<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PCI Toolkit &#187; Alerts</title>
	<atom:link href="http://www.pcitoolkit.com/category/alerts/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pcitoolkit.com</link>
	<description>Powered by CSRSI®</description>
	<lastBuildDate>Wed, 30 Jun 2010 16:28:10 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Visa Announces New Payment Application Security Mandates</title>
		<link>http://www.pcitoolkit.com/2009/10/29/visa-announces-new-payment-application-security-mandates/</link>
		<comments>http://www.pcitoolkit.com/2009/10/29/visa-announces-new-payment-application-security-mandates/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 15:55:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.pcitoolkit.com/?p=106</guid>
		<description><![CDATA[Beginning January 1, 2008, Visa will implement a series of mandates to eliminate the use of
non-secure payment applications from the Visa payment system. These mandates require
acquirers to ensure their merchants and agents do not use payment applications known to
retain prohibited data elements and require the use of payment applications that adhere to
Visa’s Payment Application Best Practices (PABP).]]></description>
			<content:encoded><![CDATA[<p>CISP BULLETIN<br />
Visa Announces New Payment Application Security Mandates<br />
October 23, 2007<br />
</br><br />
Beginning January 1, 2008, Visa will implement a series of mandates to eliminate the use of  non-secure payment applications from the Visa payment system. These mandates require  acquirers to ensure their merchants and agents do not use payment applications known to  retain prohibited data elements and require the use of payment applications that adhere to  Visa’s Payment Application Best Practices (PABP). PABP-compliant applications help  merchants and agents mitigate compromises, prevent storage of prohibited data and support  overall compliance with the Payment Card Industry Data Security Standard (PCI DSS) and the  Visa U.S.A. Inc. Operating Regulations. A list of PABP-validated applications is available at  www.visa.com/pabp.<br />
</br><br />
Vulnerable payment applications have proved to be the leading cause of compromise incidents,  particularly among small merchants. Visa U.S.A. Inc. Operating Regulations prohibit the  storage of the full content of any magnetic-stripe, CVV2 or PIN data and require compliance  with the PCI DSS. Merchants and agents that use payment applications that store prohibited  data or have inherent security weaknesses will not be compliant with the PCI DSS and are at  high risk of being compromised.<br />
</br><br />
In light of the criticality of promoting payment application security and merchant dependence on  secure payment applications to achieve compliance, Visa will implement a series of mandates,  beginning January 1, 2008, to eliminate the use of vulnerable payment applications from the  Visa payment system. These mandates support compliance with the Visa U.S.A. Inc. Operating<br />
</br><br />
Regulations, which prohibit the storage of magnetic-stripe, CVV2 and PIN data. Further, the  Operating Regulations require that acquirers comply — and ensure that their merchants and agents comply — with the requirements of the Cardholder Information Security Program (CISP).  These mandates are intended to prevent cardholder data compromises and thereby help mitigate the risk of associated financial losses such as liability from the Account Data  Compromise Recovery (ADCR) program. Additionally, Visa’s payment application security  mandates reinforce acquirer compliance efforts and create a level playing field by preventing  merchants from migrating from one acquirer to another in attempt to avoid security requirements.<br />
</br><br />
Outlined below are each of the five mandates, which will take effect over the next three years.<br />
</br><br />
