LESSONS LEARNED ON THE WAY TO PCI COMPLIANCE




























- Slides: 28
LESSONS LEARNED ON THE WAY TO PCI COMPLIANCE The University of Western Ontario & Mc. Master University’s Experiences June 7 th, 2011
Agenda • Introductions • What is PCI and Why is it Important? • Lessons Learned • What Lies Ahead?
Introductions • Sharon Farnell, Director, Internal Audit – The University of Western Ontario • Stacey Farkas – Supervisor, Financial Reporting – Mc. Master University • Tim Russell – Project Manager, University Technology Services – Mc. Master University
Introductions v. Western • 2010 - $27 million in credit card sales • 2011 - $31 million in credit card sales • 60 merchants v. Mc. Master • 2010 - $24 million in credit card sales • 2011 - $25 million in credit card sales - $ 16 million in INTERAC ONLINE transactions • 58 merchants
What is PCI? • PCI-DSS: Payment Card Industry – Data Security Standards • Standards developed by the credit card companies (Visa, M/C) to protect cardholders • PCI Data security requirements apply to all members, merchants, and service providers that store, process or transmit cardholder data • EVERY merchant is required to be in compliance with these standards
What is PCI? There are 12 requirements, grouped into six categories for PCI Compliance: • Build and Maintain a Secure Network (req. 1 & 2) • Protect Cardholder Data (req. 3 & 4) • Maintain a Vulnerability Program (req. 5 & 6) • Implement Strong Access Control Measures (req. 7, 8 & 9) • Regularly Monitor and Test Networks (req. 10 & 11) • Maintain a Policy that addresses Information Security (req. 12)
Merchant Levels Merchant Level Processing Volumes per year 1 > 6, 000 Visa transactions Validation Actions • Annual on-site PCI-DSS Assessment • Quarterly Network Scan Validation By 2 1, 000 to 6, 000 Visa transactions • Annual PCI-DSS Self Assessment Questionnaire (SAQ) • Quarterly Network Scan • Qualified Security Assessor • Merchant or Internal Audit if signed by Officer of the company • Approved Scanning Vendor
Merchant Levels Merchant Level 3 4 Processing 20, 000 to 1, 000 Visa e. Volumes per year commerce transactions 20, 000 Visa e-commerce transactions and all other merchants, up to 1, 000 transactions Validation Actions • Annual PCI-DSS Self Assessment Questionnaire (SAQ) Validation By • Quarterly Network Scan • Merchant • Approved Scanning Vendor
Merchant Types • PCI Security Council Separated out Merchant Types and introduced a SAQ for each type in 2008
Why is PCI Compliance Important? v FINANCIAL RISK – fines from payment processor and/or credit card companies – costs to notify cardholders – repayment of fraudulent charges incurred by end consumer – audit costs by PCI assessor v LOSE THE ABILITY TO PROCESS CREDIT CARDS – CAMPUS WIDE v REPUTATIONAL RISK! v OPPORTUNITY TO ENHANCE SECURITY/IT BEST PRACTICES
Our PCI ‘Approaches’ v Western • Central approach to Self Assessment Questionnaires (SAQs). v Mc. Master • Centralized management with Individual merchant responsibilities
Lessons Learned 1: Collaboration of stakeholders is key 2: Identify your PCI Scope and environment 3: Minimize Local Payment Processing 4: Centralized Merchant Approval Process 5: Audit Considerations 6: Don’t underestimate your time 7: Breach Escalation process 8: Centralized approach to PCI DSS Self Assessment Questionnaires 9: Include PCI compliance in the RFP and Purchasing Process 10: Funding: Who Pays for this? 11: It’s a learning Journey 12: Risk Management Strategies
Lesson 1 : Collaboration of Stakeholders is Key v. Western: Central Bank Card Committee • Financial Services, Internal Audit, IT, Campus Department Representatives • Chaired by AVP, Financial Services v. Mc. Master: PCI Steering Committee • Financial Services, IT, Key Departments, Internal Audit • Chaired jointly by AVP Administration and CIO
Lesson 2 : Identify your PCI Scope and Environment v. Western • Pre-RFP Review – Evaluate Environment • IT Code Review • Interviewed all campus departments v. Mc. Master • Had a PCI GAP analysis completed in 2008 • Helped us to focus on high risk areas within the 12 requirements – action plan via PCI Steering Committee
Lesson 3 : Minimize Local Payment Processing v. Western • Campus merchants are required to use Western’s internal Payment Page • Currently migrating to an external Pay Page solution v. Mc. Master • Steer merchants to Hosted Pay Page solutions • Place compliance on the software vendors • Moving from Type D to A merchants – less risk
