KioskCom 2008 Fast Transact, Inc | 2590 Willamette Dr NE, 2nd Floor | Lacey WA 98516 | 800.687.8505 / fax 360.357.1425 Fast Transact, Inc. is a registered.

Slides:



Advertisements
Similar presentations
Surviving the PCI Self -Assessment James Placer, CISSP West Michigan Cisco Users Group Leadership Board.
Advertisements

Payment Card Industry Data Security Standard AAFA ISC/SCLC Fall 08.
ISACA January 8, IT Auditor at Cintas Corporation Internal Audit Department Internal Security Assessor (ISA) Certification September 2010 Annual.
National Bank of Dominica Ltd Merchant Seminar Facilitator: Janiere Frank Fraud & Compliance Analyst June 16, 2011.
Evolving Challenges of PCI Compliance Charlie Wood, PCI QSA, CRISC, CISA Principal, The Bonadio Group January 10, 2014.
.. PCI Payment Card Industry Compliance October 2012 Presented By: Jason P. Rusch.
Mobile Payment Security The Good, the Bad and the Ugly
PCI DSS for Retail Industry
PCI-DSS Erin Benedictson Information Security Analyst AAA Oregon/Idaho.
Complying With Payment Card Industry Data Security Standards (PCI DSS)
ETA UNIVERSITY MARCH 19, 2015 Deana Rich R ICH C ONSULTING, I NC. Edward A. Marshall A RNALL G OLDEN G REGORY LLP Payments 101: Overview of the Payments.
JEFF WILLIAMS INFORMATION SECURITY OFFICER CALIFORNIA STATE UNIVERSITY, SACRAMENTO Payment Card Industry Data Security Standard (PCI DSS) Compliance.
University of Utah Financial and Business Services
Smart Payment Processing ™ Protecting Your Business from Card Data Theft Presenter: Lucas Zaichkowsky.
1 Credit card operation and the recent CardSystems incident HONG KONG MONETARY AUTHORITY 4 July 2005.
Credit Card Compliance Regulations Mandated by the Payment Card Industry Standards Council Accounting and Financial Services.
Payment Card PCI DSS Compliance SAQ-D Training Accounts Receivable Services, Controller’s Office 7/1/2012.
© Vendor Safe Technologies 2008 B REACHES BY M ERCHANT T YPE 70% 1% 9% 20% Data provided by Visa Approved QIRA November 2008 from 475 Forensic Audits.
Presented by : Vivian Eberhardt, Supervisor Cash and Credit Operations
Visa Europe Implementing PCI DSS Requirements Within Your Organisation September 2008 Simon Breeden.
PCI Compliance Forrest Walsh Director, Information Technology California Chamber of Commerce.
Data Security Standard. What Is PCI ? Who Does It Apply To ? Who Is Involved With the Compliance Process ? How We Can Stay Compliant ?
Visa Cemea Account Information Security (AIS) Programme
Beta Program for The Raiser’s Edge 7.86 PA DSS version Anne McDonell & Bucky Wall Corporate Readiness.
Credit Card Changes that Impact You! Changes to Accounts Receivable, Cash Receipts and Student Billing 7.77 Wanda Mahon & Bucky Wall Corporate Readiness.
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Commonwealth of Massachusetts Office of the State Comptroller March 2007.
Around the World, Around the Corner WorldPay for Small Business.
Why Comply with PCI Security Standards?
Northern KY University Merchant Training
Payment Card Industry (PCI) Data Security Standards (DSS) Fundamentals
PCI's Changing Environment – “What You Need to Know & Why You Need To Know It.” Stephen Scott – PCI QSA, CISA, CISSP
Disclaimer Copyright Michael Chapple and Jane Drews, This work is the intellectual property of the authors. Permission is granted for this material.
Web Advisory Committee June 17,  Implementing E-commerce at UW  Current Status and Future Plans  PCI Data Security Standard  Questions.
PCI DSS The Payment Card Industry (PCI) Data Security Standard (DSS) was developed by the PCI Security Standards Council to encourage and enhance cardholder.
MasterCard Site Data Protection Program Program Alignment.
An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.
Visa Europe Confidential PCI DSS Protecting your business Lara Fiorani, Visa Europe Basel 25 April, 2006.
PCI requirements in business language What can happen with the cardholder data?
Date goes here PCI COMPLIANCE: What’s All the Fuss? Mark Banbury Vice President and CIO, Plan Canada.
DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program.
PCI DSS Readiness Presented By: Paul Grégoire, CISSP, QSA, PA-QSA
Payment Card PCI DSS Compliance SAQ-A Training Accounts Receivable Services, Controller’s Office 7/1/2012.
Presented by Bob Wesolowski James R. Rennert, CFRE President Dir. of Mission Advancement Caring Habits, Inc. Sisters of St. Joseph Briarcliff Manor, NY.
Identity Protection (Red Flag/PCI Compliance/SSN Remediation) SACUBO Fall Workshop Savannah, GA November 3, 2009.
Smart Payment Processing ™ Recur} Happen again. Persist. Return. Come back. Reappear. Come again.
PCI Compliance: The Gateway to Paradise PCI Compliance: The Gateway to Paradise.
Data Security and Payment Card Acceptance Presented by: Brian Ridder Senior Vice President First National September 10, 2009.
Payment Card PCI DSS Compliance SAQ-B Training Accounts Receivable Services, Controller’s Office 7/1/2012.
ThankQ Solutions Pty Ltd Tech Forum 2013 PCI Compliance.
VeriShield Protect Revolutionary technology that simplifies PCI DSS compliance with no system upgrades Now available on V x Solutions!
BUSINESS CLARITY ™ PCI – The Pathway to Compliance.
Standards in Use. EMV June 16Caribbean Electronic Payments LLC2.
MARTA’s Road to PCI Compliance
Payment Card Industry (PCI) Rules and Standards
Burton Group Take 5! The PCI Half-Dozen: 6 Recommendations for PCI Compliance Diana Kelley, VP & Service Director March,
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Payment card industry data security standards
Regulatory Compliance
Internet Payment.
MIS 5121: Real World Control Failure - TJX
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Data Compliance.
PCI Compliance : Whys and wherefores
PCI DSS Erin Carrick.
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
MARTA’s Road to PCI Compliance
Utility Payment Conference
Online Payment Options for Government
Presentation transcript:

KioskCom 2008 Fast Transact, Inc | 2590 Willamette Dr NE, 2nd Floor | Lacey WA | / fax Fast Transact, Inc. is a registered ISO/MSP for Bank of America, N.A. Charlotte, N.C. and Wells Fargo Bank, N.A. Walnut Creek, C.A. PCI Compliance Protecting Consumer Data

KioskCom 2008 A Brief History PCI Compliance

KioskCom 2008 PCI = The Payment Card Industry Comprised of the 5 major payment-card brands:  Visa International  MasterCard Worldwide  American Express  Discover Financial Services  JBC

KioskCom 2008 In 2005, they formed the PCI Security Standards Council Main Objectives:  Creation, ownership, and management of the PCI DSS (Data Security Standard)  Classify audit requirements to certify compliance  Provide a certification process for compliance assessors and network scanning vendors

KioskCom 2008 The PCI DSS comprises a common set of industry tools and measurements designed to ensure the safe handling of sensitive consumer information.  In January of 2007, Visa introduced its Payment Application Best Practices (Visa PABP).  This broadened the scope of PCI DSS compliance to include any third-party payment application.  Third-party payment applications include payment gateways and ANY third-party software that store, processes or transmits credit/debit card data.

KioskCom 2008 According to an October 23, 2007 Visa Bulletin, the PCI Security Standards Council has adopted Visa’s PABP program and will be releasing the standard as the Payment Application Data Security Standard during 2008.

KioskCom 2008 Q: Where does my company fit into the PCI DSS? Unlike other regulatory programs, compliance with the PCI DSS relies on the merchant to perform a self-assessment to determine if they are compliant. Merchant Level Description 1 Any merchant – regardless of acceptance channel – processing over 6,000,000 Visa transactions per year. Any merchant that Visa, at it sole discretion, determines should meet the Level 1 merchant requirements to minimize risk to the Visa system. 2 Any merchant – regardless of acceptance channel – processing 1,000,000 to 6,000,000 Visa transactions per year. 3 Any merchant processing 20,000 to 1,000,000 Visa e-commerce transactions per year. 4 Any merchant processing fewer than 20,000 Visa e-commerce transactions per year, and all other merchants – regardless of acceptance channel – processing up to 1,000,000 Visa transactions per year.

KioskCom 2008 Compliance Requirements by Merchant Level Level Validation Action Description 1  Annual On-site PCI Data Security Assessment  Quarterly Network Scan  Qualified Security Assessor or Internal Audit if signed by Officer of the company  Approved Scanning Vendor 2  Annual PCI Self-Assessment Questionnaire  Quarterly Network Scan  Merchant  Approved Scanning Vendor 3  Same as Level 2 4  Annual PCI Self-Assessment Questionnaire  Quarterly Network Scan  Merchant  Approved Scanning Vendor

KioskCom 2008 Compliance Time Line Compliance Time Line PCI DSS 1.1 sets an enforcement date for acquirers to validate PCI compliance for Level 1 and Level 2 merchants. The enforcement dates are as follows:  LEVEL 1 MERCHANTS: September 30, 2007  New LEVEL 1 MERCHANTS: 1 year after identification as Level 1  LEVEL 2 MERCHANTS: December 31, 2007  New LEVEL 2 MERCHANTS: September 20, 2007  LEVEL 1 and LEVEL 2 MERCHANTS: Prohibited Data Retention Attestation form, or Confirmation of Report Accuracy to acquirer by March 31, 2007  LEVEL 3 MERCHANTS: contact acquirer  LEVEL 4 MERCHANTS: Must have compliance plan submitted, via acquirer, to Visa by July 30, 2007

KioskCom 2008 Q: I use third-party software that has transaction processing imbedded. How do I ensure my software is compliant with the most up-to-date PABP and PA DSS requirements?

