Northern KY University Merchant Training

Slides:



Advertisements
Similar presentations
Surviving the PCI Self -Assessment James Placer, CISSP West Michigan Cisco Users Group Leadership Board.
Advertisements

Payment Card Industry Data Security Standard AAFA ISC/SCLC Fall 08.
Evolving Challenges of PCI Compliance Charlie Wood, PCI QSA, CRISC, CISA Principal, The Bonadio Group January 10, 2014.
.. PCI Payment Card Industry Compliance October 2012 Presented By: Jason P. Rusch.
PCI DSS for Retail Industry
Payment Card Industry Data Security Standard Tom Davis and Chad Marcum Indiana University.
UCSB Credit Card Processing and PCI Compliance
PCI Compliance: The Gateway to Paradise PCI Compliance: The Gateway to Paradise.
PCI-DSS Erin Benedictson Information Security Analyst AAA Oregon/Idaho.
Complying With Payment Card Industry Data Security Standards (PCI DSS)
2014 PCI DSS Meeting OSU Business Affairs Process Improvement Team (PIT) Robin Whitlock & Dan Hough 10/28/2014.
JEFF WILLIAMS INFORMATION SECURITY OFFICER CALIFORNIA STATE UNIVERSITY, SACRAMENTO Payment Card Industry Data Security Standard (PCI DSS) Compliance.
University of Utah Financial and Business Services
Property of CampusGuard Compliance With The PCI DSS.
Credit Card Compliance Regulations Mandated by the Payment Card Industry Standards Council Accounting and Financial Services.
Payment Card PCI DSS Compliance SAQ-D Training Accounts Receivable Services, Controller’s Office 7/1/2012.
© Vendor Safe Technologies 2008 B REACHES BY M ERCHANT T YPE 70% 1% 9% 20% Data provided by Visa Approved QIRA November 2008 from 475 Forensic Audits.
PCI Compliance Forrest Walsh Director, Information Technology California Chamber of Commerce.
Data Security Standard. What Is PCI ? Who Does It Apply To ? Who Is Involved With the Compliance Process ? How We Can Stay Compliant ?
Jeff Williams Information Security Officer CSU, Sacramento
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Commonwealth of Massachusetts Office of the State Comptroller March 2007.
Joe SimonettiT-FLEx Workshop T-FLEx October Workshop The Future of Fare Collection Bank Card Transactions & Merchant Processing Joseph Simonetti October.
GPUG ® Summit 2011 November 8-11 Caesars Palace – Las Vegas, NV Payment Processing Online and Within Dynamics GP PCI Compliance and Secure Payment Processing.
Why Comply with PCI Security Standards?
Introduction to PCI DSS
Payment Card Industry (PCI) Data Security Standard
Security & PCI Compliance The Future of Electronic Payments Security & PCI Compliance Greg Grant Vice President – Managed Security Services.
Disclaimer Copyright Michael Chapple and Jane Drews, This work is the intellectual property of the authors. Permission is granted for this material.
Web Advisory Committee June 17,  Implementing E-commerce at UW  Current Status and Future Plans  PCI Data Security Standard  Questions.
Payment Card Industry Data Security Standard (PCI DSS) By Roni Argetsinger
PCI 3.0 Boot Camp Payment Card Industry Data Security Standards 3.0.
PCI DSS Managed Service Solution October 18, 2011.
Protecting Your Credit Card Security Environment (PCI) September 26, 2012 Jacob Arthur, CPA, QSA, CEH Timothy Agee, CISA, CGEIT, QSA FDH Consulting Frasier,
The Right Choice for Call Recording OAISYS and PCI DSS Compliance Managing Payment Card Industry Compliance with OAISYS Call Recording Solutions.
The influence of PCI upon retail payment design and architectures Ian White QSA Head of UK&I and ME PCI Team September 4, 2013 Weekend Conference 7 & 8.
An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.
NUAGA May 22,  IT Specialist, Utah Department of Technology Services (DTS)  Assigned to Department of Alcoholic Beverage Control  PCI Professional.
The Payment Card Industry (PCI) Data Security Standard: What it is and why you might find it useful Fred Hopper, CISSP TASK - 27 March 2007.
PCI requirements in business language What can happen with the cardholder data?
DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program.
PCI: As complicated as it sounds? Gerry Lawrence CTO
Credit Card Processing Gail “Montreal” Shoffey Keeler August 14, 2007.
Payment Card PCI DSS Compliance SAQ-A Training Accounts Receivable Services, Controller’s Office 7/1/2012.
Presented by Bob Wesolowski James R. Rennert, CFRE President Dir. of Mission Advancement Caring Habits, Inc. Sisters of St. Joseph Briarcliff Manor, NY.
Introduction to Payment Card Industry Data Security Standard
Introduction To Plastic Card Industry (PCI) Data Security Standards (DSS) April 28,2012 Cathy Pettis, SVP ICUL Service Corporation.
PCI Compliance: The Gateway to Paradise PCI Compliance: The Gateway to Paradise.
Data Security and Payment Card Acceptance Presented by: Brian Ridder Senior Vice President First National September 10, 2009.
Information Security 2013 Roadshow - PCI. Roadshow Outline  What IS PCI  Why we Care about PCI  What PCI Means to You and Me.
Payment Card PCI DSS Compliance SAQ-B Training Accounts Receivable Services, Controller’s Office 7/1/2012.
ThankQ Solutions Pty Ltd Tech Forum 2013 PCI Compliance.
1 Payment Card Industry (PCI) Security Standard Developed by the PCI Security Council formed by major card issuers: Visa, MasterCard, American Express,
Jon Bonham, CISA, QSA Director, ERC
The Unique Alternative to the Big Four ® 25 th Annual Conference of the Association of Local Government Auditors (ALGA) Understanding Payment Card Industry.
Standards in Use. EMV June 16Caribbean Electronic Payments LLC2.
By: Matt Winkeler.  PCI – Payment Card Industry  DSS – Data Security Standard  PAN – Primary Account Number.
The Payment Card Industry Data Security Standard (PCI DSS) is a proprietary information security standard for organizations that handle branded credit.
Introduction to PCI DSS
Payment Card Industry (PCI) Rules and Standards
PCI-DSS Security Awareness
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Payment card industry data security standards
Internet Payment.
Breaches by Merchant Type
Session 11 Other Assurance Services
Authorize.Net an overview
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
PCI Compliance : Whys and wherefores
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Presented by: Jeff Soukup
Presentation transcript:

