Sorry, this special offer is now expired.
In support of Data Privacy Day, the PCI Security Standards Council (PCI SSC), an open global forum for the development of payment card security standards, announced it will offer PCI Awareness online training free of charge to those who register today on the PCI SSC website. The offer for free PCI Awareness online training expires after midnight 28 January, 2014 EST.
“The Council applauds the National Cyber Security Alliance’s initiative to raise awareness and encourage global collaboration on data protection, said Bob Russo, general manager, PCI Security Standards Council. “And today, as part of our ongoing commitment to securing payment card data globally, we’re pleased to make PCI Awareness online training available at no charge.”
PCI Awareness training helps companies educate employees who handle cardholder data on the importance of payment security. It is one of a suite of training offerings designed and developed by the Council to build awareness and to train, test, and qualify organizations and individuals to assess and validate adherence to PCI Security Standards.
Again, the offer for free PCI Awareness online training expires after midnight 28 January, 2014 EST. See this page for complete information:
https://www.pcisecuritystandards.org/pdfs/14_01_28_2014_On_Data_Privacy_Day_PCI_SSC_Emphasizes_Committment_To_Securing_Payment_Card_Data_Globally.pdf
Tuesday, January 28, 2014
Monday, January 13, 2014
The 2014 Treasury Institute PCI Workshop
A Message From Pete Campbell:
As you may know, we’ve been working behind the scenes to put together a dynamic and educational agenda for the Treasury Institute PCI Workshop to take place this April 28-30 in Chicago (see http://www.treasuryinstitute.org/pages/PCI-DSS-Workshop-2014.html for details and registration). It’s a tall order but we’re trying to carry on and build on the excellent foundation Walt Conway provided. As usual there are a variety of topics but we’re trying to have a theme of how PCI DSS 3.0 changes things, looking beyond simple compliance, and solving the difficult security and compliance challenges.
The time has come to solicit presenters from within higher education. As before the Treasury Institute will cover the conference registration fee and hotel for one speaker from each school who presents. Please reply back to me (pcampbell@treasuryinstitute.org) directly with any questions or if you have a topic you’d like to suggest. Things are still a little flexible but at this point we have the following openings (the first two in each track are desired topics; if nobody steps forward then we’ll consider additional topic suggestions):
IT Track
Thanks, and I hope to see everyone in Chicago.
Pete Campbell, M.Ed., CISA, PCIP, PCI ISA
As you may know, we’ve been working behind the scenes to put together a dynamic and educational agenda for the Treasury Institute PCI Workshop to take place this April 28-30 in Chicago (see http://www.treasuryinstitute.org/pages/PCI-DSS-Workshop-2014.html for details and registration). It’s a tall order but we’re trying to carry on and build on the excellent foundation Walt Conway provided. As usual there are a variety of topics but we’re trying to have a theme of how PCI DSS 3.0 changes things, looking beyond simple compliance, and solving the difficult security and compliance challenges.
The time has come to solicit presenters from within higher education. As before the Treasury Institute will cover the conference registration fee and hotel for one speaker from each school who presents. Please reply back to me (pcampbell@treasuryinstitute.org) directly with any questions or if you have a topic you’d like to suggest. Things are still a little flexible but at this point we have the following openings (the first two in each track are desired topics; if nobody steps forward then we’ll consider additional topic suggestions):
IT Track
- Point of Sale on your network
- Scoping and your network
- Suggest a topic
- Suggest a topic
- Selecting the correct SAQ
- Service Provider Oversight: Contracts, Compliance, etc.
- Suggest a topic
- Suggest a topic
Pete Campbell, M.Ed., CISA, PCIP, PCI ISA
Co-Moderator/Co-Chair, PCI Workshop
The Treasury Institute for Higher Education
(479) 575-7353
Thursday, November 7, 2013
PCI DSS Version 3.0 Has Arrived
Here are the links on the PCI Security Standards Council web site for the new version of the Payment Card Industry Data Security Standard, PCI DSS.
https://www.pcisecuritystandards.org
Press release:
https://www.pcisecuritystandards.org/pdfs/13_11_06_DSS_PCI_DSS_Version_3_0_Press_Release.pdfInfographic:
https://www.pcisecuritystandards.org/pdfs/PCIDSS.pdfThe Standard:
https://www.pcisecuritystandards.org/security_standards/documents.php?document=pci_dss_v3-0Summary of Changes:
https://www.pcisecuritystandards.org/security_standards/documents.php?document=pci_dss_v3_summary_of_changesPA-DSS
Version 3.0 of the Payment Application Data Security Standard, PA-DSS, has also been released today. Go to the PCI Council's web site for more information:https://www.pcisecuritystandards.org
Wednesday, November 6, 2013
On the Eve of PCI DSS 3.0: Scope Creep
Okay, it's coming tomorrow. We have been hearing about it for a very long time and the wait is almost over - PCI DSS version 3.0 will be released on November 7, 2013.
