SlideShare a Scribd company logo
PCI Compliance: Avoiding the Pitfalls in Keeping 
Your SAP® System Fully Compliant and Secure 
Presenter: 
Eric 
Bushman, 
VP 
Solu6ons 
Engineering 
October 
24, 
2014 
©2014. 
Paymetric. 
All 
Rights 
Reserved. 
1
Agenda 
§ PCI 
DSS 
Requirements 
Overview 
§ Common 
Data 
Security 
Challenges 
within 
SAP® 
§ Best 
Prac6ces 
When 
Dealing 
with 
Raw 
Card 
Numbers 
§ How 
to 
Solve 
for 
these 
Challenges 
§ Why 
Paymetric 
§ Q&A 
October 
24, 
2014 
2 
©2014. 
Paymetric. 
All 
Rights 
Reserved.
3 
What 
is 
PCI 
Compliance? 
©2014. 
Paymetric. 
All 
Rights 
Reserved. 
Sec4on 
Category 
Build 
and 
Maintain 
a 
Secure 
Network 
Protect 
Cardholder 
Data 
Maintain 
a 
Vulnerability 
Management 
Program 
Implement 
Strong 
Access 
Controls 
Measures 
Regularly 
Monitor 
and 
Test 
Networks 
Maintain 
an 
Informa6on 
Security 
Policy 
Requirement 
1. 
Install 
and 
maintain 
a 
firewall 
configura6on 
2. 
Do 
not 
use 
vendor-­‐supplied 
defaults 
for 
system 
passwords 
3. 
Protect 
stored 
cardholder 
data 
4. 
Encrypt 
transmission 
of 
cardholder 
data 
5. 
Use 
and 
regularly 
update 
an6-­‐virus 
soZware 
6. 
Develop 
and 
maintain 
secure 
systems 
and 
applica6ons 
7. 
Restrict 
access 
to 
data 
by 
business 
need-­‐to-­‐know 
8. 
Assign 
a 
unique 
ID 
to 
each 
person 
with 
computer 
access 
9. 
Restrict 
physical 
access 
to 
network 
resources 
and 
card 
data 
10. 
Track 
and 
monitor 
all 
access 
to 
network 
resources 
and 
card 
data 
11. 
Regularly 
test 
security 
systems 
and 
processes 
12. 
Maintain 
a 
policy 
that 
address 
informa6on 
security
Data Security Challenges in SAP® 
§ Order 
Entry 
or 
Collec6ons 
workflows 
require 
card 
details 
to 
be 
entered 
into 
SAP 
and 
used 
for 
the 
payment 
transac6ons 
§ Even 
storing 
cards 
on 
a 
customer 
master 
record 
requires 
entry 
of 
RAW 
cards 
at 
some 
point 
in 
some 
applica6on 
October 
24, 
2014 
4 
©2014. 
Paymetric. 
All 
Rights 
Reserved.
Best Practices 
The 
Golden 
Rule: 
Avoid 
exposure 
of 
RAW 
cards 
in 
your 
SAP 
system 
as 
much 
as 
possible 
§ Don’t 
allow 
interfaces 
to 
pass 
RAW 
card 
numbers 
into 
SAP 
October 
24, 
2014 
5 
©2014. 
Paymetric. 
All 
Rights 
Reserved. 
§ Check 
BAPI 
interfaces 
§ Check 
IDOC 
interfaces 
§ Check 
File/Excel 
upload 
interfaces
Best Practices 
§ Use 
XiIntercept 
solu6ons 
to 
prevent 
direct 
entry 
of 
RAW 
cards 
in 
SAP 
GUI 
and/or 
SAP 
HTML 
interfaces 
October 
24, 
2014 
6 
©2014. 
Paymetric. 
All 
Rights 
Reserved. 
§ XiIntercept 
for 
SAP 
can 
be 
used 
during 
capture 
in 
the 
SAP 
GUI 
§ XiIntercept 
for 
Ecommerce 
can 
be 
used 
during 
capture 
in 
the 
SAP 
HTML 
GUI 
§ Use 
SAP 
Card 
Valida6on 
rules 
that 
prevent 
entry 
of 
RAW 
card 
data 
– 
flags 
it 
as 
an 
error 
and 
disallows 
entry
Best Practices 
§ Don’t 
allow 
users 
to 
view 
detokenized 
cards 
in 
SAP 
October 
24, 
2014 
7 
©2014. 
Paymetric. 
All 
Rights 
Reserved. 
§ Deac6vate 
calls 
to 
the 
detokenized 
service 
via 
SAP 
§ Only 
allow 
users 
to 
reference 
and 
view 
RAW 
card 
data 
in 
Paymetric 
Repor6ng 
Portal 
(XiPay 
Web 
GUI) 
interface 
§ Train 
users 
to 
prevent 
entry 
of 
RAW 
card 
numbers 
in 
text 
fields 
where 
valida6ons 
and 
tokeniza6on 
can’t 
be 
performed
Best Practices 
§ Convert 
to 
tokens 
and 
purge 
any 
exis6ng 
RAW 
or 
encrypted 
data 
in 
the 
SAP 
database 
October 
24, 
2014 
8 
©2014. 
Paymetric. 
All 
Rights 
Reserved. 
§ Customer 
Master 
records 
§ Historical 
transac6onal 
data 
§ Text 
fields 
§ If 
you 
are 
capturing 
CVV 
values 
for 
transmission 
in 
Authoriza6on 
calls 
in 
SAP, 
ensure 
that 
you’ve 
applied 
the 
OSS 
notes 
to 
prevent 
storage 
of 
the 
CVV 
value 
in 
the 
SAP 
DB
Solution Overview 
§ Easily 
scales 
across 
the 
SAP 
landscape 
§ Gives 
merchants 
the 
argument 
that 
SAP 
is 
out 
of 
scope 
for 
a 
PCI 
DSS 
audit 
§ Eliminates 
data 
exposure 
in 
the 
event 
of 
a 
data 
breach 
§ Centralizes 
configura6on 
and 
audi6ng 
October 
24, 
2014 
9 
©2014. 
Paymetric. 
All 
Rights 
Reserved.
