E N D
1. GTEC Meeting August 17th 2010 PCI Compliance
2. 1
3. Industry Responds to Payment Card Data Theft To combat the increasing fraud, the major card brands created the PCI SSC (Payment Card Industry Security Standards Council).
Defined a common set of standards accepted by all brands to introduce payment security best practices as a way to reduce payment system fraud.
4. PIN Entry Device Security
6. PCI – PED Visa is mandating PIN accepting dispensers (DEBIT) adhere to EPP standards to support industry migration to TDES.
7. In the future – Dispensers will be required to comply with the more comprehensive PCI UPT requirements.
Involves the entire payment terminal including:
Keypads
Card Readers
Display Prompts PCI EPP and UPT Compliance
8. Payment Security Product Overview - Flexibility
9. Additional Considerations
Payment security standards continue to evolve
PCI standards may be updated every few years
Level 1.X - Release date 2004 (Current)
Level 2.0 – Release date 2009 (Current)
Level 3.0 / UPT – Release date 2010 (Mandate ?)
Standards versions affect deployment longevity
2009 introduction of Unattended Payment Terminal (UPT)
PCI Council published PCI 3.0 in April 2010
Consolidating specs and modularizing certifications
Incremental security requirements
Inclusion of non-PIN devices – card security, open protocols
Further UPT clarifications and configuration details
10. PCI EPP Versions and UPT: Security Differences 9
12. 11
14. 13
15. 14