Phase 1 &#8211; Effective Date &#8211; 1/1/08<br />
Newly boarded merchants must not use known vulnerable payment applications, and VisaNet Processors (VNPs) and agents must not certify new payment applications<br />
</br><br />
Phase 2 &#8211; Effective Date &#8211; 7/1/08<br />
VNPs and agents must only certify new payment applications to their platforms that are PABP-compliant<br />
</br><br />
Phase 3 &#8211; Effective Date &#8211; 10/1/08<br />
Newly boarded Level 3 and 4 merchants must be PCI DSS compliant or use PABP-compliant applications<br />
</br><br />
Phase 4  &#8211; Effective Date &#8211; 10/1/09<br />
VNPs and agents must decertify all vulnerable payment applications<br />
</br><br />
Phase 5  &#8211; Effective Date &#8211; 7/1/10<br />
Acquirers must ensure their merchants, VNPs and agents use only PABP-compliant applications<br />
</br><br />
</br></p>
<h3><span style="color: #0000ff;">Phase I – January 1, 2008</span></h3>
<p></br><br />
Acquirers must not board new merchants that use known vulnerable payment applications. Furthermore, VNPs and agents must not certify new applications to their platforms that are known vulnerable payment applications. A list of vulnerable payment applications is updated quarterly and is available on Visa Online at <a href="www.us.visaonline.com/us_riskmgmt/cisp" target="_blank"><span style="color: #0000ff;">www.us.visaonline.com/us_riskmgmt/cisp</span></a>.<br />
</br><br />
Phase I will deter vendors from introducing new vulnerable payment applications into the payment system, and will reinforce acquirer compliance efforts by preventing merchants from migrating from one acquirer to another in an attempt to avoid upgrading a vulnerable payment application.<br />
</br><br />
</br></p>
<h3><span style="color: #0000ff;">Phase II – July 1, 2008</span></h3>
<p></br><br />
VNPs and agents must only certify new payment applications to their platforms that are PABPcompliant. A list of payment applications that have been validated against Visa’s PABP is available at www.visa.com/pabp.<br />
</br><br />
Phase II promotes the use of payment applications that adhere to PABP and support merchant PCI DSS compliance. This phase will also further prevent vendors from introducing new vulnerable payment applications into the payment system.<br />
</br><br />
</br></p>
<h3><span style="color: #0000ff;">Phase III – October 1, 2008</span></h3>
<p></br><br />
Acquirers must only board new Level 3 and Level 4 merchants that are PCI DSS compliant or utilize  PABP-compliant applications. PABP does not apply to applications developed for inhouse use only or to  hardware terminals.<br />
</br><br />
Phase III mitigates acquirer risk associated with boarding new merchants that are not PCI DSS compliant or that rely on payment applications that are not PABP-compliant. Further, Phase III reinforces acquirer compliance efforts by preventing merchants from migrating from one acquirer to another in an attempt to avoid compliance requirements.<br />
</br><br />
</br></p>
<h3><span style="color: #0000ff;">Phase IV – October 1, 2009</span></h3>
<p></br><br />
VNPs and agents must decertify all known vulnerable payment applications, including those published on Visa’s quarterly list of vulnerable payment applications. As future vulnerable payment applications are identified, VNPs and agents must decertify these applications within 12 months.<br />
Phase IV is intended to eliminate the continued use of vulnerable payment applications by acquirers, merchants and agents within the payment system.<br />
</br><br />
</br></p>
<h3><span style="color: #0000ff;">Phase V – July 1, 2010</span></h3>
<p></br><br />
Acquirers must ensure their merchants and agents use only PABP-compliant applications. A list of payment applications that have been validated against Visa’s PABP is available at www.visa.com/pabp.<br />
</br><br />
