SlideShare a Scribd company logo
1 of 14
Payment Card Industry Data Security Standard By: Sally Chiu ACC 626  Section 002
What is PCI DSS? Is it effective? Impact on the auditing profession Overview
“Payment Card Industry Data Security Standard” industry-wide framework for developing a robust payment card data security process aims to protect cardholder data  What is PCI DSS?
response to the growing misuse of payment card information Payment Card Industry (PCI) Security Standards Council - 5 global payment card companies:  American Express, Discover, JCB International, MasterCard, and Visa applies to entities that store, process or transmit cardholder information  Retailers, on-line merchants, payment processing companies History and Origins
6 principles, 12 major requirements, many sub-requirements and detailed requirements, and testing procedures  6 objectives: Build and Maintain a Secure Network Protect Cardholder Data Maintain a Vulnerability Management Program Implement Strong Access Control Measures Regularly Monitor and Test Networks Maintain an Information Security Policy Components of PCI DSS:
PCI Security Standards Council sets the overall high level requirements each card issuer enforces the standard, sets validation requirements and penalties different merchant / service provider levels, and requirements for each level Eg: Level 1 – merchants with 6M+ transactions annually  most stringent requirements ASV scans, QSA audits most recent version - PCI DSS v.2.0 continuously updated to as new threats emerge PCI DSS Logistics
Is PCI DSS Effective? Effectiveness of PCI DSS 2011Ponemon Institute & Imperva study: 64% of compliant firms had no breaches over the past two years, vs only 38% of non-compliant firms   2011 Cisco study: 70% feel that their organizations are more secure  87% feel that PCI compliance is necessary 60% are using PCI compliance to drive other security network projects appears that most organizations regard PCI DSS as an effective tool in improving cardholder security
Ineffectiveness of PCI DSS PCI DSS compliant firms still experience security breaches Eg: Hannaford Bros, breach in 2008:   theft of 4.2 million customer card numbers  Eg: Heartland Payment Systems, breach in 2008:  130 million credit card numbers exposed Critics: PCI DSS ineffective as it has failed to prevent data breach incidents  Is PCI DSS Effective?
Is PCI DSS Effective? Ineffectiveness of PCI DSS developed by card companies to shift blame to retailers rather than actually preventing cybercrime lack of standardization high cost of compliance - $3.8M implementation cost for Level 1 merchants Executives see PCI DSS as a burden, not an investment   ROI unknown
PCI DSS: Effective guideline, but does not guarantee security  Breaches of PCI DSS compliant firms show that even compliance does not guarantee protection against security breaches PCI DSS -  only a framework for protecting cardholder data – will not 100% guarantee security Effective from aspect of laying the groundwork for a secure system Forces entities to be continuously compliant
Canadians are among the most frequent users of debit and credit cards  Canada seen as vulnerable to hackers and data thieves due to: lack of strong Canadian privacy legislation  inadequate IS security at Canadian SMEs lag in adopting Chip & PIN technology on credit cards  Canada has relied upon PCI DSS to improve cardholder data security PCI DSS and Canada
Impact of PCI DSS on the Accounting Profession opens numerous opportunities for the accounting profession  CAs can act as consultants to businesses  CAs can act as QSAs to assess PCI DSS compliance CAs can work together with the PCI to achieve greater protection of cardholder data
Impact of PCI DSS on the Accounting Profession CAs acting as QSAs can offer integrated services to clients  PCI compliance & S. 5970 audit  efficiencies can be gained However, should be aware of differences: Framework Testing period Scope
PCI DSS is a critical step towards improving the security of cardholder data in Canada and worldwide presents new opportunities for the accounting profession Conclusion

More Related Content

What's hot

Tripwire pci basics_wp
Tripwire pci basics_wpTripwire pci basics_wp
Tripwire pci basics_wp
Edward Lam
 
P0 Pcidss Overview
P0 Pcidss OverviewP0 Pcidss Overview
P0 Pcidss Overview
b28stu
 
PCIDSS compliance made easier through a collaboration between NC State and UN...
PCIDSS compliance made easier through a collaboration between NC State and UN...PCIDSS compliance made easier through a collaboration between NC State and UN...
PCIDSS compliance made easier through a collaboration between NC State and UN...
John Baines
 
Alcumus ISOQAR PCIDSS Compliance Presentation
Alcumus  ISOQAR PCIDSS Compliance PresentationAlcumus  ISOQAR PCIDSS Compliance Presentation
Alcumus ISOQAR PCIDSS Compliance Presentation
Bhargav Upadhyay
 
Senate_2014_Data_Breach_Testimony_Richey
Senate_2014_Data_Breach_Testimony_RicheySenate_2014_Data_Breach_Testimony_Richey
Senate_2014_Data_Breach_Testimony_Richey
Peter Tran
 
Visa Compliance Mark National Certification
Visa Compliance Mark National CertificationVisa Compliance Mark National Certification
Visa Compliance Mark National Certification
Mark Pollard
 
Whitepaper - Application Delivery in PCI DSS Compliant Environments
Whitepaper - Application Delivery in PCI DSS Compliant EnvironmentsWhitepaper - Application Delivery in PCI DSS Compliant Environments
Whitepaper - Application Delivery in PCI DSS Compliant Environments
Jason Dover
 

What's hot (20)

Tripwire pci basics_wp
Tripwire pci basics_wpTripwire pci basics_wp
Tripwire pci basics_wp
 
What Everybody Ought to Know About PCI DSS and PA-DSS
What Everybody Ought to Know About PCI DSS and PA-DSSWhat Everybody Ought to Know About PCI DSS and PA-DSS
What Everybody Ought to Know About PCI DSS and PA-DSS
 
P0 Pcidss Overview
P0 Pcidss OverviewP0 Pcidss Overview
P0 Pcidss Overview
 
Pcidss qr gv3_1
Pcidss qr gv3_1Pcidss qr gv3_1
Pcidss qr gv3_1
 
PCI-DSS for IDRBT
PCI-DSS for IDRBTPCI-DSS for IDRBT
PCI-DSS for IDRBT
 
PCIDSS compliance made easier through a collaboration between NC State and UN...
PCIDSS compliance made easier through a collaboration between NC State and UN...PCIDSS compliance made easier through a collaboration between NC State and UN...
PCIDSS compliance made easier through a collaboration between NC State and UN...
 
Pci dss compliance
Pci dss compliancePci dss compliance
Pci dss compliance
 
Introduction to PCI DSS
Introduction to PCI DSSIntroduction to PCI DSS
Introduction to PCI DSS
 
Webinar: Protect Your Customers, Protect Yourself Learn How to Take Precautio...
Webinar: Protect Your Customers, Protect Yourself Learn How to Take Precautio...Webinar: Protect Your Customers, Protect Yourself Learn How to Take Precautio...
Webinar: Protect Your Customers, Protect Yourself Learn How to Take Precautio...
 
Alcumus ISOQAR PCIDSS Compliance Presentation
Alcumus  ISOQAR PCIDSS Compliance PresentationAlcumus  ISOQAR PCIDSS Compliance Presentation
Alcumus ISOQAR PCIDSS Compliance Presentation
 
Senate_2014_Data_Breach_Testimony_Richey
Senate_2014_Data_Breach_Testimony_RicheySenate_2014_Data_Breach_Testimony_Richey
Senate_2014_Data_Breach_Testimony_Richey
 
Pci dss v3-2-1
Pci dss v3-2-1Pci dss v3-2-1
Pci dss v3-2-1
 
Visa Compliance Mark National Certification
Visa Compliance Mark National CertificationVisa Compliance Mark National Certification
Visa Compliance Mark National Certification
 
ECMTA 2009 PCI Compliance and the Ecommerce Merchant
ECMTA 2009 PCI Compliance and the Ecommerce MerchantECMTA 2009 PCI Compliance and the Ecommerce Merchant
ECMTA 2009 PCI Compliance and the Ecommerce Merchant
 
Pcidss
PcidssPcidss
Pcidss
 
Payment Card Industry Introduction CMTA APR 2010
Payment Card Industry Introduction CMTA APR 2010Payment Card Industry Introduction CMTA APR 2010
Payment Card Industry Introduction CMTA APR 2010
 
Whitepaper - Application Delivery in PCI DSS Compliant Environments
Whitepaper - Application Delivery in PCI DSS Compliant EnvironmentsWhitepaper - Application Delivery in PCI DSS Compliant Environments
Whitepaper - Application Delivery in PCI DSS Compliant Environments
 
Quick Reference Guide to the PCI Data Security Standard
Quick Reference Guide to the PCI Data Security StandardQuick Reference Guide to the PCI Data Security Standard
Quick Reference Guide to the PCI Data Security Standard
 
PCI Compliance - How To Keep Your Business Safe From Credit Card Criminals
PCI Compliance - How To Keep Your Business Safe From Credit Card CriminalsPCI Compliance - How To Keep Your Business Safe From Credit Card Criminals
PCI Compliance - How To Keep Your Business Safe From Credit Card Criminals
 
