Not all data is created equal. Long ago the finance industry realized that credit card data was a special case – a type of data that needs to be protected at all costs, along with the entire data delivery and payment processing chain. Money has always attracted criminal attention, but in the digital age, criminals are less focused on stealing cash at gunpoint. They are focused on data that can provide access to money, and that’s where PCI compliance comes in.
What Is PCI
The Payment Card Industry Data Security Standards (PCI DSS) is a set of guidelines established for ensuring organizations protect the credit card information and related sensitive data as it moves between systems and stored in repositories. In 2006 The Payment Card Industry Security Standards Council (PCI SSC) was formed to mandate the development of the PCI DSS.
Who Needs PCI Compliance
Any organization that handles cardholder data (CD) and/or sensitive authentication data needs to comply with the PCI DSS. If you accept, transmit, or store credit card data ”even if the data just passes through your system ”you need to be PCI DSS compliant.
Cardholder Data (CD) encompasses all personally identifiable information (PII) that relates to a person who owns a credit or debit card, such as:
-
Primary account number (PAN)
-
Cardholder name
-
Expiration date
-
Service code
Sensitive Authentication Data (SAD) encompasses any data used to authenticate the identity of cardholders and authorize payment card transactions, such as:
-
Full track data ”magnetic-strip data or a chip equivalent.
-
CAV2/CVC2/CVV2/CID ”credit card security code.
-
Personal Identification Number (PIN) blocks ”an authentication code.
The PCI DSS prohibits storing any SAD data after authorization.
How to Determine the Scope of PCI Compliance
The PCI SSC defines merchants as any person or entity that accepts payment cards for goods and services. Merchants are categorized into levels that define the scope of validation actions required to achieve PCI DSS compliance.
The PCI SSC recognizes the differences between the sizes of businesses and requires an appropriate level of PCI compliance. In this regard, it doesn’t matter what the business sells. What matters is the number of transactions the business processes.
The 4 Levels of Merchants
-
Level 1: Processes over 6 million transactions per year
-
Level 2: Processes 1-6 million transactions per year
-
Level 3: Processes 20,000-1,000,000 transactions per year
-
Level 4: Processes less than 20,000 transactions per year
It is important to note that each credit card company has its own requirements. While most companies use the same standards, validation requirements may differ between companies and countries.
The Goals and Requirements of PCI DSS
The PCI SSI outlines a set of twelve requirements that must be met in order to achieve PCI DSS compliance. Each requirement answers a specific security need and together they form a cohesive blueprint of goals for protecting card payment transactions.
Goal #1: Develop and Maintain a Sustainable Security Program
According to a recent PCI DSS update, almost 3/4 of all attacks on retail, hospitality, and food service companies target cardholder data. Yet many companies haven’t adopted the risk-based mentality needed to sustain security at a level that balances the speed of technological advancements.
The PCI DSS guidelines emphasize the need to create and maintain an extensive security program for the protection of all digital resources, and cardholder data specifically.
Requirements:
1. Install and maintain a firewall configuration to protect cardholder data.
2. Do not use vendor-supplied defaults for system passwords and other security parameters.
Goal #2: Develop and Maintain a Program, Policy, and Procedures (PP&C)
The new PCI DSS update bumped this goal and its attributed requirement from the last place to the second place. It is now recognized that a formal compliance program can help organizations adopt and maintain PCI DSS compliance in an organized and sustainable manner.
The PP&C standardizes the strategy an organization takes towards achieving PCI DSS compliance and provides a flexible method of operation that leaves no room for doubt and confusion. Thus, helping the organization to get a 360 degrees view of PCI DSS security.
Requirement:
12. Maintain a policy that addresses information security for all personnel.
Goal #3: Protect Cardholder Data
While the first goal covers the overall security program of an organization, the third goal refers specifically to actions taken towards the protection of cardholder data. In doubt, the new update recommends following this rule of thumb when protecting cardholder data: whenever possible, don’t store cardholder data.
Requirements:
3. Protect stored cardholder data.
4. Encrypt transmission of cardholder data across open, public networks.
Goal #4: Maintain a Vulnerability Management Program
In computer security, a vulnerability is any weakness that can be exploited to gain unauthorized access and usage of a computer system. Vulnerabilities expose organizations to information security risks and may result in the theft of credit card data. Vulnerabilities can be found in the technical level of a system or network or in the human resources level of an organization.
Requirements for technical vulnerabilities:
5. Protect all systems against malware and regularly update anti-virus software or programs.
6. Develop and maintain secure systems and applications.
Requirement 12.6 for human resources vulnerabilities:
Implement a formal security awareness program to make all personnel aware of the importance of cardholder data security.
Additionally, the revised version of the PCI software security framework emphasizes the importance of assessing the maintenance and development of payment software to ensure third-party providers and open-source code don’t introduce vulnerabilities into the system of the merchant.
Goal #5: Implement Strong Access Control Measures
To protect cardholder data, the PCI DSS requires merchants to secure access to cardholder data. Access control (AC) helps merchants manage access to cardholder data. At the most basic level, this means denying or granting access to the data. Advanced identity and access management (IAM) systems provide controls such as role-based access control (RBAC).
Requirements:
7. Restrict access to cardholder data by business need to know.
8. Identify and authenticate access to system components.
9. Restrict physical access to cardholder data.
Goal #6: Regularly Monitor and Test Networks
The PCI DSS recognizes the importance of continuous monitoring to ensure the merchant remains compliant at all times. Monitoring provides merchants with the visibility needed to protect cardholder data.
The new update recommends creating a continuous monitoring strategy that includes periodic reviews of the security controls. Reviews can be either automated or manual but the monitoring frequency should comply with the timelines specified by the PCI DSS for each of the twelve requirements.
Requirements:
10. Track and monitor all access to network resources and cardholder data.
11. Regularly test security systems and processes.
Penalties for PCI Compliance Violations
The purpose of the PCI DSS is to protect credit card transactions. Therefore, compliance with the PCI DSS is not optional. That includes big organizations, medium-sized companies, and small one-person businesses.
Failure to achieve PCI compliance can result in monetary fines from $5,000 to $100,000, depending on the merchant level and the specific violation. If a PCI violation is made public, it can severely damage the reputation of the company and lead to a decrease in sales.
Conclusion
Credit card data is a special type of data that needs special protection. Everyone dealing with this data – from engineers to data architects, business analysts, e-commerce merchants and payment gateways, needs to be aware of the requirements of PCI/DSS and comply with them. We hope this article has given you an in-depth look at the requirements and logic behind the standard, and how to ensure data belonging to your organization and customers always stays safe.