Northern KY University Merchant Training

Discussion Topics What is PCI-DSS? Credit Card Processing Two specific facets (Technical & Functional) Penalties for non-compliance Risks Plan of Action

What is PCI-DSS? Payment Card Industry Data Security Standards (DSS) initially created by Visa and MasterCard (officially in 2006) now includes Discover, Amex and JCB. All credit card companies in the U.S. have endorsed the Standard PCI-DSS created so there would be common industry security requirements

Purpose Mandated by credit card companies – “If you accept our credit card(s), you must follow these rules.” Protect customers against fraud and identity theft. To avoid breaches and fraud resulting in lost revenue.

What PCI is NOT PCI is NOT something we can ignore. PCI is NOT a project -- It is an ongoing program. It is NOT a silver bullet. It is NOT an option -- If we accept credit cards as a source of payment, we must comply. It is not static

Twelve Requirements There are Twelve seemingly simple requirements….however Approximately 230 subsets of requirements depending on the Merchant Level and SAQ required to complete.

PCI DSS Requirements Goal: Build and Maintain a Secure Network 1. Install and maintain a firewall configuration to protect cardholder data 2. Do not use vendor-supplied defaults for system passwords and other security parameters Goal: Protect Cardholder Data 3. Protect stored cardholder data 4. Encrypt transmission of cardholder data across open, public networks Goal: Maintain a Vulnerability Management Program 5. Use and regularly update anti-virus software or programs 6. Develop and maintain secure systems and applications Goal: Implement Strong Access Control Measures 7. Restrict access to cardholder data by business need to know 8. Assign a unique ID to each person with computer access 9. Restrict physical access to cardholder data Goal: Regularly Monitor and Test Networks 10. Track and monitor all access to network resources and cardholder data 11. Regularly test security systems and processes Goal: Maintain an Information Security Policy 12. Maintain a policy that addresses information security for all personnel

SAQs Attestations of Compliance are included as part of each SAQ. SAQ A Card-not-present Merchants, All Cardholder Data Functions Outsourced SAQ B Merchants with Only Imprint Machines or Only Standalone, Dial-Out Terminals. No Electronic Cardholder Data Storage SAQ C-VT Merchants with Web-Based Virtual Terminals, No Electronic Cardholder Data Storage SAQ C Merchants with Payment Application Systems Connected to the Internet, No Electronic Cardholder Data Storage SAQ D All Other Merchants and All Service Providers Defined by a Payment Brand as Eligible to Complete an SAQ

Scope “Any network component, server, or application that is included in or connected to the cardholder data environment”

