per month fines levied by Visa Master card just got started Consuming the attention of the whole company Over $150,000 spent so far Now considered a Level 1 merchant 4 years

How did they recover? Completed a detailed gap analysis performed by QSAs Upgraded their POS and back office systems to the latest PA-DSS compliant versions Implemented a system to completely monitor, log, report and maintain compliance reviewed by QSAs Fines stopped after these steps were completed Instituted policies internally to be in compliance The whole company is sensitive to PCI compliance Now talking openly about their experience

PCI Compliance today PCI DSS moving to a 3 year cycle of changes PCI DSS 2.0 was released on October 28 th, 2010 Implementation started in January 2011 If you are currently compliant with DSS 1.2 you have all of 2011 to become compliant with 2.0 SAQ D has grown from 236 controls to 286 controls The council is increasing its efforts to hold acquiring banks more accountable in enforcing PCI compliance QSA annual reviews are getting tougher and many QSAs are on review Expect compliance enforcement to get a lot tougher

What s new in PCI? Notable changes: A requirement that retailers must perform extensive searches for cardholder data across all their networks and systems A move to a three-year PCI lifecycle Clarification on what constitutes acceptable network segmentation Anti Virus and Firewall logs must be retained 12 months Wireless Intrusion Detection primarily intended for multisite operations unlikely to get a pass from QSAs File integrity monitoring requirement is more explicit validation of compliance PA-DSS and PCI DSS becoming aligned

How to Ensure You ll Always be Compliant Preparation Traps to Avoid Common Gaps Insider s Tips

Common Gaps P C I C O M P L I A N C E G A P S Unnecessary and vulnerable services not removed Inadequate access controls and vulnerable remote control- 2FA Storage of magnetic stripe data Lack of monitoring Lack of segmentation in a network Lack of logging - event,firewall, and anti-virus logs Lack of internal system scanning Lack of wireless intrusion detection Lack of file integrity monitoring Lack of alerting and consolidated reporting Incomplete policies and procedures Missing and outdated security patches Default system settings and passwords

How To Ensure You ll Always Be Compliant? Preparation Understand your service and compliance levels Understand your network environment, hardware and software Prepare for an audit internally or with assistance from a service provider Do a gap analysis document it no shortcuts Determine how to address them Avoid compensating controls, fix gaps right the first time Find a partner to lead you through the evaluation process Go through the 12 PCI DSS standards and requirements Hire a Qualified Security Assessor (QSA) to Complete "Attestation of Compliance" to confirm that your business meets all PCI requirements

Traps to Avoid How To Ensure You ll Always Be Compliant? (cont d) Treating PCI as a technology checklist its not a check box game Focusing on the cost of PCI compliance tools Not practicing PCI all year long Failing to look at the whole picture Getting the auditing process started too early Taking systems out of scope to limit your work Focus on validation of compliance - proof

Insider s Tips How To Ensure You ll Always Be Compliant? (cont d) Avoid manual processes for determining the state of your systems Get tools and technologies in place that can assist you for a long time Managed firewall service is not the entire PCI compliance process Involve your senior management in discussions Manage your whole environment even if systems are out of scope Watch out for remote control access first place QSAs look for problems Get your act together - systems fixed and policies in place

Staying compliant requires a process Takes a lot of effort and requires senior management support Do a PCI readiness assessment You can do it or have a consultant do it Attempt to answer questions on SAQ Take a holistic approach, nothing piece meal Determine the gaps Start with external scanning of your sites and home office to see what are all showing up Understand the extent of issues and risks

Staying compliant requires a process Find a solution to help you determine the state of your systems and fix them. Steps include: External & Internal Scanning Monitoring Logging Patching Collecting data for evidence Looking at the evidence to support the SAQ Get someone to come in and verify that you are meeting the requirements Continue process on an ongoing basis

PCI Compliance: It Never Ends Its like changing tires in a moving car! Shekar Swamy shekar.swamy@atcusa.com Contact: 636-557-7777 x2450 Mobile: 610-639-0172