Presentation is loading. Please wait.

Presentation is loading. Please wait.

PCI Compliance Technical Overview. RM PCI Calendar Dec 2005: Began PCI 15.1 development Feb 2006: Initial PCI Audit Sept 2006: Official 15.1 PCI Release.

Similar presentations


Presentation on theme: "PCI Compliance Technical Overview. RM PCI Calendar Dec 2005: Began PCI 15.1 development Feb 2006: Initial PCI Audit Sept 2006: Official 15.1 PCI Release."— Presentation transcript:

1 PCI Compliance Technical Overview

2 RM PCI Calendar Dec 2005: Began PCI 15.1 development Feb 2006: Initial PCI Audit Sept 2006: Official 15.1 PCI Release Sept 2006: Validation Report sent to VISA Jan 2007: VISA approves certification

3 Card Data Compromises n 40% of all compromises involve a restaurant n Top 5 compromises:  Full track data retention  Default accounts  Insecure remote access  Non-use of security tools (antivirus, encryption)  SQL injection

4 Terms and Definitions n PCI DSS: Payment Card Industry Data Security Standard n PABP: Payment Application Best Practices n RM is a validated payment application that meets the PCI PABP n So what is “PCI Compliance”? Hint: It’s not simply installing RM 15.1.

5 The PCI Compliant Site Restaurant must use PCI PABP validated POS application, properly configured, implementing proper procedures, and installed following all site-specific PCI guidelines and rules. That’s 4 areas needing attention: n Use PABP validated applications n Proper configuration n Proper procedures n Follow site guidelines

6 1. Use PABP validated applications n Use RM 15.1 (final release Sept 2006 or later) n Use certified credit card processing gateways (e.g. Mercury Payment Systems, PC Charge, Datacap)

7 2. Proper Configuration n Follow ASI PCI configuration guidelines:  RM and Reseller PCI Guidance Doc RM and Reseller PCI Guidance  Logging, Audit Trail  Admin Password Expiration

8 3. Proper Procedures n Enforcing limited access to RM Server machine. n Internet use from Server machine n Remote access (allowed only during incident) n No emailing of card data

9 4. Site Guidelines n Secure RM Server (credit card server)  Physical access  Logical access (open ports)  Firewalled n Network n Remote Access 2-factor authentication (VPN + PCAnywhere passwords) n And Wireless …

10 4. Site Guidelines (WiFi) n Enable WPA with key rotation n Change SSID from default n Turn off SSID broadcast n Implement MAC address filtering n Install firewall services between APs and RM Server n Port/Service Restrictions  Only: TCP 80, DNS 53, ICMP

11 Basic Network Internet

12 Network w/ WiFi Internet

13 Network w/ WiFi Internet Symbol WS2000

14 Thank you Questions?


Download ppt "PCI Compliance Technical Overview. RM PCI Calendar Dec 2005: Began PCI 15.1 development Feb 2006: Initial PCI Audit Sept 2006: Official 15.1 PCI Release."

Similar presentations


Ads by Google