<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>PCI Toolkit</title>
	<atom:link href="http://www.pcitoolkit.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pcitoolkit.com</link>
	<description>Powered by CSRSI®</description>
	<lastBuildDate>Tue, 26 Apr 2011 04:20:48 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>CSRSI Announces New and Improved Version 2.0 of the PCI ToolKit® Program for PCI Compliance</title>
		<link>http://www.pcitoolkit.com/2011/04/26/csrsi-announces-new-and-improved-version-2-0-of-the-pci-toolkit%c2%ae-program-for-pci-compliance/</link>
		<comments>http://www.pcitoolkit.com/2011/04/26/csrsi-announces-new-and-improved-version-2-0-of-the-pci-toolkit%c2%ae-program-for-pci-compliance/#comments</comments>
		<pubDