PCI DSS Addressing Cyber-Security Threats. ETCAA June Gabriel Leperlier

Similar documents
PCI DSS COMPLIANCE 101

PCI DSS 3.2 AWARENESS NOVEMBER 2017

The Devil is in the Details: The Secrets to Complying with PCI Requirements. Michelle Kaiser Bray Faegre Baker Daniels

PCI COMPLIANCE IS NO LONGER OPTIONAL

Managing Risk in the Digital World. Jose A. Rodriguez, Director Visa Consulting and Analytics

Navigating the PCI DSS Challenge. 29 April 2011

Payment Card Industry (PCI) Data Security Standard

PCI compliance the what and the why Executing through excellence

Payment Card Industry Internal Security Assessor: Quick Reference V1.0

Payment Card Industry (PCI) Data Security Standard

PCI Compliance: It's Required, and It's Good for Your Business

Cybersecurity The Evolving Landscape

Comodo HackerGuardian. PCI Security Compliance The Facts. What PCI security means for your business

Webinar: How to keep your hotel guest data secure

FAQs. The Worldpay PCI Program. Help protect your business and your customers from data theft

Payment Card Industry (PCI) Data Security Standard

The PCI Security Standards Council

Merchant Guide to PCI DSS

PCI DSS. Compliance and Validation Guide VERSION PCI DSS. Compliance and Validation Guide

University of Sunderland Business Assurance PCI Security Policy

Site Data Protection (SDP) Program Update

All the Latest Data Security News. Best Practices and Compliance Information From the PCI Council

Will you be PCI DSS Compliant by September 2010?

June 2013 PCI DSS COMPLIANCE GUIDE. Look out for the tips in the blue boxes if you use Fetch TM payment solutions.

Cyber Security and Data Protection: Huge Penalties, Nowhere to Hide

Your guide to the Payment Card Industry Data Security Standard (PCI DSS) banksa.com.au

GUIDE TO STAYING OUT OF PCI SCOPE

2012PHILIPPINES ECC International :: MALAYSIA :: VIETNAM :: INDONESIA :: INDIA :: CHINA

White paper PCI DSS. How do you manage your customers payment card details securely and responsibly?

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Compliance

How do you manage your customers payment card details securely and responsibly? White paper PCI DSS

Data Sheet The PCI DSS

Payment Card Industry (PCI) Data Security Standard

Protect Comply Thrive. The PCI DSS: Challenge or opportunity?

Section 1: Assessment Information

2017 Annual Meeting of Members and Board of Directors Meeting

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance

Data Security Standard

AuthAnvil for Retail IT. Exploring how AuthAnvil helps to reach compliance objectives

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry Data Security Standards Version 1.1, September 2006

COMPLETING THE PAYMENT SECURITY PUZZLE

PCI Compliance Updates

What are PCI DSS? PCI DSS = Payment Card Industry Data Security Standards

Section 3.9 PCI DSS Information Security Policy Issued: November 2017 Replaces: June 2016

Payment Card Industry (PCI) Data Security Standard

Ensuring Desktop Central Compliance to Payment Card Industry (PCI) Data Security Standard

IT Audit and Risk Trends for Credit Union Internal Auditors. Blair Bautista, Director Bob Grill, Manager David Dyk, Manager

Understanding PCI DSS Compliance from an Acquirer s Perspective

Section 1: Assessment Information

Payment Card Industry (PCI) Data Security Standard

SAQ A AOC v3.2 Faria Systems LLC

Payment Card Industry (PCI) Data Security Standard

Evolution of Cyber Attacks

The Future of PCI: Securing payments in a changing world

Commerce PCI: A Four-Letter Word of E-Commerce

Payment Card Industry (PCI) Data Security Standard

DHG presenter. August 17, Addressing the Evolving Cybersecurity Landscape. DHG Birmingham CPE Seminar 1

PCI DSS Q & A to get you started

in PCI Regulated Environments

ISACA Kansas City Chapter PCI Data Security Standard v2.0 Overview

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard

Point ipos Implementation Guide. Hypercom P2100 using the Point ipos Payment Core Hypercom H2210/K1200 using the Point ipos Payment Core

Enforcing PCI Data Security Standard Compliance Marco Misitano, CISSP, CISA, CISM Business Development Manager Security Cisco Italy

Compliance Audit Readiness. Bob Kral Tenable Network Security

How PayPal can help colleges and universities reduce PCI DSS compliance scope. Prepared by PayPal and Sikich LLP.

Payment Card Industry (PCI) Data Security Standard

Advanced Certifications PA-DSS and P2PE. Erik Winkler, VP, ControlCase

Protect Comply Thrive. The PCI DSS: Challenge or opportunity?

A QUICK PRIMER ON PCI DSS VERSION 3.0

6 Vulnerabilities of the Retail Payment Ecosystem

NORTH AMERICAN SECURITIES ADMINISTRATORS ASSOCIATION Cybersecurity Checklist for Investment Advisers

Payment Card Industry (PCI) Data Security Standard

The IT Search Company

Must Have Items for Your Cybersecurity or IT Budget in 2018

A Perfect Fit: Understanding the Interrelationship of the PCI Standards

ISO COMPLIANCE GUIDE. How Rapid7 Can Help You Achieve Compliance with ISO 27002

Payment Card Industry (PCI) Data Security Standard

SIP Trunks. PCI compliance paired with agile and cost-effective telephony

Compliance Is Security. Presented by: Jeff Hall Optiv Security

PDQ Guide for the PCI Data Security Standard Self-Assessment Questionnaire C (Version 1.2)

Managing Privacy Risk & Compliance in Financial Services. Brett Hamilton Advisory Solutions Consultant ServiceNow

PCI DSS v3. Justin

INFORMATION SUPPLEMENT. Use of SSL/Early TLS for POS POI Terminal Connections. Date: June 2018 Author: PCI Security Standards Council

PCI DATA SECURITY STANDARDS VERSION 3.2. What's Next?

Defense in Depth Security in the Enterprise

Defensible and Beyond

Altius IT Policy Collection Compliance and Standards Matrix

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire C-VT and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard

PCI Compliance Assessment Module with Inspector

Payment Card Industry (PCI) Data Security Standard

David Jenkins (QSA CISA) Director of PCI and Payment Services

Cybersecurity Conference Presentation North Bay Business Journal. September 27, 2016

Payment Card Industry (PCI) Data Security Standard

Today s Security Threats: Emerging Issues Keeping CFOs Up at Night Understanding & Protecting Against Information Security Breaches

Transcription:

Welcome!

PCI DSS Addressing Cyber-Security Threats ETCAA June 2017 - Gabriel Leperlier

Short Bio Current Position Head of Continental Europe Advisory Services at Verizon. Managing 30+ GRC/PCI/Pentest Consultants across Continental Europe Professional experience Now 9 years within Verizon Enterprise Solutions. 7 years as Key Manager at Cerplus a VeriSign Affiliate Cryptography & Key Management. 8 years in the French Air Force (including Operations in Former Yugoslavia). Crypto transmissions Operator. Education & Certifications : Positive Leadership by Michigan Ross School of Business Executive Education. PCI DSS QSA by PCI SSC CISSP by (ISC)2 CISA & CISM by ISACA Non Commissioned Officer (Crypto Transmissions) in the French Air Force IAll images are property of their respective owner 3

Data Breach Investigation Report DBIR 2017

DBIR 2017 What does reality of Data Breaches looks like? How can you make it more difficult for Hackers? Download our Data Breach Investigation for free If you haven t suffered a cybersecurity breach you ve either been incredibly well prepared, or very, very lucky. Are you incredibly well prepared?

DBIR 2017 - Key Highlights

DBIR 2017 - Key Highlights

Key findings The main play is still phishing leading to installation of malware, and using stolen credentials to advance attacks. 1 in 14 users fell for phishing attacks. 25% more than once! Ransomware is now the top malware functionality within Crimeware. It has seen a 50% increase in our dataset YoY. 81% of hacking-related breaches leveraged either stolen passwords and/or weak or guessable passwords.

Focusing your defenses Single-factor authentication is compromised often, and reused as a tool for the attacker. Shift from weak authentication methods to multi-factor solutions. Malware is not going anywhere. We assume you have client-based antivirus running, which is a start. Enrich AV with network malware detection, sandboxing technologies and application whitelisting. Most breaches are starting with a compromised user device. Limit the sensitive data stored on workstations and build a properly segmented network with strong authentication between security zones.

Focusing your defenses Patch web browser software (and associated plugins) promptly. Know what assets you have from which to determine patching. Limit what attachments make it past your email gateway. Strip all executables and macroenabled Office documents, at a minimum. Encrypt all mobile devices! Threat Intelligence is the key to knowing what the next looming threat might look like and how to plan, recognize, respond and mitigate it as necessary.

GDPR General Data Protection Regulation

One Regulation to rule them all! National Laws in each EU member state, which are currently based on the EU Data Protection Directive 1995, will be replaced with the General Data Protection Regulation (GDPR) from 25 th May 2018 This is common for all the EU member states. No need for national implementations. Impact: Broader accountability Any organisation, regardless of country of origin, that offers goods and services to EU residents or monitor behaviour of EU residents is subject to the GDPR. Mandatory auditing Penalties for non-compliance Potential Fines up to 4% of Global Revenue or 20,000,000 Annual Activity Reports (reputational damage) IAll images are property of their respective owner 1

Timeline towards compliance Collaboration with Legal and Data Protection Authorities coordinated by DPO Review of Contractual Agreements between Controllers, Partners, Suppliers, Customers and Data Subjects Policy and Procedural Review, Risk Assessment Records of Processing activities Review of Data Breach procedures Identification Affected Systems and Information Lifecycle Current Technical State Analysis, Design and Implement Corrective Measures Data Protection by Design and by Default Secure Processing Right to be Forgotten Unambiguous Consent Implement additional Technical Controls Image courtesy: CC0 Public Domain https://pixabay.com/photo-699966/ 1

GDS systems PNR + Last Name : A real weakness Instagram and other Social Networks Key points to remember

PCI DSS Payment Card Industry Data Security Standard

What is PCI SSC? The PCI SSC (Payment Card Data Security Standards Council) born in 2006 version 1.1 of the standard released Responsibilities: Develop, manage, training, awareness on the PCI Security Standards In practice, the PCI Council : Promote and maintains PCI Security Programs. Ensures the qualification process and quality control (QSA, ASV, ISA, ) Maintain an up-to-date list of certified entities : QSA, ASV, PED,

PCI Security Standards PCI DSS : Secure Environments for Merchants & Service Providers PCI PA-DSS : Payment Applications for Software Developers PCI PTS : PIN Entry Devices Card Production for Manufacturers P2PE : Incorporates requirements from PCI DSS, PCI PA-DSS and PCI PTS to protect account data from the point of capture to payment processor (point to point)

Overview of PCI Ecosystem Card Brand - Decide to apply penalties (Acquirer and PSP) - Ordering the investigation (if compromised) at the expense of the compromise entity Acquirer - Responsible for merchant compliance - Work with merchant until full compliance has been validated Merchant Payment Service Provider (PSP) - Responsible of its own compliancy Web Hosting and Data Center Hosting Providers Payment applications editor/vendor Payment Terminal Provider Others providers Contractual Relationship Commercial Relationship

Service Providers Are considered Service providers, any organisation that store, transmit or process cardholder data for VISA/Mastercard/Amex/... Merchants, or for other Payment service providers. This also include Providers affecting Security of an entity elligible to PCI DSS. Different levels of services providers exist : Level of Service Provider Description 1 > 300,000 transactions per year 2 < 300,000 Visa transactions per year More than having a PCI DSS program, any service provider must be able to present an AoC (Attestation on Compliance). Level Action to complete Validated by : 1 2 Onsite Annual PCI DSS Audit Quarterly ASV Scans Self Assessment Questionnaire (SAQ) Quarterly ASV Scans QSA Approved Scaning Vendor (ASV) Service Provider itself Approved Scaning Vendor (ASV)

Merchant level As a merchant under your own Merchant ID, you should be Level 3 ecommerce or Level 4.

PCI DSS Payment Card Industry Data Security Standard This is also a IATA requirement : There is even a new resolution after this one bellow : IATA s obligations for Travel agents 2

PCI-DSS, what does an agency have to do in practice?

Protect your systems GDS Providers are PCI DSS Certified Know where your data are stored outside GDS systems Do not store if you don t really need it Storage must be encrypted Other applications for Accounting / Invoicing This does not mean you are fully protected Key points to remember Patch your systems & Applications Make your Windows/OS updates Make your applications updates Use Anti-Virus / Firewall Protection Anti-Virus / Anti-Phishing Anti-Malware / Anti-Spyware Firewall Network Protection

PCI-DSS Want some more details?

Some more details Access Management Accountability Key points to remember Only Personnal accounts - No Shared Login No shared Passwords Passwords to be changed at least every 90 days No Direct Access from Internet to Databases Network Segmentation Firewall Management Access Management Need to Know Least Privilege Security Policies and Procedures Tell what you are doing Do what you are telling

Thanks! Merci! Danke! Obrigado! Grazie!