Paymetric Cloud-Based Environment 
October 
24, 
2014 
10 
©2014. 
Paymetric. 
All 
Rights 
Reserved.
Create 
A 
Tokeniza4on 
Layer 
Around 
Your 
Enterprise 
October 
24, 
2014 
11 
©2014. 
Paymetric. 
All 
Rights 
Reserved.
October 
24, 
2014 
12 
©2014. 
Paymetric. 
All 
Rights 
Reserved. 
for SAP® 
Remove 
Systems 
from 
Your 
Cardholder 
Data 
Environment 
(CDE) 
Sensi4ve 
card 
data 
entered 
within 
SAP 
is 
intercepted 
and 
secured 
by 
XiIntercept
XiIntercept for eCommerce 
October 
24, 
2014 
13 
Intercept 
Card 
Data 
at 
the 
Earliest 
Point 
©2014. 
Paymetric. 
All 
Rights 
Reserved. 
of 
Your 
Workflow 
Paymetric 
intercepts 
and 
secures 
shaded 
data 
fields
SAQ 
Valida4on 
Types 
May 
Qualify 
Your 
Organiza4on 
for 
Self 
Assessment 
Ques4onnaire 
C, 
Reducing 
the 
Number 
of 
Compliance 
Requirements 
from 
263 
to 
139 
SAQ 
Valida4on 
Type 
October 
24, 
2014 
14 
©2014. 
Paymetric. 
All 
Rights 
Reserved. 
Descrip4on 
Number 
of 
Ques4ons 
A 
Card-­‐not-­‐present 
merchants 
14 
A-­‐EP 
eCommerce 
merchants 
redirec6ng 
to 
a 
third-­‐party 
website 
139 
C 
Merchants 
with 
payment 
applica6ons 
systems 
connected 
to 
the 
Internet 
140 
D-­‐MER 
All 
other 
SAQ-­‐eligible 
merchants 
263
Reduce 
PCI 
DSS 
Audit 
Scope 
May 
Qualify 
Your 
Organiza4on 
for 
Self 
Assessment 
Ques4onnaire 
C, 
Reducing 
the 
Number 
of 
Compliance 
Requirements 
from 
263 
to 
139 
300 
250 
200 
150 
100 
October 
24, 
2014 
15 
50 
©2014. 
Paymetric. 
All 
Rights 
Reserved. 
14 
Number 
of 
Ques4ons 
Per 
SAQ 
139 
140 
263 
0 
SAQ 
A 
SAQ 
A-­‐EP 
SAQ 
C 
D-­‐MER
Why Paymetric 
October 
24, 
2014 
16 
©2014. 
Paymetric. 
All 
Rights 
Reserved.
Cer4fica4ons 
§ SAP 
Enterprise 
Services 
Interface 
§ SAP 
Cross-­‐Applica6on 
Payment 
Card 
Interface 
§ Level 
1 
PCI 
DSS 
Cer6fied 
Service 
Provider 
Security 
§ Replaces 
stored 
data 
with 
tokens 
§ Store 
actual 
data 
in 
off-­‐site 
secure 
data 
vault 
§ XiFlex 
maintains 
original 
length 
and 
format 
of 
data 
§ Provides 
key 
management 
and 
rota6on 
outside 
of 
enterprise 
applica6ons 
elimina6ng 
down6me 
October 
24, 
2014 
17 
©2014. 
Paymetric. 
All 
Rights 
Reserved. 
Global 
Support 
§ Mul6-­‐Currency 
§ Visa 
§ Mastercard 
§ AMEX 
§ Diners 
§ Etc. 
Alterna4ve 
Payments 
§ PayPal 
§ BillMe 
Later 
§ Google 
Checkout 
§ Amazon 
§ Telecheck 
§ Etc. 
Processing 
Levels 
§ Level 
1 
§ Level 
2 
§ Level 
3 
Performance 
§ Web-­‐based 
User 
Interface 
§ Mul6-­‐Client 
Architecture 
§ Mul6ple 
Cardholder 
Authen6ca6on 
Types 
§ Mul6ple 
Integra6on 
Technologies 
§ High 
Availability 
– 
24 
x 
7 
Opera6ons 
§ Access 
Logging 
§ Monitoring 
of 
Decryp6on 
Requests 
§ Integrated 
Back-­‐up 
§ Load 
Balancing 
§ Disaster 
Recovery 
§ Database 
Clustering 
Solution Features 
Mul4ple 
Payment 
Types 
§ Credit 
§ PINless 
Debit 
§ GiZ 
§ Loyalty 
§ ACH 
§ Etc.
Challenges We Address 
PAYMENT 
MANAGEMENT 
October 
24, 
2014 
18 
©2014. 
Paymetric. 
All 
Rights 
Reserved. 
BUSINESS 
RISK 
TECHNOLOGY 
COSTS 
§ Interchange 
Costs 
§ Processing 
Expense 
§ PCI 
Costs 
§ Maintenance 
Costs 
§ Support 
Costs 
OPERATIONAL 
§ Mul6ple 
Payment 
Types 
§ Mul6ple 
Geographies 
§ Mul6ple 
Currencies 
§ Mul6ple 
Systems 
§ Mul6ple 
Par6es 
§ Data 
Security 
§ PCI 
Compliance 
§ Working 
Capital 
§ Revenue 
Recogni6on 
§ Reconcilia6on 
§ Unauthorized 
Shipments 
§ Customer 
Sa6sfac6on 
§ System 
Integra6on 
§ Upgrades 
§ Semi-­‐Annual 
Assoc. 
Releases 
§ Mul6ple 
Workflows 
§ Manual 
Authoriza6on 
§ Manual 
Reconcilia6on 
§ Manual 
Invoice 
Clearing
Award-Winning Company 
Paymetric 
is 
Recognized 
for 
Electronic 
Payments 
Innova4on 
Paymetric 
is 
an 
award-­‐winning 
company 
built 
on 
shared 
purpose, 
an 
unremilng 
pursuit 
of 
excellence, 
las6ng 
collabora6on, 
accountability 
and 
integrity. 
For 
more 
than 
15 
years, 
we 
have 
been 
recognized 
for 
our 
work 
and 
honored 
with 
awards 
for 
technical 
innova6on 
and 
thought 
leadership. 
October 
24, 
2014 
19 
©2014. 
Paymetric. 
All 
Rights 
Reserved.
Questions? 
October 
24, 
2014 
20 
©2014. 
Paymetric. 
All 
Rights 
Reserved.

