Payment Card Industry Data Security Standard - PowerPoint PPT Presentation

1 / 10
About This Presentation
Title:

Payment Card Industry Data Security Standard

Description:

Card data must be rendered unreadable before disposal. Electronic Storage ... Must be rendered unreadable everywhere it is stored: Back-up media ... – PowerPoint PPT presentation

Number of Views:173
Avg rating:3.0/5.0
Slides: 11
Provided by: administra56
Category:

less

Transcript and Presenter's Notes

Title: Payment Card Industry Data Security Standard


1
Payment Card Industry Data Security Standard
  • Protecting Payment Card Data

2
Do Not Store Payment Card Data
  • Card data defined primarily as card and
    expiration date
  • Strictly forbidden to store
  • Track data from the magnetic stripe
  • Card Security Code
  • Storage of only the last 4-digits is not
    storing
  • Unless absolutely necessary

3
Reasons Not to Store Card Data
  • Internal Audit does not require
  • Avoid many other detailed compliance requirements
  • Chargebacks often favor the cardholder
  • Balance cost of not storing with cost of breach
  • Forensic investigation 10,000
  • Onsite Audit 20,000
  • Penalties from Visa and MasterCard

4
Possible Reason to StoreCard Data
  • May need for future transaction, such as when
    goods are shipped
  • Consider using webCredit for scheduled payments

5
If You Must Store Card Data
  • Limit amount if feasible (less than full card ,
    no expiration date, etc.)
  • Limit retention (recommend no longer than 18
    months)
  • Limit access to people with a business need to
    know
  • Must do background checks on all non-regular
    employees who have access to more than one card
    number at a time (e.g., students, volunteers)

6
Paper Storage
  • Must be in a locked cabinet or limited access
    area
  • Card data must be rendered unreadable before
    disposal

7
Electronic Storage
  • Must be encrypted with a PCI DSS-approved method
  • Must be rendered unreadable everywhere it is
    stored
  • Back-up media ?Spreadsheets
  • Audit logs ?Imaged copies
  • Fax servers ?Laptop

8
Electronic Storage with Third-Party Provider
  • Must add PCI DSS language to all contracts
  • Template available
  • Strongly recommend investigation of vendors
    encryption method
  • Many proprietary methods do not meet PCI DSS
    requirements

9
Web Sites of Interest
  • Payment Card Industry Data Security Standard
    http//usa.visa.com/download/business/accepting_vi
    sa/ops_risk_management/cisp_PCI_Data_Security_Stan
    dard.pdf
  • PCI Self-Assessment Questionnaire
    https//sdp.mastercardintl.com/pdf/758_PCI_Self_As
    smnt_Qust.pdf
  • VISA Security Information web site
  • http//www.visa.com/cisp
  • Managing Sensitive Data Initiative web site
  • http//lct.msu.edu/security
  • Ambiron TrustWave
  • http//www.atwcorp.com/

10
Contact Information
  • Contract review/questions, business office
    practices
  • Mary Nelson, Controllers Office
  • 355-5023, ext 150 or nelsonm_at_ctlr.msu.edu
  • Questions about webCredit
  • 353-4420, ext 311 or webcredit_at_ais.msu.edu
  • Network configuration and security
  • Joe Budzyn, ACNS
  • 432-7448 or budzyn_at_msu.edu
  • Audit Concerns
  • Steve Kurncz
  • 355-5030 or kurncz_at_msu.edu
Write a Comment
User Comments (0)
About PowerShow.com