Showing posts with label PCI Compliance. Show all posts
Showing posts with label PCI Compliance. Show all posts
Thursday, February 20, 2014
Sunday, December 8, 2013
PCI DSS 3.0 – What's New?
Infographic - Summary of the Changes from PCI DSS 2.0 to 3.0
Last month, the PCI Security Standards Council (PCI SSC) officially released the PCI DSS v3.0 compliance standards, but much remains to be done before merchants, service providers and auditors will understand how the new mandates will impact organizations.
The effective date of the version 3.0 of the standard will be on January 1, 2014, but existing PCI DSS 2.0 compliant vendors will have until January 1, 2015 to move to the new standard, and some of the changes will continue to be best practices for several more months (until June 1, 2015).
Here’s what has changed:
Last month, the PCI Security Standards Council (PCI SSC) officially released the PCI DSS v3.0 compliance standards, but much remains to be done before merchants, service providers and auditors will understand how the new mandates will impact organizations.
The effective date of the version 3.0 of the standard will be on January 1, 2014, but existing PCI DSS 2.0 compliant vendors will have until January 1, 2015 to move to the new standard, and some of the changes will continue to be best practices for several more months (until June 1, 2015).
Here’s what has changed:
Wednesday, October 23, 2013
Aligning Security with GRC
How to Leverage GRC for Security?
Governance, Risk & Compliance (GRC) has long been viewed as a framework for tracking compliance requirements and developing business processes aligned with best practices and standards. It plays a strong role in helping security teams understand the business and to protect the organization from threats
But now, more security professionals are turning to data collected by GRC tools for insights into the organization's processes and technologies. The insights gained can help them to develop better controls to protect the organization from cyber-attacks and insider threats.
As part of GRC programs, organizations document processes, specify who owns which assets and define how various business operations align with technology. Security professionals can use this information to gain visibility into the organization's risks, such as determining what servers are running outdated software.
GRC programs collect a wealth of information and insights that can be valuable to security professionals as they manage risk and evaluate the organization's overall security posture. It provides the business context necessary to improve areas such as asset and patch management, incident response and assessing the impact of changes in technical controls on business processes.
Asset Inventory
Many compliance programs, including those for PCI-DSS [Payment Card Industry-Data Security Standard], require organizations to extensively document each asset and identify who uses it for what purpose. The documentation includes information about which business processes rely on which hardware and software. Mapping a piece of technology to a particular business function makes it possible to better identify the risks and the impact on operations if that technology is compromised.
The inventory process may identify equipment that the IT department was previously unaware of. By understanding the business processes that rely on that equipment, security teams can decide what kind of firewall rules to apply, better manage user accounts and learn what software needs to be updated. Understanding who the end-users are and how the asset is being used helps security teams assess how to prioritize the risks and plan how to reduce them.
Security professionals can use GRC programs to understand how technology maps to certain business processes and functions, says Mike Lloyd, CTO of Red Seal Networks, a network security management company. This information can help them figure out what the key threats are and identify ways to mitigate that risk, he says.
Incident Response, Controls
Security professionals can also use GRC to improve information sharing across the organization and streamline incident response. For example, because GRC makes it clear what kind of business processes depend on which assets, security teams have a clear path of who should be notified when there is a security event. Incident response teams can also look at all related processes and be able to identify other assets they should investigate to assess the magnitude of a breach.
Summary
Security professionals must understand the need to move away from a technical view of risk to a more strategic one when evaluating and deploying controls. They should evaluate how certain technical controls, while improving security, can impact business functions, and make necessary adjustments.
GRC enables security professionals to "draw a line between what security tasks are necessary and what business is concerned about.
Governance, Risk & Compliance (GRC) has long been viewed as a framework for tracking compliance requirements and developing business processes aligned with best practices and standards. It plays a strong role in helping security teams understand the business and to protect the organization from threats
But now, more security professionals are turning to data collected by GRC tools for insights into the organization's processes and technologies. The insights gained can help them to develop better controls to protect the organization from cyber-attacks and insider threats.
As part of GRC programs, organizations document processes, specify who owns which assets and define how various business operations align with technology. Security professionals can use this information to gain visibility into the organization's risks, such as determining what servers are running outdated software.
GRC programs collect a wealth of information and insights that can be valuable to security professionals as they manage risk and evaluate the organization's overall security posture. It provides the business context necessary to improve areas such as asset and patch management, incident response and assessing the impact of changes in technical controls on business processes.
Asset Inventory
Many compliance programs, including those for PCI-DSS [Payment Card Industry-Data Security Standard], require organizations to extensively document each asset and identify who uses it for what purpose. The documentation includes information about which business processes rely on which hardware and software. Mapping a piece of technology to a particular business function makes it possible to better identify the risks and the impact on operations if that technology is compromised.
The inventory process may identify equipment that the IT department was previously unaware of. By understanding the business processes that rely on that equipment, security teams can decide what kind of firewall rules to apply, better manage user accounts and learn what software needs to be updated. Understanding who the end-users are and how the asset is being used helps security teams assess how to prioritize the risks and plan how to reduce them.
Security professionals can use GRC programs to understand how technology maps to certain business processes and functions, says Mike Lloyd, CTO of Red Seal Networks, a network security management company. This information can help them figure out what the key threats are and identify ways to mitigate that risk, he says.
Incident Response, Controls
Security professionals can also use GRC to improve information sharing across the organization and streamline incident response. For example, because GRC makes it clear what kind of business processes depend on which assets, security teams have a clear path of who should be notified when there is a security event. Incident response teams can also look at all related processes and be able to identify other assets they should investigate to assess the magnitude of a breach.
Summary
Security professionals must understand the need to move away from a technical view of risk to a more strategic one when evaluating and deploying controls. They should evaluate how certain technical controls, while improving security, can impact business functions, and make necessary adjustments.
GRC enables security professionals to "draw a line between what security tasks are necessary and what business is concerned about.
Friday, July 5, 2013
Why Security Teams Fail PCI Audits?
5 Key Challenges in the way of successful auditing!
For any business accepting credit or debit card payments from its customers, Payment Card Industry Data Security Standards (PCI DSS) compliance - which offers comprehensive standards to enhance payment card data security - is an absolute must.
But for most, ensuring continuous compliance (the ongoing monitoring of rules rather than waiting for audits to show non-compliance) with the vast and ever changing set of rules can be a real drain on resources.
The 5 'C's
Undoubtedly one or all of the following challenges are getting in the way of successful auditing…the five 'C's:
Complexity- enterprises have hundreds of firewalls, routers and switches, all with their own complex configurations and thousands of access rules. All have to be tracked and catalogued which makes it almost impossible to comply with all the PCI DSS rules.
PCI DSS auditing doesn't always need to be a costly and thankless task. While compliance will always be essential for most enterprises, automation solutions can make it a much more efficient process - by slashing time spent on repetitive, manual work so that security teams can focus on strategic tasks such as security architecture, research and education.
For any business accepting credit or debit card payments from its customers, Payment Card Industry Data Security Standards (PCI DSS) compliance - which offers comprehensive standards to enhance payment card data security - is an absolute must.
But for most, ensuring continuous compliance (the ongoing monitoring of rules rather than waiting for audits to show non-compliance) with the vast and ever changing set of rules can be a real drain on resources.
The 5 'C's
Undoubtedly one or all of the following challenges are getting in the way of successful auditing…the five 'C's:
Complexity- enterprises have hundreds of firewalls, routers and switches, all with their own complex configurations and thousands of access rules. All have to be tracked and catalogued which makes it almost impossible to comply with all the PCI DSS rules.
- Change - hundreds of changes every week amounts to thousands of changes to track from one audit to the next. The combination of rapid change and time pressures mean mistakes happen which can leave businesses wide open.
- Connectivity - configuration errors very easily lead to compliance issues and service downtime. A high number of rule changes can compromise cardholder data, which can leave businesses compromised until their next audit.
- Compliance - audits are time intensive and usually changes are unchecked between audits making the process even more laborious. Yet businesses cannot afford to fail an audit.
- Communication - poor communication and a siloed culture of app owners and IT security can mean a comprehensive compliance check between audits is extremely complicated and difficult to manage.
PCI DSS auditing doesn't always need to be a costly and thankless task. While compliance will always be essential for most enterprises, automation solutions can make it a much more efficient process - by slashing time spent on repetitive, manual work so that security teams can focus on strategic tasks such as security architecture, research and education.
Sunday, February 3, 2013
New PCI Guidelines for E-Commerce
New PCI Guidelines for E-Commerce
A new set of card data security guidelines for merchants and payments providers aims to address increasing risks unique to e-commerce environments. On Jan. 31, the Payment Card Industry Security Standards Council issued its PCI DSS E-commerce Guidelines Information Supplement, a set of guidelines for e-commerce security.
The guidelines relate to online infrastructures and how merchants work with third-party providers. Developed by the PCI E-commerce Security Special Interest Group, the 39-page resource includes recommendations about topics ranging from online risks associated with payments gateways to often-overlooked security gaps Web-hosting providers can inadvertently create.
Securing the Payments Chain
The guidance reviews how merchants can work with third parties to address those risks and provides a checklist for easy-to-fix vulnerabilities related to:
A new set of card data security guidelines for merchants and payments providers aims to address increasing risks unique to e-commerce environments. On Jan. 31, the Payment Card Industry Security Standards Council issued its PCI DSS E-commerce Guidelines Information Supplement, a set of guidelines for e-commerce security.
The guidelines relate to online infrastructures and how merchants work with third-party providers. Developed by the PCI E-commerce Security Special Interest Group, the 39-page resource includes recommendations about topics ranging from online risks associated with payments gateways to often-overlooked security gaps Web-hosting providers can inadvertently create.
Securing the Payments Chain
- The guidance offers a checklist of security recommendations and reminders, such as:
- Know where cardholder data is located within the merchant's infrastructures and those of the processors and vendors to which they outsource.
- Regularly test software and applications to detect if card data or other information is being stored unintentionally.
- Evaluate risks associated within e-commerce technology.
- Review the network and database risks posed by outsourcing functions, such as payments processing and Web hosting to third parties.
- Hire PCI-approved website scanning vendors to validate, on a regular basis, Internet-facing environments for compliance with the PCI Data Security Standard.
- Define best practices for online payment application security.
- Implement security training for internal staff.
- Establish best practices for consumer awareness.
The guidance reviews how merchants can work with third parties to address those risks and provides a checklist for easy-to-fix vulnerabilities related to:
- Online injection flaws;
- Cross-site scripting, or XSS;
- Online cross-site request forgery, or CSRF;
- Buffer or temporary data storage overflows, which result when programs or processes attempt to store more data than they were designed to hold;
- Weak authentication and/or session credentials; and
- Application and software misconfigurations.
Monday, November 7, 2011
Free Webinar and Virtual Summit on various Information Security Issues
Mobiles, PCI, that big old cloud – what’s your poison?
I know there are so many resources out there in our profession, making it hard to know where to go for the really worthwhile insights on key issues like personal devices in the workplace, PCI, cloud security etc.
As such I have spoken to a few folk to give you a list of the 3 upcoming online events in these areas that have had the most sign-ups from people like you and have pasted details below. Take a look and see what you think….
1. Webcast: PCI DSS Demystified for SMEs
Streamed live to your desk on 17th November 2011 | 3pm GMT or 10am EST
Why is everything in Info Security always aimed at the big guys? No longer, thanks to this SC magazine webcast which was inspired by the spate of smaller companies being caught out recently by PCI loopholes and incurring massive reputational and financial damage as a result.
Ensure you don’t join the list by tuning in to the Barclaycard and Dell speakers at http://www.scwebcasts.tv/?btcommid=36601 .
2. Virtual Summit: Tackling the Big 3 - Cloud Security, Personal Devices and the Human Factor
Join CISOs from Skype, Vodafone, Canon, Travelex, HSBC and more in SC’s first truly Virtual World, which has set the information security world alight. Network with hundreds of other IS professionals (or avatars!), access whitepapers and tune into the sessions to give you everything you need to know to stay safe in 2012.
View the demo and create your own avatar now by visiting (it’s great fun!)
http://www.scvirtualsummit.com .
Or if you are a vendor interested in enquiring about speaking opportunities you can drop nicola.fulker@haymarket.com a line.
3. Webcast: Mobile Device Management - Locking down the mobile front
Streamed live to your desk on 23rd November at 3pm GMT or 10am EST
I know there are so many resources out there in our profession, making it hard to know where to go for the really worthwhile insights on key issues like personal devices in the workplace, PCI, cloud security etc.
As such I have spoken to a few folk to give you a list of the 3 upcoming online events in these areas that have had the most sign-ups from people like you and have pasted details below. Take a look and see what you think….
1. Webcast: PCI DSS Demystified for SMEs
Streamed live to your desk on 17th November 2011 | 3pm GMT or 10am EST
Why is everything in Info Security always aimed at the big guys? No longer, thanks to this SC magazine webcast which was inspired by the spate of smaller companies being caught out recently by PCI loopholes and incurring massive reputational and financial damage as a result.
