Navigating the New SAQs (Helping the 99% validate PCI compliance)

Slides:



Advertisements
Similar presentations
Approaches to meeting the PCI Vulnerability Management and Penetration Testing Requirements Clay Keller.
Advertisements

CONFIDENTIAL 1 Preparing for & Maintaining PCI Compliance.
Surviving the PCI Self -Assessment James Placer, CISSP West Michigan Cisco Users Group Leadership Board.
Evolving Challenges of PCI Compliance Charlie Wood, PCI QSA, CRISC, CISA Principal, The Bonadio Group January 10, 2014.
.. PCI Payment Card Industry Compliance October 2012 Presented By: Jason P. Rusch.
PCI DSS for Retail Industry
Payment Card Industry Data Security Standard Tom Davis and Chad Marcum Indiana University.
UCSB Credit Card Processing and PCI Compliance
PCI Compliance: The Gateway to Paradise PCI Compliance: The Gateway to Paradise.
MARTAs Road to PCI Compliance 1 Presenter: Yolanda Curtis, PMP AFC Project Manager.
Complying With Payment Card Industry Data Security Standards (PCI DSS)
2014 PCI DSS Meeting OSU Business Affairs Process Improvement Team (PIT) Robin Whitlock & Dan Hough 10/28/2014.
JEFF WILLIAMS INFORMATION SECURITY OFFICER CALIFORNIA STATE UNIVERSITY, SACRAMENTO Payment Card Industry Data Security Standard (PCI DSS) Compliance.
Property of CampusGuard Compliance With The PCI DSS.
Credit Card Compliance Regulations Mandated by the Payment Card Industry Standards Council Accounting and Financial Services.
Payment Card PCI DSS Compliance SAQ-D Training Accounts Receivable Services, Controller’s Office 7/1/2012.
PCI DSS Version 3.0 For Controllers and Business Users Luke Harris, Office of State the Controller David Reavis, UNC General Administration November 10,
Presented by : Vivian Eberhardt, Supervisor Cash and Credit Operations
PCI Compliance Forrest Walsh Director, Information Technology California Chamber of Commerce.
Data Security Standard. What Is PCI ? Who Does It Apply To ? Who Is Involved With the Compliance Process ? How We Can Stay Compliant ?
Jeff Williams Information Security Officer CSU, Sacramento
Credit Card Changes that Impact You! Changes to Accounts Receivable, Cash Receipts and Student Billing 7.77 Wanda Mahon & Bucky Wall Corporate Readiness.
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Commonwealth of Massachusetts Office of the State Comptroller March 2007.
GPUG ® Summit 2011 November 8-11 Caesars Palace – Las Vegas, NV Payment Processing Online and Within Dynamics GP PCI Compliance and Secure Payment Processing.
Northern KY University Merchant Training
PCI's Changing Environment – “What You Need to Know & Why You Need To Know It.” Stephen Scott – PCI QSA, CISA, CISSP
Disclaimer Copyright Michael Chapple and Jane Drews, This work is the intellectual property of the authors. Permission is granted for this material.
Web Advisory Committee June 17,  Implementing E-commerce at UW  Current Status and Future Plans  PCI Data Security Standard  Questions.
Payment Card Industry Data Security Standard (PCI DSS) By Roni Argetsinger
PCI 3.0 Boot Camp Payment Card Industry Data Security Standards 3.0.
The ABC’s of PCI DSS Eric Beschinski Relationship Manager Utility Payment Conference Kay Limbaugh Specialist, Electronic Bills & Payments &
MasterCard Site Data Protection Program Program Alignment.
Trust Guard PCI Certification Service Technical White Paper Trust Guard provides PCI DSS Compliant Scans that exceed PCI requirements. What’s more, your.
PCI DSS Managed Service Solution October 18, 2011.
Protecting Your Credit Card Security Environment (PCI) September 26, 2012 Jacob Arthur, CPA, QSA, CEH Timothy Agee, CISA, CGEIT, QSA FDH Consulting Frasier,
The influence of PCI upon retail payment design and architectures Ian White QSA Head of UK&I and ME PCI Team September 4, 2013 Weekend Conference 7 & 8.
An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.
PCI requirements in business language What can happen with the cardholder data?
Date goes here PCI COMPLIANCE: What’s All the Fuss? Mark Banbury Vice President and CIO, Plan Canada.
DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program.
PCI DSS Readiness Presented By: Paul Grégoire, CISSP, QSA, PA-QSA
Payment Card PCI DSS Compliance SAQ-A Training Accounts Receivable Services, Controller’s Office 7/1/2012.
Presented by Bob Wesolowski James R. Rennert, CFRE President Dir. of Mission Advancement Caring Habits, Inc. Sisters of St. Joseph Briarcliff Manor, NY.
North Carolina Community College System IIPS Conference – Spring 2009 Jason Godfrey IT Security Manager (919)
Introduction To Plastic Card Industry (PCI) Data Security Standards (DSS) April 28,2012 Cathy Pettis, SVP ICUL Service Corporation.
Smart Payment Processing ™ Recur} Happen again. Persist. Return. Come back. Reappear. Come again.
PCI Compliance: The Gateway to Paradise PCI Compliance: The Gateway to Paradise.
Data Security and Payment Card Acceptance Presented by: Brian Ridder Senior Vice President First National September 10, 2009.
Payment Card PCI DSS Compliance SAQ-B Training Accounts Receivable Services, Controller’s Office 7/1/2012.
Jon Bonham, CISA, QSA Director, ERC
The Payment Card Industry Data Security Standard (PCI DSS) is a proprietary information security standard for organizations that handle branded credit.
PCI 3.1 Boot Camp Payment Card Industry Data Security Standards 3.1.
PCI COMPLIANCE & A/R AUTOMATION 101 Nodus Technologies, Inc.
Credit Card Compliance
MARTA’s Road to PCI Compliance
Wake Forest University
PCI DSS Improve the Security of Your Ecommerce Environment
Summary of Changes PCI DSS V. 3.1 to V. 3.2
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Payment card industry data security standards
PCI DSS modular approach for F2F EMV mature environments
2013 PCI:DSS Meeting OSU Business Affairs
Internet Payment.
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
PCI Compliance : Whys and wherefores
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
MARTA’s Road to PCI Compliance
Utility Payment Conference
PCI 3.1 Compliance Panel for CHECO
Presented by: Jeff Soukup
Presentation transcript:

