pci dss overview

8
An independent industry standards body responsible for the development and management of Payment Card Industry security standards on a global basis Founding multinational acceptance brand members: American Express Discover Financial JCB International MasterCard Visa 1 PCI-DSS Standards and Overview

Upload: ofulue-amaka

Post on 17-Aug-2015

84 views

Category:

Documents


2 download

TRANSCRIPT

1

An independent industry standards body responsible for the development and management of Payment Card Industry security standards on a global basis

Founding multinational acceptance brand members:

American Express Discover Financial JCB International MasterCard Visa

PCI-DSS Standards and Overview

2

PCI-DSS Standards and Overview

Resources required by the council include

3

PCI Security Standards

4

PCI DSS covers security of the environment that store, process, transmit account data

– Environments receive account data from payment applications and other sources (e.g. acquirers)

PCI PA-DSS covers secure payment applications to support PCI DSS compliance

– Payment application receives account data from PIN-entry devices (PEDs) or other devices and begins payment transaction

PCI P2PE covers encryption, decryption, and key management requirements for point-to-point encryption solutions.

PCI PTS - POI covers the protection of sensitive data at point-of-interaction devices and their secure components, including cardholder PINs and account data, and the cryptographic keys used in connection with the protection of that cardholder data

PCI PTS - PIN covers secure management, processing and transmission of personal identification number (PIN) data during online and offline payment card transaction processing

PCI PTS - HSM covers physical, logical and device security requirements for securing Hardware Security Modules (HSM)

PCI Card Production covers physical and logical security requirements for systems and business processes associated with card personalization, PIN generation, PIN mailers, and card carriers and distribution.

PCI Security Standards

5

PCI-DSS Overview

PCI DSS provides a baseline of technical and operational requirements designed to protect payment card data.

PCI DSS comprises a minimum set of requirements for protecting cardholder data, and may be enhanced by additional controls and practices to further mitigate risks.

PCI DSS applies to all entities involved in payment card processing – including merchants, processors, acquirers, issuers, and service providers, as well as all other entities that store, process, or transmit cardholder data and/or sensitive authentication data.

PCI DSS requirements apply wherever account data is stored, processed, or transmitted.

6

What is Card Holder Data?

What is Card Holder Data?

What is Account data?

What is a PAN?

What is CVV/CVC?

What is PIN?

7

What is Card Holder Data?

PCI DSS requirements are applicable wherever Primary Account Number (PAN) or Sensitive Authentication Data (SAD) is stored, processed, or transmitted.

PCI DSS requirements also apply to systems that provide security services or could impact the security of account data.

Account data includes all of the information printed on the physical card as well as the data on the magnetic stripe or chip.

Sensitive Authentication Data cannot be stored after authorization.

Encrypting cardholder data or sensitive authentication data does NOT necessarily remove it from scope.

Cardholder Data includes: Sensitive Authentication Data includes Primary Account Number (PAN) Full track data (magnetic-stripe data

or equivalent on a chip)

Cardholder Name CAV2/CV2/CVV2/CID

Expiration Date Service Code

• PINs/PIN blocks

Account Data

8

The PCI Data Security Standard