All Top Banking

Showing posts with label PCI DSS. Show all posts
Showing posts with label PCI DSS. Show all posts

Society of Payment Security Professionals Welcomes 50 New CPISM/CPISAs


PARK CITY, UT--(Marketwire - March 12, 2009) - The Society of Payment Security Professionals(SPSP) is pleased to announce that they have now certified more than 200people as Certified Payment-Card Industry Security Managers (CPISMs). Inaddition, the SPSP has certified 50 Certified Payment-Card IndustrySecurity Auditors (CPISA). The enthusiasm with which the new certificationshas been adopted is further proof of the industry's need to identify thoseindividuals that have both security and payment card industry expertise.The rapid adoption of security regulation at the state and federal level,coupled with the dynamic nature of the payment card industry, make thecertifications appealing to a wide range of industry participants.

"We've seen individuals representing almost every business model in theindustry take the CPISM or CPISA courses," said Chris Mark, CPISM/A, CISSP,CIPP and Founder of the Society of Payment Security Professionals. "Thecertifications were designed specifically to create a level playing fieldfor everyone from merchants, to acquiring and issuing banks to QualifiedSecurity Assessors. The materials covered in the course go far beyondsimple compliance with the PCI DSS, to include risk management, state andfederal regulations and other vitally important topics. In addition tooffering education, the courses offer an opportunity for Payment SecurityProfessionals™ to share ideas and experiences. Ultimately, suchdiscourse can only be a positive influence on the security practices of theindustry."


The CPISM and CPISA certifications have been developed with the goal ofenabling the certificate holder to demonstrate proficiency andunderstanding of the Payment-Card Industry, fraud and data theft trends,the relevant regulations that impact the industry, and application of theregulations to various business models that are unique to the industry.The certifications were carefully developed to adhere to educationalpedagogy and instructional design theory. In addition, the certificationexams and the training were vetted by veteran Payment SecurityProfessionals to ensure that the materials were accurate, relevant, andtimely.

According to co-founder Mike Dahn, "As former QSAs, and QSATrainers that currently provide PCI related training worldwide for a majorcard brand, we understand the needs of the industry and the challenges ofsecuring data within the payment card industry. These certifications havebeen designed to allow individuals to more effectively manage risk andcomply with the PCI DSS and other related standards."

The Society is offering a public CPISM and CPISA Training and exam seminarin the San Francisco area in June 2009. For more information, or toregister for the event, please visithttps://www.paymentsecuritypros.com/training-dates/.

About the Society of Payment Security Professionals

The Society of Payment Security Professionals' objective is to provideindividuals and organizations involved in payment security with an onlinecommunity to share information, and access education and certificationopportunities. Society members come from a variety of businesses includingcard brands, merchants, acquirers, ISOs, and more. Though theirorganizations may vary, they all share one purpose: to protect sensitivecustomer data using the most current, viable technologies and processes.The SPSP is managed by The Aegenis Group. For more information about theSociety of Payment Security Professionals, please visitwww.paymentsecuritypros.com.

Contact:
Heather Mark
Company Name: Society of Payment Security Professionals
Telephone Number: 888-616-3330
Fax Number: 435-608-6403
Email Address: Email Contact
Web site address: www.paymentsecuritypros.com




Reblog this post [with Zemanta]

Updated: Acculynk...Where's the PIN Offset? My Pet PVV

Posted by John B. Frank Monday, March 9, 2009 1 comments



Updated:  I just got off the phone with Chris A. Mark, CEO and Founder of the Aegenis Group and the Society of Secure Payment Professionals.  

Apparently,  John Stewart, Editor of Digital Transaction News, saw this post and called Chris to discuss a "hardware vs. software" approach.

I had our CEO, Ken Mages join us on the phone.  Chris is probably one of the foremost experts in PCI and payments security and 1 of about 20 people in the world who "truly" understands how a PIN transaction works, so since Ken is another 1 of the 20, it made sense for him to collaborate with Chris.

In fact, here's a little backgrounder on Mr. Mark:  Quite impressive to say the least... 

The Aegenis Group is led by

Chris MarkChris Mark, CISSP, CIPP; CEO/President and Founder

Mr. Mark is an experienced information security professional and PCIexpert. Over the past six years, Mr. Mark has worked in variousinformation security capacities within the payment services’ segment.Most recently, Mr. Mark was employed at MasterCard Worldwide where hewas one of MasterCard’s representatives on the Payment Card IndustrySecurity Standards’ Council (PCI-SSC)Technical Working Group. In addition to founding an informationsecurity company and conducting numerous PCI assessments for merchants,service providers, and members, Mr. Mark has worked with bothMasterCard Worldwide and Visa USA on components of their respectivedata security programs.

Mr. Mark is also contracted with Visa to train all of their majoracquirers and the top 3000 merchants in the PCI DSS. Prior to joiningthe civilian sector, Mr. Mark served in both the United States MarineCorps, where he operated as an elite Force Reconnaissance Marine andMarine Scout/Sniper, and in the US Navy where he was selected to serveas a Navy SEAL Officer. Subsequent to sustaining a career endingtraining injury, Mr. Mark served as the Training Officer and ChiefInstructor of the US Marine Corps Basic Reconnaissance Course where hewas responsible for screening, selecting, and training eliteReconnaissance Marine Candidates. Mr. Mark is a combat veteran ofOperation Continue Hope, Mogadishu, Somalia. Mr. Mark holds the CISSP,and CIPP professional certifications, numerous technicalcertifications, and has an MBA and BA degrees.


Here's an excerpt from an email he sent me:


John,

John Stewart from Digital Transactions called to ask about the differences in Home ATM and Acculink.  I was very clear that conceptually I feel HomeATM is a much better solution.
Please feel free to call me to discuss the article comments.

Chris
Chris A Mark, CISSP, CPISA, CPISM, CIPP
The Aegenis Group, Inc.





We spoke at length about the security of our solution and he was impressed enough to want to learn more and we are happy to provide him with anything and everything we can so that we can empower his analysis.  We agreed to FedEx him a SwipePIN device (pictured below) and we'll talk again after Ken gets back from the Merchant Risk Council meeting in Las Vegas on Thursday or Friday.   I'll provide an update.   Here's the rest of the story....



In an effort to prove that I am not alone in questioning the security of Acculynk's Floating PIN Pad I am going use a respected third party resource to back up my concerns... just in case people confuse common sense for competitive jealousy.  I assure you, I have none.  (common sense that is...lol)

In fact, in an act of fairness...I hereby extend an open invitation to any C-Level Executive at Acculynk to address the two questions highlighted on the graphic on the left.  I am more than happy to allow them the opportunity to set the record straight.  It is not my intention to berate their solution.  It IS my intention to prevent a future breach that makes Heartland's pale in comparison...which is exactly what would happen if hackers got their fraudy-little fingers on PIN's.

As I said, I've spoken to Acculynk President Nandan Sheth quite a few times over the course of the last year and have nothing but good things to say about the him. As a matter of fact, after taking my cell-phone off the charger, I see that I missed a call from him earlier this afternoon, so I owe him a return call...
   

The following is from the Society of Payment Security Professionals blog written by Chris A. Mark, CISSP, CPISA, CPISM, CIPP, Founder and CEO of The Aegenis Group.

In the article he published last October, Chris questioned the security of Acculynk's Floating PIN Pad. 
Online PIN Debit; Great Idea or Not so Great Idea?

The big questions he asked about (besides security) is that if a "card is not present" (CNP) i.e. in Acculynks model one must manually type in the credit or debit card's personal account number (PAN) and if it's determined that the card can be used with a PIN, then the floating PIN Pad GUI pops up.  The e-shopper then uses the floating PIN Pad to enter their PIN.  So...with no swipe...just type...they want to know: "Where is the PIN Verification Value (PVV) and where is the PIN Offset stored?"  Good questions!  In a traditional PIN Debit transaction (like the one that most closely mimics the consumer experience in a grocery store...
the PVV and PIN Offset is resident on the magnetic stripe.  No Swipe...No Stripe!  No Stripe...No PVV...NO PIN Offset.

