PCI DSS Gap Analysis Briefing



Similar documents
1/18/10. Walt Conway. PCI DSS in Context. Some History The Digital Dozen Key Players Cardholder Data Outsourcing Conclusions. PCI in Higher Education

Understanding and Managing PCI DSS

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire

Property of CampusGuard. Compliance With The PCI DSS

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance

Adyen PCI DSS 3.0 Compliance Guide

PCI Compliance. How to Meet Payment Card Industry Compliance Standards. May cliftonlarsonallen.com CliftonLarsonAllen LLP

PCI DSS Compliance Information Pack for Merchants

PCI Compliance Overview

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire

Puzzled about PCI compliance? Proactive ways to navigate through the standard for compliance

PCI Compliance. Top 10 Questions & Answers

PCI DSS v3.0 SAQ Eligibility

Understanding the SAQs for PCI DSS version 3

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance

PCI Compliance Top 10 Questions and Answers

Payment Card Industry (PCI) Data Security Standard

Why Is Compliance with PCI DSS Important?

Agenda: A PCI DSS Deep Dive

SecurityMetrics Introduction to PCI Compliance

Payment Card Industry Data Security Standard Training. Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc.

Frequently Asked Questions

PCI DSS 3.0 Overview. OSU Business Affairs Business Affairs PIT Crew - Project, Improvement, & Technology Robin Whitlock

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008

IT Security Compliance PCI DSS FOR MERCHANTS THE PAYMENT CARD INDUSTRY DATE SECURITY STANDARD WHITE PAPER

Payment Card Industry (PCI) Data Security Standard

PCI Compliance at The University of South Carolina. Failure is not an option. Rick Lambert PMP University of South Carolina

PCI DSS Overview. By Kishor Vaswani CEO, ControlCase

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance

Project Title slide Project: PCI. Are You At Risk?

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer

Payment Card Industry (PCI) Data Security Standard. Attestation of Compliance for Self-Assessment Questionnaire C-VT. Version 2.0

Data Security Basics for Small Merchants

PCI Data Security Standards

What a Processor Needs from a University to Validate Compliance

Protecting Your Customers' Card Data. Presented By: Oliver Pinson-Roxburgh

PCI DSS Compliance What Texas BUC$ Need to Know! Ron King CampusGuard

PCI DSS Presentation University of Cincinnati

PCI DSS. CollectorSolutions, Incorporated

TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No MERCHANT DEBIT AND CREDIT CARD RECEIPTS

PCI Compliance. Crissy Sampier, Longwood University Edward Ko, CampusGuard

HOW SECURE IS YOUR PAYMENT CARD DATA? COMPLYING WITH PCI DSS

Your guide to the Payment Card Industry Data Security Standard (PCI DSS) Merchant Business Solutions. Version 5.0 (April 2011)

Payment Card Industry Compliance Overview

It is important to note, the payment brands and acquirers are responsible for enforcing compliance, not the PCI council.

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard

Complying with Payment Card Industry Data Security Standards (PCI DSS) Requirements. Approaches in Higher Education

Payment Card Industry (PCI) Data Security Standard

Becoming PCI Compliant

MasterCard PCI & Site Data Protection (SDP) Program Update. Academy of Risk Management Innovate. Collaborate. Educate.

Payment Card Industry (PCI) Data Security Standard

Technical breakout session

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard

Your Compliance Classification Level and What it Means

PAYMENT CARD INDUSTRY (PCI) ANNUAL TRAINING DECEMBER 10, 2009 WESTERN ILLINOIS UNIVERSITY OFFICE OF THE CTSO & BUSINESS SERVICES

How To Ensure Account Information Security

IT TECHNICAL SECURITY REVIEW CHECKLISTS FOR E-COMMERCE WEBSITES

Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance

PCI 3.1 Changes. Jon Bonham, CISA Coalfire System, Inc.

PCI Compliance. What is New in Payment Card Industry Compliance Standards. October cliftonlarsonallen.com CliftonLarsonAllen LLP

Merchant guide to PCI DSS

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance

Point-to-Point Encryption (P2PE)

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program

Josiah Wilkinson Internal Security Assessor. Nationwide

So you want to take Credit Cards!

