ForenSecure’17
April 27, 2017
FUTURE OF CREDIT CARD PAYMENT APPLICATION SECURITY:
PA-DSS VS P2PE
FUTURE OF CREDIT CARD PAYMENT APPLICATION SECURITY: PA-DSS VS P2PE - - PowerPoint PPT Presentation
FUTURE OF CREDIT CARD PAYMENT APPLICATION SECURITY: PA-DSS VS P2PE ForenSecure17 April 27, 2017 SPEAKER Joel Dubin, PCI QSA, PA-QSA, CISSP Senior Consultant, Application Validation -Eight years as a PA-QSA and QSA and five years in PCI
ForenSecure’17
April 27, 2017
PA-DSS VS P2PE
Joel Dubin, PCI QSA, PA-QSA, CISSP Senior Consultant, Application Validation
Payment Card Industry Security Standards Council
One standard for merchants and service providers PCI One standard for payment applications PA-DSS One standard for P2PE solution providers P2PE
Hierarchy of PCI Standards
è PIN-pad Level
è Application Level
è Network Level
è ALL OF THE ABOVE
Payment Application Data Security Standard (PA-DSS) Card industry standard for payment applications
P2PE stands for “Point-to-Point Encryption”
acquirer
. . .
1) All-in-one solution provider 2) Solution provider using P2PE components
3) Merchant provided solutions
PA-DSS P2PE Time Frame 2 to 3 months 6 months to a year Overhead 1-2 PA-QSAs Teams, sometimes multinational Reporting (ROV) About 200 pages Can be 600+ pages Implementation No change to merchant environment New PIN-pads from solution provider May have to rip out “plumbing” Assessor Training Must be QSA in good standing Must have pen test experience Must have been developer Must be CISSP Must have done two PCI ROCs >4 years experience Must pass SSC exam/requal Must be QSA/PA-QSA Must know encryption Must know PTS hardware Must have dev and pen testing Must have done two PCI ROCs >2 years experience in above Must pass SSC exam/requal Only about 60 P2PE QSAs
Will PA-DSS completely disappear as P2PE technologies advance?
technologies. Second, P2PE requires significant overhead and, until now, has been a preserve of larger merchants and larger acquirers.
In that case, since P2PE is so much more involved, will it buckle under and go back to PA-DSS?
Not necessarily. The SSC has been streamlining the standard since it came out in 2013, and we’re seeing smaller entities, other than just large acquirers entering the game. In fact, with the mix and match approach of assembling P2PE components from diverse third- parties, it’s getting easier for players to get on board.
Is P2PE the wave of the future?
Yes and no. It’s the current hot technology of today. But there are competitors with various types of tokenization, creative new encryption technologies and even cloud solutions challenging the traditional P2PE space. P2PE is here to stay, but it might be very different in a few years than what we’re seeing today.
Is there a shortage of P2PE QSAs?
Absolutely, and the demand is outstripping the supply. The barriers to entry for P2PE QSAs are high and not coming down.
P2PE compliant
1) Encryption and keys not handled by merchant 2) No card data storage by merchant 3) PTS approved PIN-pads encrypting at swipe or dip
implementation of any technology: 1) Size of application vendor or merchant 2) Complexity of their environment and ease of implementation 3) Technological constraints 4) Business needs
challenge PA-DSS and P2PE in the future