How To Write A Pca Dss Compliance Solution For Gameplan Group Ltd



Similar documents
The PCI DSS Compliance Guide For Small Business

An article on PCI Compliance for the Not-For-Profit Sector

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program

PCI Compliance: How to ensure customer cardholder data is handled with care

Payment Card Industry Data Security Standard

How To Protect Your Credit Card Information From Being Stolen

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program

Key USP s. Multiple PCI level GRC tool

Payment Card Industry Data Security Standards.

What are the PCI DSS requirements? PCI DSS comprises twelve requirements, often referred to as the digital dozen. These define the need to:

Puzzled about PCI compliance? Proactive ways to navigate through the standard for compliance

PCI Compliance. Top 10 Questions & Answers

Western Australian Auditor General s Report. Information Systems Audit Report

PCI DSS and SSC what are these?

How To Protect Visa Account Information

Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS)

PCI Compliance Overview

PCI Compliance Top 10 Questions and Answers

WHITE PAPER. PCI Basics: What it Takes to Be Compliant

Validation of PCI Compliance Requirements NC Office of the State Controller June 23, 2015

Property of CampusGuard. Compliance With The PCI DSS

How To Protect Your Business From A Hacker Attack

<COMPANY> P01 - Information Security Policy

Westpac Merchant. A guide to meeting the new Payment Card Industry Security Standards

And Take a Step on the IG Career Path

Payment Card Industry Data Security Standard Explained

MasterCard PCI & Site Data Protection (SDP) Program Update. Academy of Risk Management Innovate. Collaborate. Educate.

What a Processor Needs from a University to Validate Compliance

WEST LOTHIAN COUNCIL INFORMATION SECURITY POLICY

VISA EUROPE ACCOUNT INFORMATION SECURITY (AIS) PROGRAMME FREQUENTLY ASKED QUESTIONS (FAQS)

PCI DSS Compliance Information Pack for Merchants

/ BROCHURE / CHECKLIST: PCI/ISO COMPLIANCE. By Melbourne IT Enterprise Services

University of Sunderland Business Assurance PCI Security Policy

TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No MERCHANT DEBIT AND CREDIT CARD RECEIPTS

PCI Standards: A Banking Perspective

Platform as a Service and PCI

IT Security Compliance PCI DSS FOR MERCHANTS THE PAYMENT CARD INDUSTRY DATE SECURITY STANDARD WHITE PAPER

Your Compliance Classification Level and What it Means

POLICY & PROCEDURE DOCUMENT NUMBER: DIVISION: Finance & Administration. TITLE: Policy & Procedures for Credit Card Merchants

Brown Smith Wallace, LLC

Specialist Cloud Services. Acumin Cloud Security Resourcing

Third Party Security Requirements Policy

The Cost of Payment Card Data Theft and Your Business. Aaron Lego Director of Business Development

PCI COMPLIANCE FOR HIGHER EDUCATION BEST PRACTICES CHECKLIST. Presented By: The Treasury Institute for Higher Education.

Virtualization Impact on Compliance and Audit

TNHFMA 2011 Fall Institute October 12, 2011 TAKING OUR CUSTOMERS BUSINESS FORWARD. The Cost of Payment Card Data Theft and Your Business

PCI DSS Compliance - what you need to know

Intel Enhanced Data Security Assessment Form

Common Use Systems and PCI Compliance

COMPLIANCE FRAMEWORK AND REPORTING GUIDELINES

Payment Card Industry Compliance Overview

The Cyber Attack and Hacking Epidemic A Legal and Business Survival Guide

June 19, Bobbi McCracken, Associate Vice Chancellor Financial Services. Subject: Internal Audit of PCI Compliance.

PCI DATA SECURITY STANDARD OVERVIEW

Appendix 1 Payment Card Industry Data Security Standards Program

Security Breaches and Vulnerability Experiences Overview of PCI DSS Initiative and CISP Payment Application Best Practices Questions and Comments

The Relationship Between PCI, Encryption and Tokenization: What you need to know

NSW Government Digital Information Security Policy

PDQ Guide for the PCI Data Security Standard Self-Assessment Questionnaire C (Version 1.1)

2015 PCI DSS Meeting. OSU Business Affairs Projects, Improvement, and Technology (PIT) Robin Whitlock

Protecting Cardholder Data Throughout Your Enterprise While Reducing the Costs of PCI Compliance

Payment Card Industry Data Security Standard (PCI DSS) v1.2

PCI Requirements Coverage Summary Table

PCI DSS Gap Analysis Briefing

G-Cloud Service Definition. Atos Information Security Wireless Scanning Service

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer

Outsourcing and third party access

Information governance strategy

PII Compliance Guidelines

Introduction to PCI DSS Compliance. May 18, :15 p.m. 2:15 p.m.

HOW SECURE IS YOUR PAYMENT CARD DATA?

PAYMENT CARD INDUSTRY (PCI) ANNUAL TRAINING DECEMBER 10, 2009 WESTERN ILLINOIS UNIVERSITY OFFICE OF THE CTSO & BUSINESS SERVICES

Payment Card Industry Data Security Standard Training. Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc.

