ISACA VA Chapter Is PCI Broken? Presented By: Bryan Miller Syrinx Technologies 804-539-9154.

Slides:



Advertisements
Similar presentations
Weighing the Risks and Benefits of Online Financial Transactions
Advertisements

Surviving the PCI Self -Assessment James Placer, CISSP West Michigan Cisco Users Group Leadership Board.
Payment Card Industry Data Security Standard AAFA ISC/SCLC Fall 08.
ISACA January 8, IT Auditor at Cintas Corporation Internal Audit Department Internal Security Assessor (ISA) Certification September 2010 Annual.
Evolving Challenges of PCI Compliance Charlie Wood, PCI QSA, CRISC, CISA Principal, The Bonadio Group January 10, 2014.
.. PCI Payment Card Industry Compliance October 2012 Presented By: Jason P. Rusch.
PCI DSS for Retail Industry
PCI Compliance: The Gateway to Paradise PCI Compliance: The Gateway to Paradise.
PCI-DSS Erin Benedictson Information Security Analyst AAA Oregon/Idaho.
Complying With Payment Card Industry Data Security Standards (PCI DSS)
2014 PCI DSS Meeting OSU Business Affairs Process Improvement Team (PIT) Robin Whitlock & Dan Hough 10/28/2014.
This refresher course will:
JEFF WILLIAMS INFORMATION SECURITY OFFICER CALIFORNIA STATE UNIVERSITY, SACRAMENTO Payment Card Industry Data Security Standard (PCI DSS) Compliance.
Information Security Jim Cusson, CISSP. Largest Breaches 110, NorthgateArinso, Verity Trustees 6, Aurora St. Luke's Medical.
Credit Card Compliance Regulations Mandated by the Payment Card Industry Standards Council Accounting and Financial Services.
© 2012 Presented by: Preparation For EMV Chip Technology Keith Swiat.
Presented by : Vivian Eberhardt, Supervisor Cash and Credit Operations
Data Security Standard. What Is PCI ? Who Does It Apply To ? Who Is Involved With the Compliance Process ? How We Can Stay Compliant ?
Visa Cemea Account Information Security (AIS) Programme
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Commonwealth of Massachusetts Office of the State Comptroller March 2007.
Around the World, Around the Corner WorldPay for Small Business.
Why Comply with PCI Security Standards?
Payment Card Industry (PCI) Data Security Standard
PCI's Changing Environment – “What You Need to Know & Why You Need To Know It.” Stephen Scott – PCI QSA, CISA, CISSP
Web Advisory Committee June 17,  Implementing E-commerce at UW  Current Status and Future Plans  PCI Data Security Standard  Questions.
What to Do if Compromised
Payment Card Industry Data Security Standard (PCI DSS) By Roni Argetsinger
MasterCard Site Data Protection Program Program Alignment.
An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.
NUAGA May 22,  IT Specialist, Utah Department of Technology Services (DTS)  Assigned to Department of Alcoholic Beverage Control  PCI Professional.
Teresa Macklin Information Security Officer 27 May, 2009 Campus-wide Information Security Activities.
The Payment Card Industry (PCI) Data Security Standard: What it is and why you might find it useful Fred Hopper, CISSP TASK - 27 March 2007.
PCI requirements in business language What can happen with the cardholder data?
DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program.
PCI DSS Readiness Presented By: Paul Grégoire, CISSP, QSA, PA-QSA
Case Study: Department of Revenue Data Breach National Association of State Auditors, Comptrollers and Treasurers March 21, 2013.
Introduction to Payment Card Industry Data Security Standard
Identity Protection (Red Flag/PCI Compliance/SSN Remediation) SACUBO Fall Workshop Savannah, GA November 3, 2009.
Introduction To Plastic Card Industry (PCI) Data Security Standards (DSS) April 28,2012 Cathy Pettis, SVP ICUL Service Corporation.
PCI Compliance: The Gateway to Paradise PCI Compliance: The Gateway to Paradise.
Data Security and Payment Card Acceptance Presented by: Brian Ridder Senior Vice President First National September 10, 2009.
ThankQ Solutions Pty Ltd Tech Forum 2013 PCI Compliance.
e-Learning Module Credit/Debit Payment Card Acceptance and Security
1 Payment Card Industry (PCI) Security Standard Developed by the PCI Security Council formed by major card issuers: Visa, MasterCard, American Express,
Langara College PCI Awareness Training
Visibility. Intelligence. response Information Security: Risk Management or Business Enablement? Mike Childs Vice President Rook Security.
BUSINESS CLARITY ™ PCI – The Pathway to Compliance.
Jon Bonham, CISA, QSA Director, ERC
What lessons can we learn from other data breaches? Target Sentry Insurance Dynacare Laboratories 1 INTRODUCTION.
Standards in Use. EMV June 16Caribbean Electronic Payments LLC2.
By: Matt Winkeler.  PCI – Payment Card Industry  DSS – Data Security Standard  PAN – Primary Account Number.
The Payment Card Industry Data Security Standard (PCI DSS) is a proprietary information security standard for organizations that handle branded credit.
WHAT NEW, WHAT NEXT IN PAYMENT PROCESSING. EMV WHAT IS EMV? 3  An acronym created by Europay ®, MasterCard ® and Visa ®  The global standard for the.
MARTA’s Road to PCI Compliance
Payment Card Industry (PCI) Rules and Standards
Payment Card Industry (PCI) Rules and Standards
Performing Risk Analysis and Testing: Outsource or In-house
PCI-DSS Security Awareness
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Payment card industry data security standards
Team 4 – Mack, Josh, Felicia, Kevin and Walter
Internet Payment.
Joe, Larry, Josh, Susan, Mary, & Ken
Information Security: Risk Management or Business Enablement?
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
PCI DSS Erin Carrick.
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
MARTA’s Road to PCI Compliance
Presented by: Jeff Soukup
Payment Card Industry Data Security Standards (PCI-DSS) Training
Presentation transcript:

ISACA VA Chapter Is PCI Broken? Presented By: Bryan Miller Syrinx Technologies

ISACA VA Chapter  Speaker Introduction  What is PCI  How Compliant Are We  What Happened to Target  The Aftermath  Lessons Learned  Summary 5/1/2014Is PCI Broken?2 Agenda

ISACA VA Chapter  B.S., M.S. – VCU  Former Adjunct Faculty VCU  CISSP, former Cisco CCIE  VA SCAN, ISSA, ISACA,VCU FTEMS speaker  Published author with 30 years in the industry  Founded Syrinx Technologies in /1/2014Is PCI Broken?3 Speaker Introduction

ISACA VA Chapter 5/1/2014Is PCI Broken?4 Does anybody ever feel like this? (Does anybody other than me even remember this movie?)

ISACA VA Chapter 5/1/2014Is PCI Broken?5 What Is PCI

ISACA VA Chapter  The Payment Card Industry Data Security Standard (PCI DSS) is a proprietary information security standard for organizations that handle cardholder information for the major debit, credit, prepaid, e- purse, ATM, and POS cards.  Defined by the Payment Card Industry Security Standards Council (PCI SSC), the standard was created to increase controls around cardholder data to reduce credit card fraud via its exposure.  Source: Wikipedia 5/1/2014Is PCI Broken?6 Definition

ISACA VA Chapter If you transmit, store or process credit card data you are responsible to protect it. So….what exactly is “credit card data”? 5/1/2014Is PCI Broken?7 OK, one more time in plain English

ISACA VA Chapter  What you can store  Primary Account Number (obfuscated)  Cardholder Name  Expiration Date  What you must NEVER store  Magnetic stripe data  CVV  PIN 5/1/2014Is PCI Broken?8

ISACA VA Chapter  12 Requirements summarized by 6 control objectives  Build and Maintain a Secure Network and Systems  Protect Cardholder Data  Maintain a Vulnerability Management Program  Implement Strong Access Control Measures  Regularly Monitor and Test Networks  Maintain an Information Security Policy 5/1/2014Is PCI Broken?9 What It Is

ISACA VA Chapter  Began life as the “VISA Digital Dozen”  Current version is 3.0, released November 2013  Sponsored by  American Express  VISA  MasterCard  Discover  Japan Credit Bureau (JCB) 5/1/2014Is PCI Broken?10 What It Is

ISACA VA Chapter  A legal compliance obligation like HIPAA, GLBA, Sarbanes- Oxley  A guarantee that you won’t  Have a data breach  Suffer financial or reputational damages  Be the featured guest in the newspapers and magazines  Remember SECURE <> COMPLIANT 5/1/2014Is PCI Broken?11 What It Isn’t

ISACA VA Chapter 5/1/2014Is PCI Broken?12 Source: Rapid7

ISACA VA Chapter 5/1/2014Is PCI Broken?13 How Compliant Are We

ISACA VA Chapter 5/1/2014Is PCI Broken?14 Source: VERIZON 2014 PCI COMPLIANCE REPORT

