PCI DSS for Retail Industry

Slides:



Advertisements
Similar presentations
Surviving the PCI Self -Assessment James Placer, CISSP West Michigan Cisco Users Group Leadership Board.
Advertisements

Payment Card Industry Data Security Standard AAFA ISC/SCLC Fall 08.
ISACA January 8, IT Auditor at Cintas Corporation Internal Audit Department Internal Security Assessor (ISA) Certification September 2010 Annual.
Evolving Challenges of PCI Compliance Charlie Wood, PCI QSA, CRISC, CISA Principal, The Bonadio Group January 10, 2014.
.. PCI Payment Card Industry Compliance October 2012 Presented By: Jason P. Rusch.
The Payment Card Industry Data Security Standard (PCI DSS)
Payment Card Industry Data Security Standard Tom Davis and Chad Marcum Indiana University.
PCI Compliance and the Restaurant of the Future October 8, 2013 Presented by WEBINAR Jim Lippard Senior Product Manager Security Products EarthLink Business.
Troy Leach April 2012 The PCI Security Standards Council.
MARTAs Road to PCI Compliance 1 Presenter: Yolanda Curtis, PMP AFC Project Manager.
PCI-DSS Erin Benedictson Information Security Analyst AAA Oregon/Idaho.
2014 PCI DSS Meeting OSU Business Affairs Process Improvement Team (PIT) Robin Whitlock & Dan Hough 10/28/2014.
This refresher course will:
JEFF WILLIAMS INFORMATION SECURITY OFFICER CALIFORNIA STATE UNIVERSITY, SACRAMENTO Payment Card Industry Data Security Standard (PCI DSS) Compliance.
University of Utah Financial and Business Services
Property of CampusGuard Compliance With The PCI DSS.
Smart Payment Processing ™ Protecting Your Business from Card Data Theft Presenter: Lucas Zaichkowsky.
1 Credit card operation and the recent CardSystems incident HONG KONG MONETARY AUTHORITY 4 July 2005.
Credit Card Compliance Regulations Mandated by the Payment Card Industry Standards Council Accounting and Financial Services.
Presented by : Vivian Eberhardt, Supervisor Cash and Credit Operations
PCI Compliance Forrest Walsh Director, Information Technology California Chamber of Commerce.
Data Security Standard. What Is PCI ? Who Does It Apply To ? Who Is Involved With the Compliance Process ? How We Can Stay Compliant ?
Visa Cemea Account Information Security (AIS) Programme
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Commonwealth of Massachusetts Office of the State Comptroller March 2007.
Copyright Security-Assessment.com 2005 Payment Card Industry Digital Security Standards Presented By Carl Grayson.
PCI DSS and MasterCard Site Data Protection Program Payment System Integrity September 2008.
Northern KY University Merchant Training
PCI's Changing Environment – “What You Need to Know & Why You Need To Know It.” Stephen Scott – PCI QSA, CISA, CISSP
Disclaimer Copyright Michael Chapple and Jane Drews, This work is the intellectual property of the authors. Permission is granted for this material.
Web Advisory Committee June 17,  Implementing E-commerce at UW  Current Status and Future Plans  PCI Data Security Standard  Questions.
PCI DSS The Payment Card Industry (PCI) Data Security Standard (DSS) was developed by the PCI Security Standards Council to encourage and enhance cardholder.
Payment Card Industry Data Security Standard (PCI DSS) By Roni Argetsinger
The ABC’s of PCI DSS Eric Beschinski Relationship Manager Utility Payment Conference Kay Limbaugh Specialist, Electronic Bills & Payments &
MasterCard Site Data Protection Program Program Alignment.
PCI DSS Managed Service Solution October 18, 2011.
Protecting Your Credit Card Security Environment (PCI) September 26, 2012 Jacob Arthur, CPA, QSA, CEH Timothy Agee, CISA, CGEIT, QSA FDH Consulting Frasier,
The influence of PCI upon retail payment design and architectures Ian White QSA Head of UK&I and ME PCI Team September 4, 2013 Weekend Conference 7 & 8.
An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.
NUAGA May 22,  IT Specialist, Utah Department of Technology Services (DTS)  Assigned to Department of Alcoholic Beverage Control  PCI Professional.
PCI requirements in business language What can happen with the cardholder data?
DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program.
PCI DSS Readiness Presented By: Paul Grégoire, CISSP, QSA, PA-QSA
Introduction to Payment Card Industry Data Security Standard
Introduction To Plastic Card Industry (PCI) Data Security Standards (DSS) April 28,2012 Cathy Pettis, SVP ICUL Service Corporation.
Walter Conway, QSA 403 Labs, LLC Sneak Preview: What to Expect from PCI DSS v. 2.0  Changes  Clarifications  Guidance.
PCI Compliance: The Gateway to Paradise PCI Compliance: The Gateway to Paradise.
Data Security and Payment Card Acceptance Presented by: Brian Ridder Senior Vice President First National September 10, 2009.
ThankQ Solutions Pty Ltd Tech Forum 2013 PCI Compliance.
1 Payment Card Industry (PCI) Security Standard Developed by the PCI Security Council formed by major card issuers: Visa, MasterCard, American Express,
Payment Card Industry (PCI)
BUSINESS CLARITY ™ PCI – The Pathway to Compliance.
Jon Bonham, CISA, QSA Director, ERC
Standards in Use. EMV June 16Caribbean Electronic Payments LLC2.
By: Matt Winkeler.  PCI – Payment Card Industry  DSS – Data Security Standard  PAN – Primary Account Number.
The Payment Card Industry Data Security Standard (PCI DSS) is a proprietary information security standard for organizations that handle branded credit.
Credit Card Compliance
MARTA’s Road to PCI Compliance
Wake Forest University
PCI-DSS Security Awareness
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Payment card industry data security standards
2013 PCI:DSS Meeting OSU Business Affairs
Internet Payment.
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
PCI Compliance : Whys and wherefores
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
MARTA’s Road to PCI Compliance
Payment Card Industry - Requirements and implementation challenges in Armenian market Vladislav Muradyan Partner.
Utility Payment Conference
Presented by: Jeff Soukup
Presentation transcript:

PCI DSS for Retail Industry March 21, 2014

Agenda Threat Landscape Payment Ecosystem Overview of PCI DSS Bank’s Approach for PCIDSS Compliance

Threat Landscape Increased focus at compromising POS systems at retail outlets Successful data breaches resulting in leakage of millions of cardholder data Sophisticated attack vectors being used to breach the security controls Affected Retailers Target Neiman Marcus Schnucks Markets Inc Harbor Freight MACPO Express ..and many more Malicious executables JackPOS Dexter Chewbacca Project Hack POSRAM Trojan …and many more Implement PCI DSS and PA DSS controls Lockdown POS terminals to allow only basic requisite applications (whitelist) Implement anti-malware and anti-virus solution capable of detecting variants of malicious executables Implement advanced monitoring solutions Advanced mitigation controls

Threat landscape

Payment Ecosystem– Terminologies Customer purchasing products or services from merchant Receives the payment card and bills from the issuer Card Holder Bank or other organization issuing a payment card on behalf of a payment brand (e.g. Master Card & Visa) Payment Brand issuing a payment card directly (e.g. Amex, Discover, JCB) Issuer Visa, MasterCard, Amex, Discover, JCB Payment Brand

Payment Card Transaction Flow – Terminologies Organization accepting the payment card for payment during a purchase Merchant Bank or entity the merchant uses to process their payment card transactions Receive authorization request from merchant and forward to issuer for approval Provides authorization, clearing and settlement services to merchants Acquirer

Payment Ecosystem – Authorization Flow

Payment Ecosystem – Settlement Flow

PCIDSS Overview - Some Key Terminologies AOC – Attestation of Compliance SAQ – Self Assessment Questionnaire ROC – Report on compliance SAD – Sensitive Authentication Data CHD – Cardholder data PAN – Primary A/c. No. ASV – Approved Scanning Vendor QSA – Qualified Security Assessor