Ensure you don’t join the list by tuning in to the Barclaycard and Dell speakers at http://www.scwebcasts.tv/?btcommid=36601 .
2. Virtual Summit: Tackling the Big 3 - Cloud Security, Personal Devices and the Human Factor
Join CISOs from Skype, Vodafone, Canon, Travelex, HSBC and more in SC’s first truly Virtual World, which has set the information security world alight. Network with hundreds of other IS professionals (or avatars!), access whitepapers and tune into the sessions to give you everything you need to know to stay safe in 2012.
View the demo and create your own avatar now by visiting (it’s great fun!)
http://www.scvirtualsummit.com .
Or if you are a vendor interested in enquiring about speaking opportunities you can drop nicola.fulker@haymarket.com a line.
3. Webcast: Mobile Device Management - Locking down the mobile front
Streamed live to your desk on 23rd November at 3pm GMT or 10am EST
It is the big issue that many people are still wrestling with – what should we do as iPads, Smartphones and their friends continue to proliferate the workplace. Tune in to this SC webcast to hear realistic and practical advice to keep the mobile front secure, without hamstringing your productivity.
Take a look and secure your place at http://www.scwebcasts.tv/?btcommid=35629
……………………………………………..
I hope these are of relevance to you and your team! SC’s stuff tends to be very good because they take time to research the content and ensure that vendor involvement is always to the benefit of their audience (not just the vendor in question’s back pocket!).
Take a look and secure your place at http://www.scwebcasts.tv/?btcommid=35629
……………………………………………..
I hope these are of relevance to you and your team! SC’s stuff tends to be very good because they take time to research the content and ensure that vendor involvement is always to the benefit of their audience (not just the vendor in question’s back pocket!).
Wednesday, August 17, 2011
PCI Council issues PCI tokenization compliance guidance
PCI tokenization document mirrors the Visa Best Practices for Tokenization
The long-awaited PCI DSS Tokenization Guidelines outline how tokens can be used in merchant systems and ways to properly deploy the technology, which substitutes tokens in place of primary account numbers (PANs) to limit the movement of cardholder data in the environment. A properly deployed system in certain merchant environments can “potentially” reduce the merchant’s effort to implement PCI DSS requirements, according to the report.
The tokenization document mirrors the Visa Best Practices for Tokenization report, which was issued last summer. Tokens used within merchant analytical systems and payment applications may not need the same level of security protection.
Thursday, August 11, 2011
Survey: Median Cost of Cybercrime Up 56% in a Year
Cybercrime is expensive, Cost of Cybercrime Soaring!
Still, the survey suggests the battle against cybercrime has gotten much harder in the past year. It takes organizations longer, and costs them more, to resolve cyberattacks. In 2011, the survey shows, the average time to resolve a cyberattack took 18 days, with an average cost to participating organizations of nearly $416,000. That's a nearly 70 percent increase from the estimated $250,000 cost and a 14-day resolution period surmised from last year's study.
EMC CFO David Goulden the other day said last month's breach of the system that stores secret codes for RSA's SecurID multifactor authentication tokens cost EMC $66.3 million in the second quarter.
That's well above average, according to a just-released survey by technology provider Hewlett-Packard, conducted by the Ponemon Institute. HP's second annual Cost of Cybercrime Study pegged the median annualized cost of cybercrime incurred by a benchmark sample of organizations at $5.9 million. The survey revealed a range of $1.5 million to $36.5 million, a 56 percent increase from the median cybercrime cost reported in HP's inaugural study published in July 2010.
The battle against cybercrime has gotten much harder in the past year. It takes organizations longer, and costs them more, to resolve cyber attacks.But, as the study shows, taking the proper preventative measures is a money-saver. Organizations that had deployed security information and event management solutions realized a cost savings of nearly 25 percent over those who didn't.
Still, the survey suggests the battle against cybercrime has gotten much harder in the past year. It takes organizations longer, and costs them more, to resolve cyberattacks. In 2011, the survey shows, the average time to resolve a cyberattack took 18 days, with an average cost to participating organizations of nearly $416,000. That's a nearly 70 percent increase from the estimated $250,000 cost and a 14-day resolution period surmised from last year's study.
And, it's tougher to solve an insider crime than one perpectuated from the outside. A malicious insider attack can take more than 45 days to contain.Of course, averages can't be applied to all situations. The RSA breached occurred nearly five months ago, and no one knows - or at least no one is saying - who perpetrated that costly cybercrime that not only diminished EMC's coffers but RSA's reputation as well.
Wednesday, June 29, 2011
New FFIEC Guidance will help to reduce the increasing security threats?
Final FFIEC Authentication Guidance Issued
The Federal Financial Institutions Examination Council has formally released the long-awaited supplement to its "Authentication in an Internet Banking Environment" guidance, which was first issued by the FFIEC in October 2005.
Formal assessments for compliance with the new guidance will begin in January 2012.
The purpose of the supplement is to reinforce the risk-management framework described in the original guidance and update the FFIEC member agencies' supervisory expectations regarding customer authentication, layered security, and other controls in the increasingly hostile online environment.
The official supplement highlights the need for:
The FFIEC says it will continue to work closely with financial institutions to promote security in electronic banking. Examiners have been directed to formally assess financial institutions under the enhanced expectations outlined in the supplement beginning in January 2012.
The FFIEC is made up of the following regulatory agencies: the Board of Governors of the Federal Reserve System, Federal Deposit Insurance Corp., Office of the Comptroller of the Currency, National Credit Union Administration and Office of Thrift Supervision.
The Federal Financial Institutions Examination Council has formally released the long-awaited supplement to its "Authentication in an Internet Banking Environment" guidance, which was first issued by the FFIEC in October 2005.
Formal assessments for compliance with the new guidance will begin in January 2012.
The purpose of the supplement is to reinforce the risk-management framework described in the original guidance and update the FFIEC member agencies' supervisory expectations regarding customer authentication, layered security, and other controls in the increasingly hostile online environment.
The official supplement highlights the need for:
- Better risk assessments;
- Effective strategies for mitigating known online risks;
- Improved customer and employee fraud awareness.
The FFIEC says it will continue to work closely with financial institutions to promote security in electronic banking. Examiners have been directed to formally assess financial institutions under the enhanced expectations outlined in the supplement beginning in January 2012.
The FFIEC is made up of the following regulatory agencies: the Board of Governors of the Federal Reserve System, Federal Deposit Insurance Corp., Office of the Comptroller of the Currency, National Credit Union Administration and Office of Thrift Supervision.
