PCI DSS Overview

The Payment Card Industry Standard (PCI DSS) is a compliance standard that governs the processing, storage or transmission of cardholder data. PCI DSS applies to any organisation which processes, stores or transmits cardholder data. Organisations can be classified as a merchant or service provider. An important point to note is that the standard is not just an IT compliance standard it effects all areas of an organisation.

PCI DSS Background
The PCI DSS was founded in December 2004 by 5 major card brands – Visa, MasterCard, American Express, Discover and JCB. The ongoing maintenance and updates to the standard are performed by the Payment Security Standards Council (PCI SSC), an independent organisation, joint funded by all the participating card brands and participating organisations. The PCI DSS is now on its 4th major release which is now at v2.0.

It is important to note that compliance is not a legal requirement but it is driven by the contractual agreements between merchants and acquiring banks that cannot be ignored.

PCI DSS Requirements
The PCI DSS are broken down into 6 domains that have various sections and associated requirements within each section which are as follows:

  • Build and Maintain a Secure Network

    1. Install and maintain a firewall configuration to protect cardholder data

    2. Do not use vendor-supplied defaults for system passwords and other security parameters

  • Protect Cardholder Data

    3. Protect stored cardholder data

    4. Encrypt transmission of cardholder data across open, public networks

  • Maintain a Vulnerability Management Program

    5. Use and regularly update anti-virus software on all systems commonly affected by malware
    6. Develop and maintain secure systems and applications

  • Implement Strong Access Control Measures

    7. Restrict access to cardholder data by business need-to-know

    8. Assign a unique ID to each person with computer access

    9. Restrict physical access to cardholder data

  • Regularly Monitor and Test Networks

    10. Track and monitor all access to network resources and cardholder data

    11. Regularly test security systems and processes

  • Maintain an Information Security Policy

    12. Maintain a policy that addresses information security

Why should an organisation comply with the PCI DSS?
There are a number of benefits of attaining PCI DSS compliance;

  • Provides your customers with assurance that card transactions will be handled securely by your organisation

  • Level 1 service providers who achieve PCI DSS compliance can ask to be added to the Visa and

  • MasterCard lists of approved service providers

  • Avoidance of financial penalties which are divided into two areas:
    1. Non–Compliance Costs

    2. Data Breach Costs Can include:

      o Fines levied by your acquirer for the cardholder data breach

      o Elevation to a level 1 merchant, increasing your ongoing compliance costs

      o The need to have an onsite QSA assessment which will add significant overhead to the demonstration of compliance

      o Consultancy costs for forensic assessments & remediation advice

      o Potential liability for consequential losses due to the card data breach

      o The fines which may be levied for non-compliance are potentially unlimited

Common Misconceptions
The following are common misconceptions in relation to PCI DSS compliance;

  • You can’t fully outsource all your PCI DSS accountability although you can outsource most of the responsibility for the provision of services; remember some areas of the standard will ALWAYS remain in scope.

  • Using a PA DSS compliant application – or a PCI PTS compliant PED does not automatically make your company PCI DSS compliant

  • A PCI DSS assessment/ SAQ completion is just a snap-shot. Compliance with PCI DSS must be maintained at all times, and evidence of this needs to be available

  • PCI DSS is NOT an IT compliance standard, it affects all facets of an organisation

For further information on our PCI compliance services, please contact one of our Sales representatives by calling +353 (0)1 495 1300 or by completing our Online Enquiry Form or Request a Call Back Form.

Sysnet Global Solutions attains Approved Payment Forensics Investigator (PFI) status

Sysnet Global Solutions, a leading worldwide provider of information security and assurance services, today announced that they have attained the status of approved Payment Forensics Investigator (PFI), confirmed by the PCI Security Standards Council (PCI-SSC). Sysnet are now listed on the PCI-SCC website as approved PCI Forensic Investigators;
www.pcisecuritystandards.org/approved_companies_providers/pfi_companies.php

The PCI Security Standards Council’s PFI program establishes and maintains the rules and requirements regarding eligibility, selection and performance of companies that provide forensic investigation services to ensure they meet PCI Security Standards. The PFI program aims to help simplify and expedite procedures for approving and engaging forensic investigators. The PFI list will replace the previous ‘QFI’ list as of March 1, 2011. After March 1, the card brands will only accept forensic reports from companies that are on the PFI list.

With the growing threat of credit card fraud across the globe and more aggressive tactics shown by organised criminal groups, if an Account Data Compromise (ADC) does occur and an investigation is required, Sysnet are well equipped to minimise the potential loss and ensure that the affected organisation is back to trading in a safe, compliant manner as soon as possible.

“This achievement is the result of the cumulative effort of a number of people at Sysnet and we are delighted that we are now on the PFI list” said Nick Prescot, Senior Consultant of the Data Forensics team at Sysnet Global Solutions “Whilst we wish that no organisation suffers a data compromise, we can now demonstrate that the Sysnet approach to quality, dedication and thoroughness will ensure that, should the worst happen, the end result will be an organisation that is not only above and beyond the requirements of today’s compliance but also well prepared for the future.”