Besides the fact that in 500+ breaches, software was 92 times more likely to be breached than hardware, those were two more very important reasons why HomeATM went with a Hardware based solution.   

Here's an excerpt from the Society of Security Professional Blog:

I (Chris) want to thank Susan Kohl for sending this over. Digital Transactions has published several articles on new technology that will allow PIN Debit for eCommerce sites. Read the article here.

In short, the new technology will present a buyer with a floating ‘PIN Pad’ on the screen. Users can then enter their PIN which will then allow the merchant to immediately debit the user’s account for payment. While the technology appears very compelling from a convenience perspective I have to admit that it also gives me pause. In my mind, there are a number of potential issues with this technology. I am sure (or at least hoping) the companies, banks and card brands are working through these issues but they merit discussion here anyhow.

From a security perspective, I am challenged by the technology. My first thought is key stroke logging and malicious software. Now I know people will likely say that this is possible with traditional eCommerce transactions. This is accurate. In this scenario, however, PIN data is being transmitted. As discussed in a previous entry, there may not be a limit to the liability associated with compromise of PIN data. It brings another question to light, as well.

If the transaction is a ‘card not present’ transaction then where is the PIN Verification Value / PIN Offset stored?

In a traditional PIN Debit transaction it is resident on the magnetic stripe of the card. This has several benefits one of which is that it prevents a data thief from obtaining a PIN and only the primary account number and being able to conduct PIN based transactions.

If the card is not required to be presented, it appears that this would allow fraudsters to obtain the PAN or other card data and the PIN and conduct transactions.

Editor's Note:  Holy Grail Batman!  See I'm not biased.  And I'm not alone with my "concerns." Do you have any?  As always, feel free to leave a comment.  Click on the title of the post, and the comments will be enabled on the bottom.  Have a salubrious weekend!   






Reblog this post [with Zemanta]

65% of Irish Websites Put Cardholder Data at Risk

Posted by John B. Frank Wednesday, November 19, 2008 0 comments



65pc of Irish websites put consumers at risk


According to an analysis from Enterprise Risk Services at Deloitte, some 65pc of Irish websites put consumers at risk of fraud.


Consumers have been warned about identity theft and fraud today in the run-up to Christmas after a study found that online payment security is not fully enforced on 65 per cent of Irish websites.
According to a study done by Deloitte Enterprise Risk Services, which analysed over 100 Irish based e-commerce websites, "a significant proportion of websites" are not compliant with the payment card industry security standards.

Deloitte examined over 100 Irish e-commerce sites and checked for the kind of security measures in place to ensure safe online transactions for the shopper and found that "a significant proportion of websites" are not compliant with payment card industry security standards.

The good news, Deloitte said, is that the situation with regard to compliance with the Payment Card Industry Data Security Standards (PCI DSS) has improved since its last analysis.

A breakdown of figures showed that 100-plus companies had weak encryption for online transactions, meaning that customers entrusting their MasterCard or Visa across these sites were putting their card and personal data at risk of fraud or identity theft.

Moreover, 53 per cent of companies supported weak or legacy encryption, with 2 per cent of sites not encrypting cardholder data entry sessions at all. This means that the information that visitors to the site submit such as name, address and credit card details can potentially be compromised and accessed by fraudsters.

There were no details from the report with a breakdown of how the payments were managed, ie whether the online merchant was privy to those details, or whether they were passed on to a trusted third-party payments processor such as Realex or PayPal, both of which would automatically have extremely secure methods of encryption and data protection.

Most sites will ask you to verify your credit-card details with the three-digit CVV2 code on the back of your credit card, which is another protection against fraud, but the Deloitte analysis found that 7pc of Irish e-commerce sites did have this.

A further 3 percent had expired SSL certificates, which are certificates displayed to ensure that the site you are dealing with is actually that site – another method of protection against phishing attempts whereby a fraudster could put a false web front in place in order to steal your details.

“The results of the survey show that many websites do not have adequate levels of security for processing online transactions, which many consumers carry out on a very regular basis,” said Colm McDonnell, partner, Enterprise Risk Services, Deloitte.

