• No results found

PCI Security Standards Council

N/A
N/A
Protected

Academic year: 2021

Share "PCI Security Standards Council"

Copied!
53
0
0

Loading.... (view fulltext now)

Full text

(1)

PCI Security Standards Council

(2)

How You Can

Participate

Applying PCI

(3)

Agenda

Why PCI

(4)

About the PCI Council

Open, global forum

Founded 2006

Guiding open standards for payment card security

Development

Management

Education

(5)

PCI: Architecture for Payment Card Security

5 major card brands

drive efforts for

(6)
(7)

Your Card Data is a Gold Mine for Criminals

Types of Data on a Payment Card

Chip Pan

Expiration Date Magnetic Strip

(data on tracks 1 & 2)

CAV2/CID/CVC2/CW2

(Discover, JCB, MasterCard, Visa)

CID

(American Express)

(8)

Manufacturers

PCI PTS

Pin Entry Devices

Ecosystem of payment devices, applications, infrastructure and users

Software Developers

PCI PA-DSS

Payment Applications

PCI Security

& Compliance

P2PE

Merchants & Service Providers

PCI DSS

Secure Environments

PCI Security Standards Suite

(9)

EMV Helps Reduce Face-to-Face Fraud

Countries that have implemented EMV have reported a decrease in card fraud. According to the UK Cards

Association, “Fraud on lost and stolen cards is now at its lowest

level for two decades and counterfeit card fraud losses have also fallen and are at their

lowest level since 1999.*”

*Smart Card Alliance EMV FAQ

EMV by itself does not

protect the confidentiality

of, or inappropriate access

to sensitive authentication

data and/or cardholder data

in card-not-present or

Internet transactions

(10)
(11)

Business Sectors With the Most Breaches

Retail

45%

Food & Beverage

24%

Hospitality

9%

Financial Services 7% Nonprofit 3% Health & Beauty

2%

High Technology 2%

Other

8%

(12)

Organisations Ignored PCI … and Were Breached

96% of those breached were not PCI

compliant as of their last assessment

(or were never assessed/validated)

Top attack methods used to breach

organizations:

81% of incidents involved hacking

69% incorporated malware

(13)

Top Mistakes By Those Breached

Revealed by Forensic Audits

• Weak Passwords

• Lack of employee education

• Security deficiencies introduced by third

parties responsible for system support,

development and/or maintenance

(14)

Why we fail to maintain secure environments

Lack of awareness by IT practitioners

Incentive to keep security a primary focus

Quickly evolving technology landscape

Rapid development and distribution of

new solutions

Still unnecessary exposure of CHD

(15)

PCI Standards Help Secure Your Data

92%

97%

92% of

compromises were

simple

97% were avoidable through

simple or intermediate

controls

(16)

The PCI Data Security Standard

Six Goals

Twelve Requirements

Build and Maintain a Secure Network

1. Install and maintain a firewall configuration to protect cardholder data

2. Do not use vendor-supplied defaults for system passwords and other security parameters

Protect Cardholder Data

3. Protect stored cardholder data

4. Encrypt transmission of cardholder data across open, public networks

Maintain a Vulnerability Management Program

5. Use and regularly update anti-virus software or programs 6. Develop and maintain secure systems and applications Implement Strong Access

Control Measures

7. Restrict access to cardholder data by business need-to-know 8. Assign a unique ID to each person with computer access 9. Restrict physical access to cardholder data

Regularly Monitor and Test Networks

10. Track and monitor all access to network resources and cardholder data

11. Regularly test security systems and processes Maintain an Information

(17)

PCI Standards for Applications & Devices

PIN Transaction Security (PTS)

• Addresses characteristics & management of devices for processing payment cards

• PTS is followed by device manufacturers

• Merchants must use validated PTS devices

Payment Application Security

Data Security Standard

(PA-DSS)

• Addresses applications for payment, authorisation and settlement

• PA-DSS is followed by software developers

(18)

Getting Ready for PCI 3.0

2013 Focus: Updating

PCI Standards and

supporting

(19)

+

The Bottom Line

Compliance Doesn’t Equal Security

(20)

Why PCI

(21)

Tokenisation

P2PE

Applying PCI in Your Environment

Virtualisation

Mobile

EMV

ATM

(22)

EMV Helps Reduce Face-to-Face Fraud

EMV by itself does not

protect the

confidentiality of, or

(23)
(24)
(25)

Areas of Focus for Mobile

Devices

Tamper-responsive,

PTS Devices (e.g.

