PCI DSS is working

December 2011 Associations, Financial (Industry)

Recent figures from the UK Cards Association showed that banking industry initiatives, including PCI have been successful in decreasing the volume of card and bank account fraud. Payment card fraud losses in 2010 reached their lowest levels since 2000 and have made significant improvement from their all-time high just three years ago in 2008.

Overall, they suggested that total fraud losses on UK cards fell by 17% alone over the preceding year. Data protection laws in Europe are getting tougher, with Spain, Italy and Germany now requiring companies to notify customers of a privacy breach. Additionally, as companies take a broader look at business processes in the data-security context, PCI DSS is proving successful as a strong foundation for overall data security, with research pointing to the PCI Standards as effective in efforts to satisfy the European Data Protection Directive.

While significant progress has been made in the reduction of card fraud in Europe, more can be done. The unfortunate news is that there was still more than Euro 417,5 million in UK card fraud in 2010 – well over 1 million Euro per day. We also just saw a relatively sophisticated attack plot here in Spain, where an attack on mobile banking applications could also have spread to include card fraud. And while last year we saw a drop in fraud losses and a decline in breached data records, where will we end up as we enter into 2012?

The series of global, massive data breaches that have plagued organisations just this year proves that organisations involved in the payment chain are still being targeted and must take direct action to place security soundly into their day-to-day business efforts.

Although many organisations have tried to combat fraud and protect sensitive information through technology or processes, there is a third pillar - people - that is essential in order to be truly successful at securing card data. We cannot simply rely on a single technology to solve the problems of data breaches in today's threat landscape. We need to continually examine the people, processes and technology we have in place to prevent future card fraud.

Some of the basic steps to reducing fraud combine these elements.

We should be looking to educate our people, then develop security procedures, strategy and implement technologies designed to reduce scope and reduce risk. Only through this will we be able to address the next critical juncture of payments security, especially in new payment technology areas such as mobile security, where everyone seems to want to jump to.

Here are a few tips:

If you do not need it, do not store it!

Ok, I agree this can seem a bit like an oversimplification, but it works on so many different levels, and to be honest, this is the basis for many talked about technologies such as encryption and tokenisation. Do everything you can to eliminate data. Train your people, create the processes and then look at the appropriate technologies that help you in this effort. In many cases you can replace the data that you currently store or transmit by encrypting or tokenising the data. This will help reduce the scope of your PCI assessment and simplify your compliance efforts.

Think security, not compliance

That is basically what the first tip is about as well, but this goes further. A Report on Compliance is a piece of paper; a valuable one to many organisations, but perhaps less valuable than the peace of mind that you have when you are prepared for ongoing security.

Name an internal expert

One of the simplest and most effective means of maintaining ongoing compliance is through a dedicated internal resource you have named. Through this, you can have an individual or team that not only helps prepare for a compliance assessment, but establish the protocols to monitor and maintain not only ongoing compliance, but also security. Our Internal Security Assessor (ISA) program gives internal champions the same training as QSAs, so they know what to look for and how to keep an organisation on track and within the PCI requirements for the entire year.

Implement a risk-based approach

Once you have your internal staff on board, it is time to set your agenda. Whether you are well into your PCI process, or just beginning, a great reference for you to consult is the PCI Prioritised Approach document.

The Prioritised Approach provides guidance that will help merchants identify how to reduce risk to cardholder data as early on as possible in their compliance journey. The tool groups together the requirements of PCI DSS into six key milestones for merchants to consider in their card data security strategy. This risk-based approach eliminates the biggest vulnerabilities first and allows you to share with your assessors, acquiring banks and the card brands on how you are progressing along your journey.

Make security part of your DNA

Again, this goes to a previous point: think security rather than compliance. The PCI DSS is a fantastic foundation for establishing a core group of best practices that can serve as the foundation for your security efforts. Remember, the DSS is the floor, not the ceiling; you should always be looking to build additional layers of security on top of it. This layered approach will allow you to focus on the security part of your business, building it into every business project or activity you commence, and allow you to move beyond a compliance sideshow to one where you are an increasingly difficult target for the bad guys. All it takes is some concerted effort. The more difficult you make it for the bad guys, the more quickly they are likely to look elsewhere.

Remember, PCI DSS is a solid foundation for you to develop and maintain security practices that help enable the entire business. Get the basics sorted by following these tips and then build your layers on top for a more secure business.





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

“This Is Theft!” SASA slams Mafoko Security
News & Events Security Services & Risk Management Associations
The Security Association of South Africa (SASA) has issued a stark warning that the long-running Mafoko Security Patrols scandal is no longer an isolated case of employer misconduct, but evidence of a systemic failure in South Africa’s regulatory and governance structures.

Read more...
From friction to trust
Information Security Security Services & Risk Management Financial (Industry)
Historically, fraud prevention has been viewed as a trade-off between robust security and a seamless customer journey, with security often prevailing. However, this can impair business functionality or complicate the customer journey with multiple logins and authentication steps.

Read more...
AI rewrites financial crime
Security Services & Risk Management Financial (Industry)
Criminals are exploiting South Africa’s high connectivity and still-maturing regulation to scale attacks faster than we can defend them. The speed and sophistication of these scams are outpacing the systems designed to stop them.

Read more...
GenAI fraud forcing banks to shift from identity to intent
AI & Data Analytics Information Security Financial (Industry)
The complexity and velocity of modern fraud schemes, from deepfakes to fraud and scams involving social engineering, demand more than just investment in new tools; they need adaptability and expanding the security net.

Read more...
SAQCC Gas awareness
Associations News & Events
SAQCC Gas will raise awareness within the gas industry by emphasising the importance of using registered gas practitioners and getting a Certificate of Compliance (CoC) for all your gas systems.

Read more...
Standards for fire detection
Fire & Safety Associations
Nick Collins discussed SANS 246 – Fire Protection for Electronic Equipment Installations – Code of Practice, as it pertains to electronic equipment installations, including construction, furniture and fittings, air conditioning, raised flooring and more.

Read more...
SABRIC appoints Andre Wentzel as interim CEO
News & Events Financial (Industry) Associations
The South African Banking Risk Information Centre (SABRIC) has announced the appointment of Andre Wentzel as interim chief executive officer, effective immediately.

Read more...
Standards for fire detection
Fire & Safety Associations Editor's Choice
In previous articles in the series on fire standards, Nick Collins discussed SANS 10400-T and SANS 10139. In this editorial, he continues with SANS 322 – Fire Detection and Alarm Systems for Hospitals.

Read more...
Continuous AML risk monitoring
Access Control & Identity Management Security Services & Risk Management Financial (Industry)
AU10TIX, launched continuous risk monitoring as part of its advanced anti-money laundering (AML) solution, empowering businesses to detect behavioural anomalies and emerging threats as they arise.

Read more...
Amendments to the Private Security Industry Regulations
Technews Publishing Agriculture (Industry) News & Events Associations
SANSEA, SASA, National Security Forum, CEO, TAPSOSA, and LASA oppose recently published Amendments to the Private Security Industry Regulations regarding firearms.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.