using your qsa as a resource year round

40
© 2016 SecurityMetrics USING YOUR QSA AS A RESOURCE YEAR ROUND Winn Oakey, QSA

Upload: securitymetrics

Post on 22-Jan-2018

61 views

Category:

Technology


1 download

TRANSCRIPT

Page 1: Using Your QSA as a Resource Year Round

© 2016 SecurityMetrics

USING YOUR QSA AS A

RESOURCE YEAR

ROUND

Winn Oakey, QSA

Page 2: Using Your QSA as a Resource Year Round

ABOUT SECURITYMETRICS

• Helping organizations

comply with mandates,

avoid security breaches,

and recover from data theft

since 2000

Page 3: Using Your QSA as a Resource Year Round

AGENDA

• Achieving compliance

with your QSA

• Time saving tips for your

next audit

• Best practices to prepare

for your audit

• One year audit plan

Page 4: Using Your QSA as a Resource Year Round

ACHIEVING COMPLIANCE

Page 5: Using Your QSA as a Resource Year Round

WHAT HINDERS PCI?

• Often, management/executives

don’t see the necessity of PCI

compliance:

– Budget issues

– Company culture

– Company procedures

Page 6: Using Your QSA as a Resource Year Round

If you’re breached, it could be

a company-ending risk.

Page 7: Using Your QSA as a Resource Year Round

PCI IS A TOP-DOWN SYSTEM

• Executives need to know:

– What’s required

– What changes need to happen

– Why (e.g., financial reasons,

penalties)

Page 8: Using Your QSA as a Resource Year Round

Any time your environment

changes, tell your QSA.

Page 9: Using Your QSA as a Resource Year Round

CHANGING ENVIRONMENTS

• Whenever bringing on new

systems, ask how it changes

your:

– PCI Scope

– PCI environment

– Process of documentation

– Employee training

Page 10: Using Your QSA as a Resource Year Round

UNDERSTANDING YOUR SCOPE

• Has your environment changed?

• New PCI rules?

• What impact new rules have on compliance?

– E.g., PCI DSS 3.2

– SSL and TLS

Page 11: Using Your QSA as a Resource Year Round

The biggest problem is when

organizations think they’re

PCI compliant, but aren’t.

Page 12: Using Your QSA as a Resource Year Round

HOW A QSA HELPS

• Their goal is to help you reach compliance

• Knowledge of common issues and how they

are being handled

• Understand PCI requirements

• Offer best practices

Page 13: Using Your QSA as a Resource Year Round

WORKING WITH YOUR QSA

• Create an ongoing relationship

throughout the year

• Keep documentation up-to-date

• Send documents to QSA

– Especially when changes occur

Page 14: Using Your QSA as a Resource Year Round

COMMON QUESTIONS TO ASK

• New Requirements

– What are the new changes?

– What should I do?

– When do I have to implement?

– How does it affect my environment?

Page 15: Using Your QSA as a Resource Year Round

SAVING TIME

Page 16: Using Your QSA as a Resource Year Round

It’s not about finding time. It’s

about maximizing the little

time you have.

Page 17: Using Your QSA as a Resource Year Round

NEW TO PCI?

• PCI can be a beast

– Break into manageable

pieces (i.e., 2-3 things

per month)

– Make a process for the

future

• Ask your QSA about a

Gap Analysis

Page 18: Using Your QSA as a Resource Year Round

ALREADY PCI COMPLIANT?

• Keep documentation

• Finish requirements on timelines

• Ask QSA about new PCI requirements

• Proper scoping

Page 19: Using Your QSA as a Resource Year Round

PLACE SOMEONE IN CHARGE

• At least one individual responsible for PCI

requirements

• Give them power to act and implement changes

• Monthly, if not weekly meetings with executives

Page 20: Using Your QSA as a Resource Year Round

The PCI declaration occurs

once a year, but PCI needs to

be a continual process.

Page 21: Using Your QSA as a Resource Year Round

SCHEDULED TIMELINES

• Many PCI requirements are on

scheduled timelines.

Remember to have them:

– Completed

– Documented

– Ready to demonstrate

Page 22: Using Your QSA as a Resource Year Round

UNDERSTAND YOUR ENVIRONMENT

• L1 or L4 merchant?

• Ecommerce vs. in-person?

• Which SAQ do you need to fill out?

• How your data flows through your environment?

Page 23: Using Your QSA as a Resource Year Round

It’s better to validate your

compliance and security than

to discover problems.

Page 24: Using Your QSA as a Resource Year Round

TRANSPARENCY

• Send all necessary PCI

documents to your QSA

• Be completely open with

your QSA

– Don’t hide weaknesses; no

one gains anything

– Ultimately speeds auditing

process

Page 25: Using Your QSA as a Resource Year Round

PREPARING FOR YOUR AUDIT

Page 26: Using Your QSA as a Resource Year Round

PRE-ONSITE AUDIT

• Prior to your onsite audit, you should review:

– Your systems

– Evidence of compliance

– Your business model

– PCI questions

• Ask QSA questions

Page 27: Using Your QSA as a Resource Year Round

You should talk with your QSA

at least quarterly, if not more.

Page 28: Using Your QSA as a Resource Year Round

QUESTIONS TO ASK

• What changes are you seeing?

• How do secure organizations

address those changes?

• What are some other best

practices?

Page 29: Using Your QSA as a Resource Year Round

ONE YEAR BEFORE YOUR AUDIT

• Look at requirements that need to be done in a

timely manner (e.g., monthly, quarterly, 90 days,

etc.)

– What are those requirements

– Where you stand

– Who’s responsible

– How they capture these results

– Reporting plans

Page 30: Using Your QSA as a Resource Year Round

ONE YEAR BEFORE (CONT.)

• What changes are happening

with PCI requirements (e.g.,

EMV, new technology)

– What do you need to do

– How do you plan to meet

timelines

Page 31: Using Your QSA as a Resource Year Round

6 MONTHS BEFORE

• Start your own internal audit

– Look for card data in the “wild”

• Review logs and processes

• Work more closely with your QSA

– Pass on information and documentation

Page 32: Using Your QSA as a Resource Year Round

6 MONTHS BEFORE (CONT.)

• Prepare to fix your system

• If a tool is needed or process

changed, these changes may

take a quarter for approval,

purchase, and implementation.

Page 33: Using Your QSA as a Resource Year Round

3 MONTHS BEFORE

• Have we covered the following areas:

– Our understanding of PCI

– Review compliance

• Implement changes

• If possible, do another internal audit

Page 34: Using Your QSA as a Resource Year Round

ONE MONTH BEFORE

• Work with key individuals

– Know who should be interviewed

– Discover what’s required of them

– Put together needed documentation

– Make assignments

• E.g., gather logs, review processes

Page 35: Using Your QSA as a Resource Year Round

ONE MONTH BEFORE (CONT.)

• Review your systems

• Check-in with your QSA

Page 36: Using Your QSA as a Resource Year Round

TAKEAWAYS

Page 37: Using Your QSA as a Resource Year Round

DON’T FORGET TO . . .

• Understand what

requirements you have to

follow

• Schedule and do all

requirements on time

• Take time to understand

PCI requirements

Page 38: Using Your QSA as a Resource Year Round

DON’T FORGET TO (CONT.) . . .

• Tell your QSA when your

environment changes

• Send all necessary

documents to your QSA

• Talk with your QSA at least

quarterly

Page 39: Using Your QSA as a Resource Year Round

It’s important to be compliant,

but it’s vital for your

organization to be secure.

Page 40: Using Your QSA as a Resource Year Round

www.securitymetrics.com

QUESTIONS?