In preparing and rehearsing against potential account data compromises, Sysnet Global Solutions offer incident management workshops, intelligence briefings on the latest trends, briefings on best practice in securing personal data, guidance on how to deal with the legal aspects of an investigation and insurance services that enable organisations to be best prepared in the event of a data compromise.

“This is a very important achievement for Sysnet” said Gabriel Moynagh, General Manager at Sysnet Global Solutions “Our PFI status compliments the extensive range of products and services we currently provide and further increases our ability to assist our clients in protecting vital business information assets.”


For further information on our PFI Consultancy Services, please contact one of our Sales representatives by calling +353 (0)1 495 1300 or by completing our Online Enquiry Form or Request a Call Back Form.

Sysnet to present at the Vendorcom PCI & Payment Security Retailer Breakfast Briefing

Sysnet Global Solutions, a leading worldwide provider of information security and assurance services, will present at the Vendorcom PCI & Payment Security Retailer Breakfast Briefing on March 1st 2011. The event, which takes place in London, will address the information security issues faced by merchants.

The briefing will take the form of short presentations that will provide attendees with up-to-date information that will help improve the security of payment data and move PCI to a business as usual process.

“The data forensics team at Sysnet are very excited to be part of the Vendorcom breakfast briefings” said Nick Prescott, Senior Consultant – Data Forensics, at Sysnet Global Solutions, “Cyber warfare is a relatively new and growing phenomenon and no more so than within the realms of cardholder data. We are passionate about educating, preventing and, when an unfortunate event happens, responding to incidents and ensuring that all businesses affected from a breach emerge from an incident with a renewed confidence in security.”

The presentations will be followed by a Questions & Answers session, during which the speakers will be joined by Nick Heape of Visa Europe and Phil Jones of Barclaycard.

The briefing will take place at the Herschel Room, 76 Portland Place, London, W1B 1NT and will commence at 8.00am and will conclude at 10.30am.

To register a place at this briefing, please go to the following link: www.vendorcom.com/register.php?event_id=78

PCI & Payment Security Retailer Breakfast Briefing – Tuesday 1st March, London


and supported by BARCLAYCARD & VISA EUROPE
Sysnet Global Solutions is proud to be supporting – and speaking at – the Vendorcom PCI & Payment Security Retailer Breakfast Briefing on March 1st and we’d be delighted if you could join us.
This briefing will take the form of short, punchy, focused presentations that will provide you with up to date, accurate information that will help you improve the security of your payment data, move PCI to a business as usual process and ensure that you keep both the business and the customer happy; all this – and not a sales pitch in sight!!
In this briefing, with the help of both ourselves and Tripwire, Vendorcom will be looking at the business impact of PCI & Payment Security:
  • What is the cost of compliance (versus non compliance)?
  • How do you work with your suppliers to minimise the risk of a security breach?
  • If you are breached, what steps can you take to minimise the impact both directly on your customer and on your brand?

Following these presentations, there will also be a Q&A panel, where the speakers will be joined by Nick Heape of Visa Europe and Phil Jones of Barclaycard. This is the opportunity to ask ourselves and the rest of the expert panel your unanswered PCI & Payment Security questions. There will also be time after the session to stay on, ask any additional questions that may not have been answered in the group session – and to network with your peers, the panellists and the Vendorcom team.

It may not always feel like it, but as an industry we are here to help – please take advantage of us!!

Please Note: This briefing is FREE to attend

Agenda:

0800 - 0830 Registration, Breakfast & Networking

0830 - 0840 Welcome & Introduction
Paul Rodgers, Chairman – Vendorcom

0840 - 0905 The True Cost of Compliance

Tripwire have recently completed research into the True Cost of Compliance to determine the full costs associated with an organisation’s compliance efforts. This presentation will highlight the recently released benchmark study of multinational organisations providing a clear understanding of the differences between compliance and non-compliance costs incurred when complying with laws, regulations and policies.
Mike Shanahan, Account Director - Tripwire

0905 – 0930 The Security Breach: Guarding Against and Reacting To!

The PCI DSS is designed to help us guard our business against security breaches – that’s all well and good, but how do we work better with suppliers to ensure that they’re working to reduce our risk as well? And if the worst happens and we are breached, what is the best course of action? In essence, this session will encourage you to prepare for a breach, know how to limit your exposure to the risk of a breach and understand what best to do in the event of an account data compromise.
Nick Prescot, Senior Consultant, Forensics – Sysnet Global Solutions

0930 – 1000 Q&A Panel

What do you really want to know? What is the most burning question you have about PCI & Payment Security that remains unanswered? Now is your chance to ask it!!
Mike Shanahan (Tripwire), Nick Prescot (Sysnet), Nick Heape (Visa Europe), Phil Jones (Barclaycard), Paul Rodgers (Vendorcom)

1000 – 1030 Coffee & Networking

Your time away from the business is precious, we recognise that, and that’s why we’ve kept this session short and snappy! However, we also know that there’s never enough time to answer everybody’s questions in an open session – and indeed there may well be questions that you don’t want to ask in an open session.

So, the Vendorcom team, our speakers and our panel will all be staying on for coffee after the session so that, if you want to, you can spend an extra few minutes/half an hour, asking questions and taking the opportunity to share experiences with your peers – who knows what additional nuggets of information you could pick up that might just help your business!

