Payment Card Industry Data Security Standard

The Payment Card Industry Data Security Standard (PCI DSS) is a proprietary information security standard for organizations that handle branded credit cards from the major card schemes including Visa, MasterCard, American Express, Discover, and JCB. The PCI Standard is mandated by the card brands and administered by the Payment Card Industry Security Standards Council. The standard was created to increase controls around cardholder data to reduce credit card fraud. Validation of compliance is performed annually, either by an external Qualified Security Assessor (QSA) that creates a Report on Compliance (ROC) for organizations handling large volumes of transactions, or by Self-Assessment Questionnaire (SAQ) for companies handling smaller volumes.

History

Five different programs: Visa's Cardholder Information Security Program, MasterCard's Site Data Protection, American Express' Data Security Operating Policy, Discover's Information Security and Compliance, and the JCB's Data Security Program were started by card companies. The intentions of each were roughly similar: to create an additional level of protection for card issuers by ensuring that merchants meet minimum levels of security when they store, process and transmit cardholder data.

The Payment Card Industry Security Standards Council (PCI SSC) was then formed and these companies aligned their individual policies to create the PCI DSS.

There have been a number of versions:

Requirements

The PCI Data Security Standard specifies twelve requirements for compliance, organized into six logically related groups called "control objectives".

Each version of PCI DSS has divided these twelve requirements into a number of sub-requirements differently, but the twelve high-level requirements have not changed since the inception of the standard.

Control objectives PCI DSS requirements
Build and maintain a secure network 1. Install and maintain a firewall configuration to protect cardholder data
2. Do not use vendor-supplied defaults for system passwords and other security parameters
Protect cardholder data 3. Protect stored cardholder data
4. Encrypt transmission of cardholder data across open, public networks
Maintain a vulnerability management program 5. Use and regularly update anti-virus software on all systems commonly affected by malware
6. Develop and maintain secure systems and applications
Implement strong access control measures 7. Restrict access to cardholder data by business need-to-know
8. Assign a unique ID to each person with computer access
9. Restrict physical access to cardholder data
Regularly monitor and test networks 10. Track and monitor all access to network resources and cardholder data
11. Regularly test security systems and processes
Maintain an information security policy 12. Maintain a policy that addresses information security

Updates and supplemental information

The PCI SSC has released several supplemental pieces of information to clarify various requirements. These documents include the following

Compliance versus validation of compliance

Although the PCI DSS must be implemented by all entities that process, store or transmit cardholder data, formal validation of PCI DSS compliance is not mandatory for all entities. Currently both Visa and MasterCard require merchants and service providers to be validated according to the PCI DSS. Visa also offers an alternative program called the Technology Innovation Program (TIP) that allows qualified merchants to discontinue the annual PCI DSS validation assessment. These merchants are eligible if they are taking alternative precautions against counterfeit fraud such as the use of EMV or Point to Point Encryption (P2PE) technology, however they are still required to be PCI DSS compliant.[7] Smaller merchants and service providers are not required to explicitly validate compliance with each of the controls prescribed by the PCI DSS although these organizations must still implement all controls in order to maintain safe-harbour and avoid potential liability in the event of fraud associated with theft of cardholder data.

Issuing banks are not required to go through PCI DSS validation although they still have to secure the sensitive data in a PCI DSS compliant manner. Acquiring banks are required to comply with PCI DSS as well as to have their compliance validated by means of an audit.[8]

In the event of a security breach, any compromised entity which was not PCI DSS compliant at the time of breach will be subject to additional card scheme penalties, such as fines.

Mandated compliance

Compliance with PCI DSS is not required by federal law in the United States. However, the laws of some U.S. states either refer to PCI DSS directly, or make equivalent provisions.