Phase V mandates the use of payment applications that support PCI DSS compliance, requiring acquirers, merchants and agents to use only those payment applications that can be validated as  PABP-compliant. It is important to note that the deadline for Phase V is aligned with the Triple Data Encryption Standard (TDES) usage mandate for all point-of-sale (POS) PIN-entry devices (PEDs) to be using TDES to protect PINs. Additionally, all attended POS PEDs must be evaluated by a Visa-recognized laboratory and approved by Visa prior to this same date.<br />
</br><br />
</br></p>
<h3><span style="color: #0000ff;">Vulnerable Payment Applications</span></h3>
<p></br><br />
As a result of an increasing number of merchant compromises, Visa has identified that certain payment applications are designed to store prohibited data, including full magnetic-stripe, CVV2 or PIN data, subsequent to transaction authorization. Storage of these data elements is in violation of the PCI DSS and Visa U.S.A. Inc. Operating Regulations. Hackers are targeting merchants and agents using vulnerable payment applications and exploiting vulnerabilities to find this data. It is critical for acquirers to ensure that their merchants and agents do not use payment applications known to retain prohibited data elements and to take corrective actions to address any identified deficiencies. Acquirers, merchants and agents should ask all of their payment application vendors, resellers or system integrators to confirm that software versions used do not store magnetic-stripe, CVV2 or PIN data.<br />
</br><br />
Recently, Visa alerted acquirers of an updated list of vulnerable payment applications that retain prohibited data. Visa will continue to proactively alert acquirers as vulnerable payment applications are identified. The vulnerable payment application list is available on Visa Online at <a href="www.us.visaonline.com/us_riskmgmt/cisp" target="_blank">www.us.visaonline.com/us_riskmgmt/cisp</a>.<br />
</br><br />
</br></p>
<h3><span style="color: #0000ff;">Summary</span></h3>
<p></br><br />
<strong> </strong> To enforce the payment application security mandates, Visa will continue to identify payment applications used by Level 1 and 2 merchants through the PCI Compliance Acceleration Program, monitor acquirers’ Level 4 merchant compliance plans and determine payment applications certified by VNPs. Visa may also consider a compromised entity’s use of vulnerable payment applications or PABP-validated applications in fine and ADCR determinations.<br />
</br><br />
Visa will continue to work with all key stakeholders — acquirers, processors, merchants, agents and payment application vendors — to raise security awareness and promote the use of payment  applications validated against the PABP. In many cases, acquirers, processors and agents have indicated that they already have more aggressive plans in place to support these mandates. It is critical for acquirers and processors to begin integrating these mandates into their processes. Acquirers should also revisit their Level 4 merchant compliance plans and adjust accordingly to support these  candates. In an effort to mitigate the risk of compromise, acquirers must take prompt action to ensure that merchants and agents discontinue use of vulnerable payment applications and begin moving merchants and agents toward using only PABP-compliant applications.<br />
</br><br />
For more information on Visa’s PABP, please visit <a href="http://www.visa.com/pabp" target="_blank">http://www.visa.com/pabp</a>. Questions about this bulletin may be directed to CISP@visa.com. For the complete VBR, Visa acquirers may refer to the Visa Business Review article, “Visa Announces New Payment Application Security Mandates,” October 2007; Issue 07100902.<br />
</br><br />
© 2007 Visa Inc., all rights reserved.<br />
</br><br />
CISP BULLETIN – 102307</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pcitoolkit.com/2009/10/29/visa-announces-new-payment-application-security-mandates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Key Data Security Compliance Dates</title>
		<link>http://www.pcitoolkit.com/2009/10/29/key-data-security-compliance-dates/</link>
		<comments>http://www.pcitoolkit.com/2009/10/29/key-data-security-compliance-dates/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 15:35:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.pcitoolkit.com/?p=102</guid>
		<description><![CDATA[Listed below are Visa key dates including data security mandates and reporting deadlines.]]></description>
			<content:encoded><![CDATA[<p><strong>Key Data Security Compliance Dates</strong></p>
<p><span style="font-family: Arial; color: #666666; font-size: xx-small;">Listed below are Visa<br />
key dates including data security mandates and reporting deadlines. </span></p>
<p><a name="0.2_table01"></a></p>
<div>
<table border="2" cellspacing="0" width="636">
<tbody>
<tr valign="top">
<td bgcolor="#cccccc"><span style="font-family: Arial; color: #333333; font-size: xx-small;">Event</span></td>
<td bgcolor="#cccccc"><span style="font-family: Arial; color: #333333; font-size: xx-small;">Date</span></td>
</tr>
<tr valign="top">
<td bgcolor="#ececec"><a href="http://usa.visa.com/download/merchants/level_4_merchant_compliance.pdf" target="_blank"><span style="font-family: Arial; color: #333333; font-size: xx-small;"><span style="text-decoration: underline;">U.S.<br />
Level 4 Merchant Compliance Plan Deadline</span></span></a><span style="font-family: Arial; color: #666666; font-size: xx-small;"><br />
PDF | 56k</span></td>
<td bgcolor="#ececec"><span style="font-family: Arial; color: #666666; font-size: xx-small;">7/31/2007</span></td>
</tr>
<tr valign="top">
<td bgcolor="#ececec"><span style="font-family: Arial; color: #666666; font-size: xx-small;">TDES<br />
Mandate &#8211; All U.S. VisaNet, Interlink, DPS and Plus endpoints must use<br />
TDES</span></td>
<td bgcolor="#ececec"><span style="font-family: Arial; color: #666666; font-size: xx-small;">12/31/2007</span></td>
</tr>
<tr valign="top">
<td bgcolor="#ececec"><span style="font-family: Arial; color: #666666; font-size: xx-small;">TDES<br />
Mandate &#8211; All U.S. ATMs must be encrypting PINS using TDES end-to-end</span></td>
<td bgcolor="#ececec"><span style="font-family: Arial; color: #666666; font-size: xx-small;">12/31/2007</span></td>
</tr>
<tr valign="top">
<td bgcolor="#ececec"><a href="http://usa.visa.com/download/merchants/payment_application_security_mandates.pdf" target="_blank"><span style="font-family: Arial; color: #333333; font-size: xx-small;"><span style="text-decoration: underline;">U.S.<br />
Payment Application Security Mandate &#8211; Phase 1</span></span></a><span style="font-family: Arial; color: #666666; font-size: xx-small;"><br />
PDF | 60k</p>
<p>Newly boarded merchants must not use known vulnerable payment applications,<br />
and VisaNet Processors (VNPs) and agents must not certify new payment<br />
applications to their platforms that are known vulnerable payment applications</p>
<p></span></td>
<td bgcolor="#ececec"><span style="font-family: Arial; color: #666666; font-size: xx-small;">1/1/2008</span></td>
</tr>
<tr valign="top">
<td bgcolor="#ececec"><span style="font-family: Arial; color: #666666; font-size: xx-small;">U.S.<br />
Level 4 Merchant Compliance Plan Status Report Deadline</span></td>
<td bgcolor="#ececec"><span style="font-family: Arial; color: #666666; font-size: xx-small;">6/30/2008</span></td>
</tr>
<tr valign="top">
<td bgcolor="#ececec"><a href="http://usa.visa.com/download/merchants/payment_application_security_mandates.pdf" target="_blank"><span style="font-family: Arial; color: #333333; font-size: xx-small;"><span style="text-decoration: underline;">U.S.<br />
Payment Application Security Mandate &#8211; Phase 2</span></span></a><span style="font-family: Arial; color: #666666; font-size: xx-small;"><br />
