PCI ISA Fundamentals
Methods identified as being used to cast off stolen information from the environments:
- Use of stolen credentials to get entry to the POS surroundings
- Outdated patches or poor gadget patching procedures
- The use of default or static dealer credentials / brute pressure
- POS skimming malware being mounted on POS controllers
- POI bodily skimming devices
ninety five% of breaches feature
The use of stolen credentials leveraging seller far off get right of entry to to hack into clients
POS environments.
Skimming
Copying payment card numbers both with the aid of tampering with:
- POS Devices
- ATMs
- Kiosks
Or via copying the card's magnetic stripe manually the usage of hand-held skimmers.
Phishing
Reconnaissance
- Information gathering from numerous online sources and social networking web sites
- Business applications and software
Social Engineering
- Phishing emails or messages coming from a goal's social community
- Phone call from an assumed acknowledged entity
Break-In
- Delivery via email
,- Software vulnerabilities
Common strategies for monetizing stolen card information:
- Skimmed complete song records and transaction facts used to replicate a physical payment
card, which could then be used for fraudulent transactions in face-to-face environments, or ATM
transactions
- Captured cardholder records is used where card-not-gift transactions are prevalent, which
include e-commerce or mail-order / smartphone order (MO/TO) transactions
- Stolen cardholder statistics and sensitive authentication records are sold in bulk to other
criminals who carry out their personal fraud using the stolen data
Commonly centered industries
- Retail - 45% of breaches
- Food and Beverage - 24% of breaches
- Hospitality - nine% of breaches
- Financial Services - 7% of breaches
- Nonprofit - three%
PCI SSC founding payment brands include:
- American Express
- Discover Financial
- JCB International
- MasterCard
- Visa, Inc.
PCI DSS:
Covers security of the environments that store, system, or transmit account statistics
- Environments get hold of account records from price applications and other resources (e.G.,
acquirers)
PCI PA-DSS
Covers stable fee packages to aid PCI DSS compliance
,Payment application receives account statistics from PIN-entry devices (PEDs) or other devices
and starts offevolved charge transaction
PCI P2PE
Covers encryption, decryption, and key management requirements for factor-to-factor
encryption solutions
PCI PTS - POI
Covers the safety of sensitive information at point-of-interaction gadgets and their stable
components, which include cardholder PINs and account statistics, and the cryptographic keys
used in reference to the protection of that cardholder information
PCI PTS - PIN Security
Covers steady management, processing and transmission of personal identificationnumber
(PIN) records during on-line and offline charge card transaction processing
PCI PTS - HSM
Covers physical, logical and device protection requirements for securing Hardware Security
Modules (HSM)
PCI Card Production
Covers bodily and logical protection necessities for structures and business strategies
PA-DSS applies to 0.33 birthday party payment applications if?
An application performs authorization and/or agreement (POS, purchasing carts, and so forth.)
PA-DSS guarantees a payment application can characteristic in a PCI DSS compliant way
- To guide the PCI DSS compliance of these that use the application
- Use of a PA-DSS application by myself does not guarantee PCI DSS compliance
Are PA-DSS packages in scope for PCI DSS?
Yes
PA DSS assessor should validate that fee utility is mounted:
, - Per commands in the PA-DSS Implementation Guide supplied by way of fee application
vendor
- In a PCI DSS compliant way
A PCI P2PE answer need to consist of all of the following:
- Secure encryption of payment card information at the point-of-interplay (POI)
- Validated software(s) at the point-of-interaction
- Secure management of encryption and decryption gadgets
- Management of the decryption surroundings and all decrypted account records
- Use of stable encryption methodologies and cryptographic key operations, which include key
technology, distribution, loading/injection, management and usage
Merchants can be capable of lessen their PCI DSS scope while the usage of Council-indexed
P2PE solutions
- Merchant has no access to account facts within encryption tool (POI) or decryption
surroundings (at Solution Provider)
- Merchant has no involvement in encryption or decryption operations, or cryptographic key
management
- All cryptographic operations controlled by way of 0.33 birthday celebration Solution Provider
PTS requirements practice to:
Point of Interaction (POI) devices; Encrypting PIN Pads (EPP); Point of Sale devices (POS);
Hardware (or host) Security Modules (HSMs); Unattended Payment Terminals, (UPTs) and
non-PIN Entry module
The PTS application ensures
Terminals cannot be manipulated or attacked to allow the capture of Sensitive Authentication
statistics, nor permit get entry to to clear-textual content PINs or Keys
The Secure Read and Exchange Module, (SRED)
Allows terminals to be approved for the stable encryption of cardholder statistics as part of the
Point to Point Encryption application
PTS has been prolonged to permit
Non-PIN access modules to be evaluated in opposition to the SRED module to allow steady
encryption on the factor of interplay for non-chip and PIN playing cards
Methods identified as being used to cast off stolen information from the environments:
- Use of stolen credentials to get entry to the POS surroundings
- Outdated patches or poor gadget patching procedures
- The use of default or static dealer credentials / brute pressure
- POS skimming malware being mounted on POS controllers
- POI bodily skimming devices
ninety five% of breaches feature
The use of stolen credentials leveraging seller far off get right of entry to to hack into clients
POS environments.
