12.07.2015 Views

Card Vendor Program - Visa Asia Pacific

Card Vendor Program - Visa Asia Pacific

Card Vendor Program - Visa Asia Pacific

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Understanding Key Issues andChanges to <strong>Card</strong> <strong>Vendor</strong> <strong>Program</strong>


Key Issues1. Completion and Delivery of :A. Pre-Engagement Questionnaire• Timeliness• <strong>Card</strong> Samples are not punchedB. Action Plan and Assessment Tracker• Reminders sent by <strong>Visa</strong>• When tracker is returned for further improvement,vendor amends remediation action plan and/orremove <strong>Visa</strong> comments• <strong>Visa</strong> confidential emails are not encrypted• Huge attachments should be sent by filingattachments in CD ROM and files encrypted.Information Classification <strong>Visa</strong> Confidential as Needed55


Key Issues2. Tiering Template• Timeliness• Unable to understand the “Annual Quantity of <strong>Visa</strong> cardsstored in the vault from January to December XXXX• <strong>Vendor</strong>s collate different facilities’ statistics into onespreadsheet.• No signature on the approval column3. Cases of Noncompliance (Section 1.3.E.1)• Failure to pay annual fee• No business activity during the previous 12-monthInformation Classification <strong>Visa</strong> Confidential as Needed66


Changes and Updates1. <strong>Card</strong> <strong>Vendor</strong> <strong>Program</strong>• Management of the card vendor program for vendorsbased in <strong>Asia</strong> <strong>Pacific</strong> (AP) and Central Europe MiddleEast Africa will be handled in Singapore2. Generic Email• As <strong>Visa</strong> is now one single organization, effectiveimmediately the generic email is changed fromapsgpcardvendor@visa.com tovendorcompliance@visa.comInformation Classification <strong>Visa</strong> Confidential as Needed77


Changes and Updates3. Registration• In the event of any addition/amendment, registration andapproval will be managed from Singapore as follows:– Third Party Agent– Designated Officer Responsible for Ordering of Hologram– Shipment of indent print from personalization supplier4. <strong>Visa</strong> Product Standards• In the event of account being locked or request for access for anew user, an automatic request will be generated and sent to<strong>Visa</strong> Singapore for approval.• Do not use generic email or hot mail address to request foraccess to <strong>Visa</strong> product standards as it will be rejectedInformation Classification <strong>Visa</strong> Confidential as Needed88


Changes and Updates5. Merger of Entities/Shareholders/Change in Management• Inform <strong>Visa</strong> of merger and/or change with an official letter.• <strong>Visa</strong> will request for current audited financials to conduct afinancial litmus test• In the event of change in entity’s name, a revised SecurityAgreement will be drawn up6. Registry of Service Providers• Registered service providers are listed on publicly-accessiblewebsite at http:/www.visa-asia.com/spregistry and accessible to<strong>Visa</strong> members and service provider• There is no change to website’s address• <strong>Vendor</strong>s to inform <strong>Visa</strong> in the event of change/addition incategory and contact personInformation Classification <strong>Visa</strong> Confidential as Needed99


<strong>Card</strong> <strong>Vendor</strong> Workshop


<strong>Card</strong> <strong>Vendor</strong> Workshop?Purpose• Our goal is that the knowledge gained throughout the workshopwill enable potential vendors to understand where your businessfits into the card vendor program• Existing vendors can be in full compliance with the <strong>Visa</strong> SecurityStandardsInformation Classification <strong>Visa</strong> Confidential as Needed 11


<strong>Card</strong> <strong>Vendor</strong> Workshop?Who Can Register?• Any potential vendor wishing to join the <strong>Card</strong> <strong>Vendor</strong> <strong>Program</strong>in the category as a :– <strong>Card</strong> Manufacturer– Mag Stripe and/or IC Personalizer– IC Pre-Personalizer– IC Embedder• Existing card vendors who wish to learn indepth knowledge of thephysical and security standards and improve to meet the program’scompliance requirementsInformation Classification <strong>Visa</strong> Confidential as Needed 12


<strong>Card</strong> <strong>Vendor</strong> Workshop?Registration Form• Available in English, Mandarin and Japanese• If a vendor wishes to enroll, complete registration form in Englishand return by fax, scanned copy to vendorcompliance@visa.comand cc ang@visa.comInformation Classification <strong>Visa</strong> Confidential as Needed 13


<strong>Card</strong> <strong>Vendor</strong> Workshop?Benefits• Ideal opportunity to learn all about <strong>Visa</strong> Security Standards forboth physical and logical security standards.• <strong>Card</strong> vendors can identify and examine weaknesses and improve onsecurity standards• Workshop can be customized in-house• Trained by <strong>Visa</strong> experts knowledgeable in the field of securityInformation Classification <strong>Visa</strong> Confidential as Needed 14


THANK YOU


Understanding Key SecurityIssues to the <strong>Card</strong> <strong>Vendor</strong><strong>Program</strong>


Key Issues• Network Security• Deploy properly configured firewalls between;– Internet and Internet-facing network (DMZ)– Internet-facing network (DMZ) and data processing network– Data processing and personalization network (unless both are insame high security area or on same network)• Isolate personalization and data processing network from othernetworks• Transfer deposited files into the data processing or personalisationnetwork immediately• Perform quarterly internal vulnerability scanning• Perform quarterly external vulnerability scanningInformation Classification <strong>Visa</strong> Confidential as Needed 17


Key Issues• Data SecurityInformation Classification <strong>Visa</strong> Confidential as Needed 18


Key Issues• Protecting stored data– Move cardholder information to a secure system after receipt– Decrypt cardholder data for the minimum time required forprocessing– Encrypt stored cardholder data (including data on databaseservers, portable media, backup tapes and logs)– Mask all card account numbers (unless there is requirement to seethe full card numbers)– Delete cardholder data on the personalization machine upon jobcompletionInformation Classification <strong>Visa</strong> Confidential as Needed 19


Key Issues• Audit and accountabilityMaintain accurate audit trail which can help to establish ownership ofthe records, e.g.– Record audit trails for production job activities– Record movements of cards and components– Sign off, date and time the completion of task (e.g. review,acknowledgement and handover)– Maintain dual control of storage and card destruction– Physical inventory to be carried out under dual control– ‘In the blind’ inventoriesInformation Classification <strong>Visa</strong> Confidential as Needed 20


Key Issues• Making security systems work for you– Training of the security guards in systems and surveillancetechniques– Reporting and recording of unusual activity– Formal escalation process– Investigating unusual events– Remediation– Accurately dating and timing events– System time synchronizationInformation Classification <strong>Visa</strong> Confidential as Needed 21


Key Issues• Shipping of <strong>Card</strong> Consignments– At least 24 hours before shipping, establish an identification methodto identify and verify shipment carrier– Obtain issuer approval for transportation schedule and confirmationthat their authorized staff will receive consignment at destination– Use either dual control armored car, secure air freight or dualcontrol vehicle with accompanying vehicle (No volume restriction)– Airfreight must be via the highest level of secure cargo available– Traceable overnight courier for a maximum of 500 cards perpackage per day per issuer.Information Classification <strong>Visa</strong> Confidential as Needed 22


Thank You!Information Classification <strong>Visa</strong> Confidential as Needed 23

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!