12.07.2015 Views

PCI PED Compliance_4-7-10 - Verifonezone.com

PCI PED Compliance_4-7-10 - Verifonezone.com

PCI PED Compliance_4-7-10 - Verifonezone.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>PCI</strong> <strong>PED</strong> <strong>Compliance</strong>Lori BreitzkeApril 20<strong>10</strong>


Introduction• This presentation is geared to merchant acquirers and ISOs inthe financial services industry that sell to small to mid-sizedmerchants• It is not designed for:– Petroleum ISVs– Multi-lane retailers– VARs– Transportation– Retail Banking• If you’re in the petroleum space visit:http://www.verifone.<strong>com</strong>/sites/secure-pumppay.aspx• If you’re in the multi-lane retail space visit:http://www.verifone.<strong>com</strong>/mx-800-series.aspx2


Agenda• Breach Concerns• What is <strong>PCI</strong> <strong>PED</strong>?• Sample Scenarios• Marketing Materials Available• Partner Offers• Q&A3


Why Worry About A Breach?• Industry research indicates that many merchants do not knowmuch about security• In fact, Visa research indicates that <strong>com</strong>pliance was lowestamong level 4 merchants• According to industry research by Verizon, 81 percent of theorganizations that experienced a breach “were not PaymentCard Industry (<strong>PCI</strong>) <strong>com</strong>pliant,”• 75 percent of the breaches it investigated involved the retail (31percent), financial services (30 percent) and food & beverage(14 percent) industries• More than 80% of breaches since 2005 have happened at smallmerchants• You only hear about the bigger breaches but smaller ones occurevery day4


What Is <strong>PCI</strong> <strong>PED</strong>?• <strong>PCI</strong> <strong>PED</strong> requirements are primarily concerned with devicecharacteristics impacting the security of the PIN Entry Deviceused by the cardholder during a financial transaction.• These rules are to protect the consumer from fraud.• There are two factors involved in <strong>PCI</strong> <strong>PED</strong> requirements.– Device characteristics – the physical and logical securitycharacteristics of the device that deter a physical attack on thedevice—for example, the penetration of the device to determine itskey(s) or to plant a PIN-disclosing “bug” within it or allowing thedevice to output a clear-text PIN-encryption key– Device management considers how the <strong>PED</strong> is produced, controlled,transported, stored, and used throughout its lifecycle• The deadline to remove <strong>PCI</strong> <strong>PED</strong> ‘never approved’ devices fromthe market is July 1, 20<strong>10</strong>– Most of these devices were manufactured before 20045


<strong>PED</strong> Approval RecapNever ApprovedVisa <strong>PED</strong> ApprovedMerchants/RetailersMust Stop PIN use byJuly 20<strong>10</strong>Manufacturers MUSTNOT place for PIN afterDecember 2007But can use indefinitely<strong>PCI</strong> <strong>PED</strong> ApprovedManufacturers MUSTplace for PIN entry after12/20076


Impact To The Retailer/Merchant• There has been much confusion over the impact to a retailerwho does not meet the Visa July 1, 20<strong>10</strong> mandates for paymentsecurity• To review, there are three different mandates from Visa thatmust be met by US merchants by July 1, 20<strong>10</strong>. These are:– All never approved payment devices on which PIN debit transactionsare conducted must be removed from service. This includes anyterminal that is not either VISA <strong>PED</strong> or <strong>PCI</strong> <strong>PED</strong>.– All debit card PINs must be encrypted in TDES from the paymentdevice– All applications that “store, process, or transmit cardholderinformation” must be PA-DSS or PABP <strong>com</strong>pliant7


How Do I Upgrade My Merchants?• Replace never approved devices with higher-functioning devices• Add a <strong>com</strong>pliant <strong>PCI</strong> <strong>PED</strong> approved PIN Pad like the PP<strong>10</strong>00SE• Use this opportunity as a way to add value to replace the olderdevice– Value added applications• Gift card• Loyalty– PIN debit– Faster devices– Pay at the point of service8