Payment Card Industry Data Security Standard

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program

An article on PCI Compliance for the Not-For-Profit Sector

npc npc NPC PCI Program Protecting Your Business from Card Data Breaches

Payment Card Industry (PCI) Data Security Standard

Achieving PCI Compliance for Your Site in Acquia Cloud

2015 PCI DSS Meeting. OSU Business Affairs Projects, Improvement, and Technology (PIT) Robin Whitlock

A Compliance Overview for the Payment Card Industry (PCI)

This appendix is a supplement to the Local Government Information Security: Getting Started Guide, a non-technical reference essential for elected

Are You Ready For PCI v 3.0. Speaker: Corbin DelCarlo Institution: McGladrey LLP Date: October 6, 2014

Introduction to PCI DSS Compliance. May 18, :15 p.m. 2:15 p.m.

PROTECTION OF OUR MERCHANTS AND REFERRAL PARTNERS IS OUR FIRST CONCERN

Understanding Payment Card Industry (PCI) Data Security

Ecommerce Guide to PCI DSS 3.0

PCI: The Dark Side. May 2012 Roanoke, VA

Q: What is PCI? Q: To whom does PCI apply? Q: Where can I find the PCI Data Security Standards (PCI DSS)? Q: What are the PCI compliance deadlines?

Payment Card Industry Data Security Standards Compliance

Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions

Credit Card Processing, Point of Sale, ecommerce

Payment Card Industry Data Security Standards

PCI on Amazon Web Services (AWS) What You Need To Know Understanding the regulatory roadmap for PCI on AWS

PCI PA-DSS Requirements. For hardware vendors

North Carolina Office of the State Controller Technology Meeting

Transcription:

PCI DSS Gap Analysis Briefing The University of Chicago October 1, 2012 Walter Conway, QSA 403 Labs, LLC

Agenda The PCI DSS ecosystem - Key players, roles - Cardholder data - Merchant levels and SAQs UofC s PCI Gap Analysis University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 2

Walt Conway and 403 Labs PCI QSA, consultant, blogger, trainer, speaker, author - Former Visa VP - Consult with schools to become PCI compliant 403 Labs: Information security consulting firm - PCI QSA and PA-QSA, ASV, and PCI forensic investigator (PFI), P2PE (QSA and PA-QSA) University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 3

Some PCI DSS Basics Payment Card Industry Data Security Standard Goal is to protect Cardholder Data - And to keep UofC out of the headlines - PCI does not make you secure If you take plastic, PCI applies to you PCI Scope includes people, processes, and systems - Store, process, or transmit cardholder data (UofC s Cardholder Data Environment) - And all connected systems University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 4

Some PCI DSS Basics PCI is a program, not a project Two things you need to accept about PCI - Your costs have gone up - You will change the way you do business University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 5

The PCI Ecosystem P2PE Manufacturers PCI PTS Pin Entry Devices Software Developers PCI PA-DSS Payment Applications Merchants & Service Providers PCI DSS Secure Environments PCI Security P2PE Ecosystem of payment devices, applications, infrastructure and users University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 6

PCI DSS: 6 Goals, 12 Requirements University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 7

Key Players PCI Security Standards Council - Global forum to enhance global payment security - Multiple standards: PCI DSS, PA-DSS, PCI PTS, and P2PE - Approve assessors (QSAs) and scan vendors (ASVs) - Develop Self-Assessment Questionnaire (SAQ) - Develop and publish PCI documentation University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 8

Key Players Five Payment brands - Track compliance and enforce standards (fines, sanctions) - Determine event response (forensics) - Define merchant levels Acquirers (Merchant Banks) and processors - Set UofC s merchant level - Determine UofC s compliance - Approve compensating controls University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 9

PCI Compliance is Widespread U.S. PCI DSS Compliance Status Merchant Level Estimated Population Size Estimated % of Visa Transactions PCI DSS Compliance Validation Validated Not Storing Prohibited Data Level 1 Merchant (>6M) Level 2 Merchant ( 1-6M) Level 3 Merchant (>6M) Level 4 Merchant (<1M) 403 50% 97% 100% 1058 13% 93% 100% 3,218 < 5% 60% N/A ~ 5,000,000 32% Moderate** TBD * As of June 30, 2012 **Level 4 compliance is moderate among stand-alone terminal merchants, but lower among merchants using integrated payment applications University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 10

Who are the High Risk Merchants? University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 11

Who are the High Risk Merchants? University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 12

Merchant Level Determines Validation Level Visa and MasterCard Amex 1 >6 Million trans/yr, by brand 2 >1 Million trans/yr, by brand 3 >20K ecommerce Annual on-site assessment Quarterly network scan by Approved Scanning Vendor (ASV) Report on Compliance (ROC) Visa: Annual Self-Assessment Questionnaire (SAQ) Quarterly network scan by ASV MasterCard: Same as Level 1 Annual SAQ Quarterly network scan by ASV Annual on-site Security Audit Quarterly network scan by ASV Quarterly network scan ASV Recommend quarterly network scan by ASV 4 Determined by acquirer: Annual SAQ Quarterly network scan by ASV University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 13

