Showing posts with label payment card industry. Show all posts
Showing posts with label payment card industry. Show all posts

Thursday, 30 January 2014

Target. A Series of Unfortunate Events



Source: yahoo.news.com


It started right before the holidays, with Brian Krebs’ first report on a 40 mil. financial data breach at Target stores.  News followed that a further 70 mil. accounts containing personal identifiable information was also compromised during the heist.

From then on the focus was on how  the breach happened, what software was deployed, where did Target go wrong and who should take the best part of the blame. Meanwhile, Target provided customers with a sign up for free credit monitoring and identity theft protection system and announced it will invest $5mil in a brand new cyber security coalition. 

But that’s not the end of the problems for the retailer.

Alongside Target, the retail industry is experiencing a surge in cyber attacks and POS malware. The FBI re-assures us that they are aware of these attacks and they are not likely to stop. Compliance is widely criticised as Target was in fact compliant with the PCI DSS standards and it did nothing to stop these spectacular attacks. 

However the infosec community is looking at the entire story with a shaking head and a look of “I told you so”, because researchers have long stated that compliance does not mean security. Previous incidents at Wall-Mart and Heartland Payment Systems had left an even more embarrassing mark on compliance, as they were certified compliant while their networks were in the process of being hacked.

The implications of these recent hacks are wide and diverse. Banks will tighten their liability policies, payment providers will continue to issue fines for poor cyber security measures, while retailers deal with bad publicity and falling share prices. 
This in turn affects economies and market statutes while the customer is left in the middle with the choice of a week’s worth of hassle for cancelling a compromised card and/or the expense of a lawsuit against the retailer.

It seems that all these industries should take a break from trying to only protect themselves and come together for a long-term cooperation strategy centered around the key player: the consumer.  As it stands every industry is furiously trying to escape the responsibility and pass an already irritated and distrustful victim from one institution to another. 

This may work for the time being, but will only lead to a deeper lack of trust in a flawed system.  There is more to be done to educate, prevent and restore trust, and this will take a cooperative and supportive effort from all the industries if they continue to expect customers to hand over their data. 


Tuesday, 10 December 2013

What Is PCI Compliance?



PCI Compliance – Payment Card Industry Data Security Standard is a set of requirements designed to ensure all businesses which handle credit card information maintain a secure environment. It was created by the five major card schemes like American Express, JCB, Visa, MasterCard and Discover Financial Services to prevent and reduce card data fraud. Even though it does not have any legislative power the regulators can apply fines, or increase transaction fees or terminate the relationship with the merchant.

Source: bigcommerce.com
PCI compliance came about in order to improve payment procedure security, but the responsibility to enforce compliance lies with the merchants and customers not with the PCI council.

Even more to the benefit of individuals running businesses from home, PCI compliance can at least offer guidance on security measures, since intruders do focus on the home users as “easy targets” with home run applications that are not adequately protected.

For all external facing IP address merchants that store cardholder data, a quarterly scan by a PCI Approved Scanning Vendor is compulsory to validate the compliance.

Usually for a merchant to be declared compliant, the process will involve internal scans, penetration tests and file monitoring for the cardholder data environment. If customers need transference to a third-party website during transaction, then the third-party IP address needs to be submitted to the scan as well.

PCI DSS guide on security requirements consists of six rules:
·         Build and maintain a secure network and systems
·         Protect cardholder data
·         Maintain a vulnerability management program
·         Implement strong access control measures
·         Regularly monitor and test networks
·         Maintain an information security policy



PCI compliance council categorises merchants under 4 levels:
1.       Merchants processing over six million Visa transactions per year, regardless of transaction channel.
2.       Merchants processing one million to six million Visa transactions per year, regardless of transaction channel.
3.       Merchants processing 20,000 to 1 million Visa transactions per year, e-commerce transactions.
4.       Merchants processing fewer than 20,000 Visa e-commerce transaction, and all other merchants processing up to 1 million Visa transactions per year, regardless of transaction channel.