legal issues week 8– pci – payment card industry dss data security standard

46
Legal Issues Week 8– PCI – Payment Card Industry DSS Data Security Standard Gary A Bannister – FCMA, AICPA, CGEIT

Upload: melia

Post on 05-Jan-2016

26 views

Category:

Documents


0 download

DESCRIPTION

Legal Issues Week 8– PCI – Payment Card Industry DSS Data Security Standard. Gary A Bannister – FCMA, AICPA, CGEIT. Learning Objectives. An basic understanding of PCI and its impact on Information security. How it is used by the courts. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard

Legal Issues Week 8– PCI – Payment Card Industry DSSData Security Standard

Gary A Bannister – FCMA, AICPA, CGEIT

Page 2: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard

Learning Objectives

An basic understanding of PCI and its impact on Information security.

How it is used by the courts. The difference between best practice

compliance verses legal compliance.

Page 3: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard

Why PSI

Page 4: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard

The E-commerce Business Need for PCI

Of approximately 650,000 complaints about fraud that the US Federal Trade Commission received each year in the period 2004 – 2006, identity theft was the main complaint 35% - 36% of the time

21% of banking institutions have either suffered a security breach the past two years, or don’t know if they have. Another 35% have been victims of a phishing attack. { * State of Information Security Survey 2008 www.bankinfosecurity.com}

Page 5: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard

Understanding PCI There are 3 standards:

PCI data Security Standard – PCIDSS Core standard for merchants and processors. It is for protecting

cardholder data

Payment Application data security Standard – PA DSS This is for software developers who sell commercial

applications for accepting and processing card data

PIN Entry device Security requirements –PED This is for manufacturers of payment card devices

## We will focus on PCI DSS

Page 6: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 7: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard

The Standards Manager PCI security Standards Council founded in

2006. Founded by master Card, VISA, Discover, Amex They share equal responsibility in Council

governance Others that participate include merchants,

banks, hardware and software vendors and other technical and legal working groups

Page 8: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 9: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard

Crucial Roles in Compliance Card Brand Compliance programs

Each of the card company brands have adopted the standard but they have some small variations in how they implement.

Qualified Assessors The council qualifies two kinds of assessors:

The QSA – Qualified Security assessor The QSA is a consultant who assesses an organisation’s compliance with

the standard. ASV – Approved Scanning Vendor

They validate compliance with the standard’s external network scanning requirements.

Self-Assessment Questionnaire Some merchants are able to self-assess, primarily for levels 2 to 4

merchants.

Page 10: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 11: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 12: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 13: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 14: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 15: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard

How a credit Card payment Process works

Authorisation Merchant requests & receives authorisation Many points of vulnerability that could expose the cardholder data

to Unauthorised access

Clearing The acquirer and issuer exchange information about the purchase

Settlement The merchant’s bank pays the merchant for the card holder

purchase and the cardholder’s bank bills the cardholder or debits the cardholder’s account.

Page 16: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 17: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 18: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 19: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 20: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 21: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 22: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 23: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 24: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 25: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 26: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 27: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 28: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 29: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 30: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 31: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 32: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 33: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 34: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 35: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 36: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 37: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 38: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 39: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 40: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 41: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 42: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 43: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard
Page 44: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard

Issues Is PCI the law?

Only in Minnesota under Statue 365E.64 Legislators in at least 10 states thought Minnesota was a

good idea, and created bills have their own but they never passed

Proposals also made to congress but no bills were passed. The view from most law makers is that anything passed

would conflict with PCI DSS as it stands? Other critics say that making it law, turns the PCI Security

Standards Council and the card companies into a quasi-legislative, quasi judicial bodies with power to set regulations and punishments yet be accountable to no one

So for now PCI Is not the law but is enforceable under private contractual conditions stipulated by each of the card brands.

Page 45: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard

Issues High Cost Vendor backed standards are difficult

to maintain & sustain. Judges have looked at best practice

and along side ISO 27002 look at PCI. The credit card companies demand

compliance if business & e commerce want to use their credit cards.

Page 46: Legal Issues  Week 8– PCI – Payment Card Industry DSS Data Security Standard

Questions?