The ABC’s of PCI DSS Eric Beschinski Relationship Manager Utility Payment Conference Kay Limbaugh Specialist, Electronic Bills & Payments &

Slides:



Advertisements
Similar presentations
Surviving the PCI Self -Assessment James Placer, CISSP West Michigan Cisco Users Group Leadership Board.
Advertisements

Payment Card Industry Data Security Standard AAFA ISC/SCLC Fall 08.
Evolving Challenges of PCI Compliance Charlie Wood, PCI QSA, CRISC, CISA Principal, The Bonadio Group January 10, 2014.
.. PCI Payment Card Industry Compliance October 2012 Presented By: Jason P. Rusch.
The Payment Card Industry Data Security Standard (PCI DSS)
PCI DSS for Retail Industry
Payment Card Industry Data Security Standard Tom Davis and Chad Marcum Indiana University.
PCI Compliance: The Gateway to Paradise PCI Compliance: The Gateway to Paradise.
PCI-DSS Erin Benedictson Information Security Analyst AAA Oregon/Idaho.
Complying With Payment Card Industry Data Security Standards (PCI DSS)
2014 PCI DSS Meeting OSU Business Affairs Process Improvement Team (PIT) Robin Whitlock & Dan Hough 10/28/2014.
JEFF WILLIAMS INFORMATION SECURITY OFFICER CALIFORNIA STATE UNIVERSITY, SACRAMENTO Payment Card Industry Data Security Standard (PCI DSS) Compliance.
Property of CampusGuard Compliance With The PCI DSS.
Smart Payment Processing ™ Protecting Your Business from Card Data Theft Presenter: Lucas Zaichkowsky.
Credit Card Compliance Regulations Mandated by the Payment Card Industry Standards Council Accounting and Financial Services.
Presented by : Vivian Eberhardt, Supervisor Cash and Credit Operations
PCI Compliance Forrest Walsh Director, Information Technology California Chamber of Commerce.
Data Security Standard. What Is PCI ? Who Does It Apply To ? Who Is Involved With the Compliance Process ? How We Can Stay Compliant ?
Jeff Williams Information Security Officer CSU, Sacramento
Visa Cemea Account Information Security (AIS) Programme
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Commonwealth of Massachusetts Office of the State Comptroller March 2007.
PCI DSS and MasterCard Site Data Protection Program Payment System Integrity September 2008.
GPUG ® Summit 2011 November 8-11 Caesars Palace – Las Vegas, NV Payment Processing Online and Within Dynamics GP PCI Compliance and Secure Payment Processing.
CSE 4482, 2009 Session 21 Personal Information Protection and Electronic Documents Act Payment Card Industry standard Web Trust Sys Trust.
Why Comply with PCI Security Standards?
Northern KY University Merchant Training
Payment Card Industry (PCI) Data Security Standard
Security & PCI Compliance The Future of Electronic Payments Security & PCI Compliance Greg Grant Vice President – Managed Security Services.
Disclaimer Copyright Michael Chapple and Jane Drews, This work is the intellectual property of the authors. Permission is granted for this material.
Payment Card Industry Data Security Standard (PCI DSS) By Roni Argetsinger
PCI DSS Managed Service Solution October 18, 2011.
Protecting Your Credit Card Security Environment (PCI) September 26, 2012 Jacob Arthur, CPA, QSA, CEH Timothy Agee, CISA, CGEIT, QSA FDH Consulting Frasier,
The influence of PCI upon retail payment design and architectures Ian White QSA Head of UK&I and ME PCI Team September 4, 2013 Weekend Conference 7 & 8.
An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.
NUAGA May 22,  IT Specialist, Utah Department of Technology Services (DTS)  Assigned to Department of Alcoholic Beverage Control  PCI Professional.
Teresa Macklin Information Security Officer 27 May, 2009 Campus-wide Information Security Activities.
The Payment Card Industry (PCI) Data Security Standard: What it is and why you might find it useful Fred Hopper, CISSP TASK - 27 March 2007.
PCI requirements in business language What can happen with the cardholder data?
DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program.
PCI: As complicated as it sounds? Gerry Lawrence CTO
Credit Card Processing Gail “Montreal” Shoffey Keeler August 14, 2007.
PCI DSS Readiness Presented By: Paul Grégoire, CISSP, QSA, PA-QSA
Introduction to Payment Card Industry Data Security Standard
Introduction To Plastic Card Industry (PCI) Data Security Standards (DSS) April 28,2012 Cathy Pettis, SVP ICUL Service Corporation.
PCI Compliance: The Gateway to Paradise PCI Compliance: The Gateway to Paradise.
Data Security and Payment Card Acceptance Presented by: Brian Ridder Senior Vice President First National September 10, 2009.
Information Security 2013 Roadshow - PCI. Roadshow Outline  What IS PCI  Why we Care about PCI  What PCI Means to You and Me.
ThankQ Solutions Pty Ltd Tech Forum 2013 PCI Compliance.
1 Payment Card Industry (PCI) Security Standard Developed by the PCI Security Council formed by major card issuers: Visa, MasterCard, American Express,
VeriShield Protect Revolutionary technology that simplifies PCI DSS compliance with no system upgrades Now available on V x Solutions!
BUSINESS CLARITY ™ PCI – The Pathway to Compliance.
PCI Compliance: What You Don’t Know Could Hurt You Utility Payment Conference Eric Beschinski Relationship Manager Kay Limbaugh Specialist, Electronic.
Standards in Use. EMV June 16Caribbean Electronic Payments LLC2.
July 2015…... Michigan Community Colleges Performance with NBS Thru October, 2015.
By: Matt Winkeler.  PCI – Payment Card Industry  DSS – Data Security Standard  PAN – Primary Account Number.
The Payment Card Industry Data Security Standard (PCI DSS) is a proprietary information security standard for organizations that handle branded credit.
Credit Card Compliance
Payment Card Industry (PCI) Rules and Standards
Performing Risk Analysis and Testing: Outsource or In-house
PCI-DSS Security Awareness
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Payment card industry data security standards
Internet Payment.
Session 11 Other Assurance Services
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
PCI Compliance : Whys and wherefores
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Payment Card Industry (PCI)
Utility Payment Conference
Presented by: Jeff Soukup
Presentation transcript:

The ABC’s of PCI DSS Eric Beschinski Relationship Manager Utility Payment Conference Kay Limbaugh Specialist, Electronic Bills & Payments &

A wareness B enefits & C onsequences

What is PCI Compliance? Misnomer… PCI DSS v2.0 Comprehensive security standards –QRG is 34 pages –Official Document is 75 pages PCI SSC Standards endorsed by the card brands

Moving Target Snapshot (point in time) Requires continual monitoring One minor change could remove the organization from compliance

What isn’t PCI Compliance? Not legislation Not a “one-time-deal” Not just your processor or POS provider’s problem Not a one-size-fits-all scenario –Different for each merchant –Different for each card brand

PCI DSS Overview Goals: Build & Maintain a secure Network Protect Cardholder Data Maintain a Vulnerability Management Program Requirements: 1.Firewall 2.Change all passwords from system defaults 3.Protect stored cardholder data 4.Encrypt transmission of cardholder data across open, public networks (the Internet) 5.Use updated antivirus software 6.Develop and maintain secure systems & applications

PCI DSS Overview Goals: Implement Strong Access Control Measures Regularly Monitor & Test Networks Maintain an Information Security Policy Requirements: 7.Restrict access to cardholder data by “need-to-know” 8.Assign a unique ID to each person with computer access 9.Restrict physical access to cardholder data 10.Track & monitor all access to network resources and cardholder data 11.Regularly test security systems and processes 12.Maintain a policy that addresses information security for all personnel

Big Picture A ccountability B est Practices C onsumer Safety

Steps Assess ↔ Remediate ↔ Report

You are not compliant if you don’t… 1.Complete the SAQ annually ( 2.Have your network scanned for vulnerabilities quarterly by an ASV (for processing via system connected to the internet) 3.QSA or Internal audit

Who really knows if you’re compliant? Only top-level management (and maybe a QSA) NOT… –Your processor –Your POS provider –Your IT company –A sales person Nobody without a SAQ

Enforcement? Lacking No problem until there’s a problem Like the Health Dept... From those in authority, it’s enforcement after-the-fact Up to you to be proactively self- enforced to prevent a breach

Why be concerned? Investigative fees Fines Cost to upgrade/fix the problem Lawsuits Blacklist Media Customer confidence Very, very expensive!

A nother B reach & C ounting… 333 breaches as of 8/1 with almost 23M records affected including –Sony –Epsilon –Citigroup –Lockheed Martin 603 breaches in 2010 affecting over 12M records Since 2005, over 2600 breaches affecting over 535M records Data provided by PrivacyRights.org

Top 10 Breaches 10. TD Ameritrade Holding Corp (2007) 9. Fidelity National Information Services/Certegy Check Services Inc. (2007) 8. Sony, PlayStation Network (PSN), Sony Online Entertainment (SOE) (2011) 7. Bank of New York Mellon (2008) 6.Countrywide Financial Corp. (2008) 5.US Dept. of Veterans Affairs (2006) 4.CardSystems (2005) 3. US Military Veterans (2009) 2. TJ Stores (2007) 1. Heartland (2009)

Heartland Certified compliant just weeks before the breach Security breach discovered in Jan 2009 (had been in place for possibly 6 months prior) De-certified post-breach Hundreds of Millions in fines/fees/lawsuits Bad press

Turning it around Re-certified May 2009 Proactive response Good press National Restaurant Association Launched E3 May 2010 Earnings up Stronger than ever

Lessons to be learned from the Heartland breach PCI DSS is a good minimum standard but will not guarantee safety If your company is big enough you will become a target No security is fail-proof Criminals working continually to break- in

Who is most at risk? All merchants –Level 1 & 2 (High Value) –Level 3 (High Risk) –Level 4 (High Success / Quick Return)

Then What Good is PCI DSS? Ensures that you are not an EASY target (low-hanging fruit) Common sense security measures Possibly some protection from fines/lawsuits –Good faith argument –Responsible party argument

Key Issues for Utility Industry A pplications: Software –POS –Antivirus –Firewall –Web/Payment Gateway Hardware –Firewall –POS –Pin Pads B usiness Procedures –Recording calls –Storing card data –Access Control C onnection –VOIP –Encryption

Myths 1.One vendor/product will make us compliant 2.Outsourcing card processing will make us compliant 3.Compliance is an IT project 4.Compliance will make us secure 5.PCI DSS is unreasonable; it requires too much

Myths 6.PCI DSS requires us to hire a QSA 7.We don’t take enough credit cards to require compliance 8.We completed a SAQ so we’re compliant 9.PCI DSS makes us store cardholder data 10.PCI DSS is too hard

In Conclusion A lways BeBe C ompliant!

Alphabet Soup AOC – Attestation of Compliance ASV – Approved Scanning Vendor DSS – Data Security Standards ISA – Internal Security Assessor PA-DSS – Payment Application Data Security Standards PAN – Primary Account Number PCI – Payment Card Industry PED – PIN Entry Device PFI – PCI Forensic Investigator PIN – Personal Identification Number PTS – PIN Transaction Security (formerly PED) QRG – Quick Reference Guide QSA – Qualified Security Assessor ROC – Report On Compliance SAQ – Self Assessment Questionnaire SSC – Security Standards Council

Q & A Eric Beschinski Relationship Manager Heartland Payment Systems Kay Limbaugh Specialist, Electronic Bills & Payments Portland General Electric