How To Protect Your Business From A Hacker Attack



Similar documents
Payment Card Industry Data Security Standards.

How To Protect Visa Account Information

How To Protect Your Credit Card Information From Being Stolen

La règlementation VisaCard, MasterCard PCI-DSS

Your guide to the Payment Card Industry Data Security Standard (PCI DSS) Merchant Business Solutions. Version 5.0 (April 2011)

MasterCard PCI & Site Data Protection (SDP) Program Update. Academy of Risk Management Innovate. Collaborate. Educate.

PDQ Guide for the PCI Data Security Standard Self-Assessment Questionnaire C (Version 1.1)

PCI Compliance. Top 10 Questions & Answers

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008

Merchant guide to PCI DSS

PCI Compliance Top 10 Questions and Answers

Comodo HackerGuardian. PCI Security Compliance The Facts. What PCI security means for your business

Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS)

PCI Compliance: How to ensure customer cardholder data is handled with care

PCI Compliance at The University of South Carolina. Failure is not an option. Rick Lambert PMP University of South Carolina

WHITE PAPER. PCI Basics: What it Takes to Be Compliant

Payment Card Industry Data Security Standard Training. Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc.

PCI Security Compliance

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program

PCI DSS Compliance Information Pack for Merchants

Payment Card Industry Data Security Standard

Adyen PCI DSS 3.0 Compliance Guide

PCI Data Security Standards

PCI DSS. CollectorSolutions, Incorporated

An article on PCI Compliance for the Not-For-Profit Sector

What are the PCI DSS requirements? PCI DSS comprises twelve requirements, often referred to as the digital dozen. These define the need to:

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer

SecurityMetrics Introduction to PCI Compliance

PCI DSS Payment Card Industry Data Security Standard. Merchant compliance guidelines for level 4 merchants

Varonis Systems & The Payment Card Industry Data Security Standard (PCI DSS)

CHEAT SHEET: PCI DSS 3.1 COMPLIANCE

Frequently Asked Questions

PCI COMPLIANCE GUIDE For Merchants and Service Members

COLORADO STATE UNIVERSITY Financial Procedure Statements FPI 6-6

FAQ s. SaferPayments. Be smart. Be compliant. Be protected. The benefits of compliance SaferPayments Non-compliance fees

Payment Card Industry - Achieving PCI Compliance Steps Steps

PAYMENT CARD INDUSTRY (PCI) COMPLIANCE HISTORY & OVERVIEW

Two Approaches to PCI-DSS Compliance

IT Security Compliance PCI DSS FOR MERCHANTS THE PAYMENT CARD INDUSTRY DATE SECURITY STANDARD WHITE PAPER

PAI Secure Program Guide

2015 PCI DSS Meeting. OSU Business Affairs Projects, Improvement, and Technology (PIT) Robin Whitlock

PCI Standards: A Banking Perspective

Project Title slide Project: PCI. Are You At Risk?

PCI Compliance: Protection Against Data Breaches

Payment Card Industry Data Security Standards Compliance

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program

How To Comply With The Pci Ds.S.A.S

CREDIT CARD MERCHANT PROCEDURES MANUAL. Effective Date: 5/25/2011

Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015

PCI DSS Presentation University of Cincinnati

PCI Compliance Overview

Information for merchants. Program implementation details for merchants. Payment Card Industry Data Security Standard (PCI DSS)

Your Compliance Classification Level and What it Means

Achieving Compliance with the PCI Data Security Standard

worldpay.com Understanding the 12 requirements of PCI DSS SaferPayments Be smart. Be compliant. Be protected.

Payment Card Industry Data Security Standard

PCI DSS Compliance What Texas BUC$ Need to Know! Ron King CampusGuard

Why Is Compliance with PCI DSS Important?

Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions

PCI DSS 3.0 Overview. OSU Business Affairs Business Affairs PIT Crew - Project, Improvement, & Technology Robin Whitlock

A Compliance Overview for the Payment Card Industry (PCI)

White Paper September 2013 By Peer1 and CompliancePoint PCI DSS Compliance Clarity Out of Complexity

Payment Card Industry (PCI) Data Security Standard

PCI DSS 101 FOR CTOs AND BUSINESS EXECUTIVES

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance

How To Ensure Account Information Security

Property of CampusGuard. Compliance With The PCI DSS

Credit Card Acceptance Policy. Vice Chancellor of Business Affairs. History: Effective July 1, 2011 Updated February 2013

Payment Card Industry Data Security Standards

PCI: The Dark Side. May 2012 Roanoke, VA

VISA EUROPE ACCOUNT INFORMATION SECURITY (AIS) PROGRAMME FREQUENTLY ASKED QUESTIONS (FAQS)

Accepting Payment Cards and ecommerce Payments

Security Breaches and Vulnerability Experiences Overview of PCI DSS Initiative and CISP Payment Application Best Practices Questions and Comments

Josiah Wilkinson Internal Security Assessor. Nationwide

PCI DSS. Payment Card Industry Data Security Standard.

Registration and PCI DSS compliance validation

Payment Card Industry (PCI) Data Security Standard. Attestation of Compliance for Self-Assessment Questionnaire C-VT. Version 2.0

Westpac Merchant. A guide to meeting the new Payment Card Industry Security Standards

Becoming PCI Compliant

Q: What is PCI? Q: To whom does PCI apply? Q: Where can I find the PCI Data Security Standards (PCI DSS)? Q: What are the PCI compliance deadlines?

* Any merchant that has suffered a hack that resulted in an account data compromise may be escalated to a higher validation level.

University of Sunderland Business Assurance PCI Security Policy

E Pay. A Case Study in PCI Compliance. Illinois State Treasurer. Dan Rutherford

PCI Compliance. How to Meet Payment Card Industry Compliance Standards. May cliftonlarsonallen.com CliftonLarsonAllen LLP

PROTECTION OF OUR MERCHANTS AND REFERRAL PARTNERS IS OUR FIRST CONCERN

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance

Introduction to PCI DSS Compliance. May 18, :15 p.m. 2:15 p.m.

Payment Card Industry Data Security Standard (PCI DSS) v1.2

Transcription:

Payment Card Industry Data Security Standards

The payment card industry data security standard PCI DSS Visa and MasterCard have developed the Payment Card Industry Data Security Standard or PCI DSS as a means of managing risk of external and internal data compromises. This is a set of industry-wide requirements and processes, supported by every major international payment card system through the PCI Security Standards Council or PCI Council. The PCI DSS has 12 basic requirements that focus on using secure systems. The standards include installing a firewall, changing default passwords, protecting stored data, using antivirus software and encrypting transmissions of cardholder data across public networks. The way PCI DSS relates to your business and the way in which it should be implemented will depend on: The size and nature of your business. The configuration of your card acceptance system and processes. The service providers you work with and their respective roles. The PCI DSS requirements By following the PCI DSS requirements you can assess if your business protects cardholder data, has a secure network, maintains a security policy, maintains strong access control measures, regularly monitors and tests networks, utilises a third party and if so, if they are also meeting the PCI DSS requirements. The 12 PCI DSS requirements are as follows: Build and maintain a secure network 1. Install and maintain a firewall configuration to protect cardholder data. 2. Do not use vendor-supplied defaults for system passwords and other security parameters. Protect cardholder data 3. Protect stored cardholder data. 4. Encrypt transmission of cardholder data across open public networks. Maintain a vulnerability management program 5. Use and regularly update anti-virus software or programs. 6. Develop and maintain secure systems and applications. Implement strong access control measures 7. Restrict access to cardholder data by business need-to-know. 8. Assign a unique ID to each person with computer access. 9. Restrict physical access to cardholder data.