Skimming
Copying payment card numbers both with the aid of tampering with:
- POS Devices
- ATMs
- Kiosks
Or via copying the card's magnetic stripe manually the usage of hand-held skimmers.
Phishing
Reconnaissance
- Information gathering from numerous online sources and social networking web sites
- Business applications and software
Social Engineering
- Phishing emails or messages coming from a goal's social community
- Phone call from an assumed acknowledged entity
Break-In
- Delivery via email
,- Software vulnerabilities
Common strategies for monetizing stolen card information:
- Skimmed complete song records and transaction facts used to replicate a physical payment
card, which could then be used for fraudulent transactions in face-to-face environments, or ATM
transactions
- Captured cardholder records is used where card-not-gift transactions are prevalent, which
include e-commerce or mail-order / smartphone order (MO/TO) transactions
- Stolen cardholder statistics and sensitive authentication records are sold in bulk to other
criminals who carry out their personal fraud using the stolen data
Commonly centered industries
- Retail - 45% of breaches
- Food and Beverage - 24% of breaches
- Hospitality - nine% of breaches
- Financial Services - 7% of breaches
- Nonprofit - three%
PCI SSC founding payment brands include:
- American Express
- Discover Financial
- JCB International
- MasterCard
- Visa, Inc.
PCI DSS:
Covers security of the environments that store, system, or transmit account statistics
- Environments get hold of account records from price applications and other resources (e.G.,
acquirers)
PCI PA-DSS
Covers stable fee packages to aid PCI DSS compliance
,Payment application receives account statistics from PIN-entry devices (PEDs) or other devices
and starts offevolved charge transaction
PCI P2PE
Covers encryption, decryption, and key management requirements for factor-to-factor
encryption solutions
PCI PTS - POI
Covers the safety of sensitive information at point-of-interaction gadgets and their stable
components, which include cardholder PINs and account statistics, and the cryptographic keys
used in reference to the protection of that cardholder information
PCI PTS - PIN Security
Covers steady management, processing and transmission of personal identificationnumber
(PIN) records during on-line and offline charge card transaction processing
PCI PTS - HSM
Covers physical, logical and device protection requirements for securing Hardware Security
Modules (HSM)
PCI Card Production
Covers bodily and logical protection necessities for structures and business strategies
PA-DSS applies to 0.33 birthday party payment applications if?
An application performs authorization and/or agreement (POS, purchasing carts, and so forth.)
PA-DSS guarantees a payment application can characteristic in a PCI DSS compliant way
- To guide the PCI DSS compliance of these that use the application
- Use of a PA-DSS application by myself does not guarantee PCI DSS compliance
Are PA-DSS packages in scope for PCI DSS?
Yes
PA DSS assessor should validate that fee utility is mounted:
, - Per commands in the PA-DSS Implementation Guide supplied by way of fee application
vendor
- In a PCI DSS compliant way
A PCI P2PE answer need to consist of all of the following:
- Secure encryption of payment card information at the point-of-interplay (POI)
- Validated software(s) at the point-of-interaction
- Secure management of encryption and decryption gadgets
- Management of the decryption surroundings and all decrypted account records
- Use of stable encryption methodologies and cryptographic key operations, which include key
technology, distribution, loading/injection, management and usage
Merchants can be capable of lessen their PCI DSS scope while the usage of Council-indexed
P2PE solutions
- Merchant has no access to account facts within encryption tool (POI) or decryption
surroundings (at Solution Provider)
- Merchant has no involvement in encryption or decryption operations, or cryptographic key
management
- All cryptographic operations controlled by way of 0.33 birthday celebration Solution Provider
PTS requirements practice to:
Point of Interaction (POI) devices; Encrypting PIN Pads (EPP); Point of Sale devices (POS);
Hardware (or host) Security Modules (HSMs); Unattended Payment Terminals, (UPTs) and
non-PIN Entry module
The PTS application ensures
Terminals cannot be manipulated or attacked to allow the capture of Sensitive Authentication
statistics, nor permit get entry to to clear-textual content PINs or Keys
The Secure Read and Exchange Module, (SRED)
Allows terminals to be approved for the stable encryption of cardholder statistics as part of the
Point to Point Encryption application
PTS has been prolonged to permit
Non-PIN access modules to be evaluated in opposition to the SRED module to allow steady
encryption on the factor of interplay for non-chip and PIN playing cards