Don’t Fear PCI DSS!

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    Notes on slide 1

    What is PCI DSS? Why is it here? Who is applies to? What should you do? How to make it easier? Common myths about PCI

    Visa and MasterCard have had their own Security Programs for years, with separate, and sometimes conflicting, requirements. CISP & QDSC (VISA) SDP (MasterCard) Due to rampart Data Breaches & Credit Card Fraud, a unified approach was needed. The PCI Council was founded.

    PCI DSS is an industry standard that highlights the following: The PCI Data Security Standard is endorsed by the “Participating Brands”: Visa, MasterCard, American Express, Discover Card, JCB and Diners’ Club. Standardized Security Requirements Consistent validation requirements and protocols Common evaluator credentials and approvals Clear procedures for review and reassessment Slide Point of Contact: Eduardo Perez

    Cash business!

    PCI is a standard that can be understood and followed. All major Credit Card companies are supporting the standard. Quarterly compliance is a requirement regardless of Merchant or Service Provider Level. It is important to choose the right solutions and vendors to help you secure your critical data and automate the compliance process. Additional Information can be found at: https://www.pcisecuritystandards.org/ http://www.qualys.com/pci_compliance/wesem/

    Favorites, Groups & Events

    Don’t Fear PCI DSS! - Presentation Transcript

    1. Don’t Fear PCI DSS! Even Though It Can Be Scary At Times July 16-17, 2009 Napa Valley Marriott July 16-17, 2009 Napa Valley Marriott Dr. Anton Chuvakin [email_address] Security Warrior Consulting
    2. WARNING!
      • This is a very, very, very basic PCI DSS presentation.
      • PCI literati … take notice of that 
      July 16-17, 2009 Napa Valley Marriott
    3. Agenda
      • What is PCI DSS?
      • Who it applies to?
      • Why is it here?
      • What should you do?
      • How to make it easier?
      • Common myths about PCI
      July 16-17, 2009 Napa Valley Marriott
    4. What is PCI DSS or PCI?
      • Payment Card Industry Data Security Standard
      • Payment Card =
      • Payment Card Industry =
      • Data Security =
      • Data Security Standard =
      July 16-17, 2009 Napa Valley Marriott
    5. PCI Security Standards Council
      • New organization formed to promote PCI compliance .
      • Founded by:
        • American Express
        • Discover Financial Services
        • JCB
        • MasterCard Worldwide
        • Visa International
      • Approves security vendors
        • Approved Scanning Vendors (ASV) – Quarterly Scans
        • Qualified Security Assessor (QSA) – On-Site Assessments
    6. PCI Data Security Standard
      • The PCI Council published the PCI DSS –Data Security Standard
          • Outlined the minimum data security protections measures for payment card data.
          • Defined Merchant & Service Provider Levels, and compliance validation requirements.
          • Left the enforcement to card brands (Council doesn’t fine anybody)
      • In October 2008 the PCI Council updated the PCI DSS to v1.2
      • The next change is in 2010
    7. PCI DSS is based on fundamental data security practices PCI Data Security Standard In-Depth
      • Protect stored data
      • Encrypt transmission of cardholder data and sensitive information across public networks
      Protect Cardholder Data
      • Maintain a policy that addresses information security
      Maintain an Information Security Policy
      • Track and monitor all access to network resources and cardholder data
      • Regularly test security systems and processes
      Regularly Monitor and Test Networks
      • Restrict access to data by business need-to-know
      • Assign a unique ID to each person with computer access
      • Restrict physical access to cardholder data
      Implement Strong Access Control Measures
      • Use and regularly update anti-virus software
      • Develop and maintain secure systems and applications
      Maintain a Vulnerability Management Program
      • Install and maintain a firewall confirmation to protect data
      • Do not use vendor-supplied defaults for system passwords and other security parameters
      Build and Maintain a Secure Network
    8. Why is PCI Here?
      • Criminals need money
      • Credit card = money
      • Where are the most cards? In computers.
      • Data theft grows and reaches HUGE volume
      • Some organizations still don’t care …
      • … . especially if the loss is not theirs
      • Payment card brands enforce DSS!
      July 16-17, 2009 Napa Valley Marriott
    9. Does it Apply to Me?
      • “ PCI DSS compliance includes merchants and service providers who accept , capture , store , transmit or process credit and debit card data.”
      C O M P A N Y C O N F I D E N T I A L
    10. Can I Pretend It Doesn’t Exist?
      • Well, yes.
      • YES-YOU-CAN!!! 
      • “ It is not necessary to change. Survival is not mandatory.”
      • William Edwards Deming
      • In other words, you can do business with cash!
      July 16-17, 2009 Napa Valley Marriott
    11. Can I Make It Easier? PCI DSS Tips
      • Scope
        • “ Don’t’ touch that … ‘stuff’” (if you can) -> outsource !
        • Don’t store card prohibited card data (CVV2, PIN, etc)
        • Don’t store any card data – revisit your storage reasons
      July 16-17, 2009 Napa Valley Marriott
    12. More PCI DSS Tips
      • Protection – comes AFTER scope reduction!
        • Install and update anti-malware
        • Change passwords : writing passwords > easy passwords
        • Vulnerability scans : close the obvious hacker holes
      July 16-17, 2009 Napa Valley Marriott
    13. So, What Should I Do?
      • Less card data -> less work needed!!! (Yes, 3 times  )
      • PCI is common sense, basic data security; stop complaining about it - start doing it!
      • After validating that you are compliant, don’t stop: ongoing compliance AND security is your goal , not “passing an audit”
      July 16-17, 2009 Napa Valley Marriott
    14. Final Word: “It Can’t Happen to Me!”
      • It probably already did !
      July 16-17, 2009 Napa Valley Marriott
    15. The “PCI Compliance” Book Out Soon!
          • Get as much information as you can about PCI and how it relates to your organization!
      • Q: More information?
      • A: Get THE PCI book: “PCI Compliance” by Anton Chuvakin and Branden Williams (out in Nov 2009!)
      • Also look at authors blogs:
      • chuvakin.blogspot.com/search/label/PCI
      • brandenwilliams.com/blog
    16. Q&A C O N F I D E N T I A L Thank You [email_address]
    17. Eight Common PCI Myths
      • PCI just doesn’t apply to us , because…
      • PCI is confusing and not specific !
      • PCI is too hard
      • Recent breaches prove PCI irrelevant
      • PCI is easy : we just have to “say Yes” on SAQ and “get scanned”
      • My network, application, tool is PCI compliant
      • PCI is all we need to do for security!
      • Even if breached and then found non-compliant, our business will not suffer

    + Anton ChuvakinAnton Chuvakin, 1 month ago

    custom

    197 views, 0 favs, 0 embeds more stats

    Don’t Fear PCI DSS! Even Though It Can Be Scary more

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 197
      • 197 on SlideShare
      • 0 from embeds
    • Comments 0
    • Favorites 0
    • Downloads 0
    Most viewed embeds

    more

    All embeds

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories