Showing posts with label PA-DSS compliance. Show all posts
Showing posts with label PA-DSS compliance. Show all posts

Friday, February 20, 2015

SSL no longer acceptable for data protection, PCI SSC says

The Payment Card Industry Security Standards Council (PCI SSC) has announced that no version of secure sockets layer (SSL) technology meets its definition of "strong cryptography." Accordingly, it will need to revise its Data Security Standard and Payment Application Data Security Standards.
According to a PCI press release, the announcement was based on finding by the National Institute of Standards and Technology that the Secure Socket Layers v3.0 protocol is no longer acceptable for protection of data due to inherent weaknesses within the protocol.
With no known way to remediate vulnerabilities in the SSL protocol, the PCI SSC is urging organizations to work with IT departments and partners to determine whether they are using SSL and what options they have for upgrading to a strong cryptographic protocol as soon as possible.
Once published, PCI DSS v3.1 will be effective immediately, however, affected requirements will be future-dated to allow organizations time to implement the changes.

Wednesday, November 13, 2013

New PCI Guidelines Go Live Jan. 1, 2014

The PCI Security Standards Council has published version 3.0 of the PCI Data Security Standard and the Payment Application Data Security Standard, both of which go into effect on Jan.1.

Note that version 2.0 will remain active until Dec. 31, 2014, to allow time for merchants to make the transition.

Version 3.0 offers more flexibility and an increased focus on education, awareness and security as a shared responsibility, according to a news release from the Security Standards Council, which stated that “Version 3.0 builds on ... feedback we’ve heard from our community... to help organizations make payment security good business practice — every day, all year round."

New requirements (as summarized by RetailCustomerExperience. com) include:

PCI DSS
  • Req. 5.1.2 — evaluate evolving malware threats for any systems not considered to be commonly affected
  • Req. 8.2.3 — combined minimum password complexity and strength requirements into one, and increased flexibility for alternatives
  • Req. 8.5.1 — for service providers with remote access to customer premises, use unique authentication credentials for each customer*
  • Req. 8.6 — where other authentication mechanisms are used (for example, physical or logical security tokens, smart cards, certificates, etc.) these must be linked to an individual account and ensure only the intended user can gain access
  • Req. 9.3 — control physical access to sensitive areas for onsite personnel, including a process to authorize access, and revoke access immediately upon termination
  • Req. 9.9 — protect devices that capture payment card data via direct physical interaction with the card from tampering and substitution*
  • Req. 11.3 and 11.3.4 — implement a methodology for penetration testing; if segmentation is used to isolate the cardholder data environment from other networks, perform penetration tests to verify that the segmentation methods are operational and effective*
  • Req. 11.5.1 — implement a process to respond to any alerts generated by the change-detection mechanism
  • Req. 12.8.5 — maintain information about which PCI DSS requirements are managed by each service provider, and which are managed by the entity
  • Req. 12.9 — for service providers, provide the written, agreement/acknowledgment to their customers as specified at requirement 12.8.2*
*Indicates future dated requirements that are best practices until July 1, 2015.
PA-DSS
  • Req. 5.1.5 — payment application developers to verify integrity of source code during the development process
  • Req. 5.1.6 — payment applications to be developed according to industry best practices for secure coding techniques
  • Req. 5.4 — payment application vendors to incorporate versioning methodology for each payment application
  • Req. 5.5 — payment application vendors to incorporate risk assessment techniques into their software development process
  • Req. 7.3 — application vendor to provide release notes for all application updates
  • Req. 10.2.2 — vendors with remote access to customer premises (for example, to provide support/maintenance services) use unique authentication credentials for each customer
  • Req. 14.1 — provide information security and PA-DSS training for vendor personnel with PA-DSS responsibility at least annually
Supporting documentation, including updated self-assessment questionnaires, attestations of compliance and reporting templates, will be available in early 2014 once version 3.0 is effective.

Saturday, March 31, 2012

Dydacomp Releases SiteLINK 7, Assures PCI Compliance

Dydacomp, a leading provider of business technology platforms for small and mid-sized eCommerce and multichannel merchants, has announced SiteLINK 7, a comprehensive eCommerce shopping cart solution that increases conversions and ensures PCI compliance.

SiteLINK 7 delivers many new features to create an enriched cross-platform shopping experience for online and mobile shoppers. Dydacomp’s eCommerce hosting environment has also undergone an independent third-party audit to ensure SiteLINK 7 is a PCI DSS certified solution and hosting platform, enabling merchants to meet strict data security standards and regulations.

PCI Compliance
“One of the business-critical areas that we addressed in SiteLINK 7 is PCI compliance," ' say Fred Lizza, CEO of Dydacomp. "The ramifications of a data breach to a small or medium-sized business can be devastating. By combining SiteLINK 7 with our Multichannel Order Manager, we provide the only integrated end-to-end PCI compliant software solution for small and mid-size merchants and their customers. Our latest solution also addresses the rapid adoption of new mobile technology. SiteLINK 7 now includes mobile-optimized layouts to allow our merchants’ customers to browse and order from smartphones and wireless devices.”

