PCI Data Security Standards



Similar documents
Becoming PCI Compliant

PCI Compliance. Top 10 Questions & Answers

PCI Compliance Top 10 Questions and Answers

Why Is Compliance with PCI DSS Important?

PCI Compliance. How to Meet Payment Card Industry Compliance Standards. May cliftonlarsonallen.com CliftonLarsonAllen LLP

Josiah Wilkinson Internal Security Assessor. Nationwide

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008

PCI Compliance. What is New in Payment Card Industry Compliance Standards. October cliftonlarsonallen.com CliftonLarsonAllen LLP

PCI DSS Policies Outline. PCI DSS Policies. All Rights Reserved. ecfirst Page 1 of 7

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance

PCI DSS Overview. By Kishor Vaswani CEO, ControlCase

Presented By: Bryan Miller CCIE, CISSP

SECTION: SUBJECT: PCI-DSS General Guidelines and Procedures

How To Protect Your Business From A Hacker Attack

2015 PCI DSS Meeting. OSU Business Affairs Projects, Improvement, and Technology (PIT) Robin Whitlock

Project Title slide Project: PCI. Are You At Risk?

How To Protect Your Credit Card Information From Being Stolen

PCI COMPLIANCE GUIDE For Merchants and Service Members

University of Sunderland Business Assurance PCI Security Policy

Payment Card Industry Data Security Standard Training. Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc.

Credit Card Acceptance Policy. Vice Chancellor of Business Affairs. History: Effective July 1, 2011 Updated February 2013

Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015

Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS)

Frequently Asked Questions

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire

PCI DSS Requirements - Security Controls and Processes

PCI Security Compliance

Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance

COLORADO STATE UNIVERSITY Financial Procedure Statements FPI 6-6

Credit Cards and Oracle: How to Comply with PCI DSS. Stephen Kost Integrigy Corporation Session #600

IT Security Compliance PCI DSS FOR MERCHANTS THE PAYMENT CARD INDUSTRY DATE SECURITY STANDARD WHITE PAPER

Your guide to the Payment Card Industry Data Security Standard (PCI DSS) Merchant Business Solutions. Version 5.0 (April 2011)

GFI White Paper PCI-DSS compliance and GFI Software products

PCI Compliance: How to ensure customer cardholder data is handled with care

This appendix is a supplement to the Local Government Information Security: Getting Started Guide, a non-technical reference essential for elected

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer

SecurityMetrics Introduction to PCI Compliance

La règlementation VisaCard, MasterCard PCI-DSS

PDQ Guide for the PCI Data Security Standard Self-Assessment Questionnaire C (Version 1.1)

WHITE PAPER. PCI Basics: What it Takes to Be Compliant

The 12 Essentials of PCI Compliance How it Differs from HIPPA Compliance Understand & Implement Effective PCI Data Security Standard Compliance

PCI Compliance Overview

MasterCard PCI & Site Data Protection (SDP) Program Update. Academy of Risk Management Innovate. Collaborate. Educate.

Comodo HackerGuardian. PCI Security Compliance The Facts. What PCI security means for your business

Property of CampusGuard. Compliance With The PCI DSS

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire C and Attestation of Compliance

CHEAT SHEET: PCI DSS 3.1 COMPLIANCE

Sales Rep Frequently Asked Questions

PCI DSS v2.0. Compliance Guide

Payment Card Industry Data Security Standard

Payment Card Industry Data Security Standards.

PCI DSS. CollectorSolutions, Incorporated

What are the PCI DSS requirements? PCI DSS comprises twelve requirements, often referred to as the digital dozen. These define the need to:

How To Protect Visa Account Information

Payment Card Industry Data Security Standards

PAI Secure Program Guide

TNHFMA 2011 Fall Institute October 12, 2011 TAKING OUR CUSTOMERS BUSINESS FORWARD. The Cost of Payment Card Data Theft and Your Business

PLACE GROUP UK LONDON STUDENT HOUSING GROUP PAYMENT CARD INDUSTRY DATA SECURITY STANDARD COMPLIANCE STATEMENT PCI DSS (09) VERSION: 2009PCIDSSP4S01

North Carolina Office of the State Controller Technology Meeting

PCI DSS Compliance Information Pack for Merchants

Varonis Systems & The Payment Card Industry Data Security Standard (PCI DSS)

Merchant guide to PCI DSS

PCI Standards: A Banking Perspective

Two Approaches to PCI-DSS Compliance

TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No MERCHANT DEBIT AND CREDIT CARD RECEIPTS