More Related Content

What's hot

Payment Gateway
Payment GatewayPayment Gateway
Payment Gateway
Killian Delaney
 
Payment Gateway Integration: Growth Strategy for SAAS
Payment Gateway Integration: Growth Strategy for SAASPayment Gateway Integration: Growth Strategy for SAAS
Payment Gateway Integration: Growth Strategy for SAAS
Wayne Akey
 
Online payment gateway provider
Online payment gateway providerOnline payment gateway provider
Online payment gateway provider
Payment Gateways
 
E financing and settlement with my sap
E financing and settlement with my sapE financing and settlement with my sap
E financing and settlement with my sap
Richard Page
 
eCommerce_Product_Overview_Brochure_-_0816
eCommerce_Product_Overview_Brochure_-_0816eCommerce_Product_Overview_Brochure_-_0816
eCommerce_Product_Overview_Brochure_-_0816
Michael Vaillancourt
 
CardConnect
CardConnectCardConnect
CardConnect
AaronCSmith2
 
Blinde la seguridad de su empresa
Blinde la seguridad de su empresaBlinde la seguridad de su empresa
Blinde la seguridad de su empresa
SAP Latinoamérica
 
Safex pay wl-pg-presentation
Safex pay wl-pg-presentationSafex pay wl-pg-presentation
Safex pay wl-pg-presentation
Neha Sahay
 
[WSO2Con EU 2017] Fraud Prevention and Compliance in Financial Sector with WS...
[WSO2Con EU 2017] Fraud Prevention and Compliance in Financial Sector with WS...[WSO2Con EU 2017] Fraud Prevention and Compliance in Financial Sector with WS...
[WSO2Con EU 2017] Fraud Prevention and Compliance in Financial Sector with WS...
WSO2
 
2020 kyriba payment_network
2020 kyriba payment_network2020 kyriba payment_network
2020 kyriba payment_network
Chris-Marty MABELLA
 
CardConnect Merchant Pricing Proposal
CardConnect Merchant Pricing ProposalCardConnect Merchant Pricing Proposal
CardConnect Merchant Pricing Proposal
Tony Shap
 
Payment Gateway
Payment Gateway Payment Gateway
Payment Gateway
Rohit Srivastav
 
Direpay product note
Direpay product noteDirepay product note
Direpay product note
globalsales123
 
Peter Afanasiev - Architecture of online Payments
Peter Afanasiev - Architecture of online PaymentsPeter Afanasiev - Architecture of online Payments
Peter Afanasiev - Architecture of online Payments
Ciklum Ukraine
 
How a Payment Factory can help reduce the cost of your ERP cloud migration
How a Payment Factory can help reduce the cost of your ERP cloud migrationHow a Payment Factory can help reduce the cost of your ERP cloud migration
How a Payment Factory can help reduce the cost of your ERP cloud migration
Kyriba Corporation
 
Edenred - Reducing Customer Complaints by 40% with INETCO Insight
Edenred - Reducing Customer Complaints by 40% with INETCO InsightEdenred - Reducing Customer Complaints by 40% with INETCO Insight
Edenred - Reducing Customer Complaints by 40% with INETCO Insight
INETCO Systems Ltd.
 
How Data is Revolutionizing Authentication
How Data is Revolutionizing AuthenticationHow Data is Revolutionizing Authentication
How Data is Revolutionizing Authentication
CardinalCommerce
 
3-D Secure Acquirer and Merchant Implementation Guide
3-D Secure Acquirer and Merchant Implementation Guide3-D Secure Acquirer and Merchant Implementation Guide
3-D Secure Acquirer and Merchant Implementation Guide
- Mark - Fullbright
 
Online Retail Accounting System
Online Retail Accounting SystemOnline Retail Accounting System
Online Retail Accounting System
jrobertscvretail
 
Software Monetization for the Software Business
Software Monetization for the Software Business Software Monetization for the Software Business
Software Monetization for the Software Business
InishTech
 

What's hot (20)

Payment Gateway
Payment GatewayPayment Gateway
Payment Gateway
 
Payment Gateway Integration: Growth Strategy for SAAS
Payment Gateway Integration: Growth Strategy for SAASPayment Gateway Integration: Growth Strategy for SAAS
Payment Gateway Integration: Growth Strategy for SAAS
 
Online payment gateway provider
Online payment gateway providerOnline payment gateway provider
Online payment gateway provider
 
E financing and settlement with my sap
E financing and settlement with my sapE financing and settlement with my sap
E financing and settlement with my sap
 
eCommerce_Product_Overview_Brochure_-_0816
eCommerce_Product_Overview_Brochure_-_0816eCommerce_Product_Overview_Brochure_-_0816
eCommerce_Product_Overview_Brochure_-_0816
 
CardConnect
CardConnectCardConnect
CardConnect
 
Blinde la seguridad de su empresa
Blinde la seguridad de su empresaBlinde la seguridad de su empresa
Blinde la seguridad de su empresa
 
Safex pay wl-pg-presentation
Safex pay wl-pg-presentationSafex pay wl-pg-presentation
Safex pay wl-pg-presentation
 
[WSO2Con EU 2017] Fraud Prevention and Compliance in Financial Sector with WS...
[WSO2Con EU 2017] Fraud Prevention and Compliance in Financial Sector with WS...[WSO2Con EU 2017] Fraud Prevention and Compliance in Financial Sector with WS...
[WSO2Con EU 2017] Fraud Prevention and Compliance in Financial Sector with WS...
 
2020 kyriba payment_network
2020 kyriba payment_network2020 kyriba payment_network
2020 kyriba payment_network
 
CardConnect Merchant Pricing Proposal
CardConnect Merchant Pricing ProposalCardConnect Merchant Pricing Proposal
CardConnect Merchant Pricing Proposal
 
Payment Gateway
Payment Gateway Payment Gateway
Payment Gateway
 
Direpay product note
Direpay product noteDirepay product note
Direpay product note
 
Peter Afanasiev - Architecture of online Payments
Peter Afanasiev - Architecture of online PaymentsPeter Afanasiev - Architecture of online Payments
Peter Afanasiev - Architecture of online Payments
 
How a Payment Factory can help reduce the cost of your ERP cloud migration
How a Payment Factory can help reduce the cost of your ERP cloud migrationHow a Payment Factory can help reduce the cost of your ERP cloud migration
How a Payment Factory can help reduce the cost of your ERP cloud migration
 
Edenred - Reducing Customer Complaints by 40% with INETCO Insight
Edenred - Reducing Customer Complaints by 40% with INETCO InsightEdenred - Reducing Customer Complaints by 40% with INETCO Insight
Edenred - Reducing Customer Complaints by 40% with INETCO Insight
 
