Customer PCI 3.0 Changes = New Opportunity For You. Giles Witherspoon-Boyd SecurityMetrics



Similar documents
PCI COMPLIANCE GUIDE For Merchants and Service Members

PCI Compliance 3.1. About Us

NEW PENETRATION TESTING REQUIREMENTS, EXPLAINED

How To Protect Your Data From Being Stolen

Administrative Improvements. Administrative Improvements. Scoping Guidance. Clarifications for Segmentation

Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015

PCI DSS v3.0 SAQ Eligibility

SecurityMetrics Introduction to PCI Compliance

North Carolina Office of the State Controller Technology Meeting

SecurityMetrics. PCI Starter Kit

Credit Card Processing, Point of Sale, ecommerce

Data Security for the Hospitality

Why Is Compliance with PCI DSS Important?

Payment Card Industry Data Security Standard

PCI DSS 3.0 Overview. OSU Business Affairs Business Affairs PIT Crew - Project, Improvement, & Technology Robin Whitlock

PCI Assessments 3.0 What Will the Future Bring? Matt Halbleib, SecurityMetrics

PDQ Guide for the PCI Data Security Standard Self-Assessment Questionnaire C (Version 1.1)

So you want to take Credit Cards!

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire

PCI DSS Policies Outline. PCI DSS Policies. All Rights Reserved. ecfirst Page 1 of 7

5 TIPS TO PAY LESS FOR PCI COMPLIANCE

PCI Compliance. What is New in Payment Card Industry Compliance Standards. October cliftonlarsonallen.com CliftonLarsonAllen LLP

PCI DSS Overview. By Kishor Vaswani CEO, ControlCase

SAQ D Compliance. Scott St. Aubin Senior Security Consultant QSA, CISM, CISSP

Client Security Risk Assessment Questionnaire

PCI DSS. CollectorSolutions, Incorporated

PCI Data Security Standards

External Scanning and Penetration Testing in PCI DSS 3.0. Gary Glover, Sr. Director of Security Assessments

Project Title slide Project: PCI. Are You At Risk?

Josiah Wilkinson Internal Security Assessor. Nationwide

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire

PCI DSS 3.0 : THE CHANGES AND HOW THEY WILL EFFECT YOUR BUSINESS

PCI Compliance. How to Meet Payment Card Industry Compliance Standards. May cliftonlarsonallen.com CliftonLarsonAllen LLP

Data Security Standard (DSS) Compliance. SIFMA June 13, 2012

Becoming PCI Compliant

Payment Card Industry (PCI) Data Security Standard. Summary of Changes from PCI DSS Version 2.0 to 3.0

PCI Compliance Top 10 Questions and Answers

PCI Compliance. Top 10 Questions & Answers

COLORADO STATE UNIVERSITY Financial Procedure Statements FPI 6-6

PCI DSS Compliance Information Pack for Merchants

Enforcing PCI Data Security Standard Compliance

Qualified Integrators and Resellers (QIR) Implementation Statement

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire C and Attestation of Compliance

Information Security Services. Achieving PCI compliance with Dell SecureWorks security services

10 Step PCI Certification Process for Merchants and Service Providers

See page 16. Thomas A. Vallas

Are You Ready For PCI v 3.0. Speaker: Corbin DelCarlo Institution: McGladrey LLP Date: October 6, 2014

Bottom line you must be compliant. It s the law. If you aren t compliant, you are leaving yourself open to fines, lawsuits and potentially closure.

PCI DSS Compliance What Texas BUC$ Need to Know! Ron King CampusGuard

Payment Card Industry Data Security Standard Training. Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc.

It Won t Happen To Me! A Network and PCI Security Webinar Presented By FMS and VendorSafe

Technical breakout session

PCI 3.1 Changes. Jon Bonham, CISA Coalfire System, Inc.

PCI Compliance Overview

PLACE GROUP UK LONDON STUDENT HOUSING GROUP PAYMENT CARD INDUSTRY DATA SECURITY STANDARD COMPLIANCE STATEMENT PCI DSS (09) VERSION: 2009PCIDSSP4S01

PCI COMPLIANCE REQUIREMENTS COMPLIANCE CALENDAR

Agenda. Agenda. Security Testing: The Easiest Part of PCI Certification. Core Security Technologies September 6, 2007

Adyen PCI DSS 3.0 Compliance Guide

Payment Card Industry - Achieving PCI Compliance Steps Steps

Credit Card Acceptance Policy. Vice Chancellor of Business Affairs. History: Effective July 1, 2011 Updated February 2013

SECURING YOUR REMOTE DESKTOP CONNECTION

AUTOMATING AUDITS AND ENSURING CONTINUOUS COMPLIANCE WITH ALGOSEC

Credit Cards and Oracle: How to Comply with PCI DSS. Stephen Kost Integrigy Corporation Session #600

PCI-DSS: A Step-by-Step Payment Card Security Approach. Amy Mushahwar & Mason Weisz

worldpay.com Understanding the 12 requirements of PCI DSS SaferPayments Be smart. Be compliant. Be protected.

