SlideShare ist ein Scribd-Unternehmen logo
1 von 22
PCI Compliance and the Online Merchant
PCI Compliance Explained Melanie Beam  Director, Business Development
What does PCI DSS mean?  ,[object Object],[object Object],[object Object]
This is new, right? ,[object Object],[object Object]
Do I have to be PCI Compliant? ,[object Object],[object Object],[object Object]
PCI DSS Principles and Requirements Requirement 12: Maintain a policy that addresses information security   Maintain an Information Security Policy Requirement 10: Track and monitor all access to network resources and cardholder data Requirement 11: Regularly test security systems and processes   Regularly Monitor and Test Networks Requirement 7: Restrict access to cardholder data by business need-to-know Requirement 8: Assign a unique ID to each person with computer access Requirement 9: Restrict physical access to cardholder data  Implement Strong Access Control Measures Requirement 5: Use and regularly update anti-virus software Requirement 6: Develop and maintain secure systems and applications Maintain a Vulnerability Management Program Requirement 3: Protect stored cardholder data Requirement 4: Encrypt transmission of cardholder data across open, public networks  Protect Cardholder Data Requirement 1: Install and maintain a firewall configuration to protect cardholder data Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters Build and Maintain a Secure Network Associated Requirements Principle
What  are the merchant levels? These are based on your annual transaction volumes MOST ECOMMERCE MERCHANTS FALL INTO  LEVEL 3 OR 4 Any merchant processing fewer than 20,000 ecommerce card transactions per year, and all other merchants -- regardless of acceptance channel -- processing up to 1M transactions per year. Level 4 Any merchant processing 20,000 to 1M ecommerce credit card transactions per year. Level 3 Any merchant -- regardless of acceptance channel -- processing 1M to 6M card transactions per year. Level 2 Any merchant -- regardless of acceptance channel -- processing over 6M card transactions per year. Any merchant that the card companies, determine should meet the Level 1 merchant requirements to minimize risk. Level 1 Annual Transaction Volume Merchant Level
How do I become compliant? ,[object Object],[object Object]
Self Assessment Questionnaire Validation Must comply with requirements in SAQ-D. and may require a Report on Compliance from a Qualified Security Assessor.These are the same the requirements that are required of PCI certified service providers and are typically out of the financial and technical reach of most small ecommerce retailers.  Cost to comply is well over $50,000 and requires written policies and procedures.  Requires the operating service providers are PCI-DSS certified. This includes the web hosting provider and data center. Not required to perform quarterly scans, but recommended. Must comply with SAQ-C. Does not   require PCI compliant web hosting, but may be necessary to complete the SAQ-A. Not required to perform a quarterly vulnerability scan, but recommended. Hosting Environment Managed PCI compliant product like Rack Space PCI hosting and PCI Compliant Ecommerce application. Card holder data can be stored  for later use. Allows the customers to save cards for later purchases. Type 5 (The Hardest) Credit card payments are made at the merchant’s website. Using a shopping cart solution with Authorize.net is an example. Ecommerce merchants with shopping cart applications that transmit cardholder data via the Internet for processing.  No cardholder data can be stored. Type 4 (Most Merchants) The purchaser must be redirected to the service provider’s website to complete the purchase.  Using Paypal Payments Standard is an example.  All cardholder data functions are performed by a PCI compliant third-party.  No cardholder data can be stored or transmitted. Type 1 (The Easiest) Example Card holder Data SAQ Type
Now that you know, what do you do? ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
The Time Is Now ,[object Object],[object Object],[object Object],[object Object]
Mountain Media’s Ecommerce Platform and Data Center  are PCI Level 1 Compliant ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],Please contact us for comprehensive PCI Compliant eCommerce at 877-583-0300 Or visit  www.mountainmedia.com
PAYMENT CARD INDUSTRY (PCI) SECURITY STANDARDS Source: October 2008.  Statistics based on data gathered from 443 account data compromise cases investigated since 2001. ACCOUNT DATA COMPROMISE STATISTICS John Jacobs  Moneris Solutions Merchant Acquirer
ACCOUNT DATA COMPROMISE STATISTICS ,[object Object],[object Object],[object Object]
ACCOUNT DATA COMPROMISE STATISTICS ,[object Object],[object Object],[object Object]
ACCOUNT DATA COMPROMISE STATISTICS ,[object Object],[object Object],[object Object]
NEW ACCOUNT DATA COMPROMISE TRENDS ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
PCI SSC – SECURITY STANDARDS OVERVIEW
PCI DSS - VISA  SERVICE PROVIDER  LEVELS DEFINED ,[object Object],[object Object],[object Object],[object Object],Service Provider  Approved Scanning Vendor Annual PCI Self Assessment Questionnaire Quarterly Network Scan Any service provider that stores, processes and/or transmits less than 300,000 transactions per year 2 Annual On-Site PCI Data Security Assessment  Quarterly Network Scan Validation Action VisaNet processors or any service provider that stores, processes and/or transmits over 300,000 transactions per year Level Description Qualified Security Assessor  Approved Scanning Vendor 1 Validated By Level
PCI DSS - EFFECTS OF NOT COMPLYING ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Awarded To: June 4, 2009 eCom Merchant eCom Merchant  ("Client") is enrolled in  Compliance Validation Services to meet the Payment Card Industry Data Security Standard (PCI DSS). Validation Service has been accredited by all the major card  associations' data security programs including: Etc……
ADDITIONAL INFORMATION ,[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]

Weitere ähnliche Inhalte

Was ist angesagt?

PCI Compliance Seminar
PCI Compliance SeminarPCI Compliance Seminar
PCI Compliance Seminar
dlinehan2
 
PCIDSS compliance made easier through a collaboration between NC State and UN...
PCIDSS compliance made easier through a collaboration between NC State and UN...PCIDSS compliance made easier through a collaboration between NC State and UN...
PCIDSS compliance made easier through a collaboration between NC State and UN...
John Baines
 
Evolve Pci Compliance
Evolve   Pci ComplianceEvolve   Pci Compliance
Evolve Pci Compliance
hypknight
 
Visa Compliance Mark National Certification
Visa Compliance Mark National CertificationVisa Compliance Mark National Certification
Visa Compliance Mark National Certification
Mark Pollard
 
Small_Merchant_Guide_to_Safe_Payments
Small_Merchant_Guide_to_Safe_PaymentsSmall_Merchant_Guide_to_Safe_Payments
Small_Merchant_Guide_to_Safe_Payments
Steve Abrams
 
PCI Compliance—Love It, Hate It, But Don’t Ignore It (11NTCpci)
PCI Compliance—Love It, Hate It, But Don’t Ignore It (11NTCpci)PCI Compliance—Love It, Hate It, But Don’t Ignore It (11NTCpci)
PCI Compliance—Love It, Hate It, But Don’t Ignore It (11NTCpci)
Miminten
 
Payment card industry data security standard
Payment card industry data security standardPayment card industry data security standard
Payment card industry data security standard
sallychiu
 
Understanding Your PCI DSS Guidelines: Successes and Failures
Understanding Your PCI DSS Guidelines: Successes and FailuresUnderstanding Your PCI DSS Guidelines: Successes and Failures
Understanding Your PCI DSS Guidelines: Successes and Failures
- Mark - Fullbright
 

Was ist angesagt? (20)

Adventures in PCI Wonderland
Adventures in PCI WonderlandAdventures in PCI Wonderland
Adventures in PCI Wonderland
 
PCI Compliance Seminar
PCI Compliance SeminarPCI Compliance Seminar
PCI Compliance Seminar
 
Payment Card Industry CMTA NOV 2010
Payment Card Industry CMTA NOV 2010Payment Card Industry CMTA NOV 2010
Payment Card Industry CMTA NOV 2010
 
PCI DSS Data Security Compliance Program Overview
PCI DSS Data Security Compliance Program OverviewPCI DSS Data Security Compliance Program Overview
PCI DSS Data Security Compliance Program Overview
 
PCIDSS compliance made easier through a collaboration between NC State and UN...
PCIDSS compliance made easier through a collaboration between NC State and UN...PCIDSS compliance made easier through a collaboration between NC State and UN...
PCIDSS compliance made easier through a collaboration between NC State and UN...
 
Payment Card Industry Compliance for Local Governments CSMFO 2009
Payment Card Industry Compliance for Local Governments CSMFO 2009Payment Card Industry Compliance for Local Governments CSMFO 2009
Payment Card Industry Compliance for Local Governments CSMFO 2009
 
PCI FAQs and Myths - BluePay
PCI FAQs and Myths - BluePayPCI FAQs and Myths - BluePay
PCI FAQs and Myths - BluePay
 
An Introduction to PCI Compliance on IBM Power Systems
An Introduction to PCI Compliance on IBM Power SystemsAn Introduction to PCI Compliance on IBM Power Systems
An Introduction to PCI Compliance on IBM Power Systems
 
Evolve Pci Compliance
Evolve   Pci ComplianceEvolve   Pci Compliance
Evolve Pci Compliance
 
Visa Compliance Mark National Certification
Visa Compliance Mark National CertificationVisa Compliance Mark National Certification
Visa Compliance Mark National Certification
 
Small_Merchant_Guide_to_Safe_Payments
Small_Merchant_Guide_to_Safe_PaymentsSmall_Merchant_Guide_to_Safe_Payments
Small_Merchant_Guide_to_Safe_Payments
 
PCI Compliance—Love It, Hate It, But Don’t Ignore It (11NTCpci)
PCI Compliance—Love It, Hate It, But Don’t Ignore It (11NTCpci)PCI Compliance—Love It, Hate It, But Don’t Ignore It (11NTCpci)
PCI Compliance—Love It, Hate It, But Don’t Ignore It (11NTCpci)
 
Introduction to PCI DSS
Introduction to PCI DSSIntroduction to PCI DSS
Introduction to PCI DSS
 
Payment card industry data security standard
Payment card industry data security standardPayment card industry data security standard
Payment card industry data security standard
 
Understanding Your PCI DSS Guidelines: Successes and Failures
Understanding Your PCI DSS Guidelines: Successes and FailuresUnderstanding Your PCI DSS Guidelines: Successes and Failures
Understanding Your PCI DSS Guidelines: Successes and Failures
 
What Everybody Ought to Know About PCI DSS and PA-DSS
What Everybody Ought to Know About PCI DSS and PA-DSSWhat Everybody Ought to Know About PCI DSS and PA-DSS
What Everybody Ought to Know About PCI DSS and PA-DSS
 
Pci dss v3-2-1
Pci dss v3-2-1Pci dss v3-2-1
Pci dss v3-2-1
 
PCI FAQs and Myths
PCI FAQs and MythsPCI FAQs and Myths
PCI FAQs and Myths
 
PCI DSS Certification
PCI DSS CertificationPCI DSS Certification
PCI DSS Certification
 
Pcidss
PcidssPcidss
Pcidss
 

Ähnlich wie ECMTA 2009 PCI Compliance and the Ecommerce Merchant

Educause+PCI+briefing+4-19-20162345.pptx
Educause+PCI+briefing+4-19-20162345.pptxEducause+PCI+briefing+4-19-20162345.pptx
Educause+PCI+briefing+4-19-20162345.pptx
gealehegn
 
PCI_Presentation_OASIS
PCI_Presentation_OASISPCI_Presentation_OASIS
PCI_Presentation_OASIS
Dermot Clarke
 
Payment card industry data security standard 1
Payment card industry data security standard 1Payment card industry data security standard 1
Payment card industry data security standard 1
wardell henley
 
Pci compliance overview earth link business
Pci compliance overview earth link businessPci compliance overview earth link business
Pci compliance overview earth link business
Mike Shelah
 
Tripwire pci basics_wp
Tripwire pci basics_wpTripwire pci basics_wp
Tripwire pci basics_wp
Edward Lam
 

Ähnlich wie ECMTA 2009 PCI Compliance and the Ecommerce Merchant (20)

PCI DSS
PCI DSSPCI DSS
PCI DSS
 
Educause+PCI+briefing+4-19-20162345.pptx
Educause+PCI+briefing+4-19-20162345.pptxEducause+PCI+briefing+4-19-20162345.pptx
Educause+PCI+briefing+4-19-20162345.pptx
 
PCI_Presentation_OASIS
PCI_Presentation_OASISPCI_Presentation_OASIS
PCI_Presentation_OASIS
 
PruebaJLF.pptx
PruebaJLF.pptxPruebaJLF.pptx
PruebaJLF.pptx
 
Data Security, Fraud Prevention and PCI for Nonprofit Payment Processors in D...
Data Security, Fraud Prevention and PCI for Nonprofit Payment Processors in D...Data Security, Fraud Prevention and PCI for Nonprofit Payment Processors in D...
Data Security, Fraud Prevention and PCI for Nonprofit Payment Processors in D...
 
PCI Compliance 101
PCI Compliance 101PCI Compliance 101
PCI Compliance 101
 
Evolution Pci For Pod1
Evolution Pci For Pod1Evolution Pci For Pod1
Evolution Pci For Pod1
 
Payment card industry data security standard 1
Payment card industry data security standard 1Payment card industry data security standard 1
Payment card industry data security standard 1
 
Pci compliance overview earth link business
Pci compliance overview earth link businessPci compliance overview earth link business
Pci compliance overview earth link business
 
Pci ssc quick reference guide
Pci ssc quick reference guidePci ssc quick reference guide
Pci ssc quick reference guide
 
PCI-DSS for IDRBT
PCI-DSS for IDRBTPCI-DSS for IDRBT
PCI-DSS for IDRBT
 
PCI Certification and remediation services
PCI Certification and remediation servicesPCI Certification and remediation services
PCI Certification and remediation services
 
Introduction To SAQ 4 U
Introduction To SAQ 4 UIntroduction To SAQ 4 U
Introduction To SAQ 4 U
 
PCI Compliance for Community Colleges @One CISOA 2011
PCI Compliance for Community Colleges @One CISOA 2011PCI Compliance for Community Colleges @One CISOA 2011
PCI Compliance for Community Colleges @One CISOA 2011
 
PCI Compliance: What You Need to Know
PCI Compliance: What You Need to KnowPCI Compliance: What You Need to Know
PCI Compliance: What You Need to Know
 
Quick Reference Guide to the PCI Data Security Standard
Quick Reference Guide to the PCI Data Security StandardQuick Reference Guide to the PCI Data Security Standard
Quick Reference Guide to the PCI Data Security Standard
 
Demystifying PCI DSS: Expert Tips and Explanations to Help You Gain PCI DSS C...
Demystifying PCI DSS: Expert Tips and Explanations to Help You Gain PCI DSS C...Demystifying PCI DSS: Expert Tips and Explanations to Help You Gain PCI DSS C...
Demystifying PCI DSS: Expert Tips and Explanations to Help You Gain PCI DSS C...
 