How Data is Revolutionizing Authentication
How Data is Revolutionizing AuthenticationHow Data is Revolutionizing Authentication
How Data is Revolutionizing Authentication
 
3-D Secure Acquirer and Merchant Implementation Guide
3-D Secure Acquirer and Merchant Implementation Guide3-D Secure Acquirer and Merchant Implementation Guide
3-D Secure Acquirer and Merchant Implementation Guide
 
Online Retail Accounting System
Online Retail Accounting SystemOnline Retail Accounting System
Online Retail Accounting System
 
Software Monetization for the Software Business
Software Monetization for the Software Business Software Monetization for the Software Business
Software Monetization for the Software Business
 

Viewers also liked

Tietopyynnöt winwin
Tietopyynnöt winwinTietopyynnöt winwin
Tietopyynnöt winwinAleksi Koski
 
Seahenge
SeahengeSeahenge
Md if tourism ismdmspstc160108
Md if tourism ismdmspstc160108Md if tourism ismdmspstc160108
Md if tourism ismdmspstc160108
hayat alishah
 
Pre qualification report
Pre qualification reportPre qualification report
Pre qualification report
hayat alishah
 
Star Carr and the Mesolithic
Star Carr and the MesolithicStar Carr and the Mesolithic
Star Carr and the Mesolithic
Hutchesons'​ Grammar School
 
Aj vm pdf
Aj vm pdfAj vm pdf
Aj vm pdf
Nasir Noor
 
Thủ dâm ảnh hưởng đến sinh sản không - Tổng đài tư vấn tâm lý, sức khỏe 1900 ...
Thủ dâm ảnh hưởng đến sinh sản không - Tổng đài tư vấn tâm lý, sức khỏe 1900 ...Thủ dâm ảnh hưởng đến sinh sản không - Tổng đài tư vấn tâm lý, sức khỏe 1900 ...
Thủ dâm ảnh hưởng đến sinh sản không - Tổng đài tư vấn tâm lý, sức khỏe 1900 ...
Đông y Thọ Xuân Đường
 
Irs 22.2.2015
Irs 22.2.2015Irs 22.2.2015
Irs 22.2.2015
hayat alishah
 
To rs for consultancy environment firm tourism projects new
To rs for consultancy environment firm tourism projects newTo rs for consultancy environment firm tourism projects new
To rs for consultancy environment firm tourism projects new
hayat alishah
 
Black Church Blues Excerpts
Black Church Blues ExcerptsBlack Church Blues Excerpts
Black Church Blues Excerpts
Leander Jackie Grogan
 
Lentejas
LentejasLentejas
Lentejas
Anabel Arone
 
As archaeology S6 copy (2)
As archaeology S6   copy (2)As archaeology S6   copy (2)
As archaeology S6 copy (2)
Hutchesons'​ Grammar School
 
Probus Talk
Probus TalkProbus Talk
Mala dfr.mak
Mala dfr.makMala dfr.mak
Mala dfr.mak
hayat alishah
 
Mesolithic
MesolithicMesolithic
Introduction: some key thinkers in 20th Anthropology
Introduction: some key thinkers in 20th AnthropologyIntroduction: some key thinkers in 20th Anthropology
Introduction: some key thinkers in 20th Anthropology
Hutchesons'​ Grammar School
 

Viewers also liked (19)

Tietopyynnöt winwin
Tietopyynnöt winwinTietopyynnöt winwin
Tietopyynnöt winwin
 
Seahenge
SeahengeSeahenge
Seahenge
 
Md if tourism ismdmspstc160108
Md if tourism ismdmspstc160108Md if tourism ismdmspstc160108
Md if tourism ismdmspstc160108
 
Pre qualification report
Pre qualification reportPre qualification report
Pre qualification report
 
Star Carr and the Mesolithic
Star Carr and the MesolithicStar Carr and the Mesolithic
Star Carr and the Mesolithic
 
Padang Lamun
Padang LamunPadang Lamun
Padang Lamun
 
Aj vm pdf
Aj vm pdfAj vm pdf
Aj vm pdf
 
Thủ dâm ảnh hưởng đến sinh sản không - Tổng đài tư vấn tâm lý, sức khỏe 1900 ...
Thủ dâm ảnh hưởng đến sinh sản không - Tổng đài tư vấn tâm lý, sức khỏe 1900 ...Thủ dâm ảnh hưởng đến sinh sản không - Tổng đài tư vấn tâm lý, sức khỏe 1900 ...
Thủ dâm ảnh hưởng đến sinh sản không - Tổng đài tư vấn tâm lý, sức khỏe 1900 ...
 
Irs 22.2.2015
Irs 22.2.2015Irs 22.2.2015
Irs 22.2.2015
 
To rs for consultancy environment firm tourism projects new
To rs for consultancy environment firm tourism projects newTo rs for consultancy environment firm tourism projects new
To rs for consultancy environment firm tourism projects new
 
Presentation1
Presentation1Presentation1
Presentation1
 
Black Church Blues Excerpts
Black Church Blues ExcerptsBlack Church Blues Excerpts
Black Church Blues Excerpts
 
Lentejas
LentejasLentejas
Lentejas
 
As archaeology S6 copy (2)
As archaeology S6   copy (2)As archaeology S6   copy (2)
As archaeology S6 copy (2)
 
Probus Talk
Probus TalkProbus Talk
Probus Talk
 
Mala dfr.mak
Mala dfr.makMala dfr.mak
Mala dfr.mak
 
Archaeological Site plans
Archaeological Site plansArchaeological Site plans
Archaeological Site plans
 
Mesolithic
MesolithicMesolithic
Mesolithic
 
Introduction: some key thinkers in 20th Anthropology
Introduction: some key thinkers in 20th AnthropologyIntroduction: some key thinkers in 20th Anthropology
Introduction: some key thinkers in 20th Anthropology
 

Similar to How To Avoid PCI Pitfalls in Keeping Your SAP® System Compliant and Secure

Educause+PCI+briefing+4-19-20162345.pptx
Educause+PCI+briefing+4-19-20162345.pptxEducause+PCI+briefing+4-19-20162345.pptx
Educause+PCI+briefing+4-19-20162345.pptx
gealehegn
 
Ecommerce and digital workshop / Unlocked: the Hybrid Cloud 12 May 2014
Ecommerce and digital workshop / Unlocked: the Hybrid Cloud 12 May 2014Ecommerce and digital workshop / Unlocked: the Hybrid Cloud 12 May 2014
Ecommerce and digital workshop / Unlocked: the Hybrid Cloud 12 May 2014
Rackspace Academy
 
Data Security, Fraud Prevention and PCI for Nonprofit Payment Processors in D...
Data Security, Fraud Prevention and PCI for Nonprofit Payment Processors in D...Data Security, Fraud Prevention and PCI for Nonprofit Payment Processors in D...
Data Security, Fraud Prevention and PCI for Nonprofit Payment Processors in D...
Stephanie Gutowski
 
BAASS Connect 2013 - Sage Payment Solutions and Print Boss Essentials Unleash...
BAASS Connect 2013 - Sage Payment Solutions and Print Boss Essentials Unleash...BAASS Connect 2013 - Sage Payment Solutions and Print Boss Essentials Unleash...
BAASS Connect 2013 - Sage Payment Solutions and Print Boss Essentials Unleash...
BAASS Business Solutions Inc.
 
