Category Archives: News Update

Requirement 10: PCI’s Everest

Requirement 10: PCI’s Everest

C omplying with the Payment Card Industry (PCI) Data Security Standard (DSS) is a mandate for all merchants, regardless of acceptance channel and transaction volume. However, some requirements of the PCI DSS are more difficult to comply with than others.

In fact, my investigation of payment card compromises and PCI DSS audits of various merchants demonstrate that requirement 10 – track and monitor all access to network resources and cardholder data – proves especially difficult for merchants involved.

In my research of 350 card compromise cases, more than half of the merchants involved failed to comply with requirement 10. Also, during initial PCI DSS audits of Trustwave’s customers, 70% of them needed to remediate deficiencies within their network environment to comply with the 10th rule.

Follow the basics

Tracking and monitoring all access to network components and cardholder data is no easy feat. For example, the PCI DSS requires that audit trails record the following network events:

  • Access of cardholder data by individual user
  • Actions taken by users with root or administrative privileges
  • Access of audit trails
  • Invalid access attempts
  • User log-in
  • Audit log initialization
  • Creation and deletion of system-level objects

The PCI DSS also requires that for each of these events, the following information, at the least, be recorded:

  • User
  • Type
  • Date and time
  • Success or failure
  • Origin
  • Name of affected data, component or resource

Any entity that processes, stores or transmits payment card information must comply with the PCI DSS. Thus the standard’s requirements are at the front of many merchants’ minds, but monitoring and logging are basic tenets of any data security plan.

Bulk up on security

Monitoring and logging network events can strain any organization’s resources, but the difference between implementing and not implementing logging measures can determine the severity of a security breach.

Critical files, such as those containing cardholder data or other sensitive information, must be monitored for unauthorized changes. If attackers are able to penetrate a network, they may attempt to add additional user accounts with administrative privileges.

Once attackers have gained administrative privileges, many times they can then access any asset on a network and begin copying sensitive information and sending it off-site.

Regular review of audit logs would alert a merchant or network administrator to foul play. But hackers do not work from 9 a.m. to 5 p.m. It’s more likely that an attack on cardholder data will take place at 3 a.m. – the perfect time to invade a smaller merchant who doesn’t have the resources to maintain a 24/7 security staff. And without continual, real-time monitoring of the logs, an alert may come too late.

Many operating systems provide default software programs that can log this information. However, requirement 10 calls for more than just the recording of events. Merchants must also review firewall, router and wireless access points and authentication server logs at least daily for unauthorized traffic and access attempts.

To complicate matters, depending on the systems running on a merchant’s network, each device may perform its own form of logging. Without information technology (IT) staff expertise, it’s unlikely these logs would make sense to the average merchant.

Even with in-depth IT knowledge, consolidating logs from multiple devices deployed across an entire network and presenting them in a way conducive to analysis would require a full-time IT employee, if not an entire staff.

The complexity of a merchant’s environment also affects the amount of logs that need monitoring.

Without a centralized process by which event logs can be correlated, it becomes increasingly difficult for merchants to gain insight into what’s occurring on their networks. While they may have enabled logging on their network devices, they find themselves buried in log data rather than at a vantage point with actionable information.

Fortunately, a number of information security companies have developed automated solutions to help merchants address the challenges of log tracking and monitoring around the clock. By allowing an outside data security expert to take over the monitoring of logs, a merchant not only saves money, but gains peace of mind.

While merchants may be baffled by the barrage of data streaming from their network devices, an experienced data security company monitoring merchants’ logs can provide insight into the security status of their networks, and maintaining in-house staff becomes unnecessary.

To show that you’re concerned about your merchants’ needs, consider using an information security service, along with your payment solutions. Merchants will know you have their well-being in mind because you will be offering not only secure payment services and technology, but also data security solutions that protect their businesses.


Michael Petitti is Chief Marketing Officer of Trustwave and is responsible for all of the company’s marketing initiatives. He serves on the Merchant Risk Council’s board of advisers and on The Green Sheet Inc. Advisory Board. Call him at 312-873-7291 or e-mail him at mpetitti@atwcorp.com.

Notice to readers: These are archived articles. Contact names or information may be out of date. We regret any inconvenience.

Back to Top

Bill Hoidas
District Sales Manager
Larger B2B/MOTO/Internet Accounts
Product Development Manager
Matrix Payment Systems
(847) 381-3482 office
(847) 381-4289 fax
http://paymentconsulting.net
John 3:16 For God so loved the world, that he gave his only begotten
Son, that whosoever believeth in him should not perish, but have
everlasting life.

Gift Card Low Down

February 11, 2008 • Issue 08:02:01

Gift card muscle flex

G ift cards have long been my favorite value added solution. When you mention stored value, gift cards jump to the minds of most merchants. Gift cards store value very well and usually permanently. Name any other product that is purchased and then often goes unused. Go on, I dare you.

The Tower Group Inc. estimated Americans spent $97 billion in gift cards in 2007. Most likely, you received at least one card between your last birthday and the holiday season. And the holidays slightly edged out birthdays for the number one reason for gift card purchases. Mother’s Day, Father’s Day and graduations are also some of the biggest gift card selling days of the year.

Imagine what the initial group of merchants must have thought when they first heard of the gift card idea. MLSs gave them the bare facts: The cards are paid for upfront; 20% of consumers never use cards given to them; 50% use their cards only a few times within a year of purchase.

With such extremely favorable statistics, how many of your merchant customers would turn down offering gift cards? Not many, I believe. Gift cards can be one of the best things to ever happen to a merchant’s cash flow. This is why I truly feel that gift cards are an underrated service. They can increase merchants’ sales, while merchants may never have to exchange the value on the cards for merchandise.

Feeling the bulge

Gift cards can generate sizable profits for merchants. Most research shows that two-thirds of all holiday shoppers planned to give someone else a gift card this past holiday season. According to Comdata Corp.’s adult card study, the average amount for a gift card purchase is $45.

The Tower Group’s research placed breakage, the industry’s term for card value that was purchased and never redeemed, at $7.8 billion for 2007. Best Buy Co. Inc. had the highest amount of breakage at $16 million. A recent article in The New York Times stated $3.5 billion in gift cards went unclaimed during the 2007 holiday season alone.

There is also what retailers call up-spending: Most customers who use their gift cards often spend some of their own money to purchase merchandise that is more expensive than the value of their cards. Of those who receive cards, a whopping 51% spend more than the cards’ initial values.

One of my favorite gift card facts is that merchants retain any unused balance, depending on state laws. For example, Vermont consumers can only cash out cards if the value is less than $1. (For more information, see “California chomps on gift card leftovers,” Jan. 14, 2008, issue 08:01:01)

With the older relative of the gift card, the paper certificate, cash was given back if the purchase was under the value of the certificate. There are quite a few states that require the merchant to give back cash if the value on the card is under $5.

Gift cards are also far safer than gift certificates because they are harder to counterfeit. And if a box of gift cards gets lost or stolen, the merchant need not worry: Cards can only be activated at the POS terminal.

According to KeyCorp., switching from paper certificates to plastic can result in two to four times the average revenue growth because plastic cards are more visible and widely publicized. Additionally, carrying around a gift card that has a brand name on it gives merchants another opportunity to advertise.

Holding strong

Gift cards can do an amazing job of enhancing merchant retention. We all know the more value added services your merchant has, the lower your attrition.

Evidence has shown that merchants with gift card programs switch processors with 50% less frequency. And with recent law changes concerning gift cards, many merchants find it difficult to leave their current merchant service provider because gift cards with existing balances must be honored.

The real opportunity to offer gift cards is with your installed base of merchants. It’s fairly cheap and easy to sell to merchants with whom you are already doing business; you can make a case that the value added service will increase their sales.

If they are satisfied with the products you’ve given to them thus far, chances are they’ll take your suggestion and add gift cards to their sales floor. Some companies now offer basic cards in addition to customizable cards – designed with logos, pictures, lights, music and so forth.

Basic cards appeal to mom-and-pop merchants looking for the lowest cost to offer gift cards. These programs are great for merchants who aren’t interested in purchasing a gift card package until completing a trial run.

Some MLSs offer the first bulk of basic cards for free to all merchants as bait. This helps get merchants hooked on the cards’ revenue and benefits. Then MLSs steer them toward investing in gift card packages. This is when they mention that gift cards also capitalize on impulse purchases. Merchants who set up grab items at the POS are more likely to sell a gift card and a small item – maybe a stuffed animal, lip gloss or candy.

Online reporting and many new custom, interactive designs, such as cards that double as kaleidoscopes, have been added recently to give merchants more power and flexibility when choosing what gift cards to sell to their consumers.

If you don’t sell gift cards to your merchants, others will. If that happens, your merchants will likely leave you and take their businesses to competitors with more enticing offers. Why take that chance?

Gift cards pack a punch in the payments industry, especially in the profit margin.


Bill Hoidas
District Sales Manager
Larger B2B/MOTO/Internet Accounts
Product Development Manager
Matrix Payment Systems
(847) 381-3482 office
(847) 381-4289 fax
http://paymentconsulting.net
John 3:16 For God so loved the world, that he gave his only begotten
Son, that whosoever believeth in him should not perish, but have
everlasting life.

There is money available if your bank credit line is used up

Hi,

Lately I have been doing advance funding using credit card future sales. I have now found three sources that I feel comfortable with and feel are the best. Each one has it’s own specialty that I can match my clients up with. While you often can qualify for more money as a rule of thumb figure that you can receive an advance equal to your average one month volume of MC/Visa sales. In other words if you do about $25,000 monthly MC/Visa you can receive in a few days funding of $25,000.00.

I want all of my merchants to use utmost caution when borrowing money. Make sure you have exhausted your conventional sources first because the rates are higher for cc advance funding. The rates will vary according to your credit. However it can make sense for the right situation. I just had a merchant use the funding to buy almost new equipment for a fraction of what it is worth. He will be able to turn a nice profit on his purchase. In this situation it makes sense.

For more info go to http://paymentconsulting.net/adv_funding.html


Bill Hoidas
District Sales Manager
Larger B2B/MOTO/Internet Accounts
Product Development Manager
Matrix Payment Systems
(847) 381-3482 office
(847) 381-4289 fax
http://paymentconsulting.net
John 3:16 For God so loved the world, that he gave his only begotten
Son, that whosoever believeth in him should not perish, but have
everlasting life.

American Express is now charging you for your monthly statement-how to get it rebated

Hi,

Amex has never charged a monthly fee before for it’s regular accounts. It’s been officially 7 months now but they didn’t actually start until 3 months ago. This charge came to the best of my knowledge unannounced.

They are now charging $4.50 per month per merchant account.

To get it removed you should call 800-528-5200 /key in your merchant account # and than keep pressing “0” to wade through the multiple voice prompts.

Tell the rep that you weren’t aware of this new charge and do not need paper statements. They will enroll you for their website and to also receive your statement by email. Make sure you find out how many months you have been charged and have them rebate the charges.

You can also enroll on their website below but you won’t than get to ask to have the $4.50 monthly fees you’ve already been charged rebated.
https://home.americanexpress.com/homepage/merchant_cm.shtml

Bill


Bill Hoidas
District Sales Manager
Larger B2B/MOTO/Internet Accounts
Product Development Manager
Matrix Payment Systems
(847) 381-3482 office
(847) 381-4289 fax
http://paymentconsulting.net
John 3:16 For God so loved the world, that he gave his only begotten
Son, that whosoever believeth in him should not perish, but have
everlasting life.

great flow chart showing what really happens with a chargeback

Hi,

This is the best single thing I’ve ever seen that shows what happens when a cardholder (justifiably or not) calls their bank to do a chargeback. Contrary to popular opinion your processor doesn’t give up without a fight and does (or should) check for validity and to see if you’ve already issued a credit.

However if they can’t automatically reject it the ball’s in your court and you must fill out an answer and include all possible documentation. It’s just a sad fact of life that a cardholder can often get their bank to roll over and issue an unfair chargeback.

If your response does not succeed and the sum is large enough I do work with a consulting firm that specializes in chargebacks and can also recommend attorneys that specialize in cc law. As you can see the card holder and card issuing bank can be pushed to arbitration and whoever loses can be liable for all arbitration fees.


Bill Hoidas
District Sales Manager
Larger B2B/MOTO/Internet Accounts
Product Development Manager
Matrix Payment Systems
(847) 381-3482 office
(847) 381-4289 fax
http://paymentconsulting.net
John 3:16 For God so loved the world, that he gave his only begotten
Son, that whosoever believeth in him should not perish, but have
everlasting life.

CB_RetrvlProcessFlowChart.pdf
38K View as HTML Download

foreign payment processing including credit cards, eChecks, ACH, etc. now possible

Hi,

I have been fortunate to establish a relationship with the finest company involved in the international markets.Global Collect http://www.globalcollectusa.com/

They take all of the hassle out of setting up foreign processing and all at very reasonable rates.

Global Collect is the only global payment processing provider that provides both credit card and alternative payment processing in over 50 local currencies, and 120 countries worldwide. Their Web Collect Platform is the broadest global payment network available through a single technical and financial interface.

Let me know your level of interest

keeping up with PCI dealines for 2008-January, July & October including PABP for programmers/software vendors

Hi,

Below please find a PCI security theft update. Please note PABP for programmers & mandates for January (that would be now!), July and October.

Visa, PCI council make security move

By Michael Petitti
TrustWave

Editor’s Note: A version of this article originally appeared in the December 2007 issue of Trusted News, a TrustWave publication.

B e prepared. Two major announcements made in recent months will send merchants scrambling to their payment application vendors and merchant level salesperson (MLS) for guidance and clarity.

Visa Inc. and the Visa’s Payment Application Best Practices (PABP), it’s likely that a great number of these compromises would not have occurred.

Visa created PABP to prevent payment card compromises by guiding software vendors in developing payment applications that support a merchant’s compliance with the PCI Data Security Standard (DSS). The PCI SSC and Visa detail plans to unify a payment application security standard and begin enforcing the use of adherent applications.

Total takeover

The PCI SSC took over management of PABP in November, and renamed it the Payment Application Data Security Standard (PA DSS). New standards are expected to be released by the first quarter 2008. (For more information, see “Farewell PABP, hello PA DSS,” The Green Sheet, Nov. 26, 2007, issue 07:11:02 )

While the PA DSS is based on the PABP and remain similar, feedback received from various stakeholders may alter the PA DSS slightly. While these differences will impact software developers, merchants will not likely be affected.

Merchants will not need to look into the detailed requirements of the PA DSS or comply with it per se – applications developed for internal use only must still comply with the PCI DSS. Merchants only need to ensure that the payment applications they use are certified as PA DSS compliant. (For a list of validated, PABP-adherent payment applications, visit http://usa.visa.com/download/merchants/validated_payment_applications.pdf )

Once the transition is complete, the PCI SSC will maintain the list of validated applications. MLSs should ensure that the payment applications they offer are on this list. If not, MLSs should consider removing the offering from their portfolio of products.

As with the PCI DSS, the council will maintain its position as governing body of the PA DSS. Enforcement will continue to fall under the authority of the individual card brands.

While the transfer of the PABP standard to the PCI council will increase awareness of payment card security and increase adoption of secure payment applications, Visa’s recent announcement will probably have a more immediate effect on your merchant customers.

Calendar of events

In October, Visa set forth a plan to mandate merchants’ use of PABP-adherent (now PA DSS-adherent) applications. The plan entails a number of deadlines set by Visa to eradicate the use of vulnerable payment applications and payment applications that do not adhere to the PA DSS.

While the deadlines for the program are set for acquirers, VisaNet processors and agents because these organizations stand above merchants in the payment card acceptance process, the deadlines also apply to merchants.

Following are the specific mandates and deadlines Visa established:

* Jan. 1, 2008 – Merchants cannot use payment applications identified by Visa as vulnerable. For a list of these vulnerable payment applications, contact your acquirer.
* July 1, 2008 – VisaNet processors and agents cannot grant access to their network to new payment applications that are not PA DSS certified.
* Oct. 1, 2008 – Newly boarded level 3 or 4 merchants must prove their PCI compliance or use PA DSS-adherent payment applications.
* Oct. 1, 2009 – Payment applications identified by Visa as vulnerable will be decommissioned from the Visa network.
* July 1, 2010 – Merchants must use PA DSS-adherent applications to accept Visa transactions.

Field of queries

It’s likely that a number of current customers or potential customers will have questions about the new requirements.

Here are talking points to remember during these discussions:

* The PA DSS does not supplant the PCI DSS.
* The PA DSS supplements the PCI DSS.
* The card brands will continue to require that merchants continue to comply with the PCI DSS.
* Visa is the only card brand thus far that will require the use of PA DSS-compliant payment applications, but other card brands are likely to follow.


Bill Hoidas
District Sales Manager
Larger B2B/MOTO/Internet Accounts
Product Development Manager
Matrix Payment Systems
(847) 381-3482 office
(847) 381-4289 fax
http://paymentconsulting.net
John 3:16 For God so loved the world, that he gave his only begotten
Son, that whosoever believeth in him should not perish, but have
everlasting life.

recent regulation by FACTA (Fair and Accurate Credit Transactions Act)

Most merchants already know that FACTA says credit and debit card receipts may not include more than the last five digits of the card number. But now they have mandated thatt the card’s expiration date may not be printed on the cardholder’s receipt.However, the effective date of this provision is a long way off, and there are a couple of loopholes:

bullet This section does not apply to receipts for which the sole means of recording a credit or debt card number is by handwriting or by an imprint or copy of the card.
bullet For machines in use before January 1, 2005, the merchant has three (3) years to comply.
bullet For machines in use after January 1, 2005, the merchant has one (1) year to comply.