KioskCom 2008 The full list of PABP validated payment applications can be found at: Visa.com – PABA Validated List Visa.com – PABA Validated List  An annual validation is required for those payment applications with major upgrade or product version changes.  If there are no changes to the product, Visa will require a letter signed by an Officer of the software company indicating no changes to the payment application and continued adherence to the Payment Application Best Practices.

KioskCom 2008 Not only have the PCI DSS deadlines come and gone, new mandates have gone into effect to enforce payment applications to adhere to the PABP. As of January 1, 2008, acquirers must not board new merchants that use known vulnerable payment applications. By October 1, 2008 ALL merchant levels MUST be PCI DSS compliant OR use a PABP-compliant application.

KioskCom 2008 The Impact of Non-compliance

KioskCom 2008 Q: “I am non-compliant... so what! What can happen to me?”  Level 1 and 2 merchant can be charged $5k to $25k PER MONTH of non-compliance status.  If a security breach is not reported to Visa in a timely manner, a $100k – 500k fine can be levied.  If a full card number is stored OR provided on a customer receipt the merchant can be fined $100 - $1,000 PER TRANSACTION.

KioskCom 2008 It’s generally believed that these fines are never imposed, that they exist to “scare” merchants. In 2006, Visa levied $4.6 million in fines, up from a 2005 total of $3.4 million, to its acquirers. $$$ WRONG $$$

KioskCom 2008 Have you ever heard of TJ Maxx or Marshalls? December 2007, TJX (parent company of TJ Maxx, Marshall’s and other discount retailers) alerted Law Enforcement that more than 45 million consumer records were stolen by data thieves. Since then, they have spent more than $20m on investigation, consumer notification, and an expert legal team to protect them against the multitude of lawsuits the breach generated.

KioskCom 2008 March 27, 2008:  The FTC ruled that TJX was in violation of the “FTC Act of 1914,” by failing to employ reasonable measures to protect the sensitive consumer information on its networks.  The March 2008 ruling will help acquirers and other transaction processors become less liable for breaches caused by poor security on the part of their merchant or sales organization.

KioskCom 2008 As reported by InformationWeek.com, in-store computer kiosks are partly to blame.  The kiosks allowed individuals to apply for jobs electronically; however, the kiosks were not protected by a firewall and therefore acted as a gateway into the company’s IT systems.  Even though the kiosks were NOT performing transactions, they provided a way for data thieves to get to credit card information through unsecured USB ports.

KioskCom 2008 Historically, acquirers are responsible for any fines incurred due to non-PCI DSS compliant merchants.  August 1, 2008: The Plastic Card Security Act of Minnesota takes effect.  This legislation marks the first time that the cost associated with data breaches has shifted from the financial institutions to the retailers that mishandle consumer financial data.

KioskCom 2008 PCI “Lessons”

KioskCom 2008 Important lessons regarding PCI DSS and PABP:  Look for weak links within your organization’s network. If you don’t find them someone else will.  Fines are real. They can and will be levied against those not complying with the PCI Security Standards. and most importantly... customer data cannot be stolen if merchants are not retaining it!

KioskCom 2008 FTI PROGRAM CONTACTS: Terry RobertsAdriane Armbruster Director of Software IntegrationSenior Account Executive  ext. 126  ext. 106 FTI POST-SALE CONTACTS: Fast Transact, Inc 2590 Willamette Dr NE, 2 nd Floor Lacey WA Phone: Toll Free: Fax: Customer Service Monday - Friday 6 am - 11 pm (PST) Phone: Toll Free: Technical Support Monday - Friday 6 am - 11pm (PST) Phone: Toll Free: Contact List

KioskCom 2008 Bibliography  Greenemeir, Larry. “The TJX Effect.” Information Week. 11 Apr Information Week. 8 Nov  “FTC Files Settlement Agreement with TJX.” TheGreenSheet.com. 28 Mar Apr  Visa Announces New Payment Application Security Mandates. VISA International. VISA International,  Wollenhaupt, Gary. “PCI Standards Weight Heavy on ATMs, Kiosks.” Self Service World. 4 Jun Irvington Writers Studio. 8 Nov  Payment Card Industry (PCI) Data Security Standard. PCI Security Standards Council. Wakefield, MA: PCI Security Standards Council,  “Fine Data.” PCI Compliance Guide. 3 Apr  “Cardholder Information Security Program.” Visa International. 3 Apr