PCI Compliance: Finding Value beyond Fine Avoidance



Similar documents
Telephone Banking Authentication Practical Approaches to Securing a Popular yet Vulnerable Channel

E Commerce Platform Review:

2011 Online Account Opening:

Online Storage Vaults The Electronic Safe Deposit Box Brings Opportunities for Loyalty and Fees, but Can It Overcome Daunting Challenges?

Payment Card Industry Compliance Overview

PCI Standards: A Banking Perspective

The PCI DSS Compliance Guide For Small Business

PCI DSS Gap Analysis Briefing

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program

What are the PCI DSS requirements? PCI DSS comprises twelve requirements, often referred to as the digital dozen. These define the need to:

PCI Compliance: How to ensure customer cardholder data is handled with care

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008

Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions

SecurityMetrics Introduction to PCI Compliance

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program

Introduction to PCI Compliance

PCI Compliance Overview

WHITE PAPER. PCI Basics: What it Takes to Be Compliant

A Compliance Overview for the Payment Card Industry (PCI)

Registration and PCI DSS compliance validation

VISA EUROPE ACCOUNT INFORMATION SECURITY (AIS) PROGRAMME FREQUENTLY ASKED QUESTIONS (FAQS)

PAYMENT CARD INDUSTRY (PCI) ANNUAL TRAINING DECEMBER 10, 2009 WESTERN ILLINOIS UNIVERSITY OFFICE OF THE CTSO & BUSINESS SERVICES

PAI Secure Program Guide

Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance

1/18/10. Walt Conway. PCI DSS in Context. Some History The Digital Dozen Key Players Cardholder Data Outsourcing Conclusions. PCI in Higher Education

This appendix is a supplement to the Local Government Information Security: Getting Started Guide, a non-technical reference essential for elected

PCI PA-DSS Requirements. For hardware vendors

Project Title slide Project: PCI. Are You At Risk?

Mobile Device Payment Card Processing: How Secure is It? Richard Poworski CISSP, ISP, ITCP, SCF, PCI QSA, PCIP Managing Consultant

PCI DSS. CollectorSolutions, Incorporated

PCI Compliance Security Awareness Program For Marine Corps Community Services Contacts: Paul Watson

Understanding Payment Card Industry (PCI) Data Security

Payment Card Industry Data Security Standard Training. Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc.

Property of CampusGuard. Compliance With The PCI DSS

Payment Card Security

MasterCard PCI & Site Data Protection (SDP) Program Update. Academy of Risk Management Innovate. Collaborate. Educate.

Payment Card Industry Data Security Standard

Your Compliance Classification Level and What it Means

How To Protect Visa Account Information

Payment Card Industry Data Security Standards

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance

Frequently Asked Questions

Third Party Agent Registration and PCI DSS Compliance Validation Guide

Introduction to PCI DSS

PCI Compliance. Top 10 Questions & Answers

How To Protect Your Business From A Hacker Attack

June 19, Bobbi McCracken, Associate Vice Chancellor Financial Services. Subject: Internal Audit of PCI Compliance.

PCI-DSS: A Step-by-Step Payment Card Security Approach. Amy Mushahwar & Mason Weisz

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire

End to End Encryption, Tokenization & EMV in the U.S. Vendor Analysis of Emerging Technologies and Best Hybrid Solutions

FAQ S: TRUSTWAVE TRUSTKEEPER PCI MANAGER

The Petroleum Marketer s PCI compliance Reference Guide

Presented By: Bryan Miller CCIE, CISSP

PCI: It Never Ends. Why?

Are You Ready For PCI v 3.0. Speaker: Corbin DelCarlo Institution: McGladrey LLP Date: October 6, 2014

Payment Card Industry (PCI) Data Security Standard

Puzzled about PCI compliance? Proactive ways to navigate through the standard for compliance

PROTECTION OF OUR MERCHANTS AND REFERRAL PARTNERS IS OUR FIRST CONCERN

Merchant Services Tool Kit TEXPO 2013

Protecting Your Customers' Card Data. Presented By: Oliver Pinson-Roxburgh

SAN DIEGO STATE UNIVERSITY RESEARCH FOUNDATION CREDIT CARD PROCESSING & SECURITY POLICY MERCHANT SERVICES POLICIES & PROCEDURES

Payment Card Industry - Achieving PCI Compliance Steps Steps

Understanding and Managing PCI DSS

Payment Card Industry (PCI) Data Security Standard

Sage ERP MAS I White Paper. Payment Processing Trends, Tips, and Tricks: What You Need to Know

CHEAT SHEET: PCI DSS 3.1 COMPLIANCE

* Any merchant that has suffered a hack that resulted in an account data compromise may be escalated to a higher validation level.

Payment Card Industry (PCI) Compliance A QSA Perspective

HOW SECURE IS YOUR PAYMENT CARD DATA?

Q: What is PCI? Q: To whom does PCI apply? Q: Where can I find the PCI Data Security Standards (PCI DSS)? Q: What are the PCI compliance deadlines?

Questions and Answers PCI Compliance (Updated May 23, 2014)

Brown Smith Wallace, LLC

CREDIT CARD MERCHANT PROCEDURES. Revised 01/21/2014 Prepared by: NIU Merchant Services

Introduction to PCI DSS Compliance. May 18, :15 p.m. 2:15 p.m.