Al 2012 Sage Payment Solutions
Al 2012 Sage Payment SolutionsAl 2012 Sage Payment Solutions
Al 2012 Sage Payment Solutions
BAASS Business Solutions Inc.
 
E commerce overview
E commerce overviewE commerce overview
E commerce overview
Woodridge Software
 
ECMTA 2009 PCI Compliance and the Ecommerce Merchant
ECMTA 2009 PCI Compliance and the Ecommerce MerchantECMTA 2009 PCI Compliance and the Ecommerce Merchant
ECMTA 2009 PCI Compliance and the Ecommerce Merchant
Melanie Beam
 
eCommerce Summit Atlanta Mountain Media
eCommerce Summit Atlanta Mountain MediaeCommerce Summit Atlanta Mountain Media
eCommerce Summit Atlanta Mountain Media
eCommerce Merchants
 
Mann india sap-banking & finance
Mann india sap-banking & financeMann india sap-banking & finance
Mann india sap-banking & finance
Ekanshee Saxena
 
How to Choose Right PCI SAQ for Your Business.pdf
How to Choose Right PCI SAQ for Your Business.pdfHow to Choose Right PCI SAQ for Your Business.pdf
How to Choose Right PCI SAQ for Your Business.pdf
VISTA InfoSec
 
SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070
SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070
SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070
retheauditors
 
PCI DSS Scoping and Applicability
PCI DSS Scoping and ApplicabilityPCI DSS Scoping and Applicability
PCI DSS Scoping and Applicability
Manish Mahapatra
 
SAP S4HANA Credit Management
SAP S4HANA Credit ManagementSAP S4HANA Credit Management
SAP S4HANA Credit Management
Joe Torres
 
Hadoop and Financial Services
Hadoop and Financial ServicesHadoop and Financial Services
Hadoop and Financial Services
Cloudera, Inc.
 
PCI DSS
PCI DSSPCI DSS
PCI DSS
Duy Do Phan
 
IBP - Inventory Optimization Slides.pdf
IBP - Inventory Optimization Slides.pdfIBP - Inventory Optimization Slides.pdf
IBP - Inventory Optimization Slides.pdf
MamtaShekhawat7
 
Indonesian e-Commerce requires Scalability, Reliability and Security to Achi...
Indonesian e-Commerce requires Scalability,  Reliability and Security to Achi...Indonesian e-Commerce requires Scalability,  Reliability and Security to Achi...
Indonesian e-Commerce requires Scalability, Reliability and Security to Achi...
Sutedjo Tjahjadi
 
Disrupting Traditional Payment Systems Architecture with AWS (FSV320) - AWS r...
Disrupting Traditional Payment Systems Architecture with AWS (FSV320) - AWS r...Disrupting Traditional Payment Systems Architecture with AWS (FSV320) - AWS r...
Disrupting Traditional Payment Systems Architecture with AWS (FSV320) - AWS r...
Amazon Web Services
 
SAP S4HANA Receivables Management
SAP S4HANA Receivables ManagementSAP S4HANA Receivables Management
SAP S4HANA Receivables Management
Joe Torres
 
Risk Factory: PCI - The Essentials
Risk Factory: PCI - The EssentialsRisk Factory: PCI - The Essentials
Risk Factory: PCI - The Essentials
Risk Crew
 

Similar to How To Avoid PCI Pitfalls in Keeping Your SAP® System Compliant and Secure (20)

Educause+PCI+briefing+4-19-20162345.pptx
Educause+PCI+briefing+4-19-20162345.pptxEducause+PCI+briefing+4-19-20162345.pptx
Educause+PCI+briefing+4-19-20162345.pptx
 
Ecommerce and digital workshop / Unlocked: the Hybrid Cloud 12 May 2014
Ecommerce and digital workshop / Unlocked: the Hybrid Cloud 12 May 2014Ecommerce and digital workshop / Unlocked: the Hybrid Cloud 12 May 2014
Ecommerce and digital workshop / Unlocked: the Hybrid Cloud 12 May 2014
 
Data Security, Fraud Prevention and PCI for Nonprofit Payment Processors in D...
Data Security, Fraud Prevention and PCI for Nonprofit Payment Processors in D...Data Security, Fraud Prevention and PCI for Nonprofit Payment Processors in D...
Data Security, Fraud Prevention and PCI for Nonprofit Payment Processors in D...
 
BAASS Connect 2013 - Sage Payment Solutions and Print Boss Essentials Unleash...
BAASS Connect 2013 - Sage Payment Solutions and Print Boss Essentials Unleash...BAASS Connect 2013 - Sage Payment Solutions and Print Boss Essentials Unleash...
BAASS Connect 2013 - Sage Payment Solutions and Print Boss Essentials Unleash...
 