Scope Map network(s) and cardholder data flow Use an automated tool to find your data Interview each campus merchant Understand business and data needs Determine actual business processes Identify third-party service providers Get details on all payment applications Logs, traces Vendors can be frustrating

Penalties Fines up to $500,000 from each credit card company + $197 per account holder Forensic Investigation by QSA (Qualified Security Assessor) begins at $10,000. Increased auditing requirements Negative Public Relations Losing the ability to process credit card transactions completely Websites: www.privacyrights.org/ and www.pcisecuritystandards.org/ According to Dr Larry Poneman, an inaugural member of the Unisys Security Leadership Institute, an Adjunct Professor of Ethics & Privacy at Carnegie Mellon University’s CIO Institute, a former CEO of the Privacy Council and a former Global Managing Partner for Compliance Risk Management at PricewaterhouseCoopers, conducts independent research, educates leaders from both the private and public sectors and reports on privacy and data practices spanning a variety of industries….In his most recent survey results….The total avg cost of a data breach : in 2007 = 197.00 per compromised record; up from 182.00 in 2006, and from 138.00 in 2005. An increase in lost business due to data breach: 2007 lost business due to a data breach accounts for 65% of data breach costs compared to 54% in 2006. An increase in third-party data breaches….2007, 40% of survey respondents reported breaches by third party companies (software vendors, outsources, business partners)….i.e. the AceWare/pc charge/iModule software and payment applications being used on campus today……and lastly the increase in legal defense and public relations in respnse to a breach…..grew to 8% up from 3 percent in 2007. Can we afford it?

College & University Breaches University breaches have increased exponentially since 2005 Open vulnerable networks Numerous merchants across campuses Payment processes spread over large geographical area

Security Breaches Approximately 600,000,000 records breached since 2005. The running represents the approximate number of *records* that have been compromised due to security breaches, not necessarily the number of *individuals* affected. Some individuals may be the victims of more than one breach, which would affect the totals.  Since 2010 there have been 88 breaches (mostly universities, a few high schools) 98% of hacking successes are as the result of using default passwords. Always change default passwords.

Universities Are At Risk Network penetration, server hacking, SQL injections, stolen laptop computers, desktop computers, unlocked offices/desks, unsecured USB portable drives, CD’s, DVD’s, containing sensitive information; particularly PAN numbers, ssn, names, addresses, birthdates.

Credit Card Processing

Dial-Up Terminal $ Interchange $$$ Discount Fees Services Fees Authorization Request Authorization Confirmation Settlement $$$ Processor Merchant Card Owner’s Bank Issued Card Discount Fees Services Fees $ ACH Fees Banking Fees Merchant’s Bank

SSL Terminal $ Interchange $$$ Merchant Processor Authorization Request Merchant Settlement Authorization Confirmation Processor Card Owner’s Bank Issued Card $$$ $ Merchant’s Bank

Internet Processing $ Interchange $$$ Gateway Processor Authorization Request Settlement Authorization Confirmation Gateway Processor Card Owner’s Bank Issued Card $$$ $ Merchant’s Bank

Mobile Processing $ Interchange Cellular Network $$$ Processor Authorization Request Cellular Network Authorization Confirmation Settlement $$$ Processor Card Owner’s Bank Issued Card $ Merchant’s Bank

Cost Comparison Mobile Pay Website Omni VX570 Notes $75 for Encrypted Card Reader    (additional readers $65) $150 Initial Setup Fee (PNC) $600 for terminal purchase (Dual Comm) One-Time Fees $12 Monthly Access Fee $15 Monthly Fee   These fees are applied whether you process during the month or not. .10 per transaction So if you run 10 transactions, that will cost you $1. .06% Discount Fee This is applied to your gross $ processed $99 setup fee $50 per month Authorize.Net secure gateway or other PCI DSS/PA DSS compliant application. Authorize.Net Secure Gateway is preferred by NKU and PNC Merchant Services.

Equipment/Point of Sale System Spectrum of Risk Equipment/Point of Sale System Cash Dial Terminals Mobile (Encrypted Reader) Wireless Terminals (using cell phone networks) SSL Terminals Website Redirected Payments Virtual Terminals Web-based Applications Wi-Fi Terminals WEP/WPA Encrypted Wireless Networks- must be WPA2 Any system storing Card Holder Data (prohibited by PCI) Manual Imprinters Low Moderate Severe

In the future… EMV- Europay Visa Mastercard October 2015 P2PE- Point to Point Encryption

Questions?