• 2025
  • April - 3 articles
  • March - 14 articles
  • February - 16 articles
  • January - 15 articles
  • 2024
  • December - 15 articles
  • November - 15 articles
  • October - 20 articles
  • September - 17 articles
  • August - 20 articles
  • July - 18 articles
  • June - 20 articles
  • May - 22 articles
  • April - 12 articles
  • March - 14 articles
  • February - 13 articles
  • January - 11 articles
  • 2023
  • December - 12 articles
  • November - 12 articles
  • October - 16 articles
  • September - 11 articles
  • August - 13 articles
  • July - 13 articles
  • June - 13 articles
  • May - 12 articles
  • April - 11 articles
  • March - 15 articles
  • February - 12 articles
  • January - 13 articles
  • 2022
  • December - 14 articles
  • November - 12 articles
  • October - 11 articles
  • September - 12 articles
  • August - 13 articles
  • July - 13 articles
  • June - 13 articles
  • May - 12 articles
  • April - 12 articles
  • March - 14 articles
  • February - 12 articles
  • January - 13 articles
  • 2021
  • December - 15 articles
  • November - 12 articles
  • October - 14 articles
  • September - 11 articles
  • August - 15 articles
  • July - 12 articles
  • June - 14 articles
  • May - 12 articles
  • April - 14 articles
  • March - 15 articles
  • February - 11 articles
  • January - 11 articles
  • 2020
  • December - 14 articles
  • November - 11 articles
  • October - 13 articles
  • September - 11 articles
  • August - 9 articles
  • July - 11 articles
  • June - 16 articles
  • May - 13 articles
  • April - 13 articles
  • March - 17 articles
  • February - 10 articles
  • January - 12 articles
  • 2019
  • December - 12 articles
  • November - 11 articles
  • October - 12 articles
  • September - 12 articles
  • August - 14 articles
  • July - 11 articles
  • June - 12 articles
  • May - 14 articles
  • April - 12 articles
  • March - 14 articles
  • February - 14 articles
  • January - 17 articles
  • 2018
  • December - 14 articles
  • November - 13 articles
  • October - 17 articles
  • September - 14 articles
  • August - 14 articles
  • July - 19 articles
  • June - 17 articles
  • May - 18 articles
  • April - 20 articles
  • March - 18 articles
  • February - 18 articles
  • January - 19 articles
  • 2017
  • December - 19 articles
  • November - 16 articles
  • October - 19 articles
  • September - 21 articles
  • August - 22 articles
  • July - 17 articles
  • June - 19 articles
  • May - 20 articles
  • April - 18 articles
  • March - 20 articles
  • February - 13 articles
  • January - 6 articles
  • 2016
  • December - 10 articles
  • November - 9 articles
  • October - 8 articles
  • September - 10 articles
  • August - 10 articles
  • July - 8 articles
  • June - 11 articles
  • May - 8 articles
  • April - 11 articles
  • March - 11 articles
  • February - 11 articles
  • January - 9 articles
  • 2015
  • December - 13 articles
  • November - 13 articles
  • October - 14 articles
  • September - 13 articles
  • August - 11 articles
  • July - 12 articles
  • June - 14 articles
  • May - 11 articles
  • April - 12 articles
  • March - 12 articles
  • February - 12 articles
  • January - 9 articles
  • 2014
  • December - 10 articles
  • November - 9 articles
  • October - 13 articles
  • September - 12 articles
  • August - 13 articles
  • July - 14 articles
  • June - 10 articles
  • May - 14 articles
  • April - 15 articles
  • March - 17 articles
  • February - 14 articles
  • January - 18 articles
  • 2013
  • December - 20 articles
  • November - 18 articles
  • October - 21 articles
  • September - 19 articles
  • August - 21 articles
  • July - 22 articles
  • June - 20 articles
  • May - 23 articles
  • April - 26 articles
  • March - 24 articles
  • February - 29 articles
  • January - 24 articles
  • 2012
  • December - 22 articles
  • November - 24 articles
  • October - 27 articles
  • September - 27 articles
  • August - 25 articles
  • July - 22 articles
  • June - 20 articles
  • May - 28 articles
  • April - 24 articles
  • March - 28 articles
  • February - 24 articles
  • January - 24 articles
  • 2011
  • December - 24 articles
  • November - 18 articles
  • October - 21 articles
  • September - 21 articles
  • August - 21 articles
  • July - 20 articles
  • June - 23 articles
  • May - 27 articles
  • April - 22 articles
  • March - 22 articles
  • February - 16 articles
  • January - 20 articles
  • 2010
  • December - 21 articles
  • November - 18 articles
  • October - 20 articles
  • September - 13 articles
  • August - 11 articles
  • July - 9 articles
  • June - 8 articles
  • May - 9 articles
  • April - 11 articles
  • March - 12 articles
  • February - 10 articles
  • January - 10 articles
  • 2009
  • December - 11 articles
  • November - 9 articles
  • October - 11 articles
  • September - 10 articles
  • August - 10 articles
  • July - 10 articles
  • June - 10 articles
  • May - 11 articles
  • April - 13 articles
  • March - 13 articles
  • February - 7 articles
  • January - 10 articles
  • 2008
  • December - 12 articles
  • November - 8 articles
  • October - 16 articles
  • September - 11 articles
  • August - 13 articles
  • July - 13 articles
  • June - 14 articles
  • May - 13 articles
  • April - 13 articles
  • March - 9 articles
  • February - 14 articles
  • January - 11 articles
  • 2007
  • December - 11 articles
  • November - 12 articles
  • October - 12 articles
  • September - 4 articles
  • August - 4 articles
  • July - 4 articles
  • June - 2 articles
  • May - 6 articles
  • April - 5 articles
  • March - 1 article
  • Monday, March 23, 2015

    Verizon study details need for improved PCI security

    The Verizon 2015 PCI Compliance Report is Verizon Communications' fourth and most extensive study of global trends in payment card security. Highlights include a review of Payment Card Industry (PCI) Data Security Standards (DSS) baseline requirements and a first-time focus on sustainable security practices.

