Tuesday, January 28, 2014

Today Only, Free Training From the PCI SSC

Sorry, this special offer is now expired.

In support of Data Privacy Day, the PCI Security Standards Council (PCI SSC), an open global forum for the development of payment card security standards, announced it will offer PCI Awareness online training free of charge to those who register today on the PCI SSC website. The offer for free PCI Awareness online training expires after midnight 28 January, 2014 EST.

“The Council applauds the National Cyber Security Alliance’s initiative to raise awareness and encourage global collaboration on data protection, said Bob Russo, general manager, PCI Security Standards Council. “And today, as part of our ongoing commitment to securing payment card data globally, we’re pleased to make PCI Awareness online training available at no charge.”

PCI Awareness training helps companies educate employees who handle cardholder data on the importance of payment security. It is one of a suite of training offerings designed and developed by the Council to build awareness and to train, test, and qualify organizations and individuals to assess and validate adherence to PCI Security Standards.

Again, the offer for free PCI Awareness online training expires after midnight 28 January, 2014 EST. See this page for complete information:

https://www.pcisecuritystandards.org/pdfs/14_01_28_2014_On_Data_Privacy_Day_PCI_SSC_Emphasizes_Committment_To_Securing_Payment_Card_Data_Globally.pdf

Monday, January 13, 2014

The 2014 Treasury Institute PCI Workshop

A Message From Pete Campbell:

As you may know, we’ve been working behind the scenes to put together a dynamic and educational agenda for the Treasury Institute PCI Workshop to take place this April 28-30 in Chicago (see http://www.treasuryinstitute.org/pages/PCI-DSS-Workshop-2014.html for details and registration).  It’s a tall order but we’re trying to carry on and build on the excellent foundation Walt Conway provided.  As usual there are a variety of topics but we’re trying to have a theme of how PCI DSS 3.0 changes things, looking beyond simple compliance, and solving the difficult security and compliance challenges.

The time has come to solicit presenters from within higher education.  As before the Treasury Institute will cover the conference registration fee and hotel for one speaker from each school who presents.  Please reply back to me (pcampbell@treasuryinstitute.org) directly with any questions or if you have a topic you’d like to suggest.  Things are still a little flexible but at this point we have the following openings (the first two in each track are desired topics; if nobody steps forward then we’ll consider additional topic suggestions):

IT Track
  • Point of Sale on your network
  • Scoping and your network
  • Suggest a topic
  • Suggest a topic
Business Track
  • Selecting the correct SAQ
  • Service Provider Oversight: Contracts, Compliance, etc.
  • Suggest a topic
  • Suggest a topic
 
Thanks, and I hope to see everyone in Chicago.

Pete Campbell, M.Ed., CISA, PCIP, PCI ISA
Co-Moderator/Co-Chair, PCI Workshop
The Treasury Institute for Higher Education
(479) 575-7353
 

Thursday, November 7, 2013

PCI DSS Version 3.0 Has Arrived

Here are the links on the PCI Security Standards Council web site for the new version of the Payment Card Industry Data Security Standard, PCI DSS.

Press release:

https://www.pcisecuritystandards.org/pdfs/13_11_06_DSS_PCI_DSS_Version_3_0_Press_Release.pdf

Infographic:

https://www.pcisecuritystandards.org/pdfs/PCIDSS.pdf

The Standard:

https://www.pcisecuritystandards.org/security_standards/documents.php?document=pci_dss_v3-0

Summary of Changes:

https://www.pcisecuritystandards.org/security_standards/documents.php?document=pci_dss_v3_summary_of_changes

PA-DSS

Version 3.0 of the Payment Application Data Security Standard, PA-DSS, has also been released today. Go to the PCI Council's web site for more information:
https://www.pcisecuritystandards.org

Wednesday, November 6, 2013

On the Eve of PCI DSS 3.0: Scope Creep

Okay, it's coming tomorrow. We have been hearing about it for a very long time and the wait is almost over - PCI DSS version 3.0 will be released on November 7, 2013.

I have been on pins and needles about this for almost a year. And wondering about one part of it for over two years. When I started in my position at Michigan State University in 2011, I had many conversations about PCI scope with Walt Conway. One thing we discussed from time to time were documents from both MasterCard and Visa about the risks surrounding the use of hosted payment pages for e-commerce sites. The main point of these documents was that our usual understanding about what was in and what was out of scope for PCI compliance did not necessarily cover all the risks, and that merchants should do more than they were currently doing to protect cardholder data.

Yikes!

Like many colleges and universities back in the 00s, we listened to and followed the advice to reduce and limit our scope of PCI compliance by eliminating cardholder data wherever we could. We had a home-grown payment processing system that stored, processed, and transmitted cardholder data. Yikes! SAQ D!