In 2007, Minnesota enacted a law prohibiting the retention of payment card data.[9]

In 2009, Nevada incorporated the standard into state law, requiring compliance of merchants doing business in that state with the current PCI DSS, and shields compliant entities from liability.[10]

In 2010, Washington also incorporated the standard into state law. Unlike Nevada's law, entities are not required to be compliant to PCI DSS, but compliant entities are shielded from liability in the event of a data breach.[11]

Compliance and wireless LANs

In July 2009, the Payment Card Industry Security Standards Council published wireless guidelines[6] for PCI DSS recommending the use of wireless intrusion prevention system (WIPS) to automate wireless scanning for large organizations. Wireless guidelines clearly define how wireless security applies to PCI DSS 1.2 compliance.[12]

These guidelines apply to the deployment of wireless LAN (WLAN) in Cardholder Data Environments, also known as CDEs. A CDE is defined as a network environment that possesses or transmits credit card data.[13]

Wireless LAN and CDE classification

PCI DSS wireless guidelines classify CDEs into three scenarios depending on how wireless LANs are deployed.

Key sections of PCI DSS 1.2 that are relevant for wireless security are classified and defined below.

Secure deployment requirements for wireless LANs

These secure deployment requirements apply to only those organizations that have a known WLAN AP inside the CDE. The purpose of these requirements is to deploy WLAN APs with proper safeguards.

Minimum scanning requirements for wireless LAN

These minimum scanning requirements apply to all organizations regardless of the type of wireless LAN deployment in the CDE. The purpose of these requirements is to eliminate any rogue or unauthorized WLAN activity inside the CDE.

PCI compliance in call centers

While the PCI DSS standards are very explicit about the requirements for the back end storage and access of PII (personally identifiable information), the Payment Card Industry Security Standards Council has said very little about the collection of that information on the front end, whether through websites, interactive voice response systems or call center agents. This is surprising, given the high threat potential for credit card fraud and data compromise that call centers pose.[15][16]

In a call center, customers read their credit card information, CVV codes, and expiration dates to call center agents. There are few controls which prevent the agent from skimming (credit card fraud) this information with a recording device or a computer or physical note pad. Moreover, almost all call centers deploy some kind of call recording software, which is capturing and storing all of this sensitive consumer data. These recordings are accessible by a host of call center personnel, are often unencrypted, and generally do not fall under the PCI DSS standards outlined here.[17] Home-based telephone agents pose an additional level of challenges, requiring the company to secure the channel from the home-based agent through the call center hub to the retailer applications.[18]

To address some of these concerns, on 18 March 2011 the Payment Card Industry Security Standards Council issued a revised FAQ about call center recordings.[19] The bottom line is that companies can no longer store digital recordings that include sensitive card data if those recordings can be queried.

Technology solutions can also completely prevent skimming (credit card fraud) by agents. At the point in the transaction where the agent needs to collect the credit card information, the call can be transferred to an Interactive Voice Response system.[20] This protects the sensitive information, but can create an awkward customer interaction. Solutions such as agent-assisted automation allow the agent to capture the credit card information without ever seeing or hearing it. The agent remains on the phone and customers enter their credit card information directly into the customer relationship management software using the keypad of their phone. Agent-assisted automation can stumble however if callers read back the digits as they enter them. DTMF tones are suppressed entirely or converted to monotones so the agent cannot recognize them and so that they cannot be recorded. Some secure payment platforms allows for the masking of the DTMF tones, but are still recorded as DTMF tones by the on-site or hosted call recorders. Traditionally the only way to suppress DTMF tones is to intercept the call at the trunk using sophisticated servers and call cards to do so. This way allows for the suppression or masking of the DTMF tones to the call recorder, as well as the agent.

As recently as June 2014, we saw the introduction of cloud based telephony payment solutions hit the market, but still challenges remain with such deployments as calls need to be routed to the cloud platform before they can be executed onwards to the call center. This is done so the cloud server can intercept the call to control the DTMF tones for secure masking or clamping to both the agent and cloud call recorders. If going through the network cloud, no hardware or software needs to be installed in the organization itself, though cloud solutions remain logistic and integration challenging to both service providers and merchants.

