Confidential Property of CampusGuard 1
PCI DSS Merchant Overview
Craig A. Henninger CISSP, QSA Security Advisor
PCI DSS Merchant Overview Craig A. Henninger CISSP, QSA Security - - PowerPoint PPT Presentation
PCI DSS Merchant Overview Craig A. Henninger CISSP, QSA Security Advisor 1 Confidential Property of CampusGuard Introducing CampusGuard Full-Service QSA/ASV Firm for PCI Compliance Certified in US, Australia and New Zealand
Confidential Property of CampusGuard 1
Craig A. Henninger CISSP, QSA Security Advisor
Confidential Property of CampusGuard 2
A Merchant Preservation Services Company
Confidential Property of CampusGuard 3
Confidential Property of CampusGuard 4
Confidential Property of CampusGuard 5
secure network
sensitive information across public networks
management program
control measures
networks
cardholder data
security policy
Control Objective Requirements
Confidential Property of CampusGuard 6
SOFTWARE DEVELOPERS
PCI PA-DSS
Payment Application Vendors MANUFACTURER
PCI-PTS
PIN Transaction Security
Ecosystem of payment devices, applications, infrastructure and users
MERCHANTS & PROCESSORS
PCI DSS
Data Security Standard
P2PE
Confidential Property of CampusGuard 7
Bank
Communicates and educates merchants on PCI DSS and reports compliance status to Card Associations
Merchant
Responsible for safeguarding credit card data and complying with the PCI DSS
CREDIT CARD SECURITY
Responsible for enforcing and monitoring merchant compliance with the PCI DSS Responsible for managing the PCI DSS and certifying QSAs and ASVs
Confidential Property of CampusGuard 8
Confidential Property of CampusGuard 9
Data Element Storage Permitted Protection Required
PAN Yes Yes
Cardholder data
Cardholder name Yes No Service code Yes No Expiration date Yes No Sensitive authentication data Magnetic stripe No No storage permitted CVC2/CVV2/CID No No storage permitted PIN/PIN block No No storage permitted
Only considered CHD if full PAN stored 1st 6 / Last 4 OK “Holy Grail” for thieves
Confidential Property of CampusGuard 10
Level 1 > 6 million Visa/MC txns/yr > 2.5 million transactions/yr 2 1 to 6 million Visa/MC txns/yr 50,000 to 2.5 million txns/yr 3 20,000 to 1 million Visa/MC ecommerce txns/yr All other Amex Merchants 4 All other Visa/MC merchants N/A
Confidential Property of CampusGuard 11
Level 1
(QSA)
(QSA)
2
(QSA/ISA)
3
Questionnaire (SAQ)
4
Confidential Property of CampusGuard 12 12
SAQ Type Questions Payment Method A 14 Card-not-present Merchants, All Cardholder Data Functions Fully Outsourced A-EP 139 Partially Outsourced E-commerce Merchants Using a Third-Party Website for Payment Processing B 41 Merchants with Only Imprint Machines or Only Standalone, Dial-
B-IP 83 Merchants with Standalone, IP-Connected PTS Point-of- Interaction (POI) Terminals – No Electronic Cardholder Data Storage C 139 Merchants with Payment Application Systems Connected to the Internet – No Electronic Cardholder Data Storage C-VT 73 Merchants with Web-Based Virtual Payment Terminals – No Electronic Cardholder Data Storage D 326 All other SAQ-Eligible Merchants P2PE-HW 35 Hardware Payment Terminals in a PCI-Listed P2PE Solution Only – No Electronic Cardholder Data Storage
Confidential Property of CampusGuard 13
Confidential Property of CampusGuard 14
Confidential Property of CampusGuard 15
Confidential Property of CampusGuard 16
Confidential Property of CampusGuard 17
comes into scope
comes into scope.
Confidential Property of CampusGuard 18
alleviate some scope and PCI DSS responsibility.
a 3rd party.
compliance obligations for the Web server that hosts the site with the “Pay Now” button now fall under SAQ A-EP.
Confidential Property of CampusGuard 19
MasterCard and Visa both have statements for Merchants wishing to use Square and other Mobile Point Of Sale (MPOS) devices
“Due to the inherent security limitations of mobile devices, the PCI SSC is not certifying MPOS payment applications that reside on multi-purpose, consumer mobile devices (referred to by the PCI SSC as a Mobile Payment Acceptance Application Category 3) until further guidance is developed to ensure the security of cardholder data within the mobile device. Please refer to t to the PCI SSC Website for more information.” (MasterCard statement on Mobile payments)
Confidential Property of CampusGuard 20
Confidential Property of CampusGuard 21
Card Swipe Machine? Office Workstations? Computer Lab? Student? Shopping Cart? Phone Transaction?
Confidential Property of CampusGuard 22
Store, process or transmit cardholder data?
Point-of-Sale (POS) Mail Order/Telephone Order (MOTO) FAX E-Commerce (website where customer can input their credit
card information to complete a transaction)
Use a system that processes or stores credit card data?
And are other systems connected to them?
IF YOU ANSWER YES TO ANY OF THE ABOVE QUESTIONS THEN PCI DSS APPLIES TO YOU!
Confidential Property of CampusGuard 23
Requires executive level signoff. Be sure you are compliant before signing!
* Validation for level 4 merchants is at the discretion of the acquiring bank
Confidential Property of CampusGuard 24
Confidential Property of CampusGuard 25
2013 may be remembered as the “year of the retailer breach,” but a comprehensive assessment
suggests it was a year of transition from geopolitical attacks to large-scale attacks on payment card systems.
Confidential Property of CampusGuard 26
Confidential Property of CampusGuard 27
Challenges for PCI Compliance:
Confidential Property of CampusGuard 28
firm
Confidential Property of CampusGuard 29
Confidential Property of CampusGuard 30
Direct Costs
Indirect Costs
10,000 accounts X ~$200 / account = $2 Million
Confidential Property of CampusGuard 31
Confidential Property of CampusGuard 32
Confidential Property of CampusGuard 33
Confidential Property of CampusGuard 34
Discovery and Assessment
Confidential Property of CampusGuard 35
Confidential Property of CampusGuard 36
Discovery and Assessment
Remediation
Controls
Confidential Property of CampusGuard 37
Confidential Property of CampusGuard 38
Discovery and Assessment
Remediation
Controls Validation
Submission
Confidential Property of CampusGuard 39
Confidential Property of CampusGuard 40
Discovery and Assessment
Remediation
Controls Validation
Submission
Re-Validate every 12 months
Confidential Property of CampusGuard 41
www.pcisecuritystandards.org/
www.visa.com/cisp www.mastercard.com/sdp
http://www.privacyrights.org/
http://www.ponemon.org/
www.campusguard.com/
Confidential Property of CampusGuard 42