2010 User Conference April 23 rd – 25 th, Philadelphia, PA PCI Compliance & Security Presented By: Kevin Smith & Mark Setzer Stone Edge Technologies, Inc. April 24, :30 AM – 12:00 PM
2010 User Conference April 23 rd – 25 th, Philadelphia, PA PCI PA-DSS Compliance The Stone Edge Order Manager Payment System Presented By: Kevin Smith Senior Developer, Stone Edge Technologies, Inc. April 24, :30 AM – 12:00 PM
2010 User Conference April 23 rd – 25 th, Philadelphia, PA PA-DSS? Payment Application – Data Security Standards Created & Enforced by PCI Maintained by PCI Security Standards Council Liability Concerns as a Merchant Impacts Applications Storing Cardholder Data Certification Needed for Gateway Access Deadlines!
2010 User Conference April 23 rd – 25 th, Philadelphia, PA Dilemma! Is the Order Manager Certifiable? –Security Concerns –Time & Cost of Certification –Versioning Considerations Questions –To Store or Not To Store –Long Term Issues and Liabilities –Third Party Integration Concerns
2010 User Conference April 23 rd – 25 th, Philadelphia, PA Management Decision New Payment System –Simplicity (KISS – OOPS!) –Limited Versioning –Data Isolation –Encryption Concerns –Code Centralization –Formalized Process Flow –Streamline Processor Integrations –Achieve Certification
2010 User Conference April 23 rd – 25 th, Philadelphia, PA Order Manager Import MOP View Orders Manual Orders POS Order Approval Pack & Ship DataActionRules Format Data & Choose Processor CC Proc PaymentResult Gateway Code CC Proc CC Proc CC Proc CC Proc CC Proc User Interface and/or Code DataActionRules PaymentResult DataActionRules PaymentResult DataActionRules PaymentResult DataActionRules PaymentResult DataActionRules PaymentResult DataActionRules PaymentResult
2010 User Conference April 23 rd – 25 th, Philadelphia, PA Order Manager Import MOP View Orders Manual Orders POS Order Approval Pack & Ship Payment Management System CC Proc CC Proc CC Proc CC Proc CC Proc CC Proc Order Object Payment UI Payment Request Payment Response Payment Processor Interface Data Collection, Action, Rules Result Analysis, Record Payment, Processor Code RESULT Payment Request
2010 User Conference April 23 rd – 25 th, Philadelphia, PA Impact On Your Operations No Permanent Card Data Storage Less Liability Repeat Customers –Card Data Tokenization –Gateway Customer Management Systems –Payment Data From Website Partial Shipments & Subscriptions A Few Extra Clicks New Interface
2010 User Conference April 23 rd – 25 th, Philadelphia, PA Added Features Multiple Capture & Voice Auth Capture Blind Credit Support Additional Gateways Gift Card Support* PIN Pad Support Check Reader Support Encrypted Card Swipe Support Improved USB System
2010 User Conference April 23 rd – 25 th, Philadelphia, PA Credit Card Interface
2010 User Conference April 23 rd – 25 th, Philadelphia, PA eCheck Interface
2010 User Conference April 23 rd – 25 th, Philadelphia, PA Other Payments
2010 User Conference April 23 rd – 25 th, Philadelphia, PA Existing Transactions
2010 User Conference April 23 rd – 25 th, Philadelphia, PA Questions?
2010 User Conference April 23 rd – 25 th, Philadelphia, PA Security Presented By: Mark Setzer Senior Developer, Stone Edge Technologies, Inc. April 24, :30 AM – 12:00 PM
2010 User Conference April 23 rd – 25 th, Philadelphia, PA Types of Security Physical –Physical access means game over from a security standpoint Network –Assume attacks are inevitable –Who needs access? To what? Application –Microsoft Access, Order Manager, Microsoft SQL Server
2010 User Conference April 23 rd – 25 th, Philadelphia, PA Order Manager Security Intended for basic reporting, logging, task assignment Not “hard” security
2010 User Conference April 23 rd – 25 th, Philadelphia, PA Network Security Hardware location –Firewall rules Server administration –Shared folders –Active Directory –Needed services –Windows Updates
2010 User Conference April 23 rd – 25 th, Philadelphia, PA Application Security Microsoft Access SQL Server –Careful about “role” access –Difficult to provide “basic” access w/o allowing destructive behavior as well
2010 User Conference April 23 rd – 25 th, Philadelphia, PA Questions?