Regularly monitor and test networks 10. Track and monitor all access to network resources and cardholder data. 11. Regularly test security systems and processes. Maintain an information security policy 12. Maintain a policy that addresses information security for employees and contractors. Further information can be obtained from www.pcisecuritystandards.org The benefits to your business By following the industry-wide requirements of the PCI DSS, businesses can: Protect customer data. Provide a complete health check for any business that stores or transmits customer information. Lower exposure to financial losses and remediation costs. Maintain customer trust and safeguard the reputation of their brand. Don t put your customers or your business at risk Protecting your customers account information from the growing threat posed by high-tech criminals is one of the biggest challenges facing businesses today. As technology used by merchants and their partners has evolved, card fraud has become more sophisticated. Any business that processes, stores or transmits cardholder account data is a potential target. It is important for merchants to understand what measures need to be taken every day to ensure the security of highly sensitive personal financial information. How do I get started? The PCI Help Desk (1300 736 216) will be able to provide advice on the validation process to merchants who require it. The service will be answered by Vectra Corporation. Visa and MasterCard have created a set of tools and resources to make PCI DSS implementation simple and straightforward. Visa s program is called the Account Information Security Program AIS for details visit http://www.visa-asia.com/ap/au/ merchants/riskmgmt/ais.shtml or email vpssais@visa.com MasterCard s program is called the Site Data Protection Program SDP for details visit http://www.mastercard.com/us/sdp or email sdp@mastercard.com

Frequently asked questions Who needs to be compliant? All entities that store, process and/or transmit cardholder data, such as merchants, service providers (e.g. payment gateways, SPSP, processors), must comply with the PCI DSS. The requirements apply to all acceptance channels including retail (brick-and-mortar), mail and telephone order MOTO, and e-commerce. The obligation to comply may also arise under your Merchant Agreement. How do I know if I meet the PCI DSS requirements? To check that you have met the PCI DSS requirements, you will need to complete one or more of the following validation tasks (depending on the annual volumes you process). These standards include: The Self-Assessment Questionnaire SAQ Vulnerability Scan On-site Review. Do I have to complete all the validation tasks? Visa and MasterCard have defined four merchant levels to determine the requirements. These are summarised in the table below: Level Visa/MasterCard Validation Requirements 1 2 3 4 Merchants processing over 6 million transactions annually (all channels), or global merchants identified as Level 1 by any card scheme Merchants processing 1 million to 6 million transactions annually (all channels) Merchants processing 20,000 to 1 million e-commerce transactions annually Merchants processing less than 20,000 e-commerce transactions annually, and all other merchants processing up to 1 million transactions annually Annual on-site assessment by QSA Attestation of compliance Annual SAQ Attestation of compliance Annual SAQ Annual SAQ

What is a vulnerability scan? A vulnerability scan ensures that your systems are protected from external threats such as unauthorised access, hacking or malicious viruses. The scanning tools test all of your network equipment, hosts and applications for known vulnerabilities. Scans are intended to be non-intrusive and are conducted by an Approved Scanning Vendor (ASV). Regular quarterly scans are necessary to ensure that your systems and applications continue to afford adequate levels of protection. For a list of ASVs that provide vulnerability scanning, please visit www.pcissc.org What is the Self-Assessment Questionnaire? The SAQ is a free, confidential tool that can be used to gauge your level of compliance with the PCI DSS. It is an online tool made up of a series of yes and no questions. Once it has been completed, you will have made a good assessment of your risk level. If the assessment indicates that remedial work is needed, you will need to undertake this work in order to comply with the PCI DSS. You can complete the process internally or work with a QSA to manage it on your behalf. Once completed, the SAQ will provide you with an assessment of where potential risks may lie. The questionnaire will also point out if any remedial action is required. If this occurs, you must make sure that you act quickly to ensure compliance with the PCI DSS standards. The appropriate SAQ can be downloaded from the PCI Council website and can be completed manually and submitted to the bank. Alternatively a number of Scan vendors support acquiring online completion of the SAQ on their websites. You can visit the PCI Council website at: www.pcisecuritystandards.org/ What do I do once I acknowledge my validation to PCI DSS compliance? All information relating to PCI DSS certification should be stored in a safe location on your merchant premises and your certificate of compliance must be emailed to pci@nab.com.au What if I choose not to be involved in the program? Merchants must adhere to PCI DSS requirements, failure to do so may give rise to a breach of the Merchant Agreement and/or lead to your merchant facilities being suspended or terminated.

For more information call 1300 736 216 2010 National Australia Bank Limited ABN 12 004 044 937 AFSL 230686 69235A0610