Self-Assessment Questionnaire (SAQ) Level 3 and 4 merchants self-assess Card-not-present merchants, all cardholder data functions outsourced, no electronic cardholder data storage Imprint-only merchants, no electronic cardholder data storage Stand-alone terminal merchants, no electronic cardholder data storage A B B 13 Items 29 Items Merchants with POS systems connected to the Internet, no electronic cardholder data storage Merchants who process cards on isolated virtual terminals connected to the Internet All other merchants and service providers C C-VT D 80 Items 51 Items 280+ Items Shortened SAQ only if no electronic cardholder data University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 14

Cardholder Data University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 15

Cardholder Data PAN: OK to store first six and/or last four digits Source: PCI SSC University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 16

Why Store Cardholder Data? Policy: No electronic card data stored on any UofC device But what about? - Recurring payments acquirer has alternatives - Chargebacks, refunds let acquirer store PAN - Legal requirements these apply to banks - Paper receipts reprogram/upgrade terminals to truncate both receipts - Payment applications confirm with vendor or acquirer that software does not store sensitive data University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 17

SAQ A Card-not-present merchants only - E-commerce, mail order/telephone order (MOTO) - Never applies in a face-to-face POS environment Card processing is outsourced - No cardholder data stored, processed, or transmitted on your systems Service provider is PCI compliant Only paper records, not received electronically No electronic cardholder data University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 18

SAQ A Merchant School Website PAY Secure Third-Party Website Students log into school site, and are redirected to PCI compliant service provider to enter payment. No payment data are stored, processed, or transmitted on school s systems. Payment card data are entered and processed on PCI compliant service provider s site. University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 19

SAQ B For merchants with stand-alone dial-up terminals or imprinters (aka, zip-zap machines) - Brick-and-mortar, MOTO, or e-commerce Dial-up terminals - Not connected to any other systems - Not connected to Internet Paper records, not received electronically No electronic cardholder data University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 20

SAQ C Payment application and Internet connection on the same device - Card-present or card-not-present merchants - Can be POS or shopping cart application Device not connected to any other system Store only paper records, not received electronically No electronic cardholder data Payment application vendor provides remote support securely University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 21

SAQ C-VT Merchant uses a virtual terminal - Web browser connected to processor that hosts payment processing function - Enter card data manually (no mag stripe reader), via a secure connection, one transaction at a time - Brick-and-mortar or MOTO Single payment terminal, isolated, fixed Other requirements same as SAQ C University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 22

SAQ D Everybody else 280 questions All 12 PCI requirements University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 23

SAQ A, Outsourcing OMG! Customer Service - Merchant outsources e-commerce payments (hosted) - MOTO, fax orders persist - Staff enter transactions on their workstations - Workstations are not isolated - Result: staff workstations and all connected systems are in PCI scope Result: SAQ D - 280+ questions - Full PCI DSS including scans and pen testing University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 24

Other SAQ OMG! Dial-up POS terminal (SAQ B) - Card numbers on daily batch tape - Non-compliant PIN entry devices - Solution: upgrade or replace device Virtual terminal (SAQ C or C-VT) - Not isolated device connects to other systems - Not dedicated device used for other purposes - Solution: segment network, restrict terminal use Result: SAQ D Conclusion: Not easy to qualify for a shortened SAQ University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 25

Requirement 0 Minimize Scope What it says: - Stop and take a breath - Don t accept status quo as fixed What it means: - Minimize scope to reduce PCI cost and effort - Your mantra: If you don t need it, don t keep it How to comply: - Accept the two Laws of PCI : Your costs will go up. You will change the way you do business. University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 26

UofC s PCI DSS Gap Analysis Identify compliance gaps: no harm, no foul - Meet with all UofC merchants and IT - Understand business needs, processes, technology - Identify gaps and recommend remediation options - Provide options so merchants can meet business requirements Goal: minimize UofC s PCI scope (and risk) - Simplify PCI compliance validation - Identify business process changes (often hard!) - Identify infrastructure changes (expensive) Reporting - Debriefing session at conclusion of onsite - Written report University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 27

Thank You Your comments? Questions? Thoughts? Walter Conway wconway@403labs.com 877.403.5227, ext. 223 (or: 415.690.6876) www.403labs.com Follow my PCI column at storefrontbacktalk.com Higher Education PCI blog (Treasury Institute) treasuryinstitutepcidss.blogspot.com University of Chicago PCI DSS Overview Walter Conway, QSA, 403 Labs, LLC 2012 28