“Identity theft and credit-card fraud is a growing problem here in Ireland, and inadequate levels of security must be addressed by merchants as a matter of priority.”

By Marie Boran


Reblog this post [with Zemanta]

25 E-Commerce Tech Terms You Should Know

Posted by John B. Frank Monday, November 3, 2008 0 comments

E-commerce tech terms you should know
By Dale Buss - Forbes
Transacting business seamlessly over the internet means having a decent grasp of how things work, and more importantly, why they don't. That's why, with help form the smart folks at technology publisher O'Reilly Media, we've assembled a glossary of e-commerce-related tech terms that every entrepreneur should know.
Some of that gobbledygook is the province of tech jocks. However, if entrepreneurs want to achieve operational excellence while keeping technology investment in check, they have to be able to at least speak the language. And you don't have to know how to get down and dirty with computer code to understand the implications these issues have on strategy and budgeting.

Online retailers, for example, are trying to move beyond what has become the conventional, rather static consumer experience. One solution: real-time, individualized pricing. A new system, developed by uBee, allows merchants to "sense" what items a shopper is looking for on their websites, and spits out a custom price based on inventory levels and other particulars.

"That," says uBee CEO Bill Carpenter, "can give you personalization between buyer and seller."

The e-commerce platform that UBee plans to launch next month will rely on SOAP, for Simple Object Access Protocol, a technology standard based on using "envelopes" that retailers and uBee use to exchange information quickly enough to make these real-time offers. The "documents" in these envelopes invariably are written in XML, the most common software language in e-commerce, including variants such as XML-RPC and XML Business Reporting Language. (The acronyms are dizzying at first, but you get used to them.)

For all the billions of dollars being spent and collected online, the code at the core of e-commerce remains highly fragmented — and that creates communication breakdowns within the overall system.

"The Internet is still the wild, wild west," said Clint Page, chief executive of Dotster, a Vancouver, Wash.-based provider of Internet-business services. "It's not like more-developed parts of business and commerce where you get standardized platforms."

Take setting up a merchant account with a bank so that you can accept and process online payments. While bricks-and-mortar retailers only have to decide whether to accept checks and major credit cards, e-commerce is open to all sorts of other payment possibilities and transactions in currencies other than the dollar, such as HomeATM's PIN Debit/Credit Platform.

You'll also want to know a thing or two about affiliate programs. Under these advertising arrangements, companies collect cash for driving traffic to your site, and visa versa.

With Google now as much a verb as a company name, search engine optimization (or SEO) — the process of increasing a site's odds of ranking high in the search stacks — is a key consideration for any e-commerce player.

Says Dotster's page: "There is ferocious competition to be on the first two or three pages of each search." Editor's Note:  Do a Google Search on PIN Debit. 


Then there's the problem of security. While millions of consumers have grown comfortable with entering credit-card information into a Web site, reports of massive identity theft continue to crimp online sales. Editor's Note:  Consumers should NOT be comfortable entering their credit/debit card information into a Website. 

The lines of defense begin with authentication programs that determine whether someone signing on under a specific name is actually authorized to use the site via that specific account. Editor's Note: Dually Authenticated HomeATM PIN based transactions allow consumers to swipe their card (eliminating the risk and conveniently saving them from typing their card numbers onto a website). Entering the PIN (non-keystroke) makes for a  highly (dual) secured transaction.   Force users to jump through too many hoops, though, and you risk driving them away. Hence the single sign-on approach, in which either the user's computer or the website "remembers" passwords. Access control beefs up the barricades by granting entry only to specific site functions, such as adding an item to a shopping cart.

Want to make it clear that your site is indeed secure? Use software that adds a padlock icon in the user's browser window. Editor's Note:  Or use HomeATM's globally patented PIN based checkout system!

"Ensuring that your checkout process and, more important, the credit card form are well-secured will guarantee your customers feel safe when transmitting their information," says Pat Kaeowichien, director of information technology for Magnetic, a Tampa-based Web-development firm.

Credit card firms have taken critical steps to fend off identify thieves, too. In 2006 a consortium including Visa, MasterCard, American Express and Discover helped devise the PCI/DDS standard for providing secure communication for transactions over the Internet. 