PCI PA - DSS. Point XSA Implementation Guide. Atos Worldline Banksys XENTA SA. Version 1.00

PAYMENT CARD INDUSTRY (PCI) ANNUAL TRAINING DECEMBER 10, 2009 WESTERN ILLINOIS UNIVERSITY OFFICE OF THE CTSO & BUSINESS SERVICES

PAYMENT CARD INDUSTRY (PCI) COMPLIANCE WORKBOOK. PCI SAQ TYPE C-VT Level 4. Virtual Terminals

A MERCHANTS GUIDE TO THE PAYMENT APPLICATION DATA SECURITY STANDARD (PA-DSS)

What s New in PCI DSS Cisco and/or its affiliates. All rights reserved. Cisco Systems, Inc 1

Two Approaches to PCI-DSS Compliance

PCI Compliance Training

Data Security Basics for Small Merchants

HOW SECURE IS YOUR PAYMENT CARD DATA? COMPLYING WITH PCI DSS

What does it mean to be secure?

Accelerating PCI Compliance

Property of CampusGuard. Compliance With The PCI DSS

UCSB Credit Card Processing and PCI Compliance

Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions

Payment Card Industry - Data Security Standard (PCI-DSS) Security Policy

PCI Compliance Updates

PCI Compliance. Crissy Sampier, Longwood University Edward Ko, CampusGuard

LogLogic. Application Security Use Case: PCI Compliance. Jaime D Anna Sr Dir of Product Strategy, TIBCO Software

PCI DSS Requirements - Security Controls and Processes

paypoint implementation guide

TNHFMA 2011 Fall Institute October 12, 2011 TAKING OUR CUSTOMERS BUSINESS FORWARD. The Cost of Payment Card Data Theft and Your Business

Understanding the SAQs for PCI DSS version 3

Security Breaches and Vulnerability Experiences Overview of PCI DSS Initiative and CISP Payment Application Best Practices Questions and Comments

PCI: It Never Ends. Why?

Transcription:

Customer PCI 3.0 Changes = New Opportunity For You Giles Witherspoon-Boyd SecurityMetrics

Who is this guy? Giles Witherspoon-Boyd, PCIP 15 years in technology, 4 years at SecurityMetrics SecurityMetrics Help companies comply with regulatory compliance requirements (PCI, HIPAA, GLBA)

Merchant to do s Update 3 rd party contracts* Use PCI DSS validated 3 rd parties* Self assessment (up to 250 questions) Vulnerability scan Unencrypted card data scanning Employee training, implementation Policies and procedures Network/system updates Send compliance report to acquirer Avoid processor fees ($25 - $200/mo)

The problem with PCI Businesses feel PCI is too complicated They aren t trained in security They don t have time It changes (PCI 3.0) Too technical Little/no resources from PCI Council Little/no education about new tech Still neglect key areas of security

Top vulnerabilities Insecure remote access Lack of industry-standard malware scanning Unencrypted stored payment card data Nonexistent or improperly configured firewall rules Lack of POS environment segmentation Insecure web protocols/lack of dedicated servers Irregular/inadequate vulnerability scanning Lack of new technologies (software patches, hardware)

How can you help them through it?

Start with baby steps Reduce scope Reduce frustration Educate customer and staff How to protect themselves financially Simplify their network Give them tools

Changes and clarifications Table 2: Summary of Changes https://www.pcisecuritystandards.org/documents/pci_ DSS_v3_Summary_of_Changes.pdf

Compliance vs. validation All SAQs state, you must still comply with all applicable PCI DSS requirements in order to be PCI DSS compliant. Validation based on risk Merchants may only have to validate a few PCI requirements, but need to still be compliant in full Risk based on card processing volume and card data handling methods

An SAQ A merchant s statement of compliance Acquiring bank asks merchant for completed SAQ Bank s responsibility to track merchant PCI compliance Merchant s responsibility to accurately complete SAQ

Learn about the SAQ SAQ A https://www.pcisecuritystandards.org/appro SAQ A EP ved_companies_providers/index.php SAQ B SAQ B IP SAQ C SAQ C VT SAQ D For Merchants SAQ D For Service Providers SAQ P2PE-HW

Offer a more complete solution

SAQ A & A-EP Ensure redirect to the third party is secure Ensure third party provider is PCI compliant Clearly define roles

SAQ B & B-IP Receipts may contain card numbers POS terminal software not kept updated Ensure policies are in place to protect card data

SAQ C & C-VT Ensure data is not stored Payment system isolated within its own network environment PA DSS compliant payment software

SAQ P2PE-HW

SAQ D Anti-malware Detect, clean malware, spyware, adware Only allow access to network and payment systems to those who really need it

SAQ D External/internal vulnerability scanning PCI authorized scan vendor for external scanning Work until scans are clean

SAQ D Penetration testing Annually or after significant upgrade or modification Documentation of security policies Review regularly Employees sign annually

SAQ D Secure encryption for stored data Do you really need to store PAN data? If so, strong encryption and proper key management is needed

SAQ D Design network correctly Segment network Set up firewalls correctly Logging Active logging of all systems in the card environment, review daily

SAQ D Physical security Restrict access to network jacks, wireless access points, network hardware ID badges, visitors must be authorized, sign log, given physical token of visitor status

SAQ D Regular operating system and software updates Install critical security patches within 30 days for OS, POS, and supporting software Track system and software configuration changes

SAQ D Remove system defaults Change defaults before adding to cardholder network (passwords, SNMP, wireless safety)

Healthcare mandates Security policies Employee training Firewall Etc.

Recap Be a trusted advisor Partner with company with core competency of data security Add additional revenue streams

Questions? gilesw@securitymetrics.com