Your Compliance Classification Level and What it Means

Payment Cardholder Data Handling Procedures (required to accept any credit card payments)

Payment Card Industry - Achieving PCI Compliance Steps Steps

PCI COMPLIANCE TO BUILD HIGHER CONFIDENCE FOR CARD HOLDER AND BOOST CASHLESS TRANSACTION. Suresh Dadlani, ControlCase

Adyen PCI DSS 3.0 Compliance Guide

Payment Card Industry (PCI) Data Security Standard

PCI Training for Retail Jamboree Staff Volunteers. Securing Cardholder Data

SAQ D Compliance. Scott St. Aubin Senior Security Consultant QSA, CISM, CISSP

PCI DSS 3.0 Changes Bill Franklin Executive IT Auditor January 23, 2014

PCI DSS Presentation University of Cincinnati

University of Dayton Credit / Debit Card Acceptance Policy September 1, 2009

The Cost of Payment Card Data Theft and Your Business. Aaron Lego Director of Business Development

Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions

Credit Cards and Oracle E-Business Suite Security and PCI Compliance Issues

PCI Quick Reference Guide

PAYMENT CARD INDUSTRY (PCI) COMPLIANCE HISTORY & OVERVIEW

Continuous compliance through good governance

Payment Card Industry Data Security Standard

Payment Card Industry Data Security Standards (PCI-DSS) Guide for Contact Center Managers

HOW SECURE IS YOUR PAYMENT CARD DATA? COMPLYING WITH PCI DSS

Payment Card Industry (PCI) Data Security Standard. Summary of Changes from PCI DSS Version 2.0 to 3.0

PCI DSS Compliance Guide

Case 2:13-cv ES-JAD Document Filed 12/09/15 Page 1 of 116 PageID: Appendix A

CREDIT CARD MERCHANT PROCEDURES MANUAL. Effective Date: 5/25/2011

Credit Card Processing, Point of Sale, ecommerce

Transcription:

PCI Data Security Standards An Introduction to Bankcard Data Security

Why should we worry? Since 2005, over 500 million customer records have been reported as lost or stolen 1 In 2010 alone, over 134 million confidential customer records were compromised millions of those records included a social security number 1 The average institutional cost in 2009 for a data security breach was $7.2 million 2 Approximately 15 million Americans suffer an ID theft each calendar year The corporate cost of a breach includes legal fees, customer / compensation, loss of stock value, loss of customer confidence, loss of business, board of director embarrassment 1 Privacy Rights Clearinghouse (www.privacyrights.org) 2 - Ponemon Institute 2010 Annual Study: US Cost of a Data Breach

Unlimited markets exist to trade stolen data

How/Where is Data Lost or Stolen? 44% lost by or due to third party error 1 41% due to negligence vs. 31% malicious acts 1 Lost/stolen laptop or other mobile device 1 16% by companies that had previously suffered a data breach 1 Entities/Industries suffering losses: Government Agencies Health Care Providers Financial Services Industry Retailers Schools and Universities Payment processors (e.g. issuers, acquirers) 1 Ponemon Institute 2010 Annual Study: US Cost of a Data Breach

What is PCI? The Payment Card Industry Data Security Standard (PCI DSS) is a set of requirements developed by the banking industry for the protection of payment card data. PCI DSS is not ASSESS A federal or state regulation A comprehensive data security program A guarantee against data loss REPORT REMEDIATE A one-time objective. PCI DSS is An exceptionally useful tool in improving payment data security and reducing the risk of loss A requirement of all bankcard networks and payment acquirers A set of guidelines that can be generally applied to an institutional data protection plan

Bankcard Payments Ecosystem Merchant Acquirer PIN Debit Network Customer Payment Credit Card Network Statement Card Issuer

PCI DSS Overview (Merchant Levels) Level* Amex Discover JCB MasterCard Visa Level 1 Annual QSA review / Quarterly scan by ASV Annual QSA review / Quarterly scan by ASV Annual QSA review / Quarterly scan by ASV Annual QSA review / Quarterly scan by ASV Annual QSA review / Quarterly scan by ASV Annual Vol >2.5 Million N/A > 1 Million > 6 Million > 6 Million Level 2 Quarterly scan by ASV N/A Annual selfassessment / Quarterly scan by ASV Annual selfassessment / Quarterly scan by ASV Annual selfassessment / Quarterly scan by ASV Annual Vol 50K 2.5 Million N/A < 1 Million 1 M 6 Million 1 M 6 Million Level 3 Quarterly scan by ASV N/A N/A Annual selfassessment / Quarterly scan by ASV Annual selfassessment / Quarterly scan by ASV Annual Vol < 50K N/A N/A 20K 1 Million 20K 1 Million Level 4 N/A N/A N/A Annual selfassessment / Quarterly scan by ASV Annual Vol N/A N/A N/A < 20K < 20K Annual selfassessment / Quarterly scan by ASV