Reducing cardholder data footprint with tokenization and other techniques
Reducing cardholder data footprint with tokenization and other techniquesReducing cardholder data footprint with tokenization and other techniques
Reducing cardholder data footprint with tokenization and other techniques
 

Similar to Payment card industry data security standard

Payment card industry data security standard 1
Payment card industry data security standard 1Payment card industry data security standard 1
Payment card industry data security standard 1
wardell henley
 
Understanding Your PCI DSS Guidelines: Successes and Failures
Understanding Your PCI DSS Guidelines: Successes and FailuresUnderstanding Your PCI DSS Guidelines: Successes and Failures
Understanding Your PCI DSS Guidelines: Successes and Failures
- Mark - Fullbright
 
Online_Transactions_PCI
Online_Transactions_PCIOnline_Transactions_PCI
Online_Transactions_PCI
Kelly Lam
 
Educause+PCI+briefing+4-19-20162345.pptx
Educause+PCI+briefing+4-19-20162345.pptxEducause+PCI+briefing+4-19-20162345.pptx
Educause+PCI+briefing+4-19-20162345.pptx
gealehegn
 

Similar to Payment card industry data security standard (20)

MTBiz May-June 2019
MTBiz May-June 2019 MTBiz May-June 2019
MTBiz May-June 2019
 
Payment card industry data security standard 1
Payment card industry data security standard 1Payment card industry data security standard 1
Payment card industry data security standard 1
 
Pci ssc quick reference guide
Pci ssc quick reference guidePci ssc quick reference guide
Pci ssc quick reference guide
 
eCommerce Summit Atlanta Mountain Media
eCommerce Summit Atlanta Mountain MediaeCommerce Summit Atlanta Mountain Media
eCommerce Summit Atlanta Mountain Media
 
PCI Compliance for Payment Security
PCI Compliance for Payment SecurityPCI Compliance for Payment Security
PCI Compliance for Payment Security
 
Understanding Your PCI DSS Guidelines: Successes and Failures
Understanding Your PCI DSS Guidelines: Successes and FailuresUnderstanding Your PCI DSS Guidelines: Successes and Failures
Understanding Your PCI DSS Guidelines: Successes and Failures
 
PruebaJLF.pptx
PruebaJLF.pptxPruebaJLF.pptx
PruebaJLF.pptx
 
PCI DSS
PCI DSSPCI DSS
PCI DSS
 
PCI Certification and remediation services
PCI Certification and remediation servicesPCI Certification and remediation services
PCI Certification and remediation services
 
A Case Study on Payment Card Industry Data Security Standards
A Case Study on Payment Card Industry Data Security StandardsA Case Study on Payment Card Industry Data Security Standards
A Case Study on Payment Card Industry Data Security Standards
 
Online_Transactions_PCI
Online_Transactions_PCIOnline_Transactions_PCI
Online_Transactions_PCI
 
Requirement of PCI-DSS in India.
Requirement of PCI-DSS in India.Requirement of PCI-DSS in India.
Requirement of PCI-DSS in India.
 
Verderber Rothke What’s New With PCI
Verderber   Rothke   What’s New With PCIVerderber   Rothke   What’s New With PCI
Verderber Rothke What’s New With PCI
 
Best Practices to Protect Cardholder Data Environment and Achieve PCI Compliance
Best Practices to Protect Cardholder Data Environment and Achieve PCI ComplianceBest Practices to Protect Cardholder Data Environment and Achieve PCI Compliance
Best Practices to Protect Cardholder Data Environment and Achieve PCI Compliance
 
The  security benefits associated with maintaining PCI compliance a.docx
The  security benefits associated with maintaining PCI compliance a.docxThe  security benefits associated with maintaining PCI compliance a.docx
The  security benefits associated with maintaining PCI compliance a.docx
 
Educause+PCI+briefing+4-19-20162345.pptx
Educause+PCI+briefing+4-19-20162345.pptxEducause+PCI+briefing+4-19-20162345.pptx
Educause+PCI+briefing+4-19-20162345.pptx
 
PCI DSS introduction by khaled mosharraf,
PCI DSS introduction by khaled mosharraf,PCI DSS introduction by khaled mosharraf,
PCI DSS introduction by khaled mosharraf,
 
Webinar - pci dss 4.0 updates
Webinar - pci dss 4.0 updates Webinar - pci dss 4.0 updates
Webinar - pci dss 4.0 updates
 
PCI DSS Data Security Compliance Program Overview
PCI DSS Data Security Compliance Program OverviewPCI DSS Data Security Compliance Program Overview
PCI DSS Data Security Compliance Program Overview
 
Best practices for PCI compliance
Best practices for PCI compliance Best practices for PCI compliance
Best practices for PCI compliance
 

