150 likes | 305 Views
Session 119. Payment Card Industry (PCI ) - Data Security Standard (DSS):. Introduction and Best Practices. Michael Jacobs Development Architect - OpenEdge. What Is PCI-DSS?. Payment Card Industry – Data Security Standard. Payment Card Industry Security Standards Council
E N D
Session 119 Payment Card Industry (PCI ) -Data Security Standard (DSS): Introduction and Best Practices Michael Jacobs Development Architect - OpenEdge
What Is PCI-DSS? Payment Card Industry – Data Security Standard • Payment Card Industry Security Standards Council • Reduce credit card fraud from theft • Applies end to end card data security • 12 requirement sections • Well known best practices • Periodically updated
PCI-DSS Compliance Dependencies PCIcouncil Merchants,card processors,card issuers Serviceproviders OpenEdgepaymentapplications Network &OS software OpenEdgemiddleware
PCI-DSS Compliance Varies Card Transactions Compliance Process SAQ &Network audit QSA: Qualified Security AssessorsSAQ: Self Assessment Questionnaire
The Road To Payment Application Compliance • Become informed • Perform a self assessment • If you resell your payment application • Comply with PA-DSS (Payment Application Data Security Standard) • Optional: get QSA audit • If you develop your in-house payment applications • Comply with PCI-DSS standard • Certify your network and systems • Remember, plan for next PCI-DSS and PA-DSS versions
Limiting The Impact Of Being Compliant • Limit DSS Scope • Defined by merchant implemented internal firewalls • Behind firewall is ‘in scope’ and DSS compliant • Do not persistently store cardholder data • Use DSS certified service provider NetworksServersPayment applicationsDatabasesNon payment applications
PCI-DSS Requirements Build and Maintain a Secure Network • Install a firewall configuration to protect cardholder data • Do not use vendor-supplied system passwords and security parameters
PCI-DSS Requirements Protect Cardholder Data • Protect stored cardholder data • Encrypt transmission of cardholder data over public networks
PCI-DSS Requirements Maintain a Vulnerability Management Program • Use & update anti-virus software • Develop secure systems and applications
PCI-DSS Requirements Implement Strong Access Measures • Restrict access to cardholder data • Assign a unique ID to each person • Track & monitor access to network & cardholder data • Restrict physical access to cardholder data
PCI-DSS Requirements Monitor & Test Networks • Regularly test security systems and processes • Maintain an information security policy
For More Information, Go To… • PSDN • OpenEdge Applications in a PCI-DSS Environment • Web • www.pcisecuritystandards.org • PCI-DSS and PA-DSS standards • Payment application requirements • Self assessment questionnaire • List of validated payment applications • www.owasp.org • Books • PCI for Dummies
In Summary • PCI-DSS & PA-DSS are collections of security best practices • Plan your short and long term compliance strategy • Use OpenEdge features to assist you in making your application PCI-DSS compliant
Session 119 Payment Card Industry (PCI ) -Data Security Standard (DSS): Introduction and Best Practices Michael Jacobs Development Architect - OpenEdge