Protecting Your Customers’ Card Data ASTRA Presentation 05.14.2013 Brian Chapman and Peter O’Rourke.

Slides:



Advertisements
Similar presentations
October 28, Who? What? When? Why? Comply with PCI compliance policies set forth by industry Create internal policies and procedures to protect.
Advertisements

National Bank of Dominica Ltd Merchant Seminar Facilitator: Janiere Frank Fraud & Compliance Analyst June 16, 2011.
WHAT IS EMV? A joint effort between Europay, MasterCard and Visa It is a security framework that defines the payment interaction at the physical, electrical,
Mobile Payment Security The Good, the Bad and the Ugly
PCI DSS for Retail Industry
Complying With Payment Card Industry Data Security Standards (PCI DSS)
ETA UNIVERSITY MARCH 19, 2015 Deana Rich R ICH C ONSULTING, I NC. Edward A. Marshall A RNALL G OLDEN G REGORY LLP Payments 101: Overview of the Payments.
1 U.S. EMV Migration Update and Best Practices Hap Huynh, Senior Director Risk Products April 2015.
University of Utah Financial and Business Services
Smart Payment Processing ™ Protecting Your Business from Card Data Theft Presenter: Lucas Zaichkowsky.
Credit Card Compliance Regulations Mandated by the Payment Card Industry Standards Council Accounting and Financial Services.
© 2012 Presented by: Preparation For EMV Chip Technology Keith Swiat.
Presented by : Vivian Eberhardt, Supervisor Cash and Credit Operations
PCI Compliance Forrest Walsh Director, Information Technology California Chamber of Commerce.
Visa Cemea Account Information Security (AIS) Programme
Credit Card Changes that Impact You! Changes to Accounts Receivable, Cash Receipts and Student Billing 7.77 Wanda Mahon & Bucky Wall Corporate Readiness.
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Commonwealth of Massachusetts Office of the State Comptroller March 2007.
GPUG ® Summit 2011 November 8-11 Caesars Palace – Las Vegas, NV Payment Processing Online and Within Dynamics GP PCI Compliance and Secure Payment Processing.
Geneva, Switzerland, 4 December 2014 Evolving Payments into The Digital World Richard Smith, Vice President, MasterCard Customer Fraud Management
Why Comply with PCI Security Standards?
Northern KY University Merchant Training
PCI and how it affects College Stores… ROBIN MAYO | PCIP ECOMMERCE MANAGER EAST CAROLINA UNIVERISTY.
Emerging Technologies
PCI's Changing Environment – “What You Need to Know & Why You Need To Know It.” Stephen Scott – PCI QSA, CISA, CISSP
Travillon Consultants
Payments technology and security
Payment Card Industry Data Security Standard (PCI DSS) By Roni Argetsinger
MasterCard Site Data Protection Program Program Alignment.
Card Brand Mandates. Key EMV dates from Card Brands © 2012 VeriFone Systems, Inc.  2012: TECH Innovation Program (TIP) - PCI validation relief for Level.
Universal Transaction Gateway® (UTG®), 4Go®, and i4Go® are covered by one or more of the following U.S. Pat. Nos.: , ,
An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.
The Payment Card Industry (PCI) Data Security Standard: What it is and why you might find it useful Fred Hopper, CISSP TASK - 27 March 2007.
DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program.
R U Ready? V M E EUROPAY MASTERCARD VISA EMVco was formed in 1999.
EMV – The New Landscape 21 Days & 12 Hours
Confidential – For Discussion & General Information Purposes Only EMV to Card Not Present Fraud Gavin Levin, CTP eReceivables Consultant.
Introduction To Plastic Card Industry (PCI) Data Security Standards (DSS) April 28,2012 Cathy Pettis, SVP ICUL Service Corporation.
Walter Conway, QSA 403 Labs, LLC Sneak Preview: What to Expect from PCI DSS v. 2.0  Changes  Clarifications  Guidance.
Agenda EMV – What Is It? EMV In The UK EMV Is Coming To The US
VirtualMerchant Secure Hosted Software Solution. Introducing VirtualMerchant  Complete hosted payment solution that instantly transforms PCs into “virtual”
The next generation of payments is here. Is your business ready?
Getnationwide.com Let’s Talk about EMV Danielle Rourke.
PCI Compliance: The Gateway to Paradise PCI Compliance: The Gateway to Paradise.
TransArmorSM A Secure Transaction ManagementSM Solution
What you need to know about PCI-DSS Jane Drews Chief Information Security Officer Information Security & Policy Office
ThankQ Solutions Pty Ltd Tech Forum 2013 PCI Compliance.
e-Learning Module Credit/Debit Payment Card Acceptance and Security
1 Payment Card Industry (PCI) Security Standard Developed by the PCI Security Council formed by major card issuers: Visa, MasterCard, American Express,
EMV: transforming the payment experience
EMV: What is it and how will it impact your business.
Jon Bonham, CISA, QSA Director, ERC
Fall  Comply with PCI compliance policies set forth by industry  Create internal policies and procedures to protect cardholder data  Inform and.
Standards in Use. EMV June 16Caribbean Electronic Payments LLC2.
By: Matt Winkeler.  PCI – Payment Card Industry  DSS – Data Security Standard  PAN – Primary Account Number.
Confidential and Proprietary - NOT TO BE DISTRIBUTED WITHOUT THE EXPRESS WRITTEN PERMISSION OF BANK OF AMERICA MERCHANT SERVICES. ASTRA EMV Review/Best.
Copyright 2009, First Data Corporation. All Rights Reserved. How Does TransArmor SM Work at the POS? SafeProxy Merchant Anti FraudAnalytics First Data.
WHAT NEW, WHAT NEXT IN PAYMENT PROCESSING. EMV WHAT IS EMV? 3  An acronym created by Europay ®, MasterCard ® and Visa ®  The global standard for the.
PCI COMPLIANCE & A/R AUTOMATION 101 Nodus Technologies, Inc.
EMV.
Make This Document Your Own
PCI-DSS Security Awareness
Decrypting Tokenization What is it and why is it important?
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Payment card industry data security standards
CONFERENCE OF WESTERN ATTORNEYS GENERAL
Internet Payment.
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
New Jersey Gasoline C-Store Automotive Association
Increasing approval rates in the digital world
Presentation transcript:

Protecting Your Customers’ Card Data ASTRA Presentation Brian Chapman and Peter O’Rourke

Data Compromises In the News Bank of America Merchant Services 2

Common Causes of a Breach or Compromise Trivial and common passwords for POS systems Not changing the vendor-supplied password upon installation Outdated antivirus software definitions Use of vulnerable or non-compliant software Remote access to systems by third-party providers Having remote access turned on at all times Bank of America Merchant Services 3

What is PCI? PCI stands for the Payment Card Industry and is used to refer to: The PCI Security Standards Council ™(PCI SSC), an industry body founded by the major card brands to protect cardholder data. Founders: The global Security Standards created and maintained by the PCI SSC to protect cardholder payment data. Important: Compliance with PCI Security Standards is mandatory for merchants and their service providers, and is enforced by the major card brands that established the PCI SSC. Bank of America Merchant Services 4

Determining Your PCI Level and Validation Requirements Bank of America Merchant Services 5

A Closer Look at the PCI DSS–Requirements All card-accepting merchants must comply with all applicable requirements, below. Important: Not all PCI DSS requirements apply to all merchants. Merchants must review each requirement to determine applicability to the merchant’s card payment acceptance systems and business processes. Bank of America Merchant Services 6

PCI Level 4 Support Program Bank of America Merchant Services 23

PCI Level 4 Support Program cont… Bank of America Merchant Services 8

Enhancing Data Security and Reducing Your PCI Scope Point-to-Point Encryption (P2PE) Encryption is designed to protect cardholder data from the point of data entry. Uses a key management feature making cardholder data unreadable to anyone that does not have the encryption key. Protects Cardholder Data in Transit If properly implemented, P2PE can reduce your scope of PCI DSS validation. Tokenization Technology Replaces cardholder data (PAN) with surrogate values (Token) Designed to work in concert with encryption to eliminate storage of cardholder data Allows merchant to limit the storage of cardholder data with the tokenization system If properly implemented, tokenization can reduce your scope of PCI DSS validation EMV Chip Technology Protects against counterfeit cards by replacing static data with dynamic Works with card-present transaction only Requires a dual processing terminal (mag stripe and chip) 9

PCI Reference Websites PCI Security Standards Council: PCI Mobile PA-DSS FAQs: Point 2 Point Encryption: PCI DSS Tokenization Guidelines: Approved Scanning Vendors and Qualified Security Assessors: Validated List of Payment Applications: List of PCI SSC Approved PIN Transaction Security Devices: Navigating the PCI DSS: Visa CISP: MasterCard SDP: Discover DISC: American Express DSOP: o&ln=en&frm=US o&ln=en&frm=US Bank of America Merchant Services 10