"This standard is now in place for all merchants globally who accept credit cards — no exceptions," says Bill Bradley, senior industry marketing manager for Akamai Technologies in Cambridge, Mass. "Non-compliance can mean fines and, for that retailer, a loss of public trust. And that's the main reason people don't buy online in the first place."  Editor's Note:  Ironically, PCI DSS was initially designed for bricks and mortar retail locations, there is no specific WPCI (Web Payments Card Industry) standard...

Keeping them buying: That's what understanding e-commerce — and the technology that drives it — is all about.  Editor's Note:  Keep them buying securely, that's what HomeATM's technology is all about!
Reblog this post [with Zemanta]

PCI SSI Community Meeting in Orlando

Posted by John B. Frank Monday, September 29, 2008 0 comments

A 1976 ad promoting the change of name to VISA...Image via Wikipedia

The Green Sheet 2.0 :: Newswire
PCI SSC meeting attendees help guide payments' future

The PCI Security Standards Council (PCI SSC), a global, open industry standards body providing management of the Payment Card Industry Data Security Standard (PCI DSS), PIN Entry Device (PED) Security Requirements and the Payment Application Data Security Standard (PA-DSS), today announced that more than 550 attendees from over 325 organizations met at the Council’s second annual Community Meeting, in Orlando, Florida, to provide input and analysis of the newly released 1.2 version of the PCI DSS and other payment card security standards. This represents a 71 percent increase in attendance from 2007. The highly anticipated event, held from Sept. 23-25, welcomed the Council’s participating organizations and assessment community contributors.

The Council also is pleased to announce that in addition to its rapidly growing assessment community members, there are more than 500 participating organizations from around the world that actively contribute to the standards setting process, up from approximately 240 in 2007. Participating organizations provide the backbone of feedback and support for the PCI security standards and cross a wide spectrum of industries and locations. Participating organizations are the only group in the Council that receive early versions of draft standards and documentation, provide feedback and direction on the PCI standards, and receive regular communications and opportunities to work with the Council on cardholder data security. The list of current participating organizations can be found at https://www.pcisecuritystandards.org/participation/member_list.html .

Topics discussed at the Orlando meeting included the release of the PCI DSS version 1.2, updates to the PA-DSS and PED Security Requirements, special interest group reports on wireless and payment card pre-authorization security, the introduction of a quality assurance program for the QSA community along with keynote addresses from the Department of Justice and Forrester Research. These interactive sessions gave participants key information as they continue with their PCI standards implementation.

Because of the dramatic increase in participation in the Council, this year’s community meeting in Orlando will be followed up with a second community meeting in Brussels, Belgium, October 21-23, 2008. This second meeting will enable participating organizations and the PCI assessment community to engage with the Council at an additional venue. More than 120 delegates have already registered for this additional meeting.

In addition to the more than 500 participating organizations, the Council has 147 approved scanning vendor (ASV) companies and 164 qualified security assessor (QSA) companies that help ensure continued compliance with the PCI DSS. The Council also approves payment application QSAs (PA QSAs) as part of the PA-DSS program. Together, the assessment community and participating organizations, at the community meeting and throughout the year help define and evolve the security standards to protect payment cardholder account data.

“As we meet at our community meetings it is especially important that the Council reflects the broadest spectrum of payments system players,” said Bob Russo, general manager, PCI Security Standards Council. “The tremendous and rapid growth of our participating organization program and assessment ecosystem, as well as the increased attendance at our community meetings, is a testament to the payment industry’s commitment to protecting cardholder data while ensuring that the standards we manage truly reflect global industry desires and needs.”

For More Information:

More information on the PCI Security Standards Council and becoming a participating organization please visit www.pcisecuritystandards.org , or contact the PCI Security Standards Council at www.participation@pcisecuritystandards.org .

