02.02.2013 Views

Maestro Global Rules (PDF) - MasterCard

Maestro Global Rules (PDF) - MasterCard

Maestro Global Rules (PDF) - MasterCard

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Security<br />

8.9 Account Data Compromise Events<br />

3. Registration of any TPP(s) or DSE(s) associated with the ADC Event under<br />

the <strong>MasterCard</strong> Registration Program (MRP), in accordance with Rule 8.10.6<br />

of this manual.<br />

4. Notification of an ADC Event or Potential ADC Event to and in cooperation<br />

with the Corporation and, as appropriate, law enforcement authorities.<br />

5. Verification that the forensics investigation was initiated within seventy-two<br />

(72) hours of the ADC Event or Potential ADC Event and completed as<br />

soon as practical.<br />

6. Timely receipt by the Corporation of the unedited (by other than the<br />

forensic examiner) forensics examination findings.<br />

7. Evidence that the ADC Event or Potential ADC Event was not foreseeable or<br />

preventable by commercially reasonable means and that, on a continuing<br />

basis, best security practices were applied.<br />

In connection with its evaluation of the Customer’s or its Agent’s actions, the<br />

Corporation will consider, and may draw adverse inferences from, evidence<br />

that a Customer or its Agent(s) deleted or altered data.<br />

As soon as practicable, the Corporation will contact the Customer’s Security<br />

Contact, Principal Contact and Merchant Acquirer Contact as they are listed in<br />

the Member Information—Cirrus/<strong>Maestro</strong> tool on <strong>MasterCard</strong> Connect, notifying<br />

all impacted parties of the impending financial obligation.<br />

It is the sole responsibility of each Customer, not the Corporation, to include<br />

current and complete information in the Member Information—Cirrus/<strong>Maestro</strong><br />

tool on <strong>MasterCard</strong> Connect.<br />

NOTE<br />

An addition to this Rule appears in Chapter 17, “Europe Region,” of this rulebook.<br />

8.9.4.3 Investigation and Other Costs<br />

The Corporation may assess the responsible Customer for all investigation and<br />

other costs incurred by the Corporation in connection with an ADC Event and<br />

may assess a Customer for all investigative and other costs incurred by the<br />

Corporation in connection with a Potential ADC Event.<br />

8.9.5 Assessments for Noncompliance<br />

If the Customer fails to comply with the procedures set forth in this Rule 8.9,<br />

the Corporation may impose an assessment of up to USD 25,000 per day for<br />

each day that the Customer is noncompliant.<br />

When an Issuer becomes aware that Account data has been lost, stolen,<br />

misplaced, or the like, by any person (for example, a tape of Account data is<br />

lost during transit to a storage site), the Issuer must report the occurrence as<br />

described above. The Corporation will determine in its sole discretion whether<br />

it considers such act to be an Account data compromise event.<br />

©1993–2012 <strong>MasterCard</strong>. Proprietary. All rights reserved.<br />

8-16 9 November 2012 • <strong>Maestro</strong> <strong>Global</strong> <strong>Rules</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!