I have been on pins and needles about this for almost a year. And wondering about one part of it for over two years. When I started in my position at Michigan State University in 2011, I had many conversations about PCI scope with Walt Conway. One thing we discussed from time to time were documents from both MasterCard and Visa about the risks surrounding the use of hosted payment pages for e-commerce sites. The main point of these documents was that our usual understanding about what was in and what was out of scope for PCI compliance did not necessarily cover all the risks, and that merchants should do more than they were currently doing to protect cardholder data.
We decided to turn that part of our e-commerce business over to a third-party payment processor. We invested in a system that would allow us to continue using our internally developed e-commerce applications, but we would now send our customers off to our service provider to handle the payment part of the application. When they clicked the Checkout button their browser would then display a page from our vendor, where the cardholder data would be entered and collected for processing. Boom! No more cardholder data on MSU servers.
But then I saw these documents from the card brands about the risks of hosted payment pages. MasterCard published their bulletin back in 2010, the year when PCI DSS version 2.0 was released. And MasterCard was saying, "Wait a minute here! You're not necessarily off the hook just because someone else is handling your cardholder data for you." They warned of the rise in what are called "man-in-the-middle attacks." The problem they were seeing was that servers that did not touch cardholder data at all, but were part of the e-commerce transaction, these servers were being compromised and the URL for the payment page was being changed. Customers were being re-directed to malicious web pages that would impersonate the real payment pages and steal the customer's cardholder data. And they might even complete the real payment for the customer, who would not suspect a thing. Oh. This is not good.
I started to wonder if these warnings might eventually show up in a future version of PCI DSS, and it looks like that is what has now happened. The first official clue was in the PCI DSS E-commerce Guidelines, submitted by the E-commerce Special Interest Group in January, 2013. Then the draft of PCI DSS v3.0 confirmed this where it defines "system components" as including "Systems that...may impact the security of (for example, name resolution or web redirection servers) the CDE." And the PCI council was very explicit about web redirection servers at the PCI SSC North American Community Meeting in Las Vegas this past September. Those servers are in scope.
In a chart on page 22 of the E-commerce Guidelines, regarding hosted payment pages, we find this:
Merchant is responsible for:
But, surprisingly to me the Council told the community the very next morning that they listened to our concerns. They didn't make it a hard promise, but it sounds like they are going to create a new SAQ that covers "web redirection" servers such as I'm concerned about. For those situations where SAQ A just doesn't cut it any more. And they also talked about some additional guidance on PCI DSS scope. After all the hoopla about the Scope SIG that disappeared, they owe that to us.
PCI DSS version 3.0 will not be revolutionary, although it is still full of changes. This business about scope isn't even in one of the actual requirements. But version 3.0 looks like it will still say, as it said in version 2.0, "The first step of a PCI DSS assessment is to accurately determine the scope of the review." And scope will continue to be one of the most important things I need to consider when assessing compliance at my school.
We'll see what PCI DSS version 3.0 actually says tomorrow. Until then!
I have been on pins and needles about this for almost a year. And wondering about one part of it for over two years. When I started in my position at Michigan State University in 2011, I had many conversations about PCI scope with Walt Conway. One thing we discussed from time to time were documents from both MasterCard and Visa about the risks surrounding the use of hosted payment pages for e-commerce sites. The main point of these documents was that our usual understanding about what was in and what was out of scope for PCI compliance did not necessarily cover all the risks, and that merchants should do more than they were currently doing to protect cardholder data.
Yikes!
Like many colleges and universities back in the 00s, we listened to and followed the advice to reduce and limit our scope of PCI compliance by eliminating cardholder data wherever we could. We had a home-grown payment processing system that stored, processed, and transmitted cardholder data. Yikes! SAQ D!We decided to turn that part of our e-commerce business over to a third-party payment processor. We invested in a system that would allow us to continue using our internally developed e-commerce applications, but we would now send our customers off to our service provider to handle the payment part of the application. When they clicked the Checkout button their browser would then display a page from our vendor, where the cardholder data would be entered and collected for processing. Boom! No more cardholder data on MSU servers.
Relief & Dark Clouds
It was glorious and we breathed a sigh of relief that we had made such a significant reduction in the effort needed to maintain PCI compliance at our university. And every unit on campus that had their own e-commerce shopping cart app could continue to use them without having to be concerned about PCI DSS, except in a very minimal, SAQ A kind of way.But then I saw these documents from the card brands about the risks of hosted payment pages. MasterCard published their bulletin back in 2010, the year when PCI DSS version 2.0 was released. And MasterCard was saying, "Wait a minute here! You're not necessarily off the hook just because someone else is handling your cardholder data for you." They warned of the rise in what are called "man-in-the-middle attacks." The problem they were seeing was that servers that did not touch cardholder data at all, but were part of the e-commerce transaction, these servers were being compromised and the URL for the payment page was being changed. Customers were being re-directed to malicious web pages that would impersonate the real payment pages and steal the customer's cardholder data. And they might even complete the real payment for the customer, who would not suspect a thing. Oh. This is not good.
I started to wonder if these warnings might eventually show up in a future version of PCI DSS, and it looks like that is what has now happened. The first official clue was in the PCI DSS E-commerce Guidelines, submitted by the E-commerce Special Interest Group in January, 2013. Then the draft of PCI DSS v3.0 confirmed this where it defines "system components" as including "Systems that...may impact the security of (for example, name resolution or web redirection servers) the CDE." And the PCI council was very explicit about web redirection servers at the PCI SSC North American Community Meeting in Las Vegas this past September. Those servers are in scope.
Now What?
What will this mean? For our university, we will need to start to define controls that need to be applied to our e-commerce servers that we currently consider to be out of scope. But exactly which controls should those be? According to the E-commerce Guidelines, those would be the "Applicable PCI DSS requirements." What is applicable?In a chart on page 22 of the E-commerce Guidelines, regarding hosted payment pages, we find this:
Merchant is responsible for:
- Managing website and servers (if self-hosted), including applicable PCI DSS requirements
- Applicable PCI DSS requirements for managing third parties, (e.g., Requirement 12.8)
- Having written agreements with any third parties and ensuring they protect cardholder data on behalf of the merchant, in accordance with PCI DSS.
- Securing the web page(s) containing the redirection code and/or function(s).
But, surprisingly to me the Council told the community the very next morning that they listened to our concerns. They didn't make it a hard promise, but it sounds like they are going to create a new SAQ that covers "web redirection" servers such as I'm concerned about. For those situations where SAQ A just doesn't cut it any more. And they also talked about some additional guidance on PCI DSS scope. After all the hoopla about the Scope SIG that disappeared, they owe that to us.
PCI DSS version 3.0 will not be revolutionary, although it is still full of changes. This business about scope isn't even in one of the actual requirements. But version 3.0 looks like it will still say, as it said in version 2.0, "The first step of a PCI DSS assessment is to accurately determine the scope of the review." And scope will continue to be one of the most important things I need to consider when assessing compliance at my school.
We'll see what PCI DSS version 3.0 actually says tomorrow. Until then!
On the Eve of PCI DSS v3.0 - About
Here is a summary of information about the new standard, which will be released tomorrow.
What do we know about PCI DSS v3.0?
- Release date is November 7, 2013
- Becomes effective on January 1, 2014
- Version 2.0 remains in effect until December 31, 2014 to provide a transition period
- Version 3.0 introduces more changes than Version 2.0
- There will be several new sub-requirements
- Some of the sub-requirements will become effective on July 1, 2015. They will be best practices until then
- Not all documents will be released on November 7. These will be available in 2014:
- Revised SAQs
- New SAQ for web-redirection payment environments
- Announced at the North American Community Meeting
- ROC reporting template
- ROC reporting instructions
- New AOCs
- Prioritized Approach to PCI DSS Compliance
What factors have influenced the changes in PCI DSS v3.0?
- Criminals are still targeting cardholder data
- Many security breaches are tied to:
- Lack of payment security awareness and education
- Malware
- Weak passwords and authentication
- Slow self-detection
- Poor implementation of the PCI Standards
- Security issues with third-party providers
- Lack of maintenance to ensure compliance between assessments
- Inconsistent assessments
What will PCI DSS v3.0 do?