Protecting Cardholder Data: The TransArmor ® Solution

Introducing the TransArmor Solution –TransArmor is an easy-to-implement service that helps protects merchants and card data using a multi-level defense: Combines encryption and tokenization to protect data at every processing stage o Depending on version, uses technology from RSA, the global leader in IT security, or combined technology from RSA and VeriFone Removes payment card information from the merchant by replacing the Permanent Account Number (PAN) with a card-based “token” o Maintains all the merchant’s business benefits of storing the payment card data without the associated risk Delivered as part of the payment processing service Bank of America Merchant Services 12

How Does It Work? E-Commerce Call Center Petroleum Payment System POS & Backoffice Card Present Card Not Present Encrypted Card Data Token Card Vault MerchantBank of America Merchant Services Processing Bank of America Merchant Services 13

Tokens protect data at rest and in use. –Form of data substitution replacing sensitive PAN values with non- sensitive, randomly-generated token values –Differ from encryption: tokens have no direct relationship with the data they replace –Match the format of the initiating PAN – if PAN is 16 digits, token is 16 digits Do not overlap major brand (Visa, MC, AMEX, Discover) BIN ranges (first digit is 0-2 or 7-9) Do not pass MOD-10 or Luhn checks –Card-based, meaning they have a 1:1 relationship with an account number - same token will always be returned for a specific PAN Do not expire - same token follows the card through the entire card lifecycle What Is Tokenization? Bank of America Merchant Services 14

What Makes TransArmor Different? Important Points of DifferentiationTransArmor Combines end-to-end encryption and tokenization, rather than relying solely on encryption alone (which protects data only while in transit but not when in use or at rest) Minimizes IT resource allocation to implement and typically involves little-to-no new hardware in most cases, changes to back-end IT systems, or employee training Completely removes sensitive data from the environment, thus reducing the scope of PCI compliance. (Encryption and in-house tokenization solution cannot remove the data from the merchant environment) Flexibility to choose a software- or hardware-based model makes it easier to integrate—no new hardware or software is required, it is scalable as compliance rules change, and it is not a bolt-on product that requires a third- party vendor to touch the payment process ✔ ✔ ✔ ✔ Bank of America Merchant Services 15

EMV Cards

Bank of America Merchant Services 17 EMV –EMVCo (Europay®, MasterCard® and Visa ®) is an organization that was formed to manage, maintain and enhance chip specifications for payment, ensuring interoperability globally. –EMVCo.com is the public portal for all things EMV. –EMV cards, also known as chip-based cards, contain an embedded microprocessor. The microprocessor chip carries the business rules and authentication needed by the card for payment, and is protected by various security features to make it tamper-resistant. –Chip technology greatly reduces a criminal's ability to create counterfeit cards by introducing dynamic values for each transaction.

18Bank of America Merchant Services Card Brand Adaption and Timeline VISA October 2012 MasterCard Discover (Diners Club and PULSE) –Tech Innovation Program (TIP) –Introduction of MasterCard PCI DSS Compliance Validation Exemption Program –Discover Authorization Interface-Partial Chip Card transaction indicator introduced –Discover expands EMV program to include Contactless April 2013 –Potential Reduction of Calculated Account Data Compromise Operational Reimbursement and Fraud Recovery –U.S. Region acquirers must be capable of processing MasterCard contact and contactless chip transactions –Acquirer & Direct Connect Merchant Support for Discover’s EMV-compliant payment specification (D- PAS) October 2015–Liability Shift for credit and debit domestic and cross border transactions –Chip and Chip / PIN liability shift participation –Additional Potential Reduction of Calculated Account Data Compromise Operational Reimbursement and Fraud Recovery October 2017–Liability Shift for automated fuel dispensers –Chip and Chip / PIN Liability shift for automated fuel dispensers October 2013 –U.S. Acquirer Processors to support chip processing Acquirer Mandates American Express –U.S. Processors must be able to support American Express EMV chip-based contact, contactless and mobile transactions. –PCI Data Security Relief –Liability Shift –Liability Shift for automated fuel dispensers –Liability Shift –Liability Shift for automated fuel dispensers

Q & A—We’re standing by to answer your questions.