Date: Tuesday 1st March 2011

Time: 0800 (for a prompt 0830 start) – 1000 (with opportunity to stay on through to 1030 to ask additional questions/network)

Venue: Herschel Room, 76 Portland Place, London, W1B 1NT

Map: Click here
Nearest Underground Station: Regents Park (Bakerloo Line), Great Portland Street (Circle, Hammersmith & City, Metropolitan Lines)

Cost: This event is FREE to attend

Registration: To confirm your place at this event: Register Here

We hope that you will be able to join us, Vendorcom and Tripwire on 1st March.

Sysnet Global Solutions announces appointment of new Regional Manager for North America

Sysnet Global Solutions, a leading worldwide provider of information security and assurance services, today announced the appointment of Bill Hodge as Regional Manager for North America with immediate effect. Bill will be based in Knoxville, Tennessee.

In this role, Bill will oversee Sysnet’s North American based business activities with an emphasis on new business development and client relationship management.

“We are very pleased to welcome Bill to the company” said Tom Moynagh, Managing Director at Sysnet, “Bill has considerable experience in the Information Security industry having provided consultancy, audit and risk assessment services to businesses operating in a wide variety of industries. We look forward to working with Bill and to the further development of our US based business.

“I am delighted that Sysnet have identified North America as a key region for business growth.” said Bill Hodge, Regional Manager for North America “This is a critical time for many organizations as they struggle to both maintain regulatory compliance and protect their businesses whilst also adhering to strict budget controls. I am confident that Sysnet can provide the best value services to assist such organisations in meeting all of these requirements.”

Bill graduated from East Tennessee State University with Bachelor and Masters Degrees after serving in the United State Marine Corps. He also holds AAS in Computer Science from the Pellissippi State Technical Community College, and has earned the CISA and CISSP certifications.

Further key personnel appointments for the North American region are expected in the near future.

Sysnet announces relocation of headquarters to accomdate business expansion

Sysnet Global Solutions, a leading worldwide provider of information security and assurance services, today announced that due to significant business expansion they have relocated their Dublin headquarters to 4th Floor, The Herbert Building, The Park, Carrickmines, Dublin 18.

“We are very pleased to announce the relocation of our Dublin based headquarters to accommodate our growing workforce” said Gabriel Moynagh, General Manager at Sysnet Global Solutions “During the past year we significantly increased our staff numbers to support recently announced client wins, including two major banking clients. The majority of new hires have been to support our Compliance Managed Services solution that provides PCI DSS merchant portfolio compliance validation for banking and other acquiring organisations. Similar growth is expected during 2011 with further new client announcements to follow.”

PCI DSS is a set of comprehensive requirements for enhancing the security of payment account data, transactions and processing systems. It was developed by the founding payment brands of the PCI Security Standards Council, and has been adopted by third party processors and merchant acquirers globally to combat cardholder data fraud.

Sysnet’s new headquarters will cater for both its current and future business expansion requirements. The company also recently opened their new UK based office at Davidson House, Forbury Square, Reading, RG1 3EU Tel. +44 (0)118 900 1510.

The importance of PCI Compliance

Before the PCI DSS was established, various card brands set up their own security programmes in order to protect card holder data and identity theft due to ongoing data compromises occurring at numerous levels.

In 2006, the five major card brands (Visa, MasterCard, American Express, Discover Card and JCB) then decided to unify their policies and procedures under one universal standard that was called the Payment Card Industry Data Security Standard (PCI DSS). The PCI council governs the payment industry and ensures that all entities accepting, storing or transmitting credit card data adhere to the PCI DSS. The aim is to reduce the number of security breaches and protect the card brands.

PCI DSS can help organisations to;

• protect valuable customer information including payment card details
• protect against the loss of valuable business information and the cost associated with data compromise
• protect against the negative publicity associated with a data breech
• ensure continued customer confidence in the use of payment cards

How does an organisation attain PCI compliance?

An organisation can attain PCI compliance by conforming to the 12 security requirements set out within the PCI DSS. Depending on their merchant level an organisation that is accepting, storing or transmitting card data can become PCI DSS compliant by either submitting a validated Self-Assessment Questionnaire (SAQ) or by undergoing an onsite assessment with a Qualified Security Assessor (QSA).

The merchant level depends on the volume of transactions that they are handling per annum. An organisation that is handling 6 million transactions or more must have an onsite assessment carried out each year by a QSA as well as quarterly network scans.
However, an organisation that is handling 20,000 to 6 million transactions per year can fill out an SAQ but must also undergo quarterly scans of their external network in order to conform to PCI compliance. For organisations handling less than 20,000 transactions per year, they must also undergo quarterly scans on their network and complete an SAQ.

If an organisation that is handling card data from one of the PCI council member brands falls victim to a security breach, they can incur a significant fine and be banned from handling future credit card payments for any of the five major card brands.

For further information on our PCI compliance services, please contact one of our Sales representatives by calling +353 (0)1 495 1300 or by completing our Online Enquiry Form or Request a Call Back Form.