Navigating the New SAQs (Helping the 99% validate PCI compliance)

Agenda Introduction Presenter Background The New Self-Assessment Questionnaires o New Categories o Selection Criteria o New Expectations o New Requirements The Biggest Impact o SAQ-EP o Implications Tenable Solutions Questions

Introduction 99% of merchants do not retain a QSA for PCI DSS compliance validation – they self assess Self-Assessment Questionnaires are the ticket Any guidance is provided by vendors (easy, simple) Overview of new SAQ options Highlighting the Changes How do you know which one to use? What other activities (like ASV scanning) are required?

Presenter Jeffrey Man PCI SME/Product Manager (former QSA) T: ext. 366 Straight Talk about PCI (Moderator):

Background 30+ years experience in Information Security o 13 years with the Department of Defense Certified Cryptanalyst Designed Cryptosystems and Cryptologic Aids Founding Member of Systems & Network Attack Center o 17 years in commercial Professional Services Penetration Testing Vulnerability Assessments Security Architecture o 10 years as a QSA Lead Assessor/Assessment Team Member Trusted Advisor

Self-Assessment Questionnaires PCI DSS Version 3

The New PCI DSS V3 SAQ Options SAQ VersionQualification Criteria SAQ A Merchants that entirely outsource their e-commerce websites (including the payment processing) and only paper copy of cardholder data is retained from mail/telephone orders; no electronic storage of cardholder data SAQ A-EP (NEW) Merchants with e-commerce websites that redirect the payment processing to a third party and the website is segmented from the rest of the corporate network; no electronic storage of cardholder data SAQ B Face-to-face merchants with only imprint machines (knuckle busters) or standalone, dial-out payment terminals; no electronic storage of cardholder data SAQ B-IP (NEW) Face-to-face merchants with only standalone payment terminals IP- connected to the payment processor; no electronic storage of cardholder data