PDF | 60k</p>
<p>VNPs and agents must only certify new payment applications to their<br />
platforms that are PA-DSS-compliant</p>
<p></span></td>
<td bgcolor="#ececec"><span style="font-family: Arial; color: #666666; font-size: xx-small;">7/1/2008</span></td>
</tr>
<tr valign="top">
<td bgcolor="#ececec"><a href="http://usa.visa.com/download/merchants/payment_application_security_mandates.pdf" target="_blank"><span style="font-family: Arial; color: #333333; font-size: xx-small;"><span style="text-decoration: underline;">U.S.<br />
Payment Application Security Mandate &#8211; Phase 3</span></span></a><span style="font-family: Arial; color: #666666; font-size: xx-small;"><br />
PDF | 60k</p>
<p>Newly boarded Level 3 and 4 merchants must be PCI DSS compliant or use<br />
PA-DSS-compliant applications</p>
<p></span></td>
<td bgcolor="#ececec"><span style="font-family: Arial; color: #666666; font-size: xx-small;">10/1/2008</span></td>
</tr>
<tr valign="top">
<td bgcolor="#ececec"><span style="font-family: Arial; color: #666666; font-size: xx-small;">U.S.<br />
Level 4 Merchant Compliance Plan Status Report Deadline</span></td>
<td bgcolor="#ececec"><span style="font-family: Arial; color: #666666; font-size: xx-small;">12/31/2008</span></td>
</tr>
<tr valign="top">
<td bgcolor="#ececec"><a href="http://usa.visa.com/download/merchants/bulletin_interlink_merchants_tdes_pos.pdf" target="_blank"><span style="font-family: Arial; color: #333333; font-size: xx-small;"><span style="text-decoration: underline;">TDES<br />
Mandate &#8211; Newly deployed U.S. Automated Fuel Dispensers must contain<br />
a TDES-capable and PCI-approved Encrypting PIN Pad</span></span></a><span style="font-family: Arial; color: #666666; font-size: xx-small;"> PDF | 128k</span></td>
<td bgcolor="#ececec"><span style="font-family: Arial; color: #666666; font-size: xx-small;">1/1/2009</span></td>
</tr>
<tr valign="top">
<td bgcolor="#ececec"><span style="font-family: Arial; color: #666666; font-size: xx-small;">U.S.<br />
Level 1 and Level 2 Merchants Prohibited Data Retention Attestation<br />
Deadline*</span></td>
<td bgcolor="#ececec"><span style="font-family: Arial; color: #666666; font-size: xx-small;">3/31/2009</span></td>
</tr>
<tr valign="top">
<td bgcolor="#ececec"><span style="font-family: Arial; color: #666666; font-size: xx-small;">U.S.<br />
Level 4 Merchant Compliance Plan Status Report Deadline</span></td>
<td bgcolor="#ececec"><span style="font-family: Arial; color: #666666; font-size: xx-small;">6/30/2009</span></td>
</tr>
<tr valign="top">
<td bgcolor="#ececec"><span style="font-family: Arial; color: #666666; font-size: xx-small;">U.S.<br />
Level 1 Merchants Full PCI DSS Compliance Validation Deadline</p>
<p>Applies to newly identified Level 1 merchants late 2007 and early 2008</p>
<p></span></td>
<td bgcolor="#ececec"><span style="font-family: Arial; color: #666666; font-size: xx-small;">9/30/2009</span></td>
</tr>
<tr valign="top">
<td bgcolor="#ececec"><a href="http://usa.visa.com/download/merchants/payment_application_security_mandates.pdf" target="_blank"><span style="font-family: Arial; color: #333333; font-size: xx-small;"><span style="text-decoration: underline;">U.S.<br />
Payment Application Security Mandate &#8211; Phase 4</span></span></a><span style="font-family: Arial; color: #666666; font-size: xx-small;"><br />
PDF | 60k</p>
<p>VNPs and agents must decertify all vulnerable payment applications</p>
<p></span></td>
<td bgcolor="#ececec"><span style="font-family: Arial; color: #666666; font-size: xx-small;">10/1/2009</span></td>
</tr>
<tr valign="top">
<td><span style="font-family: Arial; color: #666666; font-size: xx-small;">U.S.<br />
Level 2 Merchants Full PCI DSS Compliance Validation Deadline</p>
<p>Applies to newly identified Level 2 merchants late 2007 and early 2008</p>
<p></span></td>