How To Upgrade Your Merchant – Sample Scenario• Type of Retailer: Sporting Good Store• Scenario: Accepting electronicpayments for many years using an Omni32<strong>10</strong> countertop device• Upgrade Strategy:• Omni 32<strong>10</strong> utilizing debit will need tobe replaced OR– A PIN Pad <strong>10</strong>00SE can be added to thedevice– A configuration option would need to bechanged in SoftPay to enable theexternal PP<strong>10</strong>00SE9


How To Upgrade Your Merchant – Sample Scenario• Type of Retailer: Jewelry• Scenario: Accepting electronic payments for many yearsusing an Omni 3740 countertop device. The merchantaccepts credit and debit using an external PP<strong>10</strong>00SE• Upgrade Strategy:• Verify the PIN Pad <strong>10</strong>00SE has TDES keys injected• If the correct keys are not injected, the PIN Pad will need to beshipped to a distributor and have the proper keys injected<strong>10</strong>


How To Upgrade Your Merchant – Sample Scenario• Type of Retailer: Specialty Retailer• Scenario: Accepting electronic payments using an V x 5<strong>10</strong>countertop device and PIN Pad <strong>10</strong>00SE with DUKPT keys• Upgrade Strategy:• Proper TDES keys must be injected into the PP<strong>10</strong>00SE– The PIN Pad will need to be shipped to a distributor and havethe keys injected– OR a NEW PIN Pad <strong>10</strong>00SE with TDES keys injected can be addedto the device and the older PP returned11


How To Upgrade Your Merchant – Sample Scenario• Type of Retailer: Beauty Salon• Scenario: Accepting electronic payments using an NURIT2085+ countertop device• Upgrade Strategy:• Replace the NURIT device with a V x 5<strong>10</strong> using the internalPIN Pad with TDES keys injected12


Acquirer Collateral• White Paper• Flyer• FAQs• How to upsell your merchants• Tool Kit (Interactive PDF)• Product Upgrade Chart• All materials are available on thelanding pagewww.verifone.<strong>com</strong>/pciped• And the VeriFone Zonewww.verifonezone.<strong>com</strong>13


Merchant Collateral• Merchant Educational Package– Easy to understand overview, product charts, frequentlyasked questions, additional resources• Merchant Flyer– One page sheets with key dates and deadlines• Online Resources:– <strong>PCI</strong> Security Council– Merchant SAQ– www.verifone.<strong>com</strong>/pciped (Merchant Tab)14


<strong>PCI</strong> <strong>PED</strong> Landing Page• Breach Calculator• Countdown clock• Collateral• White Paper• Product Upgrade ChartCountdown ClockBreach CalculatorProduct UpgradeChartCollateralWhite Paper15


<strong>PCI</strong> <strong>PED</strong> <strong>Compliance</strong> ChartThis chart appliesto countertop andmobile merchants16


<strong>PCI</strong> <strong>PED</strong> <strong>Compliance</strong> ChartThis chart appliesto multi-lane retaildevices17


PIN Pad <strong>10</strong>00SE• Number one selling PIN pad in theindustry!• Easy to use PIN debit entry• <strong>PCI</strong> <strong>PED</strong> approved to meet the lateststandards for secure PIN entry• Future-proof payment solution, fullyupdatable and <strong>com</strong>patible• Provides the best protection againstfraud for merchants and consumers;• USB option provides another way toconnect to a PC software programwhich minimizes cabling andcountertop clutter18


Additional Resources• <strong>PCI</strong> <strong>PED</strong> websitehttps://www.pcisecuritystandards.org/security_standards/ped/index.shtml• <strong>PCI</strong> <strong>PED</strong> list of approved deviceshttps://www.pcisecuritystandards.org/security_standards/ped/pedapprovallist.html• VeriFone Security Page www.verifone.<strong>com</strong>/security• Secure Retail Paymentshttp://www.verifone.<strong>com</strong>/industry-solutions/retail/payment-trends--security/secureretailpayments<strong>com</strong>.aspx• Visahttp://broadcast01p.visabroadcasts.<strong>com</strong>/doc/20090422091220/5163459b29ec9fcdb6f98ceddad92d3d19

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!