Tripwire pci basics_wp
Tripwire pci basics_wpTripwire pci basics_wp
Tripwire pci basics_wp
 
PCI Compliance for Payment Security
PCI Compliance for Payment SecurityPCI Compliance for Payment Security
PCI Compliance for Payment Security
 
PCI DSS: What it is, and why you should care
PCI DSS: What it is, and why you should carePCI DSS: What it is, and why you should care
PCI DSS: What it is, and why you should care
 

ECMTA 2009 PCI Compliance and the Ecommerce Merchant

  • 1. PCI Compliance and the Online Merchant
  • 2. PCI Compliance Explained Melanie Beam Director, Business Development
  • 3.
  • 4.
  • 5.
  • 6. PCI DSS Principles and Requirements Requirement 12: Maintain a policy that addresses information security Maintain an Information Security Policy Requirement 10: Track and monitor all access to network resources and cardholder data Requirement 11: Regularly test security systems and processes Regularly Monitor and Test Networks Requirement 7: Restrict access to cardholder data by business need-to-know Requirement 8: Assign a unique ID to each person with computer access Requirement 9: Restrict physical access to cardholder data Implement Strong Access Control Measures Requirement 5: Use and regularly update anti-virus software Requirement 6: Develop and maintain secure systems and applications Maintain a Vulnerability Management Program Requirement 3: Protect stored cardholder data Requirement 4: Encrypt transmission of cardholder data across open, public networks Protect Cardholder Data Requirement 1: Install and maintain a firewall configuration to protect cardholder data Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters Build and Maintain a Secure Network Associated Requirements Principle
  • 7. What are the merchant levels? These are based on your annual transaction volumes MOST ECOMMERCE MERCHANTS FALL INTO LEVEL 3 OR 4 Any merchant processing fewer than 20,000 ecommerce card transactions per year, and all other merchants -- regardless of acceptance channel -- processing up to 1M transactions per year. Level 4 Any merchant processing 20,000 to 1M ecommerce credit card transactions per year. Level 3 Any merchant -- regardless of acceptance channel -- processing 1M to 6M card transactions per year. Level 2 Any merchant -- regardless of acceptance channel -- processing over 6M card transactions per year. Any merchant that the card companies, determine should meet the Level 1 merchant requirements to minimize risk. Level 1 Annual Transaction Volume Merchant Level
  • 8.
  • 9. Self Assessment Questionnaire Validation Must comply with requirements in SAQ-D. and may require a Report on Compliance from a Qualified Security Assessor.These are the same the requirements that are required of PCI certified service providers and are typically out of the financial and technical reach of most small ecommerce retailers. Cost to comply is well over $50,000 and requires written policies and procedures. Requires the operating service providers are PCI-DSS certified. This includes the web hosting provider and data center. Not required to perform quarterly scans, but recommended. Must comply with SAQ-C. Does not require PCI compliant web hosting, but may be necessary to complete the SAQ-A. Not required to perform a quarterly vulnerability scan, but recommended. Hosting Environment Managed PCI compliant product like Rack Space PCI hosting and PCI Compliant Ecommerce application. Card holder data can be stored for later use. Allows the customers to save cards for later purchases. Type 5 (The Hardest) Credit card payments are made at the merchant’s website. Using a shopping cart solution with Authorize.net is an example. Ecommerce merchants with shopping cart applications that transmit cardholder data via the Internet for processing. No cardholder data can be stored. Type 4 (Most Merchants) The purchaser must be redirected to the service provider’s website to complete the purchase. Using Paypal Payments Standard is an example. All cardholder data functions are performed by a PCI compliant third-party. No cardholder data can be stored or transmitted. Type 1 (The Easiest) Example Card holder Data SAQ Type
  • 10.
  • 11.
  • 12.
  • 13. PAYMENT CARD INDUSTRY (PCI) SECURITY STANDARDS Source: October 2008. Statistics based on data gathered from 443 account data compromise cases investigated since 2001. ACCOUNT DATA COMPROMISE STATISTICS John Jacobs Moneris Solutions Merchant Acquirer
  • 14.
  • 15.
  • 16.
  • 17.
  • 18. PCI SSC – SECURITY STANDARDS OVERVIEW
  • 19.
  • 20.
  • 21. Awarded To: June 4, 2009 eCom Merchant eCom Merchant ("Client") is enrolled in Compliance Validation Services to meet the Payment Card Industry Data Security Standard (PCI DSS). Validation Service has been accredited by all the major card associations' data security programs including: Etc……
  • 22.