Monday, June 13, 2011
New PCI standard version 2.0 has been finalized
Changes Minor, But Non-Compliant Merchants Won't Get Leniency
Merchants and service provider validation requirements are the still the same. In fact, if you were compliant in the past, there was nothing terribly new. But if you had once sought shortcuts or attempted granular inferences, 2.0 may indeed prove discomforting.
Clarifications in 2.0
First and foremost, the new standard clearly spells out that the cardholder data environment includes "people, processes and technology" that touch the payments chain in any way. That means any entity that stores card data, processes or transmits card data, or touches authentication data must comply with the PCI-DSS.
Secondly, the standard's use of "system components" was given a more inclusive definition. System components include all virtualization components, such as virtual machines, virtual switches/routers, virtual appliances, virtual applications/desktops and hypervisors. Virtualization was further integrated into requirement 2.2.1's limitation to one primary function per virtual server or device, though whether or not DMZ-based and internal network zone devices could be virtualized within the same physical hardware was not clarified.
Among the 314 other clarifications included in the new version and guidance, several other points are worthy of mention:
Merchants and service provider validation requirements are the still the same. In fact, if you were compliant in the past, there was nothing terribly new. But if you had once sought shortcuts or attempted granular inferences, 2.0 may indeed prove discomforting.
Clarifications in 2.0
First and foremost, the new standard clearly spells out that the cardholder data environment includes "people, processes and technology" that touch the payments chain in any way. That means any entity that stores card data, processes or transmits card data, or touches authentication data must comply with the PCI-DSS.
If your organization ever sought to escape the stringency of the DSS by theorizing that it was only applicable to electronic cardholder data, the new guidance should clarify that even you must comply.If your organization ever sought to escape the stringency of the DSS by theorizing that it was only applicable to electronic cardholder data, the new guidance should clarify that even you must comply.
Secondly, the standard's use of "system components" was given a more inclusive definition. System components include all virtualization components, such as virtual machines, virtual switches/routers, virtual appliances, virtual applications/desktops and hypervisors. Virtualization was further integrated into requirement 2.2.1's limitation to one primary function per virtual server or device, though whether or not DMZ-based and internal network zone devices could be virtualized within the same physical hardware was not clarified.
Among the 314 other clarifications included in the new version and guidance, several other points are worthy of mention:
- The standard applies to issuers and recognition was given to their need to securely store any retained sensitive authentication data.
- Requirement 3.6 allows the use of cryptoperiods, rather than solely annual key rotation. If the impact of annual rotation has proven burdensome and the risk posed by less frequent key rotation is low, this should be a welcomed change. [See NIST Special Publicaiton 800-57 for more information about the standard cryptoperiod.]
- Requirement 3.6.6 was clarified as requiring split knowledge and dual control for manual clear-text cryptographic key management operations only. For those using dynamic key management appliances, this should already be a native function.
- Requirement 6.2 included the use of risk rankings for identified vulnerabilities as a best practice until June 30, 2012, after which it becomes a requirement. To accomplish this, NIST Special Publication 800-30 are suggested resources. Further, most organizations will likely find that documenting all operating system related critical patches as being "high" risk easier than ranking each individual patch.
- Requirement 12.3.10 added the ability to copy, move or store cardholder data on local hard drives and removable electronic media for authorized individuals; presumably, however, many will be challenged by scope implications.
It may sound counter-intuitive, but 53 testing procedures were added to simplify assessment and compliance management. Most of these are breakouts of the requirement verbiage. For instance, what had been listed as bullets under 4.1.a is now broken out into 4.1.a-4.1.e.
Redundancies also found in v1.2.1, which related to internal and Web-based application requirements 6.3 and 6.5, have been consolidated. Now, 6.5 includes the SANS CWE Top 25 and CERT Secure Coding best practice references.
Nevertheless, many hot button items, such as tokenization, remain open to interpretation. Questions surrounding tokenization, virtualization and physical hardware remain unanswered?
Redundancies also found in v1.2.1, which related to internal and Web-based application requirements 6.3 and 6.5, have been consolidated. Now, 6.5 includes the SANS CWE Top 25 and CERT Secure Coding best practice references.
Nevertheless, many hot button items, such as tokenization, remain open to interpretation. Questions surrounding tokenization, virtualization and physical hardware remain unanswered?
For now, and potentially until 2013 when release version 3.0 is expected, we may be left to wonder. In the meantime, for those looking to adopt 2.0, take a look at the PCI Council's tips for understanding the guidance: Navigating PCI DSS: Understanding the Intent of the Requirements.
Wednesday, May 18, 2011
Protecting against the Malware and other Security Risks
Latest Information Security Whitepapers
Here are some new security white papers I'd like to share - I hope you find them interesting (registration required).
Embracing Employee-Acquired Smartphones without Compromising Security
http://bit.ly/lRXkS0
Protecting Against the New Wave of Malware
http://bit.ly/k5lMdz
Social Networking and Security Risks
http://bit.ly/lmu7yI
PCI Compliance for Dummies Guide
http://bit.ly/imTwKd
Security Considerations for Small and Medium-Sized Enterprises
http://bit.ly/lugcpb
Here are some new security white papers I'd like to share - I hope you find them interesting (registration required).
Embracing Employee-Acquired Smartphones without Compromising Security
http://bit.ly/lRXkS0
Protecting Against the New Wave of Malware
http://bit.ly/k5lMdz
Social Networking and Security Risks
http://bit.ly/lmu7yI
PCI Compliance for Dummies Guide
http://bit.ly/imTwKd
Security Considerations for Small and Medium-Sized Enterprises
http://bit.ly/lugcpb
Friday, March 18, 2011
AM & Fraud: Risk that put burdens on Banks
AML & Fraud: The Global Challenge
Just when you think you've filled all the gaps by investing in all the right technology, crafty criminals will come up with an unexpected way to commit fraud. Increased cross-border transaction volume means more opportunity not just for money laundering, but also for ACH fraud, card fraud and identity theft, and that means greater need for real-time transaction monitoring.
As global transactions increase, and political unrest in Northern Africa continues, U.S. regulators will more closely scrutinize compliance with the USA Patriot Act and the Bank Secrecy Act, to name two regulations.
In other parts of the world, such as Europe, where privacy mandates often conflict with U.S. policy, regulators are just as intent on ensuring standards and sanctions are adhered to by banks and businesses operating within their borders.
From an AML perspective, most international banks are complying well with existing regulatory mandates. But enhanced monitoring, going forward, will be a must.
Regulators are looking for more efficient monitoring, and now banks are going to be expected to have more streamlined fraud-detection tools. Centralizing data is the only cost-effective way to streamline.