<td><span style="font-family: Arial; color: #666666; font-size: xx-small;">12/31/2009</span></td>
</tr>
<tr valign="top">
<td><span style="font-family: Arial; color: #666666; font-size: xx-small;">U.S.<br />
Level 4 Merchant Compliance Plan Status Report Deadline</span></td>
<td><span style="font-family: Arial; color: #666666; font-size: xx-small;">12/31/2009</span></td>
</tr>
<tr valign="top">
<td><span style="font-family: Arial; color: #666666; font-size: xx-small;">U.S.<br />
Level 1 and Level 2 Merchants Prohibited Data Retention Attestation<br />
Deadline**</span></td>
<td><span style="font-family: Arial; color: #666666; font-size: xx-small;">3/31/2010</span></td>
</tr>
<tr valign="top">
<td><a href="http://usa.visa.com/download/merchants/cisp_update_tdes_042209.pdf%20" target="_blank"><span style="font-family: Arial; color: #333333; font-size: xx-small;"><span style="text-decoration: underline;">TDES<br />
Mandate &#8211; All U.S. POS PEDs must be encrypting PINS using TDES end-to-end</span></span></a><span style="font-family: Arial; color: #666666; font-size: xx-small;"> PDF | 115k</span></td>
<td><span style="font-family: Arial; color: #666666; font-size: xx-small;">7/1/2010</span></td>
</tr>
<tr valign="top">
<td><a href="http://usa.visa.com/download/merchants/cisp-pin-entry-device-faq.pdf%20" target="_blank"><span style="font-family: Arial; color: #333333; font-size: xx-small;"><span style="text-decoration: underline;">All<br />
attended POS PIN acceptance device models must have passed testing by<br />
a PCI-recognized or Pre-PCI recognized laboratory and have been approved<br />
by Visa</span></span></a><span style="font-family: Arial; color: #666666; font-size: xx-small;"> PDF<br />
| 45k</span></td>
<td><span style="font-family: Arial; color: #666666; font-size: xx-small;">7/1/2010</span></td>
</tr>
<tr valign="top">
<td><a href="http://usa.visa.com/download/merchants/payment_application_security_mandates.pdf" target="_blank"><span style="font-family: Arial; color: #333333; font-size: xx-small;"><span style="text-decoration: underline;">U.S.<br />
Payment Application Security Mandate &#8211; Phase 5</span></span></a><span style="font-family: Arial; color: #666666; font-size: xx-small;"><br />
PDF | 60k</p>
<p>Acquirers must ensure their merchants, VNPs and agents use only PA-DSS<br />
compliant applications</p>
<p></span></td>
<td><span style="font-family: Arial; color: #666666; font-size: xx-small;">7/1/2010</span></td>
</tr>
<tr valign="top">
<td><span style="font-family: Arial; color: #666666; font-size: xx-small;">U.S.<br />
Level 1 Merchants Full PCI DSS Compliance Validation Deadline</p>
<p>Applies to newly identified Level 1 merchants late 2008 and early 2009</p>
<p></span></td>
<td><span style="font-family: Arial; color: #666666; font-size: xx-small;">9/30/2010</span></td>
</tr>
<tr valign="top">
<td><span style="font-family: Arial; color: #666666; font-size: xx-small;">U.S.<br />
Level 2 Merchants Full PCI DSS Compliance Validation Deadline</p>
<p>Applies to newly identified Level 2 merchants late 2008 and early 2009</p>
<p></span></td>
<td><span style="font-family: Arial; color: #666666; font-size: xx-small;">12/31/2010</span></td>
</tr>
</tbody>
</table>
</div>
<p><span style="font-family: Arial; color: #666666; font-size: xx-small;">*Note: this timeframe<br />
applies to newly identified Level 1 and Level 2 merchants late 2007<br />
and early 2008</span></p>
<p>**Note: this timeframe applies to newly identified Level 1 and Level<br />
2 merchants late 2008 and early 2009</p>
<p><span style="font-family: Arial; color: #666666; font-size: xx-small;">Source: <a href="http://usa.visa.com/merchants/risk_management/cisp_key_dates.html" target="_blank">http://usa.visa.com/merchants/risk_management/cisp_key_dates.html</a></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pcitoolkit.com/2009/10/29/key-data-security-compliance-dates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