Al 2012 Sage Payment Solutions
Al 2012 Sage Payment SolutionsAl 2012 Sage Payment Solutions
Al 2012 Sage Payment Solutions
 
E commerce overview
E commerce overviewE commerce overview
E commerce overview
 
ECMTA 2009 PCI Compliance and the Ecommerce Merchant
ECMTA 2009 PCI Compliance and the Ecommerce MerchantECMTA 2009 PCI Compliance and the Ecommerce Merchant
ECMTA 2009 PCI Compliance and the Ecommerce Merchant
 
eCommerce Summit Atlanta Mountain Media
eCommerce Summit Atlanta Mountain MediaeCommerce Summit Atlanta Mountain Media
eCommerce Summit Atlanta Mountain Media
 
Mann india sap-banking & finance
Mann india sap-banking & financeMann india sap-banking & finance
Mann india sap-banking & finance
 
How to Choose Right PCI SAQ for Your Business.pdf
How to Choose Right PCI SAQ for Your Business.pdfHow to Choose Right PCI SAQ for Your Business.pdf
How to Choose Right PCI SAQ for Your Business.pdf
 
SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070
SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070
SAS 70 in a Post-Sarbanes, SaaS World: Quest Session 52070
 
PCI DSS Scoping and Applicability
PCI DSS Scoping and ApplicabilityPCI DSS Scoping and Applicability
PCI DSS Scoping and Applicability
 
SAP S4HANA Credit Management
SAP S4HANA Credit ManagementSAP S4HANA Credit Management
SAP S4HANA Credit Management
 
Hadoop and Financial Services
Hadoop and Financial ServicesHadoop and Financial Services
Hadoop and Financial Services
 
PCI DSS
PCI DSSPCI DSS
PCI DSS
 
IBP - Inventory Optimization Slides.pdf
IBP - Inventory Optimization Slides.pdfIBP - Inventory Optimization Slides.pdf
IBP - Inventory Optimization Slides.pdf
 
Indonesian e-Commerce requires Scalability, Reliability and Security to Achi...
Indonesian e-Commerce requires Scalability,  Reliability and Security to Achi...Indonesian e-Commerce requires Scalability,  Reliability and Security to Achi...
Indonesian e-Commerce requires Scalability, Reliability and Security to Achi...
 
Disrupting Traditional Payment Systems Architecture with AWS (FSV320) - AWS r...
Disrupting Traditional Payment Systems Architecture with AWS (FSV320) - AWS r...Disrupting Traditional Payment Systems Architecture with AWS (FSV320) - AWS r...
Disrupting Traditional Payment Systems Architecture with AWS (FSV320) - AWS r...
 
SAP S4HANA Receivables Management
SAP S4HANA Receivables ManagementSAP S4HANA Receivables Management
SAP S4HANA Receivables Management
 
Risk Factory: PCI - The Essentials
Risk Factory: PCI - The EssentialsRisk Factory: PCI - The Essentials
Risk Factory: PCI - The Essentials
 

Recently uploaded

Session 1 - Intro to Robotic Process Automation.pdf
Session 1 - Intro to Robotic Process Automation.pdfSession 1 - Intro to Robotic Process Automation.pdf
Session 1 - Intro to Robotic Process Automation.pdf
UiPathCommunity
 
Demystifying Knowledge Management through Storytelling
Demystifying Knowledge Management through StorytellingDemystifying Knowledge Management through Storytelling
Demystifying Knowledge Management through Storytelling
Enterprise Knowledge
 
Nordic Marketo Engage User Group_June 13_ 2024.pptx
Nordic Marketo Engage User Group_June 13_ 2024.pptxNordic Marketo Engage User Group_June 13_ 2024.pptx
Nordic Marketo Engage User Group_June 13_ 2024.pptx
MichaelKnudsen27
 
Essentials of Automations: Exploring Attributes & Automation Parameters
Essentials of Automations: Exploring Attributes & Automation ParametersEssentials of Automations: Exploring Attributes & Automation Parameters
Essentials of Automations: Exploring Attributes & Automation Parameters
Safe Software
 
The Microsoft 365 Migration Tutorial For Beginner.pptx
The Microsoft 365 Migration Tutorial For Beginner.pptxThe Microsoft 365 Migration Tutorial For Beginner.pptx
The Microsoft 365 Migration Tutorial For Beginner.pptx
operationspcvita
 
Apps Break Data
Apps Break DataApps Break Data
Apps Break Data
Ivo Velitchkov
 
A Deep Dive into ScyllaDB's Architecture
A Deep Dive into ScyllaDB's ArchitectureA Deep Dive into ScyllaDB's Architecture
A Deep Dive into ScyllaDB's Architecture
ScyllaDB
 
JavaLand 2024: Application Development Green Masterplan
JavaLand 2024: Application Development Green MasterplanJavaLand 2024: Application Development Green Masterplan
JavaLand 2024: Application Development Green Masterplan
Miro Wengner
 
Astute Business Solutions | Oracle Cloud Partner |
Astute Business Solutions | Oracle Cloud Partner |Astute Business Solutions | Oracle Cloud Partner |
Astute Business Solutions | Oracle Cloud Partner |
AstuteBusiness
 
Christine's Supplier Sourcing Presentaion.pptx
Christine's Supplier Sourcing Presentaion.pptxChristine's Supplier Sourcing Presentaion.pptx
Christine's Supplier Sourcing Presentaion.pptx
christinelarrosa
 
zkStudyClub - LatticeFold: A Lattice-based Folding Scheme and its Application...
zkStudyClub - LatticeFold: A Lattice-based Folding Scheme and its Application...zkStudyClub - LatticeFold: A Lattice-based Folding Scheme and its Application...
zkStudyClub - LatticeFold: A Lattice-based Folding Scheme and its Application...
Alex Pruden
 
GNSS spoofing via SDR (Criptored Talks 2024)
GNSS spoofing via SDR (Criptored Talks 2024)GNSS spoofing via SDR (Criptored Talks 2024)
GNSS spoofing via SDR (Criptored Talks 2024)
Javier Junquera
 
Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving | Nameplate Manufacturing Process - 2024Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving
 
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Pitangent Analytics & Technology Solutions Pvt. Ltd
 
PRODUCT LISTING OPTIMIZATION PRESENTATION.pptx
PRODUCT LISTING OPTIMIZATION PRESENTATION.pptxPRODUCT LISTING OPTIMIZATION PRESENTATION.pptx
PRODUCT LISTING OPTIMIZATION PRESENTATION.pptx
christinelarrosa
 
Leveraging the Graph for Clinical Trials and Standards
Leveraging the Graph for Clinical Trials and StandardsLeveraging the Graph for Clinical Trials and Standards
Leveraging the Graph for Clinical Trials and Standards
Neo4j
 
"Scaling RAG Applications to serve millions of users", Kevin Goedecke
"Scaling RAG Applications to serve millions of users",  Kevin Goedecke"Scaling RAG Applications to serve millions of users",  Kevin Goedecke
"Scaling RAG Applications to serve millions of users", Kevin Goedecke
Fwdays
 
What is an RPA CoE? Session 1 – CoE Vision
What is an RPA CoE?  Session 1 – CoE VisionWhat is an RPA CoE?  Session 1 – CoE Vision
What is an RPA CoE? Session 1 – CoE Vision
DianaGray10
 