Payment Card Industry – Security Standards Council Description PCI PTS This standard applies to hardware developers that design and build PIN entry devices. PCI PA-DSS This standard provides security requirements to software developers that build and resell payment applications to merchants P2PE The Point-to-Point Encryption (p2pe) program is optional and provides a comprehensive set of security requirements for p2pe solution providers to validate their hardware-based solutions, and may help reduce the PCI DSS scope of merchants using such solutions. PCI DSS Security requirements for entities processing, storing and/or transmitting CHD

PCI DSS Overview – The standard 6 Goals 12 Requirements 62 Main clauses 289 Testing Procedures Goal 1: Build and Maintain a Secure Network Goal 2: Protect Cardholder Data Goal 3: Maintain a Vulnerability Management Program Goal 4: Implement Strong Access Control Measures Goal 5: Regularly Monitor and Test Networks Goal 6: Maintain an Information Security Policy

Merchant Levels PAYMENT BRAND MERCHANT LEVEL Level 1 Level 2 Level 3 AMEX > 2.5million 50000 >< 2.5million <50000 NA DISCOVER > 6million 1million >< 6million 20000 ><1million Others JCB >1million < 1million MasterCard 20000 >< 1million VISA 20000 to 1million (ecommerce) < 20000 (ecommerce). < 1million (other) Payment Brand reserves the right to deem the level irrespective of transaction volume

Merchant Reporting Requirements PAYMENT BRAND MERCHANT LEVEL Level 1 Level 2 Level 3 Level 4 AMEX Annual OA by QSA or IA EU Only: Annual SAQ Quarterly N/W scan (ASV) (R) EU Only: SAQ (R) NA Quarterly Network Scan (ASV) JCB Annual OA by QSA Quarterly N/W scan(ASV) Annual SAQ DISCOVER Acquirer to determine compliance validation Annual SAQ (R) MasterCard VISA Quarterly N/W scan (ASV) Attestation of Compliance form OA: Onsite Assessment R: Recommended IA: Internal Auditor

Service Provider Levels PAYMENT BRAND SERVICE PROVIDER LEVEL Level 1 Level 2 AMEX All TPPs NA DISCOVER Does not categorize Service providers into levels JCB MasterCard >1million <1million VISA Inc >300,000 <300,000 Payment Brand reserves the right to deem the level irrespective of transaction volume TPP: Third Party Processors

Service Provider Reporting Requirements PAYMENT BRAND SERVICE PROVIDER LEVEL Level 1 Level 2 AMEX Annual OA by QSA or IA DISCOVER Annual OA by QSA OR IA OR Annual SAQ Quarterly network scans by ASV JCB Annual OA by QSA MasterCard Annual onsite review by QSA Quarterly network scan by ASV Annual SAQ VISA Attestation of Compliance form OA: Onsite Assessment IA: Internal Auditor

Need for PCIDSS Compliance RBI/2012-13/424: Section A – Point iv: Banks should ensure that all acquiring infrastructure that is currently operational on IP (Internet Protocol) based solutions are mandatorily made to go through PCI-DSS and PA-DSS certification. This should include acquirers, processors / aggregators and large merchants RBI Mandate It is not about just compliance. It is a security imperative, especially in the wake of recent high profile data breach incident at Service Providers & Merchants. Compliance is incidental, end objective is security. Remain resilient to data breaches

Bank’s Approach for PCIDSS Compliance Bank Compliance 1. On boarded a QSA Company to support in implementing PCI DSS controls at the enterprise level 2. Current State Assessment and Implementation in progress for all payment applications (switch, payment gateways, etc.), infrastructure, network and processes Merchant Compliance 1. Deployed a portal to monitor PCI DSS compliance for merchants and service providers 2. Monitoring compliance status of Level 1, Level 2 and Level 3 merchants and Level 1 and Level 2 service providers 3. Assist merchants and service providers in filling the applicable SAQ Two streams of compliance program HDFC Bank has taken the initiative to share the data security alerts and advisories received from Payment brands with all its merchants. Take these alerts/advisories seriously. If not actioned on time you will get hit – as a target or by a random attack.

Thank You Manish Pal, Information Security Group