Transcription of PCI Security Standards Council - c.ymcdn.com
1 PCI Security Standards CouncilToday s SpeakerMark MrotekCertifications Program ManagerPCI Security Standards CouncilNEED MARK PHOTOT oday s Agenda About the PCI Security Standards Council Protecting Payments with PCI Standards , Best Practices & Services 2016 Updates Educational Resources & training Involvement OpportunitiesAbout the PCI Security Standards CouncilFounded in 2006 -Guiding open Standards for payment card Security Development Management Education AwarenessOur FocusCollaboration and information sharingEducationSimplified solutions for merchants538% more Security incidents were detected in 2015 than the year before. PWC 2016 Global State of Information Security Survey Cyber$ million -average cost of global cybercrime in 2015 Ponemon/HPCybercrime is on the RiseISACA, January 2016 Breaches can be Prevented92%97%compromises were simplewere avoidable through simple or intermediate of breaches were preventable caused by known vulnerabilities with fixable patches76% of companies took weeks or more to discover breach67% of organizations did not adequately test the Security of all in-scope systems72 percent of hackers say they won't waste time on an attack that doesn't hold the promise of quick and high-value information, and 69 percent will quit if they see that the target has a strong defense.
2 PonemonInstitutePCI Security StandardsBest Practices & ServicesTraining Assessors, InvestigatorsCertification Equipment, Service Providers, Assessors, InvestigatorsPayment EquipmentPayment SoftwareMerchant & Payment Service ProviderEnvironmentsPCI Security Standards Point of InteractionDatacenterEcommerceMotoIn Store Server3rdParty ProcessorTheInternet3rdparty suppliersStock and MarketingAcquiringBankMerchantProtect cardholder data throughout the transaction cycleSix GoalsTwelve RequirementsBuild and Maintain a Secure and maintain a firewall configuration to protect cardholder not use vendor-supplied defaults for system passwords and other Security parametersProtect Cardholder stored cardholder transmission of cardholder data across open, public networksMaintain a Vulnerability Management Program and regularly update anti-virus software or and maintain secure systems and applications Implement Strong Access Control access to cardholder data by business a unique ID to each person with computer physical access to cardholder dataRegularly Monitor and Test and monitor all access to network resources and cardholder test Security systems and processesMaintain an Information Security a policy that addresses information Security for employees and contractorsPCI Data Security Standard (PCI DSS)
3 Other Standards & Solutions Point-to-Point Encryption Payment card production Payment terminals Payment applications Cover wide variety of payment Security challenges Provide protection for payment data in multiple channels online, mobile, in-store Ensure lab-tested devices and technology solutions Token Service ProvidersCertification Payment Application Assessors PCI Forensic Investigators Internal Security Assessors Approved Scanning Vendors Point-to-Point Encryption Assessor Qualified Security Assessor Qualified Integrator & Reseller EMV VAR Qualification ProgramTraining PCI Awareness training PCI Essentials pci professional Program (PCIP) Internal Security Assessor (ISA) Online! Qualified Security Assessor (QSA) Qualified Integrators and Resellers (QIR) Program Corporate Group training Let Us Come To You!To learn more, visit: and monitoring controls (PCI DSS Req.)
4 10) Maintaining secure systems (PCI DSS Req. 11)Ongoing Security Remains ChallengeTesting Security systems (PCI DSS Req. 11)Key problem areas for breached organizations The Security benefits associated with maintaining PCI compliance are vital to the long-term success of all merchants who process card payments. This includes continual identification of threats and vulnerabilities that could potentially impact the organization. Most organizations never fully recover from data breaches because the loss is greater than the data itself. QSR MagazineWhy we fail to maintain secure environments Lack of awareness by IT practitioners Incentive to keep Security a primary focus Quickly evolving technology landscape Rapid development and distribution of new solutions Still unnecessary exposure of card holder dataWhy?Compliance vs. SecurityReliance on annual assessmentsPressure to meet customer demandsFailing to adapt to changesCompliance vs.
5 Security While validation is no assurance of Security , not being compliant is pretty much a guarantee that you re not secure. -2015 Verizon PCI Compliance ReportMoving From Compliance to Protection Focus on Security not compliance PCI DSS is not a once-a-year activity Don t forget about peopleMitigate Risk with Vigilance Software patched & up-to-date Configuration settings don t expose payment card data Monitor internal & 3rdparty access Use strong authentication & strong passwordsRegularly Monitor Controls! Ongoing Security Understand how changes in the organization affect Security controlsMonitor Security control operationConduct periodic Security control assessmentsDetect and respond to Security control failuresThe Standards Continually EvolveResearchThreat and Risk LandscapeIndustry FeedbackSecure Sockets Layer (SSL)SSL to TLS Background and Timeline SSL/TLS used as example in DSS v3 and earlier Example of strong cryptography Example of additional Security for insecure services Marketplace feedback Technical issues -relatively easy Business issues -complexApril 2014 NIST SSL&TLS UnsafePCI SSC Seeks Industry InputApril 2015 PCI SSC Issues PCI DSS and GuidanceMarketplace FeedbackDecember 2015 PCI SSC Issues New Migration Dates SSL and Early TLS.
