Tuesday, November 1, 2011

Straight Talk on Tokenization

Are you looking at tokenization as a way to reduce your PCI scope? My guess is that you or at least some of your campus merchants are, and therefore you will want to be as up-to-date as you can especially with the recent PCI Council guidance on tokenization and PCI scoping.

Many campus merchants are considering various tokenization strategies (or at least their software and service providers are pitching tokenization to them). As I've written before (see here, and here), tokenization has a lot of benefits. It also has some things you need to be careful of, and definitely some things you need to know before you go signing any contracts with token providers.

On Thursday, November 3 I will be participating in a tokenization webinar entitled: Straight Talk on the New PCI Tokenization Guidelines -- A QSA's Viewpoint. The webinar is sponsored by Intel (which also sponsored some of my tokenization research and the Tokenization Buyer's Guide). I will discuss tokenization in general, some of the different approaches, and which implementation might be best for which types of merchants.

If you are interested, you can register using this link. Yes, there will be a description of (i.e., pitch for) Intel's product offering at the end, but the majority (my part) is vendor agnostic and explores both third-party hosted and internal solutions.

If you are considering tokenization, you may want to have a listen. If you can't make the live webinar, I'm guessing they will have a recording available.

Friday, October 28, 2011

PCI Council Webinar to Address Point-to-Point Encryption Security

The PCI Security Standards Council has announced will provide a detailed overview to the recent updates to the PIN Transaction Security (PTS) program on November 8. A second, repeat webinar will be November 10.

Schools interested in P2PE may want to consider attending to get the latest information on the latest release of the PCI PTS requirements. Many institutions and their auxiliaries are very interested in this exciting technology that can reduce your PCI scope greatly. There are still some details like testing the POS devices to make sure they work as advertised, and this webinar should address some of those security questions.

Here are the details. You can also check out the PCI Council’s Website link:

PIN Transaction Security Program Updates: PTS 3.1 and PCI PIN Security Requirements 1.0

Tuesday, November 8, 2011 at noon PT/3:00 pm ET/8:00 pm GMT



Thursday, November 10, 2011 at 8:00 am PT/11:00 am ET/4:00 pm GMT


Please join members of the PCI Standards team for a detailed overview of the newest updates to the PIN Transaction Security (PTS) program, followed by a live Q&A session. The presentation will cover key changes to PTS requirements including:


Updates to PTS Point of Interaction (POI) Requirements 3.1 that include two new approval classes for Secure Card Readers and Non-PIN Entry Devices


Extension of Secure Reading and Exchange of Data (SRED) and Open Protocol (OP) modules to version 2 devices


Explanation of how these changes can facilitate the secure deployment of point-to-point encryption (P2PE) technology and mobile payments


Overview of PCI PIN Security Requirements 1.0 and the use of this criteria for the protection of PIN data enhancements to HSM Security Requirements
I have written about P2PE before on this blog (click here to read it). Those of you new to this may want to have a read before the webinar.

Tuesday, October 25, 2011

Voting for PCI Special Interest Groups is Open

I know a number of your institutions are Participating Organizations (POs) in the PCI Council. If you are, it is time you get your PCI team -- including business and IT groups -- together to decide how to cast your vote for the Special Interest Groups (SIGs) for 2012.

The Council received 31 nominations for SIGs, and they narrowed it down to seven. Based on how POs vote, three will be selected for 2012. The seven are (in no particular order):

  • Managing administrative access to systems and devices
  • Preparing a risk assessment
  • Patch management
  • eCommerce security
  • Cloud technology
  • PCI for small businesses
  • Managing hosted service providers.

Looking at the seven, four are more technical in nature and three are business focused. That is why I suggest you want to get your whole team together so you gather ideas from all over the institution.

As most of you know, I (along with Tom Davis of Indiana University) represent NACUBO which is a PO. We finished our analysis and have recommended NACUBO's vote (which I'm casting later today) to reflect the mix of needs of Higher Ed institutions of all sizes. You now need to do the same for your institution. Voting opened Monday (Oct 24) and closes November 3, so don't wait!

Schools that are POs were sent an email last week with a link to the Council's PO portal. The portal has videos of the brief presentations from the Community Meeting where they previewed each nominated SIG. I recommend you view the videos, discuss your priorities, and cast your vote.

