PCI DSS Certification

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

6 comments

Comments 1 - 6 of 6 previous next Post a comment

Post a comment
Embed Video
Edit your comment Cancel

3 Favorites

PCI DSS Certification - Presentation Transcript

  1. PCI Certification Issues
      • May 2008
  2. Evolution of PCI DSS
    • 2000 Visa CISP(USA) and AIS (EU)‏
    • 2000 Mastercard SDP.
    • 2004 – Visa, Mastercard, American Express and JCB agree PCI Standard.
      • The objective of PCIDSS compliance is designed to protect the card companies, merchants and consumers from suffering financial and data loss because of unprotected network systems.
  3. Validation Requirements
  4. The Requirements
  5. Recent Changes
    • Self Assessment Questionnaire (SAQ)‏
      • Four SAQ's instead of one.
  6. Recent Changes
    • Payment Application Best Practices
      • Launched in 2005
      • List of validated payment applications published monthly since January 2006.
      • PABP to move to the Payment Application Security Standard (PASS) and will be administrated through the PCI SSC.
      • Applicable to any third party payment application that is involved in authorisation and settlement of credit/debit card transactions.
      • Is not applicable to dumb terminals, database or web server software. Does apply to applications built on DB & Web.
  7. Top Reasons for Audit Failures
  8. PCI Pitfalls
    • Track2/CVV2/CVC2 logging.
    • Implementing Policies that address each of the requirements of the PCI DSS.
    • Restricting Access to Databases
    • Performing Log review.
    • File Integrity Monitoring
  9. Risk Reduction Strategies
    • Data Elimination
    • Tokenisation
  10. Actions
    • Only deploy third party applications on the PABP/PASS list
    • Confirm all entities in the transaction chain are PCI certified and audited
    • Ensure all current staff aware of their data security obligations
    • Verify that no card data is extracted to be further analysed
    • Check what happens sensitive data files after transmission/receipt
  11. Actions
    • Make PCI Compliance a year round activity
    • Confirm that all new processes and procedures vetted against the PCI Data Security Standard
    • Investigate opportunities for the elimination of card data.
  12. Further Information
    • Knowledge Base at
      • http://www.o-cgroup.com
    • PCI Validation Requirements
      • http://www.o-cgroup.com/pci-requirements.php

+ hodonoghuehodonoghue, 2 years ago

custom

1211 views, 3 favs, 0 embeds more stats

An understanding of and practical tips for PCI DSS more

More info about this document

© All Rights Reserved

Go to text version

  • Total Views 1211
    • 1211 on SlideShare
    • 0 from embeds
  • Comments 6
  • Favorites 3
  • Downloads 56
Most viewed embeds

more

All embeds

less

Flagged as inappropriate Flag as inappropriate
Flag as inappropriate

Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

Cancel
File a copyright complaint
Having problems? Go to our helpdesk?

Categories