SCR) using P2PE

Applications

Requirements and/or

Best Practices for

authorisation and

settlement

Service Providers

Service provider

protection of

cardholder data and

validation

(26)

Mobile payments and the PCI Council

Identified mobile applications that

can be validated to PA-DSS

Published merchant guidance for

‘mobile’ solutions leveraging P2PE

Developed best practices for

(27)

Guidance on Mobile

(28)

New Mobile Guidance for Merchants

Guidance for merchants on the

factors and risks that need to be

addressed in order to protect card

data when using mobile devices,

such as smart phones and tablets,

to accept payments, including:

• Objectives and guidance

for the security of a

payment transaction

• Guidelines for securing the

mobile device

• Guidelines for securing the

payment acceptance

(29)

Point-to-Point Encryption

Available to all members of the

payment chain

Also called “P2PE”

Optional standard for

decreasing scope

PCI 2PE hardware /hardware

requirements available

PCI P2PE “Hybrid” requirements

available

(30)

Tokenisation

Work on tokenization standards has begun

Ensure that process of creating token from

PAN doesn’t leak information about PAN

Ensure that a token or collection

of tokens by themselves cannot feasibly allow

discovery of PAN

Ensure that adequate controls exist over

de-tokenisation process

Ensure that token cannot be used in lieu of

PAN for impermissible purposes

PAN

T

(31)

2013 Training Highlights

Online Internal Security Assessor

(ISA) Training

P2PE Assessor Training

Corporate PCI Awareness – Let Us

Come To You!

Online Awareness Training in Four

Hours

Qualified Integrators and Resellers

(QIR)™ Program

PCI Professional Program (PCIP)™

To learn more, visit:

(32)
(33)

QIR Addresses Common Misconceptions

I’m using a PA-DSS validated

application, so I must be OK.

I’m using a “reputable” 3

rd

party, so

they must be doing a secure

installation.

(34)

Payment Card Industry Professional (PCIP)™

Support your

organisation

Professional

credibility

Competitive

advantage

directory

Global

(35)

A comprehensive PCI DSS training and qualification program for eligible

internal audit security professionals that you asked for!

Internal Security Assessor (ISA) Program

• Improves your understanding

of PCI DSS and compliance

procedures

• Helps your organisation build

internal expertise

(36)

PCI Awareness Training

Team

Building

Convenience

Cost

(37)
(38)
(39)

How You Can Participate

Why PCI

(40)

Chief Security Officers Information Security Professionals Compliance

Officers Investigators Forensic Technologists

IT Managers Risk Managers Information Chief

Officers Legal Experts

Data Security Experts

Join! Become a

Participating

Organisation today

(41)
(42)

PCI SSC Special Interest Groups (SIG)

(43)
(44)

New SIG Guidance – PCI DSS Risk Assessment

Go to our website today to download these new guidelines!

https://www.pcisecuritystandards.org/index.php

Guidance for choosing the risk

assessment approach that works

best for your business to secure

your card data

(45)

New SIG Guidance – eCommerce

Go to our website today to download these new guidelines!

https://www.pcisecuritystandards.org/index.php

eCommerce

(46)

New SIG Guidance – Cloud

Go to our website today to download these new guidelines!

https://www.pcisecuritystandards.org/index.php

Cloud

(47)

Best Practices for Maintaining PCI Compliance Third Party Security Assurance

2013 Special Interest Groups- Join us!

(48)

Board of Advisor Nominations and

Elections 2013

27 January

Nominations Open

25 February

Nominations

Close

7 March

Voting

Commences

Join as a Participating Organisation by going to

https://www.pcisecuritystandards.org/get_involved/join.php

(49)
(50)

Get Involved – We Need Your Input

Join

Learn

Input

Network

(51)

The Formula for PCI Success

+

(52)

Summary: Why PCI Matters to You!

(53)

Please visit our website at

www.pcisecuritystandards.org

References

Related documents

• PCI DSS coverage within security circles • PCI DSS Council Participating Organizations. PCI DSS in

DSS= Data Security Standard PCI SSC= PCI Security Standards Council QSA= Qualified Security Assessor SAQ=Self Assessment... PCI DSS Structure

We have a focus on the Payment Card Industry Data Security Standard (PCI DSS), since Requirement #12 of the PCI DSS requires all Merchants to “maintain a policy that

White Paper: Varonis Systems & The Payment Card Industry Data Security Standard (PCI DSS).. Varonis Systems & The Payment Card Industry Data Security Standard

The council develops, maintains and manages the PCI Security Standards, which include the Data Security Standard DSS, Payment Application Data Security Standard PA-DSS, and

Purpose of Payment Card Industry Data Security Standards (PCI-DSS).. §   Set of global security standards and

Software Developers PCI PA-DSS Payment Applications PCI Security & Compliance P2PE Merchants & Service Providers PCI DSS Secure Environments.. PCI

Requirement 6 Develop and maintain secure systems and applications (6.5 - OWASP Guide, CWE/SANS Top 25, CERT Secure Coding).. Implement Strong Access