Y-Combinator seed pitch deck template PP
Y-Combinator seed pitch deck template PPY-Combinator seed pitch deck template PP
Y-Combinator seed pitch deck template PP
c5vrf27qcz
 
Christine's Product Research Presentation.pptx
Christine's Product Research Presentation.pptxChristine's Product Research Presentation.pptx
Christine's Product Research Presentation.pptx
christinelarrosa
 

Recently uploaded (20)

Session 1 - Intro to Robotic Process Automation.pdf
Session 1 - Intro to Robotic Process Automation.pdfSession 1 - Intro to Robotic Process Automation.pdf
Session 1 - Intro to Robotic Process Automation.pdf
 
Demystifying Knowledge Management through Storytelling
Demystifying Knowledge Management through StorytellingDemystifying Knowledge Management through Storytelling
Demystifying Knowledge Management through Storytelling
 
Nordic Marketo Engage User Group_June 13_ 2024.pptx
Nordic Marketo Engage User Group_June 13_ 2024.pptxNordic Marketo Engage User Group_June 13_ 2024.pptx
Nordic Marketo Engage User Group_June 13_ 2024.pptx
 
Essentials of Automations: Exploring Attributes & Automation Parameters
Essentials of Automations: Exploring Attributes & Automation ParametersEssentials of Automations: Exploring Attributes & Automation Parameters
Essentials of Automations: Exploring Attributes & Automation Parameters
 
The Microsoft 365 Migration Tutorial For Beginner.pptx
The Microsoft 365 Migration Tutorial For Beginner.pptxThe Microsoft 365 Migration Tutorial For Beginner.pptx
The Microsoft 365 Migration Tutorial For Beginner.pptx
 
Apps Break Data
Apps Break DataApps Break Data
Apps Break Data
 
A Deep Dive into ScyllaDB's Architecture
A Deep Dive into ScyllaDB's ArchitectureA Deep Dive into ScyllaDB's Architecture
A Deep Dive into ScyllaDB's Architecture
 
JavaLand 2024: Application Development Green Masterplan
JavaLand 2024: Application Development Green MasterplanJavaLand 2024: Application Development Green Masterplan
JavaLand 2024: Application Development Green Masterplan
 
Astute Business Solutions | Oracle Cloud Partner |
Astute Business Solutions | Oracle Cloud Partner |Astute Business Solutions | Oracle Cloud Partner |
Astute Business Solutions | Oracle Cloud Partner |
 
Christine's Supplier Sourcing Presentaion.pptx
Christine's Supplier Sourcing Presentaion.pptxChristine's Supplier Sourcing Presentaion.pptx
Christine's Supplier Sourcing Presentaion.pptx
 
zkStudyClub - LatticeFold: A Lattice-based Folding Scheme and its Application...
zkStudyClub - LatticeFold: A Lattice-based Folding Scheme and its Application...zkStudyClub - LatticeFold: A Lattice-based Folding Scheme and its Application...
zkStudyClub - LatticeFold: A Lattice-based Folding Scheme and its Application...
 
GNSS spoofing via SDR (Criptored Talks 2024)
GNSS spoofing via SDR (Criptored Talks 2024)GNSS spoofing via SDR (Criptored Talks 2024)
GNSS spoofing via SDR (Criptored Talks 2024)
 
Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving | Nameplate Manufacturing Process - 2024Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving | Nameplate Manufacturing Process - 2024
 
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
 
PRODUCT LISTING OPTIMIZATION PRESENTATION.pptx
PRODUCT LISTING OPTIMIZATION PRESENTATION.pptxPRODUCT LISTING OPTIMIZATION PRESENTATION.pptx
PRODUCT LISTING OPTIMIZATION PRESENTATION.pptx
 
Leveraging the Graph for Clinical Trials and Standards
Leveraging the Graph for Clinical Trials and StandardsLeveraging the Graph for Clinical Trials and Standards
Leveraging the Graph for Clinical Trials and Standards
 
"Scaling RAG Applications to serve millions of users", Kevin Goedecke
"Scaling RAG Applications to serve millions of users",  Kevin Goedecke"Scaling RAG Applications to serve millions of users",  Kevin Goedecke
"Scaling RAG Applications to serve millions of users", Kevin Goedecke
 
What is an RPA CoE? Session 1 – CoE Vision
What is an RPA CoE?  Session 1 – CoE VisionWhat is an RPA CoE?  Session 1 – CoE Vision
What is an RPA CoE? Session 1 – CoE Vision
 
Y-Combinator seed pitch deck template PP
Y-Combinator seed pitch deck template PPY-Combinator seed pitch deck template PP
Y-Combinator seed pitch deck template PP
 
Christine's Product Research Presentation.pptx
Christine's Product Research Presentation.pptxChristine's Product Research Presentation.pptx
Christine's Product Research Presentation.pptx
 