Best Practices
Enhancements were made based on best practices for increasing purchases and to help smaller companies compete with large eCommerce sites. SiteLINK7makes it easier for customers to leave product reviews which improve conversions, incorporates a persistent cart to allow visitors to add items to the shopping cart and complete the order at a later time, and presents a recently viewed items listing. All of these new features enrich the overall shopping experience for online consumers while the integration with Multichannel Order Manager provides SMBs with the ability to manage all commerce processes needed to run and scale a successful online or cross-channel business through a single solution.

The new features of SiteLINK 7 enrich the overall online shopping experience while the integration with Multichannel Order Manager provides SMBs with a single commerce management solution that manages all processes needed to run and scale a successful online or cross-channel business. SiteLINK 7 also incorporates numerous enhancements to create effective and visually powerful eCommerce sites, such as the ability to sell e-gift cards that can also be redeemed through point-of-purchase, new HTML templates to increase conversions, and integration with buySAFE to provide shoppers with a purchase guarantee.

“The new release reflects Dydacomp’s continued commitment to providing the complete end-to-end solution for small and mid-sized merchants," says CEO  Lizza. "The features and functionality we’ve incorporated into our solutions are designed to meet the expanding needs of today’s eCommerce marketplace. In addition, merchants can process credit cards and collect payment-related data with the reassurance that SiteLINK 7 has received the PCI DSS compliance certifications that will simplify meeting the requirements for annual merchant qualifications.”

Thursday, August 12, 2010

PCI Standards: Room for Improvement

Kelly Jackson Higgins reports on the Dark Reading Website that Joshua Corman, research director for the enterprise security practice at The 451 Group, believes that the forthcoming PCI version 2.0 going into effect this fall "needs more teeth."

"The standard in its current 1.2 and 2.0 forms is not sufficient to prevent attack from a determined adversary," in Corman's opinion.

Gary Palgon, lead chair for the PCI SSC Scoping Special Interest Group's tokenization working group, said in a blog post that the card brands themselves may be hindering PCI's success, as some continue to issue their own, independent standards for PCI compliance instead of conforming exclusively to PCI SSC-derived standards. "Having a universal, singular standards set is paramount for easing compliancy requirements and reducing complexity for merchants and service providers alike."

Palgon, who is also VP of product management at nuBridges, a tokenization vendor, says that while the new PCI changes clarify many of the PCI requirements, more specific guidance is needed for emerging technologies, such as encryption and tokenization -- both of which are due to arrive with the new spec this fall

"As the lead chair for the PCI SSC Scoping Special Interest Group’s Tokenization Working Group," notes Palgon in his blog post, "I am helping drive efforts to ensure that guidance on these important security technologies will be forthcoming. Just as the industry’s needs with regard to protecting enterprise data are evolving rapidly, such guiding standards need to be put into place more quickly, as well."

Bob Russo, general manager of the PCI Standards Council, suggests that PCI DSS now reinforces the need for a "scoping exercise" to identify bundled cardholder data. "We're not endorsing any discovery tools. But before you bring in a QSA, you really need to use some kind of methodology to find where cardholder data is on the network," he says. "Before, we hadn't really talked about using any of these methodologies. We just said you should know where your data is. We are now encouraging people to reach out using one of these discovery methods."

The PA-DSS is also now more closely aligned with the PCI DSS. The spec adds a requirement for payment applications to support centralized logging, which is part of PCI DSS. "Centralized logging is really important to us," Russo says.

There is also accommodation for risk tolerance factors in the new PCI Data Security Standard, and low risk issues "don't necessarily have to be addressed."

"Another clarification," notes Jackson, "addresses PCI DSS 3.3 and 3.4, which require that payment application passwords be made unreadable (encrypted) while being transmitted and stored. The clarification notes that this applies only to the primary account number (PAN)."

Jaikumar Vijayan of Computerworld reports that according to Gartner Analyst Avivah Litan many Gartner clients are trying to understand whether their adoption of new technologies such as chip cards, tokenization and end-to-end encryption will limit the scope of their compliance requirements. Most of the clarifications around such issues, however, have been left for Special Interest Groups (SIG) to figure out. "These SIGS are not being held to any particular deadlines and it's still unclear how their reports will fold into PCI requirements," said Litan.

"The PCI Security Council's guidance around virtualization technologies is going to be another area that is going to be closely watched," according to James Paul, Senior VP, Delivery at Trustwave, says Vijayan. Trustwave provides PCI assessment services for many of the largest retailers in the country. Many Trustwave customers want to know today if their use of virtualization technologies will increase the scope of their PCI requirements, said Paul. "It's an emerging technology. There are a lot of questions around it. There are a lot of people somewhat hesitant to dive into it until they see some guidance."

Friday, April 30, 2010

Sterling Adds nuBridges Token Manager for PA-DSS Compliance

nuBridges has announced that Sterling Commerce, an AT&T company, has added support for nuBridges Protect™ Token Manager into its Sterling Selling and Fulfillment Suite, a direct commerce order management and fulfillment solution. Adding this support enables the company’s customers to reduce corporate risk due to security breaches and to meet Payment Card Industry Data Security Standard (PCI DSS) requirements.