The benefits of increasing the security around the collection of personally identifiable information goes beyond credit card fraud to include helping merchants win chargebacks due to friendly fraud.[21]

Controversies and criticisms

According to Stephen and Theodora "Cissy" McComb, owners of Cisero’s Ristorante and Nightclub in Park City, Utah (which was fined for a breach that two forensics firms could not find evidence even occurred), "the PCI system is less a system for securing customer card data than a system for raking in profits for the card companies via fines and penalties. Visa and MasterCard impose fines on merchants even when there is no fraud loss at all, simply because the fines 'are profitable to them.'"[22]

Additionally, Michael Jones, CIO of Michaels' Stores, testifying before a U.S. Congress subcommittee regarding the PCI DSS, says "(...the PCI DSS requirements...) are very expensive to implement, confusing to comply with, and ultimately subjective, both in their interpretation and in their enforcement. It is often stated that there are only twelve 'Requirements' for PCI compliance. In fact there are over 220 sub-requirements; some of which can place an incredible burden on a retailer and many of which are subject to interpretation."[23]

In contrast, others have suggested that PCI DSS is a step toward making all businesses pay more attention to IT security, even if minimum standards are not enough to completely eradicate security problems.

"Regulation—SOX, HIPAA, GLBA, the credit-card industry's PCI, the various disclosure laws, the European Data Protection Act, whatever—has been the best stick the industry has found to beat companies over the head with. And it works. Regulation forces companies to take security more seriously, and sells more products and services." - Bruce Schneier[24]

Further, per PCI Council General Manager Bob Russo's response to the National Retail Federation: PCI is a structured "blend...[of] specificity and high-level concepts" that allows "stakeholders the opportunity and flexibility to work with Qualified Security Assessors (QSAs) to determine appropriate security controls within their environment that meet the intent of the PCI standards."[25]

Compliance and compromises

According to Visa Chief Enterprise Risk Officer, Ellen Richey, "...no compromised entity has yet been found to be in compliance with PCI DSS at the time of a breach."[26] In 2008, a breach of Heartland Payment Systems, an organisation validated as compliant with PCI DSS, resulted in the compromising of one hundred million card numbers.[27] Around this same time Hannaford Brothers[28] and TJX Companies, also validated as PCI DSS compliant, were similarly breached as a result of the alleged coordinated efforts of Albert "Segvec" Gonzalez and two unnamed Russian hackers.[29]

Assessments examine the compliance of merchants and services providers with the PCI DSS at a specific point in time and frequently utilize a sampling methodology to allow compliance to be demonstrated through representative systems and processes. It is the responsibility of the merchant and service provider to achieve, demonstrate, and maintain their compliance at all times both throughout the annual validation/assessment cycle and across all systems and processes in their entirety.[30] Though it could be that a breakdown in merchant and service provider compliance with the written standard was to blame for the breaches, Hannaford Brothers had received its PCI DSS compliance validation one day after it had been made aware of a two-month-long compromise of its internal systems.[31] The failure of this to be identified by the assessor suggests that incompetent verification of compliance undermines the security of the standard.

Other criticism lies in that compliance validation is required only for Level 1-3 merchants and may be optional for Level 4 depending on the card brand and acquirer. Visa's compliance validation details for merchants state that level 4 merchants compliance validation requirements are set by the acquirer,[32] Visa level 4 merchants are "Merchants processing less than 20,000 Visa e-commerce transactions annually and all other merchants processing up to 1 million Visa transactions annually". At the same time over 80% of payment card compromises between 2005 and 2007 affected Level 4 merchants; they handle 32% of transactions.[33][34]

Compliance as a snapshot

The state of being PCI DSS compliant might appear to have some temporal persistence, at least from a merchant point of view. In contrast, the PCI Standards Council General Manager Bob Russo has indicated that liabilities could change depending on the state of a given organization at the point in time when an actual breach occurs.[35]

Industry best practice for PCI DSS compliance is to continually improve processes to ensure on going compliance, rather than treating compliance as a point in time project.[36]