The New SAQ Options - continued SAQ VersionQualification Criteria SAQ C Merchants with payment application systems connected to the Internet; no electronic storage of cardholder data SAQ C-VT Merchants with Web-based virtual payment terminals (not eCommerce though); no electronic storage of cardholder data SAQ D-Merchant (NEW) Every other merchant (if you don't fit in one of the previous categories - this is what you fill out) SAQ D-Service Provider (NEW) Service Providers stop here. Period. This is the one you fill out. (Don't bother filling out another version SAQ-P2PE-HW Hardware payment terminals using a PCI-approved P2PE solution Only (did I mention it needs to be a hardware solution) ; no electronic storage of cardholder data

Expected Testing (more than a checkbox)

Which SAQs Require ASV Scanning SAQ VersionASV Scanning Required SAQ-A: Card-not present; all cardholder functions outsourcedNO SAQ-A-EP: Partially outsourced e-commerce; payment processing by third party YES SAQ-B: Imprint or Stand-alone or dial-out terminalsNO SAQ-B-IP: Stand-alone, IP-connected PTS POI terminalsYES SAQ-C: Payment application systems connected to the InternetYES SAQ-C-VT: Web-based virtual payment terminalsNO SAQ-D (Merchant/Service Provider):YES SAQ-P2PE-HW: HW-based PCI-listed P2PE solutionNO

Validate Compliance with an ASV External Vulnerability Scanning o Must be performed by ASV o Quarterly Scan Reports that show “PASS” o Entire Internet presence – not just the ecommerce app or payment/checkout page Provide Attestation signed by an Officer of the company

New SAQ Categories Highlighting the SAQs with the biggest impact

The New SAQ D – Service Providers

Biggest Impact Merchants that have been completing SAQ A because they redirect the payment processing from their e-commerce site to a PCI compliant third party are now going to have to determine which of the new SAQs applies to them. The goal is to bring PCI DSS requirements to the e-commerce site that controls the redirection of the consumer to the payment processor.

E-commerce w/Payment Processor CONSUMER E-COMMERCE SITE SHOPPING CART CHECKOUT (REDIRECT) PAYMENT PROCESSOR CONSUMER BANK

SAQ A-EP Applicability SAQ A-EP has been developed to address requirements applicable to e-commerce merchants with a website(s) that does not itself receive cardholder data but which does affect the security of the payment transaction and/or the integrity of the page that accepts the consumer’s cardholder data. SAQ A-EP merchants are e-commerce merchants who partially outsource their e-commerce payment channel to PCI DSS validated third parties and do not electronically store, process, or transmit any cardholder data on their systems or premises

Leading Payment Gateways

SAQ A-EP Qualifications

Validating PCI DSS Compliance Tenable can help you validate PCI DSS

Tenable Solutions Nessus Vulnerability Scanner (Nessus) o Internal (CDE) vulnerability scanning solution o Configuration and compliance auditing (Credentialed) o Monitor and maintain numerous technical PCI controls Nessus Perimeter Service (PS) o ASV-certified External vulnerability scanning solution o Multi-Scanner feature allows management of all internal and external PCI scans Passive Vulnerability Scanner (PVS) o Identify/confirm data flows; maintain integrity of CDE o Detect unintentional/unknown data flows SecurityCenter Continuous View (SC CV) o Provides real-time compliance monitoring to maintain a compliant state. o Identifies problems with sustaining secure business processes Log Correlation Engine (LCE) o Centralized event logging, analysis, and correlation o File integrity monitoring capabilities

Have More Questions about PCI? Tenable hosts a PCI Discussion Forum where anyone can ask questions related to all aspects of PCI. If your question is a little too sensitive for a public forum, feel free to contact me directly. Jeff Man T: ext. 366 Straight Talk about PCI (Moderator):

Questions?