Payment Card Data PAN CARDHOLDER NAME EXPIRATION DATE CID

PCI DSS Overview (Basic Rules) PCI DSS applies only if the merchant stores the PAN (personal account number) 12 core requirements and approximately 200 subrequirements are organized within six groups Build and Maintain a Secure Network Protect Cardholder Data Maintain a Vulnerability Management Program Implement Strong Access Control Measures Regularly Monitor and Test Networks Maintain an Information Security Policy

Build and Maintain a Secure Network Install and maintain a firewall configuration to protect cardholder data Between stored data and all external systems Between stored data and other internal systems Between the payment processing system and all other programs By minimizing communications traffic and access to that data On all remote devices used to access the data Do not use vendor-supplied defaults for system passwords and other security parameters Change passwords regularly Disable unnecessary and unsecure services and protocols

Protect Cardholder Data Protect cardholder data When obtained from cardholders over the phone When provided on paper or in any electronic medium When stored in any form When transmitted or transferred in any form When electronic copies are accessed Store it ONLY when required to support business processes Never store prohibited payment data Render PAN useless to unauthorized persons Protection cryptographic keys Encrypt transmission of cardholder data across open, public networks Apply strong encryption to wireless networks Never send unencrypted PANs via common messaging systems (e.g. e- mail, chat, IM)

Maintain a Vulnerability Management Program Use and regularly update anti-virus software On central systems and desktop devices Configure for automated use Develop and maintain secure systems and applications Monitor, validate and track system accesses Use encryption and limit access to data whenever/wherever possible Maintain a schedule for installing and testing patches and updating virus ware Maintain separate environments for testing and production Strict change control

Implement Strong Access Control Measures Restrict access to cardholder data by business need-to-know Automated process for access control User access based on roles and responsibilities Process for user to access set-up and changes Process for user access setup and changes Establish minimum required access (not maximum) Assign a unique ID to each person with computer access Unique ID for each user Two-factor login Establish rules requiring strong passwords Restrict or remove system accesses, where required Establish auto-lockout after multiple logon errors Restrict physical access to cardholder data Monitor and record all access to data storage facilities Secure shipping and transport Require and verify IDs for employees and visitors Badge access only for restricted areas Restrict remote access

Regularly Monitor and Test Networks Track and monitor all accesses to network resources and cardholder data Log all accesses to the network and / or data including Unsuccessful attempts Viewing of audit trails Creation, deletion of system-level objects Record everything (e.g. User ID, date, time, data accessed) Limit access to audit logs and prohibit changes Regularly test security systems and processes Run vulnerability scans Test for wireless access points Deploy file integrity monitoring Conduct annual internal and external penetration testing Utilize intrusion detection

Maintain an Information Security Policy Maintain a policy that addresses information security Create the Policy Distribute it Review and update it annually Define consistent policies Establish corresponding procedures Establish CISO and security team Educate Staff and vendors Maintain an incident response plan

PCC DSS Overview (Audits and Scans) Certified Vendor Community QSV (Qualified Security Assessors) PA QSQ (Payment Application Qualified Security Assessor) ASV (Approved Scanning Vendor) Self-Assessment Questionnaire Tool used to perform self-evaluation of compliance with the Standard Always valid for use by any organization Meets full audit requirements for certain merchant levels

The Self Assessment Questionnaire Description Card Not Present (e-commerce and Mail Order / Telephone Order MOTO). All cardholder data functions outsourced. Imprint-only merchants with no cardholder data storage, or standalone, dial-out terminal merchants with no electronic cardholder data storage SAQ A B Merchants using only web-based virtual terminals, no electronic cardholder data storage Merchants with payment application systems connected to the Internet, no electronic cardholder data storage All other merchants (not included in descriptions for SAQ types A through C above) and all service providers defined by a card brand as eligible to complete an SAQ. C-VT C D

Questionnaire Sample

About édept LLC is an independent consultancy providing business and technical assistance and advice regarding the applicability and implementation of payment systems. It specializes in the evaluation, development and implementation of payment solutions and security. For additional information regarding our services, contact: Gary Yamamura g_yamamura@msn.com 760-443-3967 Artwork featured in this presentation are by the late artist Frank Frazetta