We decided to turn that part of our e-commerce business over to a third-party payment processor. We invested in a system that would allow us to continue using our internally developed e-commerce applications, but we would now send our customers off to our service provider to handle the payment part of the application. When they clicked the Checkout button their browser would then display a page from our vendor, where the cardholder data would be entered and collected for processing. Boom! No more cardholder data on MSU servers.

Relief & Dark Clouds

It was glorious and we breathed a sigh of relief that we had made such a significant reduction in the effort needed to maintain PCI compliance at our university. And every unit on campus that had their own e-commerce shopping cart app could continue to use them without having to be concerned about PCI DSS, except in a very minimal, SAQ A kind of way.

But then I saw these documents from the card brands about the risks of hosted payment pages. MasterCard published their bulletin back in 2010, the year when PCI DSS version 2.0 was released. And MasterCard was saying, "Wait a minute here! You're not necessarily off the hook just because someone else is handling your cardholder data for you." They warned of the rise in what are called "man-in-the-middle attacks." The problem they were seeing was that servers that did not touch cardholder data at all, but were part of the e-commerce transaction, these servers were being compromised and the URL for the payment page was being changed. Customers were being re-directed to malicious web pages that would impersonate the real payment pages and steal the customer's cardholder data. And they might even complete the real payment for the customer, who would not suspect a thing. Oh. This is not good.

I started to wonder if these warnings might eventually show up in a future version of PCI DSS, and it looks like that is what has now happened. The first official clue was in the PCI DSS E-commerce Guidelines, submitted by the E-commerce Special Interest Group in January, 2013. Then the draft of PCI DSS v3.0 confirmed this where it defines "system components" as including "Systems that...may impact the security of (for example, name resolution or web redirection servers) the CDE." And the PCI council was very explicit about web redirection servers at the PCI SSC North American Community Meeting in Las Vegas this past September. Those servers are in scope.

Now What?

What will this mean? For our university, we will need to start to define controls that need to be applied to our e-commerce servers that we currently consider to be out of scope. But exactly which controls should those be? According to the E-commerce Guidelines, those would be the "Applicable PCI DSS requirements." What is applicable?

In a chart on page 22 of the E-commerce Guidelines, regarding hosted payment pages, we find this:

Merchant is responsible for:
  • Managing website and servers (if self-hosted), including applicable PCI DSS requirements
  • Applicable PCI DSS requirements for managing third parties, (e.g., Requirement 12.8)
  • Having written agreements with any third parties and ensuring they protect cardholder data on behalf of the merchant, in accordance with PCI DSS.
  • Securing the web page(s) containing the redirection code and/or function(s).
 Again, "applicable PCI DSS requirements" as well as "Securing the web page(s) containing the redirection code." But what, exactly, is applicable? What does "securing" entail? They may as well have said, "It depends." Those question were on the mind of many assessors in Las Vegas in September. As it stands now, I will have to go through every requirement and sub-requirement to decide if it is applicable. As much as I dislike PCI DSS being denigrated as "checkbox security," the fact is in this situation I want a checklist! If, goodness forbid, we had a data breach and had decided a particular PCI requirement didn't apply but the forensic investigator decided it did apply, we would have an even bigger problem than we thought we had.

But, surprisingly to me the Council told the community the very next morning that they listened to our concerns. They didn't make it a hard promise, but it sounds like they are going to create a new SAQ that covers "web redirection" servers such as I'm concerned about. For those situations where SAQ A just doesn't cut it any more. And they also talked about some additional guidance on PCI DSS scope. After all the hoopla about the Scope SIG that disappeared, they owe that to us.

PCI DSS version 3.0 will not be revolutionary, although it is still full of changes. This business about scope isn't even in one of the actual requirements. But version 3.0 looks like it will still say, as it said in version 2.0, "The first step of a PCI DSS assessment is to accurately determine the scope of the review." And scope will continue to be one of the most important things I need to consider when assessing compliance at my school.

We'll see what PCI DSS version 3.0 actually says tomorrow. Until then!

On the Eve of PCI DSS v3.0 - About

Here is a summary of information about the new standard, which will be released tomorrow.

What do we know about PCI DSS v3.0?

  • Release date is November 7, 2013
  • Becomes effective on January 1, 2014
  • Version 2.0 remains in effect until December 31, 2014 to provide a transition period
  • Version 3.0 introduces more changes than Version 2.0
  • There will be several new sub-requirements
  • Some of the sub-requirements will become effective on July 1, 2015. They will be best practices until then
  • Not all documents will be released on November 7. These will be available in 2014:
    • Revised SAQs
    • New SAQ for web-redirection payment environments
      • Announced at the North American Community Meeting
    • ROC reporting template
    • ROC reporting instructions
    • New AOCs
    • Prioritized Approach to PCI DSS Compliance

What factors have influenced the changes in PCI DSS v3.0?

