1 of 23

Payment

Card Industry Data Security Standards

Purple 7

Andrew, Billy, Pallavi, Shivangi, Slim, Vanessa

2 of 23

History of

PCI DSS

The 12

Requirements

Applicable Industries

Advantages & Disadvantages

Similar Framework: PA- DSS

Compliance to the Framework

TABLE OF CONTENTS

01

02

03

04

05

06

3 of 23

PCI DSS

History

01

4 of 23

About PCI DSS

What?

Payment

Card

Industry

Data

Security

Standard

Who?

Developed to enhance cardholder data security by adopting data security measures

Applies to all merchants and service providers that process, transmit, or store cardholder data

Why?

5 of 23

2004

1988-1999

1999

Late 1980’s

History of PCI DSS

Visa introduces Card Information Security Program

Emergence of E-Commerce Sector

Payment Card Industry Data Security Standards formed

$750M Worth of Online Fraud Losses

6 of 23

Formation of PCI DSS

PCI DSS

7 of 23

The 12 Requirements

02

8 of 23

12 Requirements of PCI DSS

Build and Maintain a Secure Network and Systems

Protect Cardholder Data

Maintain a Vulnerability Management Program

1

6 Control Objectives

Installing and maintaining a firewall configuration

Changing vendor-supplied defaults for system passwords and other security parameters

1

2

2

Protect stored cardholder data

Encrypt transmission of cardholder data across open, public networks

3

4

3

Use and regularly update anti-virus software

Develop and maintain secure systems and applications

5

6

9 of 23

12 Requirements of PCI DSS

Implement Strong Access Control Measures

Regularly Monitor and Test Networks

Maintain an Information Security Policy

4

6 Control Objectives

Restrict access to cardholder data by business need-to know

Assign a unique ID to each person with computer access

Restrict physical access to cardholder data

7

8

5

Track and monitor all access to network resources and cardholder data

Regularly test security systems and processes

10

11

6

Maintain a policy that addresses information security

12

9

10 of 23

11 of 23

Financial Institutions

Online Creditors

Credit Card Companies

Industries Suited for PCI DSS

12 of 23

Four Industry Stages of PCI DSS

02

03

01

04

Level 1

Merchants processing over 6,000,000 transactions annually

Level 2

1,000,000 to 6,000,000 transactions annually

Level 3

20,000 to 1,000,000 transactions annually

Level 4

Fewer than 20,000 transactions annually

13 of 23

14 of 23

Advantages of PCI Certified

  • Prevent data breaches
    • Periodic checks help reduce the chance of breaches.

  • Build customer trust
    • Improved security improved better relationship with customers and stakeholders.

  • Helps you meet global standards
    • Your security practices are inline with global standards.

  • Set a high security bar
    • Organisations have a benchmark to compare themselves

15 of 23

Disadvantages of PCI Certified

  • Constant update needs constant attention.
    • Old information is useless information.

  • Often seen as "Check-the-box" routine.
    • Security should be top of mind, not a necessary evil.

  • Intra Enterprise process coordination is necessary
    • For easier compliance unit, get to know your business unit better.

16 of 23

17 of 23

Applies to software vendors and others, who product and sell payment applications

Applies to all companies that store, process, or transmit sensitive authentication data.

Credit Card Information

Payment portals

18 of 23

  • Log payment activity.
  • Test and updates the applications.
  • No magnetic stripe, verification code, or PIN data.
  • Protect stored cardholder data
  • Never store data connected to the internet.
  • Protect wireless transmissions.
  • Encrypt sensitive traffic over public networks.
  • Develop secure payment applications.
  • Facilitate secure network implementation.
  • Provide access authentication features.
  • Facilitate secure remote access.
  • Secure all non-console access.
  • Documentation and training for personnel.
  • Assign responsibilities for personnel.

PA-DSS

19 of 23

Compliance to the Framework

06

20 of 23

Authority Behind the Framework

Official Law

Enforcing Government Authorities

Supervised by PCI DSS Committee

  • Penalty Up to $ 500,000

  • Denial of Payment Card Processing Access

21 of 23

Level 4

Level 3

Level 2

Level 1

Mild

Strict

< 20,000 transactions/year

Ex: Mom & Pop Stores

> 6 million transactions/year

Ex: Target, Walmart,

7-Eleven

Moderately Strict

Moderate

Compliance to the Standards Across Levels

The higher the level, the more rigorous the standard

22 of 23

23 of 23

References

https://www.pcisecuritystandards.org/pci_security/maintaining_payment_security

https://reciprocity.com/resources/what-is-the-difference-between-pa-dss-and-pci-dss/

https://en.wikipedia.org/wiki/Payment_Card_Industry_Data_Security_Standard