- Focus more on higher risk areas
- Clarify many of the requirements
- Help to improve understanding of the intent of the requirements
- Add flexibility to implementation
- Help improve consistency of assessments with more stringent assessment procedures
- Evolve with changing best practices, as well as risks and threats
What are the major themes in PCI DSS v3.0?
- Encourage proactive approaches that focus on security rather than compliance
- Make PCI DSS “business-as-usual”.
- Increase awareness and education
- Increase flexibility to allow better security
- Security as a shared responsibility
What kinds of changes are included in PCI DSS v3.0?
- Clarification – Concise wording to ensure that each requirement matches the desired intent
- Additional Guidance – To increase understanding
- Evolving Requirement – Keep standards up-to-date with market changes and emerging threats
Friday, September 13, 2013
Announcements and Introduction
![]() |
| Walter T. Conway, Jr. |
Going forward, the Institute will continue its commitment to PCI DSS education. We have asked three individuals, Ron King, Pete Campbell and Gene Willacker to lead our efforts in this important area.
- Ron will be responsible for overall coordination and co-moderation for the 2014 workshop, including chairing the Program Committee.
- Pete will co-chair the 2014 workshop Program Committee and co-moderate the workshop and serve as a representative of the Institute and NACUBO on the PCI Council.
- Gene will oversee the Institute's PCI Blog.
First and foremost we thank Ron, Pete and Gene for their continuing the Institute's PCI work and growing the presence developed by Walt. Most importantly, we are excited that the Institute's PCI blog is back online and we will begin planning the 2014 PCI DSS workshop. Expect the program committee to be reaching out to the higher education PCI community in the near future to solicit presenters and topic ideas as it prepares the 2014 agenda.
By way of introduction...
Gene Willacker is the PCI Compliance Officer for Michigan State University (MSU). This position was created in 2011 in order to improve information security and to minimize institutional risk by strengthening the university's PCI compliance efforts for its nearly 450 merchant operations. At MSU, PCI compliance is a Treasury function under the Office of the Controller, supporting the university through the MSU Cashier's Office.Gene has been working in several areas of the information technology field since 1990, focusing on IT security since 2002. Prior to joining the Controller's Office, he was the Information Security Administrator for MSU's Division of Residential and Hospitality Services (RHS), a 5,000-employee business unit operating in every area of the MSU campus. While there, Gene developed PCI compliance strategies for the division and managed its network security operations. Gene is certified by the PCI Security Standards Council as a PCI Professional and as a PCI Internal Security Assessor (ISA).
Gene's philosophy is that information security and PCI compliance need to be approached with the understanding that they must be an everyday part of business as usual. They are not simply information technology initiatives or checkbox audits, but the end result of business and technology working together to minimize institutional risk.
Please join us in welcoming Gene to our PCI blog.
And remember to save the date for the 2014 PCI DSS workshop:
Monday, April 28th through Wednesday, April 30th
The Palmer House
Chicago, Illinois, US
Dennis W. Reedy
Jon K. Speare
Executive Directors
Treasury Institute for Higher Education
Monday, July 15, 2013
Walt Conway Memorial
Walter
Conway
June
25th, 2013
It is with
great sadness that the Treasury Institute’s Board announces the passing of a
good friend and colleague, Walt Conway.
Over the past twenty years, Walt was a major part of the Treasury
Institute and its predecessor programs, helping all of us in higher education. Walt became a friend and mentor teaching us
much more than treasury management. He
was loved and respected by all that had the opportunity to work with him.
The Treasury
Institute for Higher Education is a stronger organization because of Walt’s
involvement and his drive to make us all better. Along the way, Walt taught us
to enjoy our work, our roles, and more importantly, to build upon the
difference we can all make. The Treasury
Institute will continue Walt’s work with the hope that eventually we can live
up to his accomplishments.
The
Treasury Institute will be making a contribution to the Walter T. Conway, Jr.
Fund at Episcopal Community Services, www.ecs-sf.org.
For
the present, this blog will go silent, but hopefully not for long. Walt’s commitment to PCI education within
Higher Education was second to none. We
will do our best to continue this commitment by resuming the PCI DSS Blog
within the next few months.
--The
Treasury Institute for Higher Education
Subscribe to:
Posts (Atom)