About the PCI Security Standards Council

The mission of the PCI Security Standards Council is to enhance payment account security by driving education and awareness of the PCI Data Security Standard and other standards that increase payment data security. The PCI Security Standards Council was formed by the major payment card brands American Express, Discover Financial Services, JCB International, MasterCard Worldwide and Visa Inc. to provide a transparent forum in which all stakeholders can provide input into the ongoing development, enhancement and dissemination of the PCI Data Security Standard (DSS), PIN Entry Device (PED) Security Requirements and the Payment Application Data Security Standard (PA-DSS). Merchants, banks, processors and other vendors are encouraged to join as Participating Organizations.

Source: Company press release.
Reblog this post [with Zemanta]

ChargeAnywhere Touts PIN Debit for Quickbooks

Posted by John B. Frank Tuesday, September 16, 2008 0 comments

QuickBooks


The Green Sheet 2.0 :: Newswire
South Plainfield, N.J., Sept. 12, 2008 -- CHARGE Anywhere®, a leading provider of secure Point-of-Sale (POS) solutions and electronic payment services, is delighted to announce the ability to accept PIN Debit payments with their card payment plug-in designed for use with QuickBooks®. This is extremely beneficial to the Small and Medium Merchant Business community by allowing them to process PIN Debit transactions without changing their compatible QuickBooks software.

CHARGE Anywhere designed for use with QuickBooks with PIN Debit capability not only expands the merchant's level of service, but reduces cost a merchant pays per transaction. With the increased fraud protection, PIN Debit is a smart decision for small and medium sized merchants that can assist in reducing chargebacks due to less fraudulent purchases. When you integrate these functions into the merchant's QuickBooks software, you are going to have a happier and more productive merchant.

CHARGE Anywhere with PIN Debit feature is available with the use of a PIN pad that will be attached to the computer via cable. The compatible PIN pad devices are the LinkPoint BankPoint II, the VeriFone SE1000, and the Ingenico 3010. All of the mentioned PIN pads are PCI PED compliant and certified. In addition, the CHARGE Anywhere Point of Sale software has been validated* and meets PCI PABP compliance standards and the ComsGate® Payment Gateway is certified as PCI DSS Level 1 compliant. With the addition of PIN Debit, CHARGE Anywhere has significantly improved the functionality of their CHARGE Anywhere payment software for retailers. With PIN Debit devices added, the CHARGE Anywhere designed for use with QuickBooks payment plug-in is now, more than ever, one of the most versatile, secure payment software plug-ins on the market. PIN Debit adds to a long list of features that include customizable software settings, gift, loyalty, versatility, and security.

For more information about CHARGE Anywhere with PIN Debit, please cut and paste the following link into your browser:
http://uploads.comstarinteractive.com/pub/dlerman/CHARGE_Anywhere_Application_Designed_For_QuickBooks_Overview.pdf

Source: Company press release.
Reblog this post [with Zemanta]

Powered by Blogger.

Search This Blog

Our Manufacturing Facility

Learn More About Us

Find out how our patented technology can empower your financial institution.

Our secure two-factor online banking authentication eliminates dangerous passwords and usernames and replicates the same trusted process used to access cash at ATM's. (Insert Bank Issued Card, Enter Bank Issued PIN)

There is an R.O.I. as FI's also earn recurring revenue from each transaction conducted using our PCI 2.0 Certified PIN Entry Device. Our technology also provides a unique real-time P2P "Instant-Transfer" which allows your online banking customer to transfer cash from ANY of their bankcards to ANY other bankcard...with the Swipe of a card.

Help your bank eliminate phishing and your customers avoid identity theft by providing them with the ability to stop typing and start swiping. There is no safer way to conduct financial transactions online than by 3DES DUKPT encrypting the cardholder details, which we do at the mag-head "inside the box/outside the browser."

Total Pageviews

SLIM for PC or SmartPhone

SLIM for PC or SmartPhone
Click to Inquire

Chip and PIN eCommerce and Mobile

Chip and PIN eCommerce and Mobile
Click to Inquire

Kapersky Calls for Mass Adoption of Card Readers

Kapersky Calls for Mass Adoption of Card Readers

Translate This Blog

BobCaps

Search ePayment News (example: NFC)

About Me

My photo
Named one of the best Payment Industry News Blogs 4 Years Running

Feedjit

My Zimbio