Example: air traffic controller

PCI Security Standards Council - EMV Connection

Guiding open Standards for global payment card Security PCI Security Standards Council Guiding open Standards for global payment card Security Bob Russo, General Manager December 2013 Guiding open Standards for global payment card Security 2 Get Involved PCI DSS and EMV Why PCI DSS Agenda Guiding open Standards for global payment card Security About the PCI Council Open, global forum Founded 2006 Guiding open Standards for payment card Security Development Management Education Awareness Guiding open Standards for global payment card Security Expanding Global Representation Guiding open Standards for global payment card Security Manufacturers PCI PTS Pin Entry Devices Ecosystem of payment devices, applications, infrastructure and users Software Developers PCI PA-DSS Payment Applications PCI Security & Compliance P2PE Merchants & Service Providers PCI DSS Secure Environments PCI Security Standards Suite Protection of Cardholder Payment Data Guiding open Standards for global payment card Security PCI Community Feedback Process Changes made per our lifecycle Open Standards development process Feedback from our global PCI community Feedback period started in Fall of 2011 Guiding open Standards for global payment card Security Market Trends & Drivers Weak or default passwords Lack of employee education Security deficiencies introduced by third parties Slow self-detection Source: 2013 Trustwa

Training ! Corporate PCI Awareness – Let Us Come To You! ! Online Awareness Training in Four Hours ! Qualified Integrators and Resellers ... Payment Card Industry Professional (PCIP)™ Support your organization Professional credibility Competitive advantage Global directory Now Available ...

Tags:

  Training, Professional, Industry, Payments, Card, Ipcp, Payment card industry professional

Information

Domain:

Source:

Link to this page:

Please notify us if you found a problem with this document:

Other abuse

Advertisement

Transcription of PCI Security Standards Council - EMV Connection

1 Guiding open Standards for global payment card Security PCI Security Standards Council Guiding open Standards for global payment card Security Bob Russo, General Manager December 2013 Guiding open Standards for global payment card Security 2 Get Involved PCI DSS and EMV Why PCI DSS Agenda Guiding open Standards for global payment card Security About the PCI Council Open, global forum Founded 2006 Guiding open Standards for payment card Security Development Management Education Awareness Guiding open Standards for global payment card Security Expanding Global Representation Guiding open Standards for global payment card Security Manufacturers PCI PTS Pin Entry Devices Ecosystem of payment devices, applications, infrastructure and users Software Developers PCI PA-DSS Payment Applications PCI Security & Compliance P2PE Merchants & Service Providers PCI DSS Secure Environments PCI Security Standards Suite Protection of Cardholder Payment Data Guiding open Standards for global payment card Security PCI Community Feedback Process Changes made per our lifecycle Open Standards development process Feedback from our global PCI community Feedback period started in Fall of 2011 Guiding open Standards for global payment card Security Market Trends & Drivers Weak or default passwords Lack of employee education Security deficiencies introduced by third parties Slow self-detection Source: 2013 Trustwave Global Security Report Guiding open Standards for global payment card Security Key Considerations What will improve payment Security ?

2 Global applicability and local market concerns Appropriate sunset dates for other Standards or requirements Cost/benefit of changes to infrastructure Cumulative impact of any changes Guiding open Standards for global payment card Security Why PCI DSS Visit to view this infographic Guiding open Standards for global payment card Security PCI DSS, PA-DSS Key Themes Make PCI your compass, not your roadmap Education Awareness Flexibility Security as a Shared Responsibility Guiding open Standards for global payment card Security At a 12 core Security principles of PCI DSS remain the same Several new sub-requirements that will impact PCI DSS Security efforts Future implementation dates provided for more significant changes Clarified PCI DSS Applicability Enhanced testing procedures to clarify level of validation expected for each requirement Aligned language between requirements and testing procedures for consistency Instructions for Report on Compliance (ROC) reporting now separate ROC reporting template Guiding open Standards for global payment card Security Maintaining Compliance Best Practices for Implementing PCI DSS into Business-as-Usual (BAU)