ISACA VA Chapter 5/1/2014Is PCI Broken?15 Source: VERIZON 2014 PCI COMPLIANCE REPORT

ISACA VA Chapter 5/1/2014Is PCI Broken?16 Source: VERIZON 2014 PCI COMPLIANCE REPORT

ISACA VA Chapter 5/1/2014Is PCI Broken?17 Source: VERIZON 2014 PCI COMPLIANCE REPORT

ISACA VA Chapter 5/1/2014Is PCI Broken?18 What Happened to Target

ISACA VA Chapter  Attack began with phishing attack on HVAC vendor  Attack began around 2 months before the actual breach  Malware from phishing allowed attackers to gain Target network credentials  Vendor claimed “…our IT system and security measures are in full compliance with industry practices.”  Vendor allegedly used free version of malware software 5/1/2014Is PCI Broken?19

ISACA VA Chapter  Using credentials obtained from HVAC, attackers expanded to internal Target networks  Unclear whether or not 2-factor authentication required by PCI was employed by HVAC vendor  Initial compromise between Nov. 27 – Dec. 15  Target announced breach December 19 5/1/2014Is PCI Broken?20

ISACA VA Chapter  What about warning signs?  Target allegedly warned two months before breach by internal security employees that its systems were not sufficiently secure (ignored?)  At the time Target was updating POS software  FireEye installed six months earlier  Security monitoring performed by a team in Bangalore  Reported findings November 30 (apparently ignored)  Malware updated December 2 5/1/2014Is PCI Broken?21

ISACA VA Chapter 5/1/2014Is PCI Broken?22

ISACA VA Chapter 5/1/2014Is PCI Broken?23 Supplier Portal Home Page – no credentials required

ISACA VA Chapter 5/1/2014Is PCI Broken?24 Facilities Management Home Page – no credentials required

ISACA VA Chapter 5/1/2014Is PCI Broken?25 Supplier Download Page – no credentials required

ISACA VA Chapter 5/1/2014Is PCI Broken?26 Metadata Obtained from Files Harvested from Downloads Page

ISACA VA Chapter 5/1/2014Is PCI Broken?27

ISACA VA Chapter 5/1/2014Is PCI Broken?28 The Aftermath

ISACA VA Chapter  January in-store and online traffic drops from 43% to 33% of US households  Target spent $61 million during Q4 related to breach  Estimated 5-10% will never shop there again  March 5 – Target replaces CIO and hires two additional positions  Chief Security Officer  Chief Compliance Officer 5/1/2014Is PCI Broken?29

ISACA VA Chapter  Lawsuits (at least 53) filed by multiple banks, including several in Target’s home state  Target’s PCI auditing firm Trustwave Holdings also named in lawsuits  Estimated losses could reach $18 billion  Estimated 110 million cardholders affected 5/1/2014Is PCI Broken?30

ISACA VA Chapter  Security engineer who first broke the story could soon be the subject of a Hollywood movie  Target accelerating plan to offer upgraded credit cards with chip technology  Current goal to release updated REDcards in early /1/2014Is PCI Broken?31

ISACA VA Chapter 5/1/2014Is PCI Broken?32 Lessons Learned

ISACA VA Chapter  Four Questions the CIO Must Answer  Do we have an ISO/CISO providing direction?  Do we have an incident response plan?  Which alerts can we safely ignore?  What are we overlooking as insignificant? 5/1/2014Is PCI Broken?33

ISACA VA Chapter  Steps Every Organization Can Take 1. Accept that you have a problem. 2. Diagram credit card data flows in, through and out. 3. Ensure you have a tested incident response plan. 4. Clean up the “low hanging fruit”. 5. Invest in and maintain quality monitoring systems. 6. Review contracts with vendors, partners, clients, etc. 7. Create build lists for all systems to ensure consistency. 8. Limit the systems in PCI scope. 9. Build security audits into every project. 10. Provide feedback to all departments on progress. 5/1/2014Is PCI Broken?34

ISACA VA Chapter 5/1/2014Is PCI Broken?35 Summary

ISACA VA Chapter  PCI compliance (and security in general) should not be ignored or seen as just another business expense.  Start building monitoring systems and trust them when they report incidents.  Continue practicing due diligence. Security is a never ending issue. 5/1/2014Is PCI Broken?36

ISACA VA Chapter 5/1/2014Is PCI Broken?37 Q&A