  • Criminals are still targeting cardholder data
  • Many security breaches are tied to:
    • Lack of payment security awareness and education
    • Malware
    • Weak passwords and authentication
    • Slow self-detection
    • Poor implementation of the PCI Standards
    • Security issues with third-party providers
    • Lack of maintenance to ensure compliance between assessments
    • Inconsistent assessments

What will PCI DSS v3.0 do?

  • Focus more on higher risk areas
  • Clarify many of the requirements
  • Help to improve understanding of the intent of the requirements
  • Add flexibility to implementation
  • Help improve consistency of assessments with more stringent assessment procedures
  • Evolve with changing best practices, as well as risks and threats

What are the major themes in PCI DSS v3.0?

  • Encourage proactive approaches that focus on security rather than compliance
  • Make PCI DSS “business-as-usual”.
  • Increase awareness and education
  • Increase flexibility to allow better security
  • Security as a shared responsibility

What kinds of changes are included in PCI DSS v3.0?

  • Clarification – Concise wording to ensure that each requirement matches the desired intent
  • Additional Guidance – To increase understanding
  • Evolving Requirement – Keep standards up-to-date with market changes and emerging threats


Friday, September 13, 2013

Announcements and Introduction

Walter T. Conway, Jr.
Over the past ten years, The Treasury Institute for Higher Education has committed resources to promote education in PCI DSS compliance and best practices throughout the industry.  This includes facilitating well attended workshops annually, managing an industry PCI-DSS blog and being a strong voice on industry councils.  As most of you know, the Institute lost a friend and colleague with the passing of Walt Conway who put a tremendous amount of time into this effort.

Going forward, the Institute will continue its commitment to PCI DSS education.  We have asked three individuals, Ron King, Pete Campbell and Gene Willacker to lead our efforts in this important area.

  • Ron will be responsible for overall coordination and co-moderation for the 2014 workshop, including chairing the Program Committee.
  • Pete will co-chair the 2014 workshop Program Committee and co-moderate the workshop and serve as a representative of the Institute and NACUBO on the PCI Council.
  • Gene will oversee the Institute's PCI Blog.

First and foremost we thank Ron, Pete and Gene for their continuing the Institute's PCI work and growing the presence developed by Walt.  Most importantly, we are excited that the Institute's PCI blog is back online and we will begin planning the 2014 PCI DSS workshop.  Expect the program committee to be reaching out to the higher education PCI community in the near future to solicit presenters and topic ideas as it prepares the 2014 agenda.

By way of introduction...

Gene Willacker is the PCI Compliance Officer for Michigan State University (MSU). This position was created in 2011 in order to improve information security and to minimize institutional risk by strengthening the university's PCI compliance efforts for its nearly 450 merchant operations. At MSU, PCI compliance is a Treasury function under the Office of the Controller, supporting the university through the MSU Cashier's Office.

Gene has been working in several areas of the information technology field since 1990, focusing on IT security since 2002. Prior to joining the Controller's Office, he was the Information Security Administrator for MSU's Division of Residential and Hospitality Services (RHS), a 5,000-employee business unit operating in every area of the MSU campus. While there, Gene developed PCI compliance strategies for the division and managed its network security operations. Gene is certified by the PCI Security Standards Council as a PCI Professional and as a PCI Internal Security Assessor (ISA).

Gene's philosophy is that information security and PCI compliance need to be approached with the understanding that they must be an everyday part of business as usual. They are not simply information technology initiatives or checkbox audits, but the end result of business and technology working together to minimize institutional risk.

Please join us in welcoming Gene to our PCI blog.


And remember to save the date for the 2014 PCI DSS workshop:

Monday, April 28th  through Wednesday, April 30th
The Palmer House
Chicago, Illinois, US

Dennis W. Reedy
Jon K. Speare
Executive Directors
Treasury Institute for Higher Education
  

Monday, July 15, 2013

Walt Conway Memorial


Walter Conway
June 25th, 2013

It is with great sadness that the Treasury Institute’s Board announces the passing of a good friend and colleague, Walt Conway.  Over the past twenty years, Walt was a major part of the Treasury Institute and its predecessor programs, helping all of us in higher education.  Walt became a friend and mentor teaching us much more than treasury management.  He was loved and respected by all that had the opportunity to work with him.  

The Treasury Institute for Higher Education is a stronger organization because of Walt’s involvement and his drive to make us all better. Along the way, Walt taught us to enjoy our work, our roles, and more importantly, to build upon the difference we can all make.  The Treasury Institute will continue Walt’s work with the hope that eventually we can live up to his accomplishments.

The Treasury Institute will be making a contribution to the Walter T. Conway, Jr. Fund at Episcopal Community Services, www.ecs-sf.org.

For the present, this blog will go silent, but hopefully not for long.  Walt’s commitment to PCI education within Higher Education was second to none.  We will do our best to continue this commitment by resuming the PCI DSS Blog within the next few months.

--The Treasury Institute for Higher Education