3 Processes Focus on Security not compliance PCI DSS is not a once-a-year activity Don t forget about people Guiding open Standards for global payment card Security Understanding Intent of Requirements Guiding open Standards for global payment card Security Strong Authentication Include guidance for users: Selecting strong authentication credentials Protecting authentication credentials Not reusing previous passwords Changing passwords if suspicion of compromise Provide authentication procedures and policies to all users PCI DSS PCI DSS Guiding open Standards for global payment card Security Security Policies and Procedures Security policies and operational procedures for managing firewalls are documented and in use Security policies and operational procedures for managing vendor defaults and Security parameters are documented and in use Maintain a Security policy that addresses all PCI DSS requirements Develop daily operational Security procedures that are consistent with requirements in the PCI DSS PCI DSS PCI DSS Guiding open Standards for global payment card Security Consistent Assessment Procedures Enhanced testing procedures Clarify what it means to verify a requirement has been met Promote

4 Consistent validation methods Combine template with reporting instructions Clarify level of detail required Reduce repetition Improve reporting Guiding open Standards for global payment card Security Flexibility: PCI DSS Requirements Guiding open Standards for global payment card Security Log Reviews Review at least daily: All Security events Logs from systems that store, process, or transmit CHD/SAD Logs of system components that perform Security functions Review other logs periodically as determined by the organization s annual risk assessment Review logs for all system components at least daily PCI DSS PCI DSS Guiding open Standards for global payment card Security Security as a Shared Responsibility . Outsourcing PCI DSS responsibilities Guidance Service providers use unique credential per customer Requirement 8 Service providers acknowledge responsibility Requirement 12 Guiding open Standards for global payment card Security Physical Security for POS Devices Protect devices that capture payment card data from tampering and substitution Maintain an up-to-date list of devices Periodically inspect device surfaces to detect tampering or substitution Provide training for personnel to be aware of attempted tampering or replacement of devices Guiding open Standards for global payment card Security Penetration Testing and Effective Scoping Implement a penetration testing methodology If segmentation is used, perform penetration tests to verify that the segmentation methods are operational and effective.

5 Guiding open Standards for global payment card Security Effective Dates for PCI DSS is effective on January 1st 2014 Version is valid until December 31st 2014 Different supporting documents Check our website for the latest documents Do not mix and match Guiding open Standards for global payment card Security EMV Chip Roadmap in US EMV Chip Helps Reduce Face-to-Face Fraud EMV Needs PCI EMV chip needs PCI Even EMV Chip Needs PCI Guiding open Standards for global payment card Security Terminal Security Guiding open Standards for global payment card Security PTS Listings Guiding open Standards for global payment card Security And Emerging Technologies? +People Processes Technology Security +=Guiding open Standards for global payment card Security Mobile Payment Acceptance PCI Standards focus on merchant-acceptance Mobile payment acceptance still evolving Understand risk and use PCI SSC resources PCI SSC is working with industry Guiding open Standards for global payment card Security Mobile Payment Acceptance Guidelines published 2012-2013 PCI Mobile Payment Acceptance Guidelines for Developers PCI Mobile Payment Acceptance Guidelines for Merchants as End-Users Accepting Mobile payments with a Smartphone or Tablet Guiding open Standards for global payment card Security PCI Special Interest Groups Visit to download this guidance Guiding open Standards for global payment card Security 2014 Special Interest Groups Formal Security Awareness.

6 Best Practices for Implementing a Formal Security Awareness Program Penetration Testing Guidance Guiding open Standards for global payment card Security Online Internal Security Assessor (ISA) training Corporate PCI Awareness Let Us Come To You! Online Awareness training in Four Hours Qualified Integrators and Resellers (QIR) Program PCI professional Program (PCIP) To learn more, visit: training Options Guiding open Standards for global payment card Security Qualified Integrators and Resellers (QIR) Guiding open Standards for global payment card Security I m using a reputable 3rd party, so they must be doing a secure installation. This applies only to brick and mortar establishments. I m using a PA-DSS validated application, so I must be OK. QIR Addresses Common Misconceptions Guiding open Standards for global payment card Security Payment card industry professional (PCIP) Support your organization professional credibility Competitive advantage Global directory Now Available Guiding open Standards for global payment card Security PCI SSC Website Documents library Dedicated page for small merchants Listings of approved companies and providers Videos and webinars Frequently asked questions microsite Guiding open Standards for global payment card Security Security is a shared responsibility Guiding open Standards for global payment card Security Get Involved We Need Your Input Join Learn Input Network Nominate Vote Share Influence Guiding open Standards for global payment card Security Please visit our website at Questions?

7


Related search queries