Lesson 4 : Centralized Merchant Approval Process v. Western • New e-commerce merchants must be approved by Bank Card Committee • PCI Compliance is a requirement v. Mc. Master • Upfront Approval Process – new merchants must meet PCI DSS requirement before a merchant number is issued • Merchants can be suspended if not in compliance
Lesson 5 : Audit Considerations v. Western • Limited Scope – Lower Costs • Important for Auditor to apply PCI to a University setting • Consistency of Auditor key • Demonstration of Compliance v. Mc. Master • Pre-audit in 2008 – helped to limit scope • Focus on individual (Type D) merchants
Lesson 6 : Don’t Underestimate Your Time v. Western • Six months became 2+ years • IT Resources – Significant Impact – Documentation • Have people to help keep on track v. Mc. Master • Committee commenced work in 2006, still ongoing • Education and clarification of requirements took a long time
Lesson 7 : Breach Escalation Process v. Western • Requirement of PCI-DSS • Took time to get it ‘right’ v. Mc. Master • Developing protocols for front-line workers and internal response • Escalating communication plan dependent on nature of the breach
Western Breach Protocol Legend IPO – Information Privacy Office UWO IT – Western Information Technology NSO – Network Security Officer (CISO) CISO – Campus Information Security Officer Moneris – corporate payment processor ACT FAST! Perceived Breach 4. 5. 6. Types of Breaches Receipts compromised POS compromised Electronic Client data compromised Missing items Technical breach Unauthorized wireless device UWO Police IDENTIFY: INFORM AND CONTAIN, USER ASCERTAINS RISK AND NOTIFIES ACCORDINGLY CONTAIN THE DAMAGE USER POLICE ENGAGE CRIMINAL INVESTIGATION AND INFORM NSO TRANSACTIONAL ITEMS ON STOP OR ALERT Moneris: 1 -866 -319 -7450 ITS as i niti ato r TRANSACTIONAL ITEMS ON STOP OR ALERT Moneris: 1 -866 -319 -7450 FINANCE ASSESSES FINANCIAL RISK AND NOTIFIES NSO ON DATA AND VENDORS FOR TRANSACTIONAL ITEMS x 911 DEVICE THEFT OR DEVICE TAMPERING Types 1, 2, 3, 5 MISSING FILES, MACHINE, DATA Type 4 PRESERVE EVIDENCE DO NOT ACCESS COMPROMISED SYSTEM 1. 2. 3. UWO NSO IT SECURITY NSO/CISO ASSESSES DATA RISK AND CONTAINS, NOTIFIES IPO AND FINANCE 519 661 3800 nso@uwo. ca UWO Finance x 85432 finance@uwo. ca AFTER RISK ASSESSMENTS AND VENDOR NOTIFICATION, LEGAL IS INFORMED BY IPO IF NECESSARY UWO Legal x 84217 jarrett@uwo. ca UWO IPO x 84541 privacy. office@uwo. ca IPO INTERFACES WITH NSO, LEGAL AND COMM IF PRIVACY AT RISK UWO Communications
Lesson 8 : Centralized Approach to Self Assessment Questionnaires v. Western • Created own internal SAQ to be filled out by departments • Fill out SAQ for the university as a whole centrally v. Mc. Master • Each merchant is responsible for filling out PCI SAQ • SAQ questionnaires now automated through on-line submission • 3 rd party company for both SAQ submission and Quarterly scanning
Lesson 9 : Include PCI Compliance in the RFP & Purchasing process v. Western • Push your knowledge to external partners / vendors v. Mc. Master • Smaller companies weren’t always aware of PCI compliance. • Integrated into Policy and Purchasing documents
Lesson 10 : Funding – Who Pays for This? v. Western • Funded centrally v. Mc. Master • Yearly internal Merchant ‘PCI Levy’ • Base charge plus volume based charge with caps • Essentially covers the cost of 1 FTE in IT and 0. 5 in Financial Services • Now covers cost of 3 rd party assessor
Lesson 11 : It is a Learning Journey v. Western • PCI Changes – Helps to have ‘experts’ v. Mc. Master • On-going changes: the risks change therefore the compliance also changes • Adapt to new business processes • Learning journey for software vendors as well
Lesson 12 : Risk Management Strategies v. Both Universities: • Governance and oversight • Third-party assessors and PCI advisors • Pro-active compliance by doing more than required • Migration to Hosted Payment Page • Required annual merchant training
What Lies Ahead? v. Western: • Keep ahead of PCI – change approaches as you go v. Mc. Master: • Monthly, quarterly and annual activities, based on merchant type. v. PCI Security Council • Three year cycle for standard revisions • Now possible for internal auditors to be certified to conduct PCI audits
References v. PCI Security Council: § https: //www. pcisecuritystandards. org/index. shtml v. University of Western Ontario: § http: //commerce. uwo. ca/index. html v. Mc. Master University: § http: //www. mcmaster. ca/bms/BMS_FS_Payment_Card. htm
Thank you!/ Merci! Contact Information: Sharon Farnell sfarnell@uwo. ca Stacey Farkas farkas@mcmaster. ca Tim Russell trussel@mcmaster. ca