See also

References

  1. "PCI SECURITY STANDARDS COUNCIL RELEASES VERSION 2.0 OF THE PCI DATA SECURITY STANDARD AND PAYMENT APPLICATION DATA SECURITY STANDARD" (PDF). PCI Security Standards Council. Retrieved 2014-10-14.
  2. Johnson, Laura. "Preparing for PCI DSS 3.2: What to Expect in 2016". blog.pcisecuritystandards.org. Retrieved 2016-02-18.
  3. "Information Supplement: Requirement 11.3 Penetration Testing" (PDF). Retrieved 2014-06-24.
  4. "Information Supplement: Requirement 6.6 Code Reviews and Application Firewalls Clarified" (PDF). Retrieved 2014-06-24.
  5. "Navigating the PCI DSS - Understanding the Intent of the Requirements" (PDF). Retrieved 2014-06-24.
  6. 1 2 "PCI DSS Wireless Guidelines" (PDF). Retrieved 2009-07-16.
  7. "Technology Innovation Program Expanded to Merchants That Implement Point-to-Point Encryption -". Bluefin Payment Systems. Retrieved 2016-02-17.
  8. "PCI Compliance scan". Retrieved 2015-02-12.
  9. "Minnesota Session Laws - CHAPTER 108--H.F.No. 1758".
  10. Nevada Revised Statutes, Chap. 603A §215.
  11. "Wash. Rev. Code § 19.255.020 (2011)" (PDF). Retrieved 2014-04-11.
  12. "Don’t Let Wireless Detour your PCI Compliance" (PDF). Retrieved 2009-07-22.
  13. "Payment Card Industry (PCI) Data Security Standard Glossary, Abbreviations and Acronyms". Pcisecuritystandards.org. Retrieved 2014-06-24.
  14. "Walk Around Wireless Security Audits – The End Is Near" (PDF). Retrieved 2009-07-22.
  15. Little, Allan (March 19, 2009). "Overseas credit card scam exposed". bbc.co.uk.com.
  16. Loviglio, Joann (March 2012). "If Microsoft co-founder's ID isn't safe, is yours?". MSNBC.
  17. "PCI Compliance in the Call Center a Headache for Many". searchcrm.com. Retrieved 2011-01-28.
  18. "PCI Compliance: What it Means to the Call Center Industry". tmcnet.com. Retrieved 2008-02-13.
  19. "Call Center FAQ Significantly Changes".
  20. "Restructuring the Contact Center for PCI Compliance". tmcnet.com. Retrieved 2008-11-10.
  21. Adsit, Dennis (February 21, 2011). "Error-proofing strategies for managing call center fraud". iSixSigma (Ideal Media, LLC).
  22. Zetter, Kim (January 11, 2012). "Rare Legal Fight Takes On Credit Card Company Security Standards and Fines". Wired. Retrieved January 16, 2012.
  23. Jones, Michael (2009-03-31). "TESTIMONY OF MICHAEL JONES BEFORE THE EMERGING THREATS, CYBERSECURITY, AND SCIENCE AND TECHNOLOGY SUBCOMMITTEE" (PDF). Congress of the United States. Archived from the original (PDF) on 2009-03-31. Retrieved 2010-07-19.
  24. "Bruce Schneier reflects on a decade of security trends". Retrieved 2009-02-15.
  25. Russo, Bob (2009-06-15). "Letter to NRF" (PDF). PCI Council. Retrieved 2010-10-19.
  26. Vijayan, Jaikumar (2009). "Visa: Post-breach criticism of PCI standard misplaced".
  27. "Heartland data breach sparks security concerns in payment industry".
  28. McGlasson, Linda (2008-04-04). "Hannaford Data Breach May Be Top of Iceberg". BankInfo Security. Retrieved 2009-01-28.
  29. Goodin, Dan (2009). "TJX suspect indicted in Heartland, Hannaford breaches".
  30. Spier, Peter (2010-03-22). "The QSA's Perspective: PCI Compliance Risk Abounds". BankInfo Security. Retrieved 2010-10-19.
  31. Vijayan, Jaikumar (2009-01-04). "PCI security standard gets ripped at House hearing". Computerworld Security. Retrieved 2009-05-04.
  32. "Merchant PCI DSS Compliance". Visa.
  33. Pastor, Adrian (2009). "A Pentester’s Guide to Credit Card Theft Techniques" (PDF).
  34. "Level 4 Merchant Compliance Program (slide 6)" (PDF). June 28, 2007.
  35. "Q and A: Head of PCI council sees security standard as solid, despite breaches". Retrieved 2009-02-15.
  36. "Best Practice For Implementing PCI DSS In To Your Organisation". Retrieved 2015-02-15.

Books on PCI DSS

External links

This article is issued from Wikipedia - version of the Wednesday, May 04, 2016. The text is available under the Creative Commons Attribution/Share Alike but additional terms may apply for the media files.