Centralizing your data is so important, for fraud detection, as well as knowing your customer. After all, knowing your customer leads to better service and fewer fines in the long run
Compliance is always looked at as a cost center. But when you know your customers and how they behave, not only can you meet the requirements of regulatory compliance, but you also can more effectively target your customers and shape your products around what they need, rather than around what you assume they want.
Just when you think you've filled all the gaps by investing in all the right technology, crafty criminals will come up with an unexpected way to commit fraud. Increased cross-border transaction volume means more opportunity not just for money laundering, but also for ACH fraud, card fraud and identity theft, and that means greater need for real-time transaction monitoring.
As global transactions increase, and political unrest in Northern Africa continues, U.S. regulators will more closely scrutinize compliance with the USA Patriot Act and the Bank Secrecy Act, to name two regulations.
In other parts of the world, such as Europe, where privacy mandates often conflict with U.S. policy, regulators are just as intent on ensuring standards and sanctions are adhered to by banks and businesses operating within their borders.
From an AML perspective, most international banks are complying well with existing regulatory mandates. But enhanced monitoring, going forward, will be a must.
Regulators are looking for more efficient monitoring, and now banks are going to be expected to have more streamlined fraud-detection tools. Centralizing data is the only cost-effective way to streamline.
Centralizing your data is so important, for fraud detection, as well as knowing your customer. After all, knowing your customer leads to better service and fewer fines in the long run
Compliance is always looked at as a cost center. But when you know your customers and how they behave, not only can you meet the requirements of regulatory compliance, but you also can more effectively target your customers and shape your products around what they need, rather than around what you assume they want.
Wednesday, March 16, 2011
Visa Pushes for Dynamic Authentication
The Answer to Card Fraud?
Visa recently announced the launch of its Technology Innovation Program, designed to eliminate eligible merchants from the annual requirement to validate their compliance with the Payment Card Industry Data Security Standard. The program, which takes effect March 31, aims to fuel dynamic data authentication through the continued deployment of EMV chip terminals in all parts of the world except the U.S.
What is 'Dynamic Authentication'?
The concept of dynamic authentication is intended to promote the use of a dynamic variable that will be included as part of each transaction that flows through the payment system. And the notion is that if there is a dynamic variable that accompanies that transaction that changes with every transaction, then that information cannot be used in the future to replay a transaction for fraudulent purposes. So, the notion of dynamic data is very powerful in that, again, each transaction would be unique. EMV chip, in particular, promotes the transmission of dynamic data by generating a cryptographic message that accompanies the transaction, and thereby makes that transaction dynamic.
Refer here or here to read more details on this initiative.
Visa recently announced the launch of its Technology Innovation Program, designed to eliminate eligible merchants from the annual requirement to validate their compliance with the Payment Card Industry Data Security Standard. The program, which takes effect March 31, aims to fuel dynamic data authentication through the continued deployment of EMV chip terminals in all parts of the world except the U.S.
What is 'Dynamic Authentication'?
The concept of dynamic authentication is intended to promote the use of a dynamic variable that will be included as part of each transaction that flows through the payment system. And the notion is that if there is a dynamic variable that accompanies that transaction that changes with every transaction, then that information cannot be used in the future to replay a transaction for fraudulent purposes. So, the notion of dynamic data is very powerful in that, again, each transaction would be unique. EMV chip, in particular, promotes the transmission of dynamic data by generating a cryptographic message that accompanies the transaction, and thereby makes that transaction dynamic.
Refer here or here to read more details on this initiative.
Saturday, March 12, 2011
HSBC to issue credit card sized Internet banking keycode device
OTP Card or SecurID tokens? What about soft tokens?
HSBC is to issue all customers with a one-time password code reader that can be used without the need to insert a Chip and PIN card.
The device, which is small enough to keep in a wallet or purse, generates a unique PIN code each time a customer logs on to their accounts. Users must enter a personal four-digit PIN to generate the six digit passcode.
Called the HSBC Secure Key, it differs from the approach taken by other UK banks such as the Co-operative Bank, Barclays, RBS and Nationwide which have equipped customers instead with bulkier Chip and PIN card readers.
The device will be issued to all new HSBC customers that register for online banking from 23 March and will be rolled out to all existing customers over the coming months.
HSBC is to issue all customers with a one-time password code reader that can be used without the need to insert a Chip and PIN card.
The device, which is small enough to keep in a wallet or purse, generates a unique PIN code each time a customer logs on to their accounts. Users must enter a personal four-digit PIN to generate the six digit passcode.
Called the HSBC Secure Key, it differs from the approach taken by other UK banks such as the Co-operative Bank, Barclays, RBS and Nationwide which have equipped customers instead with bulkier Chip and PIN card readers.
The device will be issued to all new HSBC customers that register for online banking from 23 March and will be rolled out to all existing customers over the coming months.
Wednesday, February 16, 2011
Aussie banks expose credit card details
Australia's biggest banks are posting credit card numbers in clear view on mailed customer statements in a direct violation of credit card security regulations.
Placing numbers where any mail thief could grab them is a fundamental breach of the troubled Payment Card Industry Card Data Security Standard (PCI DSS), according to sources in the industry.
The industry standard, drafted by card issuers Visa, MasterCard and American Express and enforced by banks, is a series of security rules to which any business dealing with credit card transactions must adhere.
The standard is a collaborative industry effort to reduce financial fraud by mandating baseline security measures that essentially must accompany any credit card transaction. A call centre operator, for example, would be required to destroy a paper note if it was used to temporarily jot down a credit card number, while a website that stores transaction information must ensure it is adequately secure.
Non-compliant large businesses — or Tier 1 organisations bound by strict rules — face hundreds of thousands of dollars in fines, and risk losing their ability to process credit cards. The fines scale according to the number of credit card transactions processed.
But St George and the Commonwealth Bank have breached rule 101 of the standard by sending out potentially millions of paper statements to letterboxes that clearly detail credit card numbers in full.
Refer here for more details.
Placing numbers where any mail thief could grab them is a fundamental breach of the troubled Payment Card Industry Card Data Security Standard (PCI DSS), according to sources in the industry.
The industry standard, drafted by card issuers Visa, MasterCard and American Express and enforced by banks, is a series of security rules to which any business dealing with credit card transactions must adhere.
The standard is a collaborative industry effort to reduce financial fraud by mandating baseline security measures that essentially must accompany any credit card transaction. A call centre operator, for example, would be required to destroy a paper note if it was used to temporarily jot down a credit card number, while a website that stores transaction information must ensure it is adequately secure.
