.. PCI Payment Card Industry Compliance October 2012 Presented By: Jason P. Rusch.

Slides:



Advertisements
Similar presentations
Surviving the PCI Self -Assessment James Placer, CISSP West Michigan Cisco Users Group Leadership Board.
Advertisements

Payment Card Industry Data Security Standard AAFA ISC/SCLC Fall 08.
Session 4: Data Privacy and Fraud Moderator: Bill Houck, Director, Risk Management, UATP Panelist: Peter Warner, EVP, Retail Decisions Cherie Lauretta,
ISACA January 8, IT Auditor at Cintas Corporation Internal Audit Department Internal Security Assessor (ISA) Certification September 2010 Annual.
National Bank of Dominica Ltd Merchant Seminar Facilitator: Janiere Frank Fraud & Compliance Analyst June 16, 2011.
Evolving Challenges of PCI Compliance Charlie Wood, PCI QSA, CRISC, CISA Principal, The Bonadio Group January 10, 2014.
Mobile Payment Security The Good, the Bad and the Ugly
The Payment Card Industry Data Security Standard (PCI DSS)
PCI DSS for Retail Industry
Payment Card Industry Data Security Standard Tom Davis and Chad Marcum Indiana University.
Protecting Credit Card Information
PCI Compliance: The Gateway to Paradise PCI Compliance: The Gateway to Paradise.
MARTAs Road to PCI Compliance 1 Presenter: Yolanda Curtis, PMP AFC Project Manager.
PCI-DSS Erin Benedictson Information Security Analyst AAA Oregon/Idaho.
Complying With Payment Card Industry Data Security Standards (PCI DSS)
2014 PCI DSS Meeting OSU Business Affairs Process Improvement Team (PIT) Robin Whitlock & Dan Hough 10/28/2014.
This refresher course will:
JEFF WILLIAMS INFORMATION SECURITY OFFICER CALIFORNIA STATE UNIVERSITY, SACRAMENTO Payment Card Industry Data Security Standard (PCI DSS) Compliance.
University of Utah Financial and Business Services
Property of CampusGuard Compliance With The PCI DSS.
Credit Card Compliance Regulations Mandated by the Payment Card Industry Standards Council Accounting and Financial Services.
Presented by : Vivian Eberhardt, Supervisor Cash and Credit Operations
PCI Compliance Forrest Walsh Director, Information Technology California Chamber of Commerce.
Data Security Standard. What Is PCI ? Who Does It Apply To ? Who Is Involved With the Compliance Process ? How We Can Stay Compliant ?
Visa Cemea Account Information Security (AIS) Programme
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Commonwealth of Massachusetts Office of the State Comptroller March 2007.
Copyright Security-Assessment.com 2005 Payment Card Industry Digital Security Standards Presented By Carl Grayson.
Northern KY University Merchant Training
PCI's Changing Environment – “What You Need to Know & Why You Need To Know It.” Stephen Scott – PCI QSA, CISA, CISSP
Disclaimer Copyright Michael Chapple and Jane Drews, This work is the intellectual property of the authors. Permission is granted for this material.
Web Advisory Committee June 17,  Implementing E-commerce at UW  Current Status and Future Plans  PCI Data Security Standard  Questions.
PCI DSS The Payment Card Industry (PCI) Data Security Standard (DSS) was developed by the PCI Security Standards Council to encourage and enhance cardholder.
Payment Card Industry Data Security Standard (PCI DSS) By Roni Argetsinger
The ABC’s of PCI DSS Eric Beschinski Relationship Manager Utility Payment Conference Kay Limbaugh Specialist, Electronic Bills & Payments &
MasterCard Site Data Protection Program Program Alignment.
PCI DSS Managed Service Solution October 18, 2011.
Protecting Your Credit Card Security Environment (PCI) September 26, 2012 Jacob Arthur, CPA, QSA, CEH Timothy Agee, CISA, CGEIT, QSA FDH Consulting Frasier,
An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.
Visa Europe Confidential PCI DSS Protecting your business Lara Fiorani, Visa Europe Basel 25 April, 2006.
NUAGA May 22,  IT Specialist, Utah Department of Technology Services (DTS)  Assigned to Department of Alcoholic Beverage Control  PCI Professional.
PCI requirements in business language What can happen with the cardholder data?
DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program.
PCI DSS Readiness Presented By: Paul Grégoire, CISSP, QSA, PA-QSA
North Carolina Community College System IIPS Conference – Spring 2009 Jason Godfrey IT Security Manager (919)
Introduction To Plastic Card Industry (PCI) Data Security Standards (DSS) April 28,2012 Cathy Pettis, SVP ICUL Service Corporation.
Data Security and Payment Card Acceptance Presented by: Brian Ridder Senior Vice President First National September 10, 2009.
ThankQ Solutions Pty Ltd Tech Forum 2013 PCI Compliance.
1 Payment Card Industry (PCI) Security Standard Developed by the PCI Security Council formed by major card issuers: Visa, MasterCard, American Express,
BUSINESS CLARITY ™ PCI – The Pathway to Compliance.
Standards in Use. EMV June 16Caribbean Electronic Payments LLC2.
By: Matt Winkeler.  PCI – Payment Card Industry  DSS – Data Security Standard  PAN – Primary Account Number.
PCI COMPLIANCE & A/R AUTOMATION 101 Nodus Technologies, Inc.
Credit Card Compliance
MARTA’s Road to PCI Compliance
Payment Card Industry Data Security Standards
Payment Card Industry (PCI) Rules and Standards
Summary of Changes PCI DSS V. 3.1 to V. 3.2
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Payment card industry data security standards
Internet Payment.
Session 11 Other Assurance Services
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
PCI Compliance : Whys and wherefores
PCI DSS Erin Carrick.
Rld pci compliance project
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Payment Card Industry (PCI)
MARTA’s Road to PCI Compliance
Utility Payment Conference
Presented by: Jeff Soukup
Presentation transcript:

.. PCI Payment Card Industry Compliance October 2012 Presented By: Jason P. Rusch

15 years experience Information Technology 8 years experience I.T. governance, risk, compliance and security management US Navy Communications and Intelligence Specialist Humana Inc., The Walt Disney Company, Hard Rock Int. (CISSP) - Certified Information Systems Security Professional (CISA) - Certified Information Systems Auditor (CISM) - Certified Information Systems Manager Jason P. Rusch

2004 Payment Card Industry Security Standards Council (PCI-SSC) is formed by VISA Inc., Master Card, AMEX and Discover The PCI-SSC merges their individual security standards to form the Payment Card Industry Data Security Standard (PCI- DSS v1.0) PCI-SSC Members - The PCI-SSC also consists of other stakeholders including merchants, processing banks and payment system vendors (i.e. Wal-Mart, The Walt Disney Company, Chase, PayPal, Micros, Radiant). Where did PCI-DSS come from??

PCI-DSS contains 6 control groups comprising of 12 standards and 324 total requirements/sub requirements. What is the PCI-DSS??

The PCI data security standard is not a law; it is a set of requirements created and governed by the PCI-SSC and enforced by the banks (acquiring banks). The PCI-DSS is updated every 3 three years and is currently on version 2. PCI-DSS Governed Entities – Banks (acquiring and processing) – Merchants – Service Providers – Vendors What is the PCI-DSS??

What does PCI-DSS include (scope)??

CVV/CVV2 - Card Verification Value, Card Verification Value Code (black data strip) PAN – Primary Account Number Security Code – 3 or 4 digit code located on back of MC, VISA, Discover (front of AMEX) IMPORTANT NOTE You cannot store the CVV or security code under any circumstances, encrypted or not! PCI-DSS includes (the basics)?

The CVV code and Security PIN?. Security Code – NEVER store the 3 or 4 digit code located on back of MC, VISA, Discover (front of AMEX)

Merchant Transactions Level 1 Merchants processing over 6 million transactions annually. 2 Merchants processing 1 million to 6 million transactions annually. 3 Merchants processing 20,000 to 1 million e-commerce transactions annually 4 Merchants processing less than 20,000 e-commerce transactions annually and all other merchants processing up to 1 million transactions annually Merchant Levels Defined

Merchant level 1 and 2 merchants - Validation of compliance is required annually by a external Qualified Security Assessor (QSA) and a Report On Compliance (ROC) be submitted to the merchants acquiring bank annually. VISA and MasterCard enforce PCI-DSS differently on Merchant level 1 and 2s. VISA only requires a ROC from merchant level 1s, whereas MasterCard requires a ROC from both merchant level 1 and 2s (2010). Merchant level 3 and 4 merchants – Submission of a (SAQ) Self Assessment Questionnaire to acquiring bank annually. What does a Merchant have to do??

The credit card companies fine the acquiring bank of the merchant, and the bank then passes that fine down to the merchant. Important Note - The bank can and in many cases does add to the fine and increases the total amount fined. Non-Compliance, Data Breach Fine Process

Damage to public image due to news broadcasts. Brand name degradation. Loss of customer confidence. Fines and penalties for non-compliance. Short or long term suspension of the merchants ability to accept credit and debt cards. Increase in transaction fees. Cost of lawsuits, legal settlements/judgments. Forensics, investigative and containment costs. What happens if there is a credit card breach??

Large YMCAs If you are a large YMCA, group of YMCAs and/ or in a large market I would recommend the following. Consult with a QSA firm Determine your merchant level and TOTAL transaction count. If your systems/applications/data reside with a service provider, inquire about their PCI compliance status Pursue with the assistance of a QSA the completion of your Self Assessment Questionnaire (SAQ) and communicate with your bank. What Should You Do?

o Define Scope & Data Flows (define credit card data environment (CDE). o Policy & Procedure (maintain a simple information governance and security policy framework. o User Account Management (role based access, password management, account reviews) o Vulnerability Management (patch management, Antivirus, PCI vulnerability scans) o Change Management (add procedures in your change management processes to identify PCI scope systems to add the required controls) Things You Can Focus On?

Encryption – PCI-DSS requires that the Primary Account Number be encrypted both in transmission and while at rest. Penetration Tests – PCI-DSS requires that a merchant have a penetration test performed by a certified specialist on both its external/web facing DMZ and internal card holder environment. Logging & Monitoring – Logging and monitoring of all access to credit card data and credit card data environment. Areas That Are The Most Challenging

Audio – (IVR) recording of customer calls/conversations by CSRs that contain credit card information. Because QSAs see recorded audio credit card information as low risk, this is not an area they are actively going after or being strict on. However they still will require compensating controls at the least. Images – Scanning of physical paper forms with customer credit card information, i.e. TIFFs, JPEGs, PDFs. Scanned forms and physical paper that then becomes digital credit card information due to scanning is an area that is increasingly being targeted by QSAs and the credit card companies. Areas Not Often Though About?

Questions?