Available now in Sterling Selling and Fulfillment 9.0, these capabilities also enable the solution to meet Visa’s fifth Payment Application Data Security Standard (PA-DSS) security mandate requiring all merchants to use a PA-DSS compliant solution before the deadline of July 1, 2010.
“Tokenization is rapidly gaining traction with companies that want to reduce the high costs of PCI DSS compliance and audits, and also the risks that come with collecting and storing large volumes of consumer information”
nuBridges Protect Token Manager, the company’s "Format Preserving Tokenization™" solution, enables Sterling Selling and Fulfillment Suite to use tokens in place of credit card numbers in order to protect consumer data, reduce scope for PCI DSS audits, and to reduce corporate risk due to security breaches.

“The popularity of Sterling Selling and Fulfillment Suite in the retail industry is growing dramatically as retailers look for ways to optimize their cross-channel selling and fulfillment operations,” said Jim Bengier, global industry executive, Retail, at Sterling Commerce. “Delivering the highest levels of security has always been paramount, especially as we add new mobile apps as access points to the Suite. Adding security capabilities such as those offered by nuBridges enables us to meet our customers’ strictest security requirements.”

Sterling Selling and Fulfillment Suite is a comprehensive solution for a seamless customer experience across all channels, including in-store, online, catalog, call center and mobile. The suite allows companies to present a tailored buying experience in all the ways they sell—Web, call center, store and field sales—and provides control over the entire fulfillment lifecycle, including order management, transportation and delivery to supply management, returns and settlement. The company also recently launched mobile applications that extend the order and transportation management capabilities of Sterling Selling and Fulfillment Suite to a mobile device.

Tuesday, December 08, 2009

Morse Data Preparing for PA-DSS Compliance

Morse Data Corp., Orland Park, IL, vendors of the InOrder multichannel order management system, are completing the auditor's "Discovery Phase" for PA-DSS Compliance, the first of five audit phases. They also plan to release a new, PA-DSS-compliant version of InOrder next year, well in advance of the July 1, 2010, deadline for PA-DSS compliance.

Monday, October 12, 2009

Ecometry PA-DSS-Compliant

Escalate Retail reports on Twitter that Ecometry vers. 10.0.4 passed it's PA-DSS audit and that its PCI Council Website listing will be coming soon.

Tuesday, September 22, 2009

MOM Vers. 7i is PA-DSS-Compliant

Dydacomp, a provider of business automation software for multi-channel merchants, retailers, and cataloguers, has released the latest version of its Mail Order Manager (M.O.M.) software solution, Version 7i, the company's first PCI PA-DSS certified product.

"PCI compliance is of vital importance to our customers as the way they will need to process credit cards and store data is about to drastically change," said John V. Healy, Dydacomp CEO. "We've eliminated our customers' primary pain point by pursuing and receiving PCI PA-DSS compliance certification for Version 7i as well as adding numerous customer requested enhancements."

M.O.M. Version 7i includes more than a dozen significant enhancements to Version 6 (on which the current release is built). Key features include (but are not limited to) graphical and text on-demand reporting, advanced automated drop shipping, EDI, branded gift cards as a payment method, detailed data transmission to QuickBooks , and mobile access from the iPhone, iPod Touch, or other PDA devices.

Tuesday, July 14, 2009

PCI Compliance to Become Law in NV

According to PCI DSS Compliance Blog, beginning January 1, 2010, the state of Nevada will mandate PCI DSS compliance for businesses accepting credit cards. In so doing, Nevada will become the first state to transform the PCI DSS requirements into law.

With non-compliant businesses already facing steep financial penalties, as well as risks of not being able to accept credit cards and lawsuits (almost sure to follow any data security breach), non-compliance with PCI DSS would seem sufficiently punitive already. But with states like Nevada making law of PCI DSS, PCI compliance will certainly take on a new level of visibility and, perhaps, controversy.

Nevada’s law will actually serve to shield PCI compliant businesses from additional liability should a data security breach occur and litigation ensue. Nevada’s new law will provide relief for Nevada businesses (at least those that accept or process credit card payments) by protecting compliant companies from potentially bankrupting lawsuits.

Friday, June 12, 2009

Escalate on PA-DSS List

Escalate Retail is now on the official list of PA-DSS-compliant applications, along with Abison Commerce Suite, Celerant, and CommercialWare. AssistCornerstone is currently in the formal assessment process.

Thursday, April 09, 2009

Abison Passes PA-DSS Compliance

Abison Comprehensive Commerce Suite is the first direct commerce solution to be included on the official list of Payment Application Data Security Standard (PA-DSS) of "Verified Payment Applications" that have met all the PA-DSS security standards.

Vendors have until July 1, 2010 to be compliant. For further information, see material at the Guide to Direct Commerce Systems and Services site.
Web Analytics