Recently uploaded

zidauu _business communication.pptx /pdf
zidauu _business  communication.pptx /pdfzidauu _business  communication.pptx /pdf
zidauu _business communication.pptx /pdf
zukhrafshabbir
 
Constitution of Company Article of Association
Constitution of Company Article of AssociationConstitution of Company Article of Association
Constitution of Company Article of Association
seri bangash
 
What is social media.pdf Social media refers to digital platforms and applica...
What is social media.pdf Social media refers to digital platforms and applica...What is social media.pdf Social media refers to digital platforms and applica...
What is social media.pdf Social media refers to digital platforms and applica...
AnaBeatriz125525
 
ch 2 asset classes and financial instrument.ppt
ch 2 asset classes and financial instrument.pptch 2 asset classes and financial instrument.ppt
ch 2 asset classes and financial instrument.ppt
ZawadAmin2
 

Recently uploaded (20)

tekAura | Desktop Procedure Template (2016)
tekAura | Desktop Procedure Template (2016)tekAura | Desktop Procedure Template (2016)
tekAura | Desktop Procedure Template (2016)
 
zidauu _business communication.pptx /pdf
zidauu _business  communication.pptx /pdfzidauu _business  communication.pptx /pdf
zidauu _business communication.pptx /pdf
 
How to Maintain Healthy Life style.pptx
How to Maintain  Healthy Life style.pptxHow to Maintain  Healthy Life style.pptx
How to Maintain Healthy Life style.pptx
 
Engagement Rings vs Promise Rings | Detailed Guide
Engagement Rings vs Promise Rings | Detailed GuideEngagement Rings vs Promise Rings | Detailed Guide
Engagement Rings vs Promise Rings | Detailed Guide
 
PitchBook’s Guide to VC Funding for Startups
PitchBook’s Guide to VC Funding for StartupsPitchBook’s Guide to VC Funding for Startups
PitchBook’s Guide to VC Funding for Startups
 
Hyundai capital 2024 1q Earnings release
Hyundai capital 2024 1q Earnings releaseHyundai capital 2024 1q Earnings release
Hyundai capital 2024 1q Earnings release
 
Blinkit: Revolutionizing the On-Demand Grocery Delivery Service.pptx
Blinkit: Revolutionizing the On-Demand Grocery Delivery Service.pptxBlinkit: Revolutionizing the On-Demand Grocery Delivery Service.pptx
Blinkit: Revolutionizing the On-Demand Grocery Delivery Service.pptx
 
Chapter 2ppt Entrepreneurship freshman course.pptx
Chapter 2ppt Entrepreneurship freshman course.pptxChapter 2ppt Entrepreneurship freshman course.pptx
Chapter 2ppt Entrepreneurship freshman course.pptx
 
Raising Seed Capital by Steve Schlafman at RRE Ventures
Raising Seed Capital by Steve Schlafman at RRE VenturesRaising Seed Capital by Steve Schlafman at RRE Ventures
Raising Seed Capital by Steve Schlafman at RRE Ventures
 
Inside the Black Box of Venture Capital (VC)
Inside the Black Box of Venture Capital (VC)Inside the Black Box of Venture Capital (VC)
Inside the Black Box of Venture Capital (VC)
 
Sedex Members Ethical Trade Audit (SMETA) Measurement Criteria
Sedex Members Ethical Trade Audit (SMETA) Measurement CriteriaSedex Members Ethical Trade Audit (SMETA) Measurement Criteria
Sedex Members Ethical Trade Audit (SMETA) Measurement Criteria
 
HAL Financial Performance Analysis and Future Prospects
HAL Financial Performance Analysis and Future ProspectsHAL Financial Performance Analysis and Future Prospects
HAL Financial Performance Analysis and Future Prospects
 
Constitution of Company Article of Association
Constitution of Company Article of AssociationConstitution of Company Article of Association
Constitution of Company Article of Association
 
LinkedIn Masterclass Techweek 2024 v4.1.pptx
LinkedIn Masterclass Techweek 2024 v4.1.pptxLinkedIn Masterclass Techweek 2024 v4.1.pptx
LinkedIn Masterclass Techweek 2024 v4.1.pptx
 
stock price prediction using machine learning
stock price prediction using machine learningstock price prediction using machine learning
stock price prediction using machine learning
 
What is social media.pdf Social media refers to digital platforms and applica...
What is social media.pdf Social media refers to digital platforms and applica...What is social media.pdf Social media refers to digital platforms and applica...
What is social media.pdf Social media refers to digital platforms and applica...
 
ch 2 asset classes and financial instrument.ppt
ch 2 asset classes and financial instrument.pptch 2 asset classes and financial instrument.ppt
ch 2 asset classes and financial instrument.ppt
 
Potato Flakes Manufacturing Plant Project Report.pdf
Potato Flakes Manufacturing Plant Project Report.pdfPotato Flakes Manufacturing Plant Project Report.pdf
Potato Flakes Manufacturing Plant Project Report.pdf
 
HR and Employment law update: May 2024.
HR and Employment law update:  May 2024.HR and Employment law update:  May 2024.
HR and Employment law update: May 2024.
 