    The 84-page study explores why four out of five companies fall out of compliance after passing their PCI audits. Additionally, two thirds of the companies studied used incomplete or inadequate test scripts for their in-scope security systems.

    PCI Council sounds wake-up alarm

    The PCI Security Standards Council, established in 2006 by American Express Co., Discover Financial Services, JCB International Credit Card Co. Ltd., MasterCard Worldwide and Visa Inc., is an open global forum focused on developing, managing, educating, and raising awareness of the PCI DSS for increased payment data security.

    Stephen W. Orfei, the PCI SSC's General Manager, called the Verizon report "a wake-up call for every business that cares about payment security," adding that despite overall progress, businesses still have a long way to go in prioritizing and implementing payment security.

    Orfei acknowledged that there is no "silver bullet" to preventing security breaches and urged companies to take a "multilayered approach to security" by managing access, strengthening security at the POS and remaining vigilant to the evolving threat landscape.

    Report highlights

    The report noted a global increase in credit card spending, predicting that total world card payments will exceed $20 trillion in 2015. The PCI DSS provided the framework for the report's quantified analysis. Following are three takeaways from the report.

    1. Compliance is up

      Overall PCI compliance increased between 2013 and 2014 for 11 of the 12 PCI DSS requirements, with an average increase of 18 percent per business.

    2. Sustainability is low

      Less than one third (28.6 percent) of companies retained PCI compliance in the 12 months following successful validation.

    3. Data security is still inadequate

      Verizon's viewpoint is that the PCI DSS is "a baseline, an industry-wide minimum acceptable standard, not the pinnacle of payment card security. PCI DSS compliance should not be seen in isolation, but as part of a comprehensive information security and risk-management strategy."

    Requirement-by-requirement analysis

    The report examined all 12 of the PCI DSS requirements: maintaining firewalls, securing configurations, protecting stored data, protecting data in transit, maintaining anti-virus tools, maintaining secure systems, restricting access, authenticating access, controlling physical access, logging and monitoring, testing security systems and maintaining security policies.

    Each requirement was reviewed according to its role in a comprehensive security strategy. The report also examined newer versions of each requirement that reflect emerging technologies and the evolving threat environment.

    For example, Requirement 2 prohibits using default passwords or security parameters. This requirement has been affected by Cloud and virtual technologies.

    "Requirement 2 is one of the requirements most affected by the emergence of virtualization and cloud," the report stated, referring to technologies that simplify information technology (IT) infrastructures. The introduction of new technology can pose challenges to IT professionals tasked with separating in-scope and out-of-scope systems that coexist on the same physical server.

    EMV may drive fraud to card-not-present transactions

    Orfei noted that the U.S. transition to EMV (Europay, MasterCard and Visa) chip technology will make 2015 a pivotal year in payments. His tone of cautious optimism is reflected in Verizon's report, which references the coming Oct. 1, 2015, liability shift for POS terminals, and Oct. 1, 2017, for automated fuel dispensers. The report pointed out that EMV is not a panacea, and suggested that experience gained from other countries shows that it displaces, rather than eliminates fraud. EMV cards may initially increase the security of card-present transactions, and "attackers may focus their attention on 'card not present' (CNP) transactions, including online shopping," the report stated. The report also noted that banks and card issuers are developing new methods of encryption, tokenization and behavioral analytics to enhance the security of e-commerce transactions.

    Becoming and remaining compliant

    In addition, Verizon's 2015 report explored why companies fail to sustain PCI compliance – in many cases for less than a year after achieving successful audits.

    Verizon noted the problems stem from failure to build robust procedures, which need to be not only built, but also managed and maintained, and failure to see an assessment as a snapshot that captures only a moment in time and demonstrates that a company and its selected sites, devices and systems assessed during sampling were deemed compliant.

    Real payment card data security requires ongoing controls and vigilance beyond the PCI assessment. Orfei described passing an annual compliance assessment as a starting point for a implementing a broader, vigilant and proactive security program. "Only a combination of people, process and technology, and a focus on making security a 'business-as-usual' practice will help thwart these constant threats," he said.

    Editorial Note:

    Whether you want to upgrade your POS offerings, find a payment gateway partner, bone up on fintech regs or PCI requirements, find an upcoming trade show, read about faster payments, or discover the latest innovations in merchant acquiring, The Green Sheet is the resource for you. Since 1983, we've helped empower and connect payments professionals, starting with the merchant level salespeople who bring tailored payment acceptance and digital commerce tools, along with a host of other business services to merchants across the globe. The Green Sheet Inc. is also a proud affiliate of Bankcard Life, a premier community that provides industry-leading training and resources for payment professionals.

    Notice to readers: These are archived articles. Contact information, links and other details may be out of date. We regret any inconvenience.

    skyscraper ad