Non-compliant large businesses — or Tier 1 organisations bound by strict rules — face hundreds of thousands of dollars in fines, and risk losing their ability to process credit cards. The fines scale according to the number of credit card transactions processed.
But St George and the Commonwealth Bank have breached rule 101 of the standard by sending out potentially millions of paper statements to letterboxes that clearly detail credit card numbers in full.
Refer here for more details.
Monday, October 25, 2010
Verizon report connects PCI non-compliance and data breaches
Verizon Business report shows a correlation between non-compliance with the Payment Card Industry Data Security Standard (PCI DSS) and data breaches
A new Verizon Business report released today shows a correlation between non-compliance with the Payment Card Industry Data Security Standard (PCI DSS) and data breaches. The results revealed that organizations that had suffered data breaches were 50% more likely to exhibit PCI non-compliance.
The report also ranked the top attack techniques used to steal payment card data. Remote access to systems via backdoors was the top attack, followed closely by SQL injection attacks. Poor authentication was also a problem, in particular, attackers exploiting default or easily guessable passwords to gain access to systems storing or processing payment data.
Further, 11% of companies met less than half of the requirements, while 22% met 100% of the requirements. The report also covers compensating controls, and determined that Requirement 3.4, which mandates that a primary account number (PAN) be unreadable, is the control most compensated for.
Quick Summary
A new Verizon Business report released today shows a correlation between non-compliance with the Payment Card Industry Data Security Standard (PCI DSS) and data breaches. The results revealed that organizations that had suffered data breaches were 50% more likely to exhibit PCI non-compliance.
The report also ranked the top attack techniques used to steal payment card data. Remote access to systems via backdoors was the top attack, followed closely by SQL injection attacks. Poor authentication was also a problem, in particular, attackers exploiting default or easily guessable passwords to gain access to systems storing or processing payment data.
Further, 11% of companies met less than half of the requirements, while 22% met 100% of the requirements. The report also covers compensating controls, and determined that Requirement 3.4, which mandates that a primary account number (PAN) be unreadable, is the control most compensated for.
Quick Summary
- 22% of organizations were validated compliant at the time of their Initial Report on Compliance (IROC). These tended to be year after year repeat clients.
- On average, organizations met 81% of all test procedures defined within PCI DSS at the IROC stage. Naturally, there was some variation around this number but not many (11% of clients) passed less than 50% of tests.
- Organizations struggled most with requirements 10 (track and monitor access), 11 (regularly test systems and processes), and 3 (protect stored cardholder data).
- Requirements 9 (restrict physical access), 7 (restrict access to need-to-know), and 5 (use and update anti-virus) showed the highest implementation levels.
- Sub-requirement 3.4 (render the Primary Account Number (PAN) unreadable) was met through compensating controls far more often than any other in the standard.
- Organizations do not appear to be prioritizing their compliance efforts based on the PCI DSS Prioritized Approach published by the PCI Security Standards Council.
- Overall, organizations that suffered a data breach were 50% less likely to be compliant than a normal population of PCI clients.
Thursday, April 22, 2010
Fraudsters Swapping Out POS Devices, Stealing Card Data
Data at Risk
Once the device has been swapped, the amount of data to be stolen is related to the amount of time the compromised terminal is in place at the retail location. It also depends on the number of cards that transact during that time. It can run into thousands of cards.
In most of the POS terminal compromises Urban says he has seen in the U.S. that the data is stored on the POS terminal until the terminal is swapped back out. But there is a trend where card compromising devices will broadcast data via Bluetooth or other wireless protocols.
The Hancock Fabrics data breach continues to raise new questions about the security of point of sale (POS) devices at retail stores.
In March, the national fabric store chain publicly confirmed the breach it suffered last summer, sending an open letter to its customers, revealing: "PIN pad units at a limited number of Hancock Fabrics stores were stolen and replaced with visually identical, but fraudulent, PIN pad units. This may have allowed criminals to capture - or "skim" -- payment card data during transactions."
Hancock didn't reveal the locations or number of stores where point of sale scanners were compromised -- nor the number of customers who had their card data taken -- but at least 140 reports from customers in California, Wisconsin and Missouri show the pervasive nature of the fraud.
The lesson here: It is relatively easy for fraudsters to tamper with or even swap out POS PIN Entry Device (PED) pads, and these types of incidents are likely to increase, putting retailers, consumers and banking institutions at risk of future card-related fraud.
According to Bank Info Security, It is conceivable that the data captured can be Track 2 data plus the user's PIN, "which means the criminal may be able to manufacture fake debit cards," says Chuvakin. This data with full access to bank account withdrawal up to a daily limit of $500 could inflict real damage to individual victims - with banking institutions then footing the bill to replace cards and/or monitor accounts.
Prevention and Education
The Hancock Fabrics breach points to several steps that retailers can take to prevent this kind of crime from happening to them:
Ensure PCI Compliance -- Making sure all POS terminals are PCI compliant, using Derived Unique Key Per Transaction (DUKPT). Securely install terminals with unique hardware as a deterrent, and visibly inspect them along with the registers every day.
Educate Employees -- Security awareness training for all store employees would be a great start. Newer pin pads that have more built-in security measures like device tamper resistance can help, but it's important to keep spare PIN pads locked away, and employees should periodically check them while at work to make sure the device ID still matches.
Auditing the PEDs -- on a regular basis, recording them and cross checking the serial numbers. Chuvakin, who recommends retailers follow PED Security Guidelines and review the condition and placement of internal CCTV systems to cover all till areas.
Watch Your Staff -- The PCI Security Council's PIN Transaction working group also recommends performing background checks on employees, as well as keeping a complete record of any work done on the POS pads by service providers. If a service engineer arrives at the store unannounced to do work on the PEDs, the working group recommends that before any work is performed that their identity be confirmed by contacting the service company.
Once the device has been swapped, the amount of data to be stolen is related to the amount of time the compromised terminal is in place at the retail location. It also depends on the number of cards that transact during that time. It can run into thousands of cards.
In most of the POS terminal compromises Urban says he has seen in the U.S. that the data is stored on the POS terminal until the terminal is swapped back out. But there is a trend where card compromising devices will broadcast data via Bluetooth or other wireless protocols.
The Hancock Fabrics data breach continues to raise new questions about the security of point of sale (POS) devices at retail stores.
In March, the national fabric store chain publicly confirmed the breach it suffered last summer, sending an open letter to its customers, revealing: "PIN pad units at a limited number of Hancock Fabrics stores were stolen and replaced with visually identical, but fraudulent, PIN pad units. This may have allowed criminals to capture - or "skim" -- payment card data during transactions."