Client Security Risk Assessment Questionnaire

Accepting Payment Cards and ecommerce Payments

Introduction to PCI Compliance

Strategies To Effective PCI Scoping ISACA Columbus Chapter Presentation October 2008

PCI DSS Compliance What Texas BUC$ Need to Know! Ron King CampusGuard

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008

MASSIVE NETWORKS Online Backup Compliance Guidelines Sarbanes-Oxley (SOX) SOX Requirements... 2

Secure Mobile Shredding and. Solutions

A MERCHANTS GUIDE TO THE PAYMENT APPLICATION DATA SECURITY STANDARD (PA-DSS)

Transcription:

PCI Compliance reporting solution This document describes GamePlan s PCI DSS compliance solution and its ability to assist organisations to be compliant with the regulatory requirements of the Payment card industry s Data Security Standards (PCI DSS). We have developed a solution, which could be entirely hosted within a PCI Level 1 VISA accredited hosting facility, to provide any organisation with the ability to meet its PCI DSS compliance in a structured and easy to manage environment. Our PCI compliance solution and reporting tool is based on project experience gained over many years by our team of certified PCI DSS Experts. Our collective experience is gained from working with various QSAs, Acquiring Banks, Payment processing companies and clients across various industry sectors who need to build, implement and maintain PCI compliance. Our solution is designed to be the least intrusive and can run within our client s in-house IT topology, partially outsourced or even 100% outsourced including hosting, design, implementation and maintenance of PCI DSS compliance against an agreed strategy. Company Gameplan Group Ltd is a niche consultancy that specialises on integrating Solutions, Processes and People to ensure our clients remain agile, within tolerance of their business processes, compliant to external governing bodies and above all achieve a rapid ROI from our projects. In addition to providing consultancy services around financial compliance we have also built mobile security and data encryption solutions that ensure PCI data protection on intranet and extranet networks as well as remote or mobile devices for clients across industries. Gameplan Group Ltd works closely with its chosen partners (such as Netplan, a VISA PCI level 1 accredited hosting facility) in order to deliver world class solutions with sustained return on investment to its customers. Gameplan Group Ltd will always act as prime contractor and in turn assume all legal responsibilities for the complete implementation.

Solution Overview Our solution is based on consulting services and a web based PCI compliance solution for third party compliance monitoring. The proposed PCI self-assessment solution would enable our clients to perform the following: 1. Allow access to key information for key stakeholders such as Business Owners, PCI, Data Protection Officers and Information Security staff. 2. Enable 3rd party PCI compliance management and monitoring 3. Provide PCI Asset registers with named owners 4. PCI change management procedures 5. PCI risk register linked to PCI assets and change requests 6. Enable PCI Audits (External/Internal audit, Information Security and Data Protection Officer) 7. A central repository of all PCI policies and procedures with owner aid maintenance The task of maintaining compliance can be a very challenging and expensive if not properly managed, we have therefore structured our solution to address our client s operational needs by putting together features that takes away the operational headaches involved with PCI DSS compliance and using our Experts previous experience to ease the process of compliance for our clients.

Our PCI compliance reporting solution There are three main services we provide: 1. PCI compliance framework 2. Third Party Supplier compliance management 3. PCI compliance management operational service PCI compliance framework Our PCI compliance framework sets out the foundational structure of your PCI compliance and acts as the starting point of your PCI compliance scope as defined by your QSA, if one has been appointed. We convert the agreed PCI scope into our compliance reporting software and solidify the foundation of your compliance efforts to ensure all stakeholders are able to access the data that relates to their area of responsibility. PCI DSS requires that key stakeholders in the organisation are to be engaged in order to maintain compliance with the PCI requirements. The following will be the key stakeholders given access on the web based compliance tool enabling multiple stakeholders to have a role in the management of the compliance. a. Customer services To have overall responsibility for PCI estate. b. External auditors To provide QSA services and ensure we are complying with the PCI DSS requirements. c. Security Manager d. Internal auditors To provide periodic checks on our compliance efforts and identify areas of non-compliance during the course of the year. e. Information security To ensure information security principles that govern PCI DSS are adhered to and also to provide information security reviews on the PCI estate. f. PCI asset owners Primary responsibility for PCI compliance, they would be set a number of tasks to complete at set times or periodically during the year. g. Compliance (Data Protection Officer) To ensure data protection and privacy issues are adhered to operationally and strategically as well as also to ensure that all PCI DSS policies and procedures also comply with the ICO requirements for safeguarding confidential data, of which, card data is a subset.

Third Party Supplier compliance management PCI DSS requires organisations that outsource its card data functions to 3rd parties to ensure that each 3rd party complies with the PCI DSS requirements. This requires ensuring, from the point of engagement, that there is a requirement for PCI DSS and during the course of the contract that there is periodic reporting on their levels of compliance. Each 3rd party will be required to comply with PCI DSS and will do so by self-assessing their compliance as well as report their compliance quarterly. All 3rd party suppliers will be assessed against the agreed PCI DSS standard and measured according to their level of compliance. This feature means our clients would be able to adequately manage all 3rd parties that handle its card data from a single web based platform.

Above, is the snapshot of a 3rd party compliance report against the 12 requirements of PCI DSS. The 3rd party will be measured against each area and they will be required to complete it quarterly as well as provide evidence of compliance. The information provided will then be rated and if the organisation meets the minimum standard required, they will be deemed to have passed and be compliant for that quarter. The 3rd party will need to maintain the level of compliance throughout the duration of the contract. As result, our clients would only need to focus on 3rd parties that are not compliant.

PCI compliance management operational service Our PCI compliance management operation service is based on our PCI compliance managed service whereby we insource your PCI compliance requirements and provide operational support for your PCI compliance governance requirements. Some of the features of our managed service are detailed below. We implement the PCI DSS compliance solution as part of a standard implementation methodology and project plan. This plan is pre-agreed with our client in accordance with resources available. Milestones are agreed and monitored via regular review meetings between Gameplan and the client Program Manager. Please contact us for more information how we could assist you to remain within tolerance of your PCI compliance requirements.