6 New Migration DatesAll processing and third party entities including Acquirers, Payment Processors, Gateways and Service Providers must provide a TLS or greater serviceofferingby 30 June entities must cutover to a secure version of TLS (as defined by NIST) by June with the existing language in PCI DSS , all new implementationsmust be enabled with TLS or greater (TLS recommended). POI terminals (and the SSL/TLS termination points to which they connect) that can be verified as not being susceptibleto all known exploits for SSL and early TLS, can continue to use SSL/early TLS beyond June 2018consistent with the current & early TLS not considered strong cryptography & not allowed as Security control after 30 June 2018 Key Recommendations Migrate to a minimum of TLS , preferably TLS Patch TLS software against implementation vulnerabilities Configure TLS securelyAdditional GuidanceInformation Supplement & FAQ Clarification on new vs.
7 Existing implementations Guidance on allowances for POS POI environments Suggestions/examples of risk mitigation techniques Suggestions/examples on alternative cryptographic options to replace SSL/early TLS Best practices for proper TLS configuration FAQs and tips for small merchant environments PCI DSS Version DSS to be released in first half of 2016 To address SSL/TLS migration Additionally Under Review for DSS Access controls for authentication to CDE Review of Designated Entities requirements for inclusion Review of existing PAN criteria for masking, Technology: Devalue Data and Reduce RiskEMV chipTokenizationPoint-to-Point Encryption Improve your Security . Reduce your risk. Simplify your PCI DSS compliance efforts. Fraud is evolving at a frantic the industry cracks down on one type of fraud, criminals quickly shift their attack vector and area of operation.
8 Al Pascual, Fraud & Security , Javelin ResearchMagnetic Stripe FraudData on magnetic stipe is staticCan be easily captured or copiedWritten onto a second card to make a cloneUsed to undertake fraudulent transactionsHand held skimmer Skimmerin POI deviceSkimmer attached to ATMI mpact of EMV Chip on F2F FraudIf I Have EMV Chip, Do I Need PCI?The Security Fruit TreeLow hanging fruitBulk fruitHigh FruitCard-Not-Present dataEMV chip card dataPCI and EMV chip together Card-not-present (CNP) fraud is expected to more than double from $ billion to more than $ billion by 2018. AiteGroupPreparing for EMV Chip with PCI There is no silver bullet EMV does not negate the need for secure passwords, patching systems, logging monitoring for intrusions, using firewalls, etc. EMV chip brings great benefits to transactions in your stores, but fraud will migrate to the online marketplace Multi-channel organizations need to consider their entire payment infrastructure, not just brick and mortar, and ensure proper Security protocols are in place Talk to your acquiring bank to understand implications and benefits of EMV chip migration for your business Talk to you technology vendors and service providers to make sure you are securing the other parts of your system and purchasing the right products and servicesEMV chip needs PCI protectionsDon t forget e-commerce securityUse trusted partnersUpgrade your terminals and devices for the best Security and to take advantage of the latest technology options to enable your any version that has expired choose a version device or higher from the PCI PIN Transaction Security listing.
9 Consider any future Point-to-Point Encryption (P2PE) and tokenization plans and what additional layers of Security you may want to make the best for EMV Chip with PCIP oint-to-Point Encryption and TokenizationPCI Guidance and Best Practices Tokenization best practices Merchant Guide to Point-to-Point Encryption PCI DSS compliance in the cloud Building a Security awareness program Protecting against malware Skimming prevention Defending against phishing attacks Working with third parties Maintaining PCI DSS compliance Accepting payments with a mobile phoneAvailable at: 90% of all incidents were attributed to human error or misuse of systems. Verizon 2015 Data Breach Investigation Report PCI Awareness training Entry-level course that provides baseline knowledge of PCI DSS for organizations that must meet compliance with PCI DSSWhat is it? Managers or business owners charged with PCI DSS compliance / data Security Who should attend?
10 Drive understanding of PCI DSS compliance across your business Learn how and where to implement PCI across your organizationWhat s the benefit? One day instructor led training Four hour online course How is this course offered? pci professional (PCIP) TrainingProfessionals in payment industry with two years experience in an IT or IT related role and knowledge of information technology, network Security and architecture, and the payment industry Who?What you get? Anytime, from home or office -Six hour self-paced eLearning course. Final exam administered at Pearson VUE Testing CenterWhen and Where? You ll learn : Principles of PCI DSS, PA-DSS, PCI PTS, and PCI P2PE Appropriate uses of compensating controls How new technologies effect PCI And moreWhy? Two year individual qualification that demonstrates knowledge of PCI standardsISA TrainingExperienced Security assessment, risk management and audit staff at ISA Sponsor companies Who?