Hancock didn't reveal the locations or number of stores where point of sale scanners were compromised -- nor the number of customers who had their card data taken -- but at least 140 reports from customers in California, Wisconsin and Missouri show the pervasive nature of the fraud.
The lesson here: It is relatively easy for fraudsters to tamper with or even swap out POS PIN Entry Device (PED) pads, and these types of incidents are likely to increase, putting retailers, consumers and banking institutions at risk of future card-related fraud.
According to Bank Info Security, It is conceivable that the data captured can be Track 2 data plus the user's PIN, "which means the criminal may be able to manufacture fake debit cards," says Chuvakin. This data with full access to bank account withdrawal up to a daily limit of $500 could inflict real damage to individual victims - with banking institutions then footing the bill to replace cards and/or monitor accounts.
Prevention and Education
The Hancock Fabrics breach points to several steps that retailers can take to prevent this kind of crime from happening to them:
Ensure PCI Compliance -- Making sure all POS terminals are PCI compliant, using Derived Unique Key Per Transaction (DUKPT). Securely install terminals with unique hardware as a deterrent, and visibly inspect them along with the registers every day.
Educate Employees -- Security awareness training for all store employees would be a great start. Newer pin pads that have more built-in security measures like device tamper resistance can help, but it's important to keep spare PIN pads locked away, and employees should periodically check them while at work to make sure the device ID still matches.
Auditing the PEDs -- on a regular basis, recording them and cross checking the serial numbers. Chuvakin, who recommends retailers follow PED Security Guidelines and review the condition and placement of internal CCTV systems to cover all till areas.
Watch Your Staff -- The PCI Security Council's PIN Transaction working group also recommends performing background checks on employees, as well as keeping a complete record of any work done on the POS pads by service providers. If a service engineer arrives at the store unannounced to do work on the PEDs, the working group recommends that before any work is performed that their identity be confirmed by contacting the service company.
Wednesday, April 7, 2010
6 Steps to Reduce Online Fraud
What Must Be Done to Protect Business Accounts
What can - and should - a banking institution do to help protect its business customers?
Current Fraud Trends
There are three variations of fraud that is commonly seen as particularly prevalent now:
First Party - where criminals open accounts and use them as pass-through accounts to move money. Additionally, there also may be legitimate business owners who are kiting -- they create additional float so they have additional line of credit. They're not meaning to defraud the bank, but creating float type of credit.
Internal - where employees sell information about a business' accounts to outside organizations. Another scenario is where the small business employee who is accessing the business accounts moves out money and then leaves town. One twist to detecting internal fraud is the possibility that employees who perform the transactions will muddy the trail by saying their account credentials were taken in a phishing email. They can almost use that as an excuse, and it can't be proven unless the business has internet web logs, So it is hard to prove if the employee was colluding with outsiders, or their account actually was phished.
Third party - where most of the warnings are coming in via phishing, social engineering or spear-phishing. There are even infected webpages that can compromise a user's PC. Criminals attack the business, compromise the online credentials and move money out of the accounts.
Areas to Improve Security
Many institutions impose transaction limits as a way to stop fraud. This is a "stop gap measure" and these additional steps should be followed:
Account Level Check - Look at the types of transactions that are happening -- what is typical behavior, logins, when they happen. Then if they start logging in at night or over weekend, that's a red flag to hold transactions until you can talk to the business owner, stopping fraud from taking place. The key is to use analytics to scope "out of the ordinary" transactions. Look across all of the customer's behavior to spot what is unusual for that account holder.
Create Unique Account User IDs - Make sure users all have different log-in identification. Do not let them use the same user name and password. There should be a unique user names for each person in order for the institution to be able to create unique profiles of use for each of the users. This is similar to the PCI requirements; for anyone who accesses data, they each need a separate log-in.
Dual Control - Have two unique users approve transactions. If you can implement that, it goes a long way in reducing the chances of criminals stealing from the SMB account with a single user logon, and it also stops the threat of internal fraud as well.
Multi-Factor Authentication - Even though this solution is susceptible to man-in-the-middle and man- in-the-browser attacks, it is still an effective layer of protection. A lot of times business owners will ask 'I have so many users on the account' how many tokens will I need?' You need a unique token for every user."
SMS Messaging - This out-of-band message to users and account owners is important. It can be bypassed if a criminal can get into and change numbers or email contacts. But an institution can get around that by contacting the old number or email when a change is requested to verify that it was the account holder -- not a criminal -- making that request. This is something that banks already do with address changes. You need to realize that criminals will go in and change email and phone number contact information, so it is a heads-up that something is taking place.
IP-Email Address Controls - Only allowing certain email address/IP locations to go to the bank's online website to do transactions is another good control to put in place. It can be overcome, but it is another good layer of control. What's the risk that someone has just changed their phone and email contact information and is coming in from another email IP location to make these transactions? If they're coming in from another IP address, by looking at the risk, the institution can stop and look at it and question the transaction.
What can - and should - a banking institution do to help protect its business customers?
Current Fraud Trends
There are three variations of fraud that is commonly seen as particularly prevalent now:
First Party - where criminals open accounts and use them as pass-through accounts to move money. Additionally, there also may be legitimate business owners who are kiting -- they create additional float so they have additional line of credit. They're not meaning to defraud the bank, but creating float type of credit.
Internal - where employees sell information about a business' accounts to outside organizations. Another scenario is where the small business employee who is accessing the business accounts moves out money and then leaves town. One twist to detecting internal fraud is the possibility that employees who perform the transactions will muddy the trail by saying their account credentials were taken in a phishing email. They can almost use that as an excuse, and it can't be proven unless the business has internet web logs, So it is hard to prove if the employee was colluding with outsiders, or their account actually was phished.
Third party - where most of the warnings are coming in via phishing, social engineering or spear-phishing. There are even infected webpages that can compromise a user's PC. Criminals attack the business, compromise the online credentials and move money out of the accounts.
Areas to Improve Security
Many institutions impose transaction limits as a way to stop fraud. This is a "stop gap measure" and these additional steps should be followed:
Account Level Check - Look at the types of transactions that are happening -- what is typical behavior, logins, when they happen. Then if they start logging in at night or over weekend, that's a red flag to hold transactions until you can talk to the business owner, stopping fraud from taking place. The key is to use analytics to scope "out of the ordinary" transactions. Look across all of the customer's behavior to spot what is unusual for that account holder.
Create Unique Account User IDs - Make sure users all have different log-in identification. Do not let them use the same user name and password. There should be a unique user names for each person in order for the institution to be able to create unique profiles of use for each of the users. This is similar to the PCI requirements; for anyone who accesses data, they each need a separate log-in.