HOW SECURE IS YOUR PAYMENT CARD DATA? COMPLYING WITH PCI DSS

Your guide to the Payment Card Industry Data Security Standard (PCI DSS) Merchant Business Solutions. Version 5.0 (April 2011)

Transcription:

November 2007

Overview Safeguarding customer data is a necessary component of good business practice, yet the numbers of data breached accounts are at an all time high. Data security has not been given front line priority, and as a consequence an environment of mistrust of the card eco-system has developed among consumers, merchants, acquirers, and issuing banks. To stem this tide, the payment networks have responded with a renewed emphasis, harsher penalties, and more specific deadlines for Payment Card Industry Data Security Standards (PCI DDS) compliance. Merchants are spending untold amounts to come into compliance, and many are confused as to the value of PCI compliance above and beyond fine avoidance. This report explores the challenges and issues presented by PCI compliance from the merchant perspective including the five biggest compliance problems causing data breaches for merchants extracting from qualitative executive interviews conducted with the PCI council, payment networks, PCI vendors, Qualified Security Assessors (QSAs), and merchants themselves. Primary Questions What is the real value of PCI compliance, aside from avoiding fines? What role does state legislation have in PCI compliance? What is the nature of merchant confusion with the PCI compliance process, and who is responsible for allaying this confusion? How can merchants be assured of safe harbor from lawsuits based on their compliance? What are the top five security weaknesses facing merchants becoming compliant? Are there any innovative approaches to help merchants deal with sensitive data storage? Audience: Authors: Merchants, processors, QSAs, ASVs, service providers, vendors, financial institutions (FIs) issuers and acquirers, and payment networks Rachel Kim, Associate Analyst Mary Monahan, Partner and Editor Bruce Cundiff, Research Director Publication date: November 2007 Price: $1,500 Length: 26 pages 15 charts/graphs

Table of Contents Overview...3 Primary Questions...3 Findings and Analysis...3 What Is the Real Value of PCI Compliance?...4 Consumers Will Reward Security Leaders, But How to Tell?...6 Consumers Prefer a PCI-Brand to Help them Feel Safer When Shopping... 7 Safe Harbor Needed to Ensure Conformity and Effectiveness for Merchants...8 What Do State PCI and Data Breach Laws Imply for Merchants?... 8 Is Effective QSA Management a Missing Link in the PCI Compliance Process?...11 Even with Progress in Outreach and Education, Merchant Confusion Lingers...13 Despite Strong Improvement, All Payment Networks Must Be Actively Involved...15 The Cost of Is it Worth the Expense?...16 What Are the Five Top Weaknesses for Merchants Facing Compliance?...18 Highly Distributed, Sensitive Data,... 18 Data Controlled by Third Parties or Taken Off-Site... 18 Problems at the POS... 19 Legacy Systems and Niche Applications Bring Heightened Risk... 19 Lack of Logging and Oversight... 19 Innovative Approach: Eliminate Storage and Passage of Card Information...20 Standing PCI Compliance on its Head... 20 EPX BuyerWall... 20 Shift4 s SafeSwipe... 20 Where Is PCI Compliance Heading in 2008?...21 Merchant Questions Linger over PCI DDS 6.6... 21 Payment Application-Data Security Standard (PA-DSS)... 21 Appendix...22 Related Research...24 Glossary...25

Table of Figures Figure 1: Top Ten Largest Publicly Reported Security Breaches... 4 Figure 2: Consumers Are More Inclined to Shop at merchants that Are Security Leaders... 6 Figure 3: Consumers Feel Most Protected by a Brand When Shopping... 7 Figure 4: Current PCI State PCI Bills and Outcomes for Merchants... 8 Figure 5: Payment Networks Are Managing their Acquirers, Acquirers Are Managing their Merchants: Who Is Managing the QSAs?... 11 Figure 6: Inconsistencies among PCI Programs and the Lack of a Universal PCI Support Center Are Preventing Higher Compliance Rates... 13 Figure 7: Slow but Steady Progress in Compliance Rates for Visa Merchants... 15 Figure 8: Compliance Costs for Level 1 or 2 Merchant... 16 Figure 9: Costs of Non-Compliance for Level 1 or 2 Merchant... 16 Figure 10: Compliance Costs/Steps for a Level 4 Merchant... 17 Figure 11: Which Cardholder Data Elements Can Be Stored under PCI Compliance Rules?... 18 Figure 12: Payment Application-Data Security Standards (PA-DSS) Timeline... 21 Figure 13: Consumer Viewpoint: Who Is Least Secure in Protecting Account Information?... 22 Figure 14: Definitions of Merchant Levels One to Four... 23 Figure 15: Visa PCI Compliant Merchants as of August 31, 2007... 23

Companies/Organizations Mentioned in Report America Online MasterCard American Express National Retail Federation CardSystems Shift4 Chase Paymentech Symantec Citigroup TD Ameritrade Dai Nippon Printing Company TJX Companies Data Processors International TrustWave Electronic Payment Exchange UPS Fidelity National Information Services US Department of Veteran Affairs KDDI Visa Sample Pages

Health Savings Accounts: Focus on Transactions and Product Development Will Lead to Asset Growth Target Place Your Order as Follows: 1) Call us at 925 225 9100, x26 2) Email us at 3) Fax or Mail using the form below: Please send me the following report(s): Report Title Publication Date Price Name Title Organization Division or group Email Phone Fax Address Signature to confirm your order: Payment Method: [ ] Payment card [ ] Check Enclosed [ ] Invoice me Visa, MC, AE or Disc. card #: Exp date: / Name on Card: Signature For invoicing, provide PO number: (Invoicing is available to financial institutions or publicly owned firms) Note: Reports are provided in electronic PDF form only. Javelin reports are subject to standard terms and conditions, as described on our web site. Javelin will contact you in the future to provide our free research newsletter or other mailings. If you do not wish to receive our newsletter or other mailings, you may advise us of this. Your contact information will not be sold to other organizations.