Not many standards or regulatory organizations let their 'constituents' decide where to do research and provide guidance. The PCI Council does, so I hope all schools who are POs will be sure and vote.


Wednesday, September 21, 2011

Self-Assess Like a QSA?

Just about everyone reading this self-assesses their institution's PCI compliance using one or a set of Self-Assessment Questionnaires (SAQs). This is the PCI Council's -- and the card brands' -- own version of the honor system.

But the very largest Level 1 merchants don't get to use the honor system. Instead they must get an outside assessment, either by a Qualified Security Assessor (QSA, like me) or a member of their own staff who attended training and qualified as an Internal Security Assessor (ISA).

The QSA prepares a Report on Compliance (ROC, pronounced "rock"). This covers all of PCI. Moreover, the QSA needs to see multiple pieces of evidence before she/he can mark a requirement as "in place." The Council has released its updated guidance on just what the QSA does. It could make informative reading. It is now available for everyone to see.

Click here to download a copy of the ROC Reporting Instructions, then see how your own internal self-assessment measures up.

Staying in Touch With Developments

I'm getting ready to head off on vacation for a few weeks, and it has me thinking about staying in touch. I mention this because I probably won't be making many blog posts for a bit, and at the same time there is a lot happening in the PCI world that you want to make sure you stay current.

One way is to set up your Google (or Safari or whatever) reader and load up the RSS feeds for your favorite blogs. That is what I do, and it's great for filtering what you need to see. A great way to start is with the blogroll on the right. These are some of the blogs I follow (or participate in), and I'd add them to whatever list you put together.

Of particular interest might be the StorefrontBacktalk link. While they have gone to a premium pricing model (hey...everybody's got to eat!), I am pleased to announce that my PCI columns shortly will all be "free." There is a lot of other great retail content there, too, so if you have auxiliaries or other retail-like operations on campus, I'd point your RSS feed there.

With so much happening on point-to-point encryption (with the painful acronym P2PE), tokenization, and the reality of PCI 2.0, you should take a few minutes to skim the highlights so you can stay up to date with what's happening.

Over the next few weeks, I'll be relying on my iPad and assorted English, Belgian, and French hotel WiFi links to stay connected. Yes, I'll still be on vacation, but I'll also be staying in touch. You may want to do the same.

Friday, September 2, 2011

Certificate Attacks on Google

Like many of you involved in security, I have been following the recent news about the recent compromise of a Dutch certificate authority (presumably by the government of Iran, but not proven). There was a brief piece earlier in the New York Times (click here). You also can find a great explanation and exposition of exactly what happened and what it means in this blog post.

Yes, the Internet is a very scary place.

UPDATE:
Here are some additional articles that shed some more light on the risks and what you need to know:
  • If you read nothing else, please read this post (click here) from my colleague, Morgan Tremper. As he says, "Far and away, the most essential method for staying ahead of threats to your security is fixing the problems that the industry already knows about." A very clever man is our Morgan. What Morgan points out is that there is something you can do to protect yourself, but you (and all your users) have to *do* it!

  • "The disturbingly complete compromise of DigiNotar, the Dutch certificate authority, has broad ramifications for other CAs, enterprises and consumers who rely on the shaky web of trust that comprises the CA system. Here's what you should know about the attack and what you can do to protect yourself against intrusions resulting from it." (Click here to read more) .

  • "The details of the attack on DigiNotar that began to leak out on Monday have gotten uglier by the day as more and more researchers have looked into the compromise and the depth of the problem became clear." (Click here to read more).
Happy reading on this holiday weekend.

Friday, August 26, 2011

PCI Tokenization Buyer's Guide Available


I am very pleased and excited to tell you about a project I just completed. That project was to write a buyer's guide for tokenization. The project was sponsored by Intel Corporation. While they got to look at the draft, I (and my colleagues at 403 Labs) had complete editorial independence and control. The result is a vendor-neutral, technology-neutral discussion of tokenization, how it might reduce your PCI scope, how to evaluate alternative vendor products, and what you can expect.

Together with the guidance from the PCI Council, I hope this Buyer's Guide will help merchants determine if tokenization is right for them, and if it is how they should evaluate their options. If your bookstore, food service operation, parking garages, or other auxiliary organization has any retail-type payment activities, they likely are (or should) be looking at tokenization as a way to reduce their PCI scope. This guide was designed for them.

You can download a pdf of the white paper at Intel's website. I hope you find it useful.