PCI Compliance Updates
E-Commerce / Cloud Security
Adam Goslin, Chief Operations Officer AGoslin@HighBitSecurity.com www.HighBitSecurity.com Direct: 248.388.4328
PCI Compliance Updates E-Commerce / Cloud Security Adam Goslin, - - PowerPoint PPT Presentation
PCI Compliance Updates E-Commerce / Cloud Security Adam Goslin, Chief Operations Officer AGoslin@HighBitSecurity.com www.HighBitSecurity.com Direct: 248.388.4328 PCI Guidance Google: PCI e - commerce guidance
Adam Goslin, Chief Operations Officer AGoslin@HighBitSecurity.com www.HighBitSecurity.com Direct: 248.388.4328
for responsibilities
Source for all images and some content is acknowledged as coming from the above guidelines documents.
www.HighBitSecurity.com
responsibilities
responsibility for ensuring that payment card data is protected. Connections and redirections between the merchant and the third party can be compromised, and the merchant should monitor its systems to ensure that no unexpected changes have occurred and that the integrity of the connection/redirection is maintained.
should apply extra due diligence to ensure the web application is developed securely and undergoes thorough penetration testing.
www.HighBitSecurity.com
www.HighBitSecurity.com
applications (created or acquired) onto the cloud infrastructure, using programming languages, libraries, services, and tools supported by the provider.
www.HighBitSecurity.com
merchant PCI responsibility
www.HighBitSecurity.com
www.HighBitSecurity.com
www.HighBitSecurity.com
1)
2)
processing layer (application)
3)
data-storage layer
www.HighBitSecurity.com
processor
www.HighBitSecurity.com
www.HighBitSecurity.com
indirect via browser using third party API
www.HighBitSecurity.com
“iFrames” allow a web page to be embedded within another web page.
www.HighBitSecurity.com
customer is redirected to the payment page on the e-commerce payment processor’s site to enter payment card data.
processed, acknowledgement is sent back to the merchant’s web application.
www.HighBitSecurity.com
www.HighBitSecurity.com
www.HighBitSecurity.com
(CSRF) , Buffer Overflows , Weak Authentication and/or Session Credentials
authorized, publicly accessible services, and to prohibit unauthorized outbound traffic (PCI DSS Requirements 1.3.1 and 1.3.4)
those with access (PCI DSS Requirements 7 and 8)
www.HighBitSecurity.com
www.HighBitSecurity.com
www.HighBitSecurity.com
Adam Goslin, Chief Operations Officer AGoslin@HighBitSecurity.com www.HighBitSecurity.com Direct: 248.388.4328