How To Avoid PCI Pitfalls in Keeping Your SAP® System Compliant and Secure

  • 1. PCI Compliance: Avoiding the Pitfalls in Keeping Your SAP® System Fully Compliant and Secure Presenter: Eric Bushman, VP Solu6ons Engineering October 24, 2014 ©2014. Paymetric. All Rights Reserved. 1
  • 2. Agenda § PCI DSS Requirements Overview § Common Data Security Challenges within SAP® § Best Prac6ces When Dealing with Raw Card Numbers § How to Solve for these Challenges § Why Paymetric § Q&A October 24, 2014 2 ©2014. Paymetric. All Rights Reserved.
  • 3. 3 What is PCI Compliance? ©2014. Paymetric. All Rights Reserved. Sec4on Category Build and Maintain a Secure Network Protect Cardholder Data Maintain a Vulnerability Management Program Implement Strong Access Controls Measures Regularly Monitor and Test Networks Maintain an Informa6on Security Policy Requirement 1. Install and maintain a firewall configura6on 2. Do not use vendor-­‐supplied defaults for system passwords 3. Protect stored cardholder data 4. Encrypt transmission of cardholder data 5. Use and regularly update an6-­‐virus soZware 6. Develop and maintain secure systems and applica6ons 7. Restrict access to data by business need-­‐to-­‐know 8. Assign a unique ID to each person with computer access 9. Restrict physical access to network resources and card data 10. Track and monitor all access to network resources and card data 11. Regularly test security systems and processes 12. Maintain a policy that address informa6on security
  • 4. Data Security Challenges in SAP® § Order Entry or Collec6ons workflows require card details to be entered into SAP and used for the payment transac6ons § Even storing cards on a customer master record requires entry of RAW cards at some point in some applica6on October 24, 2014 4 ©2014. Paymetric. All Rights Reserved.
  • 5. Best Practices The Golden Rule: Avoid exposure of RAW cards in your SAP system as much as possible § Don’t allow interfaces to pass RAW card numbers into SAP October 24, 2014 5 ©2014. Paymetric. All Rights Reserved. § Check BAPI interfaces § Check IDOC interfaces § Check File/Excel upload interfaces
  • 6. Best Practices § Use XiIntercept solu6ons to prevent direct entry of RAW cards in SAP GUI and/or SAP HTML interfaces October 24, 2014 6 ©2014. Paymetric. All Rights Reserved. § XiIntercept for SAP can be used during capture in the SAP GUI § XiIntercept for Ecommerce can be used during capture in the SAP HTML GUI § Use SAP Card Valida6on rules that prevent entry of RAW card data – flags it as an error and disallows entry
  • 7. Best Practices § Don’t allow users to view detokenized cards in SAP October 24, 2014 7 ©2014. Paymetric. All Rights Reserved. § Deac6vate calls to the detokenized service via SAP § Only allow users to reference and view RAW card data in Paymetric Repor6ng Portal (XiPay Web GUI) interface § Train users to prevent entry of RAW card numbers in text fields where valida6ons and tokeniza6on can’t be performed
  • 8. Best Practices § Convert to tokens and purge any exis6ng RAW or encrypted data in the SAP database October 24, 2014 8 ©2014. Paymetric. All Rights Reserved. § Customer Master records § Historical transac6onal data § Text fields § If you are capturing CVV values for transmission in Authoriza6on calls in SAP, ensure that you’ve applied the OSS notes to prevent storage of the CVV value in the SAP DB
  • 9. Solution Overview § Easily scales across the SAP landscape § Gives merchants the argument that SAP is out of scope for a PCI DSS audit § Eliminates data exposure in the event of a data breach § Centralizes configura6on and audi6ng October 24, 2014 9 ©2014. Paymetric. All Rights Reserved.
  • 10. Paymetric Cloud-Based Environment October 24, 2014 10 ©2014. Paymetric. All Rights Reserved.
  • 11. Create A Tokeniza4on Layer Around Your Enterprise October 24, 2014 11 ©2014. Paymetric. All Rights Reserved.
  • 12. October 24, 2014 12 ©2014. Paymetric. All Rights Reserved. for SAP® Remove Systems from Your Cardholder Data Environment (CDE) Sensi4ve card data entered within SAP is intercepted and secured by XiIntercept
  • 13. XiIntercept for eCommerce October 24, 2014 13 Intercept Card Data at the Earliest Point ©2014. Paymetric. All Rights Reserved. of Your Workflow Paymetric intercepts and secures shaded data fields
  • 14. SAQ Valida4on Types May Qualify Your Organiza4on for Self Assessment Ques4onnaire C, Reducing the Number of Compliance Requirements from 263 to 139 SAQ Valida4on Type October 24, 2014 14 ©2014. Paymetric. All Rights Reserved. Descrip4on Number of Ques4ons A Card-­‐not-­‐present merchants 14 A-­‐EP eCommerce merchants redirec6ng to a third-­‐party website 139 C Merchants with payment applica6ons systems connected to the Internet 140 D-­‐MER All other SAQ-­‐eligible merchants 263
  • 15. Reduce PCI DSS Audit Scope May Qualify Your Organiza4on for Self Assessment Ques4onnaire C, Reducing the Number of Compliance Requirements from 263 to 139 300 250 200 150 100 October 24, 2014 15 50 ©2014. Paymetric. All Rights Reserved. 14 Number of Ques4ons Per SAQ 139 140 263 0 SAQ A SAQ A-­‐EP SAQ C D-­‐MER
  • 16. Why Paymetric October 24, 2014 16 ©2014. Paymetric. All Rights Reserved.
  • 17. Cer4fica4ons § SAP Enterprise Services Interface § SAP Cross-­‐Applica6on Payment Card Interface § Level 1 PCI DSS Cer6fied Service Provider Security § Replaces stored data with tokens § Store actual data in off-­‐site secure data vault § XiFlex maintains original length and format of data § Provides key management and rota6on outside of enterprise applica6ons elimina6ng down6me October 24, 2014 17 ©2014. Paymetric. All Rights Reserved. Global Support § Mul6-­‐Currency § Visa § Mastercard § AMEX § Diners § Etc. Alterna4ve Payments § PayPal § BillMe Later § Google Checkout § Amazon § Telecheck § Etc. Processing Levels § Level 1 § Level 2 § Level 3 Performance § Web-­‐based User Interface § Mul6-­‐Client Architecture § Mul6ple Cardholder Authen6ca6on Types § Mul6ple Integra6on Technologies § High Availability – 24 x 7 Opera6ons § Access Logging § Monitoring of Decryp6on Requests § Integrated Back-­‐up § Load Balancing § Disaster Recovery § Database Clustering Solution Features Mul4ple Payment Types § Credit § PINless Debit § GiZ § Loyalty § ACH § Etc.
  • 18. Challenges We Address PAYMENT MANAGEMENT October 24, 2014 18 ©2014. Paymetric. All Rights Reserved. BUSINESS RISK TECHNOLOGY COSTS § Interchange Costs § Processing Expense § PCI Costs § Maintenance Costs § Support Costs OPERATIONAL § Mul6ple Payment Types § Mul6ple Geographies § Mul6ple Currencies § Mul6ple Systems § Mul6ple Par6es § Data Security § PCI Compliance § Working Capital § Revenue Recogni6on § Reconcilia6on § Unauthorized Shipments § Customer Sa6sfac6on § System Integra6on § Upgrades § Semi-­‐Annual Assoc. Releases § Mul6ple Workflows § Manual Authoriza6on § Manual Reconcilia6on § Manual Invoice Clearing
  • 19. Award-Winning Company Paymetric is Recognized for Electronic Payments Innova4on Paymetric is an award-­‐winning company built on shared purpose, an unremilng pursuit of excellence, las6ng collabora6on, accountability and integrity. For more than 15 years, we have been recognized for our work and honored with awards for technical innova6on and thought leadership. October 24, 2014 19 ©2014. Paymetric. All Rights Reserved.
  • 20. Questions? October 24, 2014 20 ©2014. Paymetric. All Rights Reserved.