Special Purpose Vehicle (Purpose, Formation & examples)
Special Purpose Vehicle (Purpose, Formation & examples)Special Purpose Vehicle (Purpose, Formation & examples)
Special Purpose Vehicle (Purpose, Formation & examples)
 

Payment card industry data security standard

  • 1. Payment Card Industry Data Security Standard By: Sally Chiu ACC 626 Section 002
  • 2. What is PCI DSS? Is it effective? Impact on the auditing profession Overview
  • 3. “Payment Card Industry Data Security Standard” industry-wide framework for developing a robust payment card data security process aims to protect cardholder data What is PCI DSS?
  • 4. response to the growing misuse of payment card information Payment Card Industry (PCI) Security Standards Council - 5 global payment card companies: American Express, Discover, JCB International, MasterCard, and Visa applies to entities that store, process or transmit cardholder information Retailers, on-line merchants, payment processing companies History and Origins
  • 5. 6 principles, 12 major requirements, many sub-requirements and detailed requirements, and testing procedures 6 objectives: Build and Maintain a Secure Network Protect Cardholder Data Maintain a Vulnerability Management Program Implement Strong Access Control Measures Regularly Monitor and Test Networks Maintain an Information Security Policy Components of PCI DSS:
  • 6. PCI Security Standards Council sets the overall high level requirements each card issuer enforces the standard, sets validation requirements and penalties different merchant / service provider levels, and requirements for each level Eg: Level 1 – merchants with 6M+ transactions annually most stringent requirements ASV scans, QSA audits most recent version - PCI DSS v.2.0 continuously updated to as new threats emerge PCI DSS Logistics
  • 7. Is PCI DSS Effective? Effectiveness of PCI DSS 2011Ponemon Institute & Imperva study: 64% of compliant firms had no breaches over the past two years, vs only 38% of non-compliant firms 2011 Cisco study: 70% feel that their organizations are more secure 87% feel that PCI compliance is necessary 60% are using PCI compliance to drive other security network projects appears that most organizations regard PCI DSS as an effective tool in improving cardholder security
  • 8. Ineffectiveness of PCI DSS PCI DSS compliant firms still experience security breaches Eg: Hannaford Bros, breach in 2008: theft of 4.2 million customer card numbers Eg: Heartland Payment Systems, breach in 2008: 130 million credit card numbers exposed Critics: PCI DSS ineffective as it has failed to prevent data breach incidents Is PCI DSS Effective?
  • 9. Is PCI DSS Effective? Ineffectiveness of PCI DSS developed by card companies to shift blame to retailers rather than actually preventing cybercrime lack of standardization high cost of compliance - $3.8M implementation cost for Level 1 merchants Executives see PCI DSS as a burden, not an investment ROI unknown
  • 10. PCI DSS: Effective guideline, but does not guarantee security Breaches of PCI DSS compliant firms show that even compliance does not guarantee protection against security breaches PCI DSS - only a framework for protecting cardholder data – will not 100% guarantee security Effective from aspect of laying the groundwork for a secure system Forces entities to be continuously compliant
  • 11. Canadians are among the most frequent users of debit and credit cards Canada seen as vulnerable to hackers and data thieves due to: lack of strong Canadian privacy legislation inadequate IS security at Canadian SMEs lag in adopting Chip & PIN technology on credit cards Canada has relied upon PCI DSS to improve cardholder data security PCI DSS and Canada
  • 12. Impact of PCI DSS on the Accounting Profession opens numerous opportunities for the accounting profession CAs can act as consultants to businesses CAs can act as QSAs to assess PCI DSS compliance CAs can work together with the PCI to achieve greater protection of cardholder data
  • 13. Impact of PCI DSS on the Accounting Profession CAs acting as QSAs can offer integrated services to clients PCI compliance & S. 5970 audit efficiencies can be gained However, should be aware of differences: Framework Testing period Scope
  • 14. PCI DSS is a critical step towards improving the security of cardholder data in Canada and worldwide presents new opportunities for the accounting profession Conclusion