Search in ISMS Guides

Google
 
Showing posts with label PCI DSS. Show all posts
Showing posts with label PCI DSS. Show all posts

Tuesday, August 14, 2007

PCI DATA SECURITY STANDARD

The PCI Data Security Standard was originally developed by Visa and MasterCard, and endorsed by other payment providers including American Express, Diner's Club and Discover. This Standard included the requirements of Visa's Cardholder Information Security Program (CISP) and MasterCard's Site Data Protection (SDP). Version 1 was withdrawn from 31 December 2006 and the new PCI DSS version 1.1(here's the download) is applicable and is controlled by the independent PCI Security Standards Council. Here is a Summary of Changes between the two versions of the standard.

The PCI Security Standards Council ('SSC') also defines qualifications for Qualified Security Assessors (QSAs) and Approved Scanning Vendors (ASVs); and it trains, tests and certifies QSAs and ASVs.

QSAs (here is a current list) carry out inspections of PCI DSS implementations and determine a recommendation of compliance to the various payment brands. Each individual payment brand will separately determine whether to accept the recommendation of compliance and whether a detailed review of the report of compliance and compensating controls is warranted. .

The Standard basically requires merchants and member service providers (MSPs) who store, process or transmit cardholder data to:

* Build and maintain a secure IT network
* Protect cardholder data
* Maintain a vulnerability management program
* Implement strong access control measures
* Regularly monitor and test networks
* Maintain an information security policy

While the PCI Standard was not written to map specifically to BS7799, ISO17799, CobiT or any other existing framework, it sits clearly within the ISO 17799 framework and organizations that have implemented an ISO 17799 ISMS should be able, with minor additional work, to also demonstrate their conformance with the PCI standard. A document that maps the individual clauses of the PCI DSS v1.1 to the individual clauses of ISO/IEC 27001 Annex A/ISO 17799:2005 is available to subscribers. Subscribers can also access additional guidance on using ISO27001 as a PCI DSS management framework.

All existing merchants and MSPs were required to have complied with the standard by 30 June 2005.



What are the consequences to my business if I do not comply with the PCI DSS?
The PCI Security Standards Council encourages all businesses that store payment account data to comply with the PCI DSS to help lower their brand and financial risks associated with account payment data compromises. The PCI Security Standards Council does not manage compliance programs and does not impose any consequences for non-compliance. Individual payment brands, however, may have their own compliance initiatives, including financial or operational consequences to certain businesses that are not compliant. (FAQ from the PCI website)

PCI DSS Resources

Glossary - this document defines terms used in PCI DSS v 1.1 and the other resources available to ASVs and QSAs.


The PCI Self-Assessment Questionnaire (SAQ)

This is an important validation tool that is primarily used by smaller merchants and service providers to demonstrate compliance to the PCI DSS. The currently posted version of the SAQ is based on the Payment Card Industry (PCI) Data Security Standard (DSS) v. January 2005, and it will be valid until version 1.1 of the SAQ is released.

Payment Card Industry Self-Assessment Questionnaire (pdf)
PCI DSS Payment Card Industry Self-Assessment Questionnaire (locked Word)


The Security Audit Procedures document is designed for use by assessors conducting onsite reviews for merchants and service providers required to validate compliance with PCI DSS requirements. The requirements and audit procedures presented in this document are based on the PCI DSS.

PCI DSS Security Audit Procedures (pdf)
PCI DSS Security Audit Procedures (locked Word)


PCI Security Scanning Procedures. The purpose and scope of the PCI DSS Security Scan for merchants and service providers subject to scans to help validate compliance with the PCI DSS. ASVs also use this document to assist merchants and service providers in determining the scope of the PCI Security Scan.

PCI DSS Security Scanning Procedures


PCI DSS Validation Requirements for Qualified Security Assessors (QSAs) v 1.1.
To be recognized as a QSA by PCI SSC, QSAs must meet or exceed the requirements described in this document and execute the QSA Agreement with PCI SSC attached to this document as Appendix A.
PCI Qualified Security Assessor (QSA) Agreement
Sample QSA Feedback Form



PCI DSS Validation Requirements for Approved Scanning Vendors (ASVs)v 1.1
Recognition as an ASV by PCI SSC requires the ASV, its employees, and its scanning solution to meet or exceed the described requirements and execute the “PCI ASV Compliance Test Agreement” attached as Appendix A with PCI SSC. The companies that qualify are then identified on PCI SSC’s ASV list on PCI SSC’s web site in accordance with the Agreement.
PCI ASV Compliance Test Agreement
Sample ASV Feedback Form



PCI DSS Technical and Operational Requirements for Approved Scanning Vendors (ASVs) v 1.1
This document provides guidance and requirements applicable to ASVs in the framework of the PCI DSS and associated payment brand data protection programs. Security scanning companies interested in providing scan services as part of the PCI program must comply with the requirents in this document and must successfully complete the PCI Security Scanning Vendor Testing and Approval Process.

From :
www.itgovernance.co.uk

Thursday, July 26, 2007

Using ISO 27001 for PCI DSS Compliance Frist Page (2)

PCI, as it is almost universally known,
was originally developed by MasterCard
and Visa through an alignment of
security requirements contained in the
MasterCard Site Data Protection Plan
(SDP) and two Visa programs, the
Cardholder Information Security Plan
(CISP) and the international Account
Information Security (AIS). In September
of 2006, a group of five leading payment
brands including American Express,
Discover Financial Services, JCB,
MasterCard Worldwide and Visa
International jointly announced
formation of the PCI Security Standards
Council, an independent council
established to manage ongoing evolution
of the PCI standard. Concurrent with the
announcement, the council released
version 1.1 of the PCI standard. Since
then it has rapidly become the ‘de-facto’
standard within the card industry for
both merchant and service provider.
While the newly-established PCI Security
Standards Council manages the
underlying data security standard,
compliance requirements are set
independently by individual payment
card brands. While requirements vary
between card networks, MasterCard’s
Site Data Protection Plan and Visa’s
Cardholder Information Security Program
are representative. They stipulate
separate compliance validation
requirements for merchants and service
providers, which vary depending on the
size of the company and its transaction /
business throughout.
PCI DSS is based on established best
practice for securing data (such as
ISO 27001) and applies to any parties
involved with the transfer or processing
of credit card data.
Its purpose is to ensure that confidential
cardholder account data is always secure
and comprises 12 key requirements:

1.Build and maintain a secure network
2.Protect cardholder data
3.Maintain a vulnerability management program
4.Implement strong access control measures
5.Regularly monitor and test networks
6.Maintain an information security policy
7.PCI validation requirements & ISO 27001 compliance requirements
8.Annual on-site security audits
9.PCI annual self-assessment questionnaire
10.Quarterly external network scans
11.PCI DSS Validation Enforcement Table
12.PCI and ISO 27001 - the comparisons

See 12 key requirements Detail

Back To Using ISO 27001 for PCI DSS Compliance Frist Page

Using ISO 27001 for PCI DSS Compliance

A white paper by Steve Wright,
Siemens Insight Consulting

The Payment Card Industry Data Security
Standard (PCI DSS) isn’t dramatically
different to the requirements of the best
practice security standard - ISO 27001,
except that PCI doesn’t mention any of
the prerequisites required for a
management framework, e.g.
management commitment, scope
definition, security awareness training,
ongoing improvement plans, whereas
ISO 27001 omits a lot of the detail
around how controls are actually
implemented. So therefore, one could
be forgiven for believing that MasterCard
and Visa assumed PCI would contain
additional security requirements to sit on
top of an already established Information
Security Management System (ISMS).

There is no getting away from the fact that this is good news for
industry as a whole. Any new baseline security standard that
helps measure the security of systems is good news. For
example, making sure that firewalls are only passing traffic on
accepted and approved ports, ensuring that servers are running
only those services that really need to be live and validating those
databases aren’t configured with vendor supplied defaults.
The problem is, like with any baseline standard, it is only as good
as the last review; and herein lays a dilemma. ISO 27001 has
deliberately moved away from specifying or dictating too many
detailed controls (133 in ISO 27001, but over 200 in PCI), as it did
not want it to become a simple tick box exercise. ISO 27001
stipulates that an organisation should ensure any control to be
implemented should reflect the level of risk (or vulnerability), that
could cause unnecessary pain should it not be addressed.
PCI does refer to conducting a formal risk assessment (see section
12.1.2 of the standard), but how flexible would a certified
third-party auditor be during the audits?

Would he /she agree with the
organisation that the risks acceptable to
one organisation were deemed
unacceptable to another (depending
upon the risk appetite of the
organisations)?

Using ISO 27001 for PCI DSS Compliance Next Page