Top Banner
An Introduction to PCI Compliance
17

An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.

Dec 25, 2015

Download

Documents

Clement Houston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.

An Introduction to PCI Compliance

Page 2: An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.

•Data Breach Trends

•About PCI-SSC

•12 Requirements of PCI-DSS

•Establishing Your Validation Level

•PCI Basics

•Benefits of PCI Compliance

•Benefits of Accepting Credit Cards

Page 3: An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.

Source: http://www.verizonbusiness.com/resources/security/reports/2009_databreach_rp.pdf

Page 4: An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.

“From the chart, it is evident…unauthorized access viadefault, shared, or stolen credentials constituted more than a third of the entire hacking category and over half of allcompromised records. “

Example: “Tito’s Taco Shack”

Source: http://www.verizonbusiness.com/resources/security/reports/2009_databreach_rp.pdf

Page 5: An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.

PCI-SSC

Page 6: An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.

Payment Card Industry - Security Standards Council

Does Does Not

Data Security Standard (DSS)

Payment Application Data Security Standard (PA-DSS)

Pin Transaction Security (PTS) Requirements.

Enforce standards Set fine and fee structures

Set validation levels

Page 7: An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.

• Build and Maintain a Secure Network– Requirement 1: Install and maintain a firewall configuration to protect cardholder data– Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters

• Protect Cardholder Data– Requirement 3: Protect stored cardholder data– Requirement 4: Encrypt transmission of cardholder data across open, public networks

• Maintain a Vulnerability Management Program

– Requirement 5: Use and regularly update anti-virus software– Requirement 6: Develop and maintain secure systems and applications

• Implement Strong Access Control Measures– Requirement 7: Restrict access to cardholder data by business need-to-know– Requirement 8: Assign a unique ID to each person with computer access– Requirement 9: Restrict physical access to cardholder data

• Regularly Monitor and Test Networks

– Requirement 10: Track and monitor all access to network resources and cardholder data– Requirement 11: Regularly test security systems and processes

• Maintain an Information Security Policy– Requirement 12: Maintain a policy that addresses information security

Page 8: An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.

= State PCI Law = Breach Notification Laws

Page 9: An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.

• Any merchant that processes, transmits, or stores credit card data regardless of processing volume must comply to PCI-DSS regulations.

• Every merchant must validate compliance every year.*

• MIDs under different TAXIDs will need to certify separately.

* Check with your Acquiring bank for specific validation requirements and deadlines

Page 10: An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.
Page 11: An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.

Source: www.visa.com/cisp

Page 12: An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.

Source: www.pcisecuritystandards.org

Page 13: An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.
Page 14: An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.

• Peace of mind for your business and clients

• Decreased risk of security breaches

• Boost in customer confidence

• Protection from costly fines

• Relatively quick and easy

• Safeguard your business reputation

Page 15: An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.

•Stay viable in the marketplace – “The number of payments made by debit, credit, or EBT card grew by 12.8 billion from 2003 to 2006, reaching 48.1 billion and exceeding the number of checks paid by 17.6 billion.“*

•Offer payment flexibility to clients

•Improve cash flow

•Reduce the hassle of collections

*http://www.federalreserve.gov/pubs/bulletin/2008/articles/payments/default.htm

Page 16: An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.

www.visa.com/cisp

www.pcisecuritystandards.org

www.mastercard.com/us/sdp/education

www.pcicentral.com/docs/pciscc_ten_common_myths.pdf

http://www.federalreserve.gov/pubs/bulletin/2008/articles/payments/default.htm

http://www.verizonbusiness.com/resources/security/reports/2009_databreach_rp.pdf

Page 17: An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.

Amy Airhart

[email protected]

www.pcicentral.com