Dual Control - Have two unique users approve transactions. If you can implement that, it goes a long way in reducing the chances of criminals stealing from the SMB account with a single user logon, and it also stops the threat of internal fraud as well.
Multi-Factor Authentication - Even though this solution is susceptible to man-in-the-middle and man- in-the-browser attacks, it is still an effective layer of protection. A lot of times business owners will ask 'I have so many users on the account' how many tokens will I need?' You need a unique token for every user."
SMS Messaging - This out-of-band message to users and account owners is important. It can be bypassed if a criminal can get into and change numbers or email contacts. But an institution can get around that by contacting the old number or email when a change is requested to verify that it was the account holder -- not a criminal -- making that request. This is something that banks already do with address changes. You need to realize that criminals will go in and change email and phone number contact information, so it is a heads-up that something is taking place.
IP-Email Address Controls - Only allowing certain email address/IP locations to go to the bank's online website to do transactions is another good control to put in place. It can be overcome, but it is another good layer of control. What's the risk that someone has just changed their phone and email contact information and is coming in from another email IP location to make these transactions? If they're coming in from another IP address, by looking at the risk, the institution can stop and look at it and question the transaction.
Wednesday, April 2, 2008
My Blog is PCI Certified by Scanless PCI
Get PCI Certified for free....
Jeremiah Grossman has posted a very interesting post about getting PCI Certified for free.
Scanless PCI is faster and less intrusive to deploy, yet is as effective as competitive solutions for a fraction of the cost.
I qoute from Jeremiah's post:
Scanless PCI claims they’ve found a unique (patent-pending) way to certify merchant websites with no-setup, no technology changes, and at absolutely no cost! Sounded too good to be true so I investigated their website. To my amazement I left the site completely convinced that their offering is every bit as effective at stopping hackers as other ASVs we’ve discussed here in the past. Their process was so straight forward I figured there was no excuse for my blog not to be PCI Certified as well. Check out the right side column, compliance was zip zap!
I encourage everyone to jump on board and give the service a try.
Jeremiah Grossman has posted a very interesting post about getting PCI Certified for free.
Scanless PCI is faster and less intrusive to deploy, yet is as effective as competitive solutions for a fraction of the cost.
I qoute from Jeremiah's post:
Scanless PCI claims they’ve found a unique (patent-pending) way to certify merchant websites with no-setup, no technology changes, and at absolutely no cost! Sounded too good to be true so I investigated their website. To my amazement I left the site completely convinced that their offering is every bit as effective at stopping hackers as other ASVs we’ve discussed here in the past. Their process was so straight forward I figured there was no excuse for my blog not to be PCI Certified as well. Check out the right side column, compliance was zip zap!
I encourage everyone to jump on board and give the service a try.
Tuesday, February 12, 2008
Understanding Third-Party Vendor In PCI Compliance
Recognizing the value of outside assistance in achieving PCI Compliance
While some companies do elect to develop, deploy, assess and penetration test a compliance strategy on their own, others find that there are certain advantages to using a third-party vendor for these activities. For some organizations, an outside vendor can provide external validation that the appropriate processes and policies are in place; this validation can provide reassurance to customers, partners, shareholders and card issuers. A third-part vendor can also provide an objective analysis, of your current compliance status, along with recommendations for closing any gaps.
When compliance validation activities are executed in house, company officials become fully liable for any ommissions or erros. Using a third-party vendor can shift the risk away from corporate management. Companies can conduct their own penetration testing if they prefer. Quarterly external network scans are required for the majority of merchants and service providers, and these scans must be performed by an approved third-party assessor. When companies reach a certain threshold of payment card transactions, a ceritified PCI assessor must be used to validate PCI compliance. The PCI Security Standards Council manages a Qualified Scurity Assessor (QSA) program, ensuring that assessors are fully certified to conduct PCI assessments.
Selecting a Third-Party Vendor:
Allowing a third-party assessor to shift through your data can be a scary proposition, so it's important to choose a trusted, experienced, certified provider that understands the PCI standard in relation to your industry. The ability to handle all phases of your PCI compliance validation, from pre-assessment through report of compliance (ROC) submission, is key. Your vendor should be willing to offer you multiple alternatives for achieving the same level of protection and should provide you with a detailed roadmap in each case. The assessor's cire competency should extend beyond compliance services to addressing your overall security posture and providing recommendations for securing your infrastructure. The services provided should be clearly delineated, particularly if the contract spans multiple years.
As you proceed through the selection process, you should ask yourself these questions:
While some companies do elect to develop, deploy, assess and penetration test a compliance strategy on their own, others find that there are certain advantages to using a third-party vendor for these activities. For some organizations, an outside vendor can provide external validation that the appropriate processes and policies are in place; this validation can provide reassurance to customers, partners, shareholders and card issuers. A third-part vendor can also provide an objective analysis, of your current compliance status, along with recommendations for closing any gaps.
When compliance validation activities are executed in house, company officials become fully liable for any ommissions or erros. Using a third-party vendor can shift the risk away from corporate management. Companies can conduct their own penetration testing if they prefer. Quarterly external network scans are required for the majority of merchants and service providers, and these scans must be performed by an approved third-party assessor. When companies reach a certain threshold of payment card transactions, a ceritified PCI assessor must be used to validate PCI compliance. The PCI Security Standards Council manages a Qualified Scurity Assessor (QSA) program, ensuring that assessors are fully certified to conduct PCI assessments.
Selecting a Third-Party Vendor:
Allowing a third-party assessor to shift through your data can be a scary proposition, so it's important to choose a trusted, experienced, certified provider that understands the PCI standard in relation to your industry. The ability to handle all phases of your PCI compliance validation, from pre-assessment through report of compliance (ROC) submission, is key. Your vendor should be willing to offer you multiple alternatives for achieving the same level of protection and should provide you with a detailed roadmap in each case. The assessor's cire competency should extend beyond compliance services to addressing your overall security posture and providing recommendations for securing your infrastructure. The services provided should be clearly delineated, particularly if the contract spans multiple years.
As you proceed through the selection process, you should ask yourself these questions:
- What am I getting for my investment? Do I receive simply the output of a scan, or do I benefit from the vendor's security expertise?
- How customized is the assessment that this vendor offers me?
- Is my vendor fully certified to perform all phases of the PCI compliance validation?
- Has this vendor fully explained the timeline involved in the process? From pre-assessment through ROC submission, the process can take from 9 - 18 months; am I prepared for that?
In short, you want a trusted security adviser that can be your advocate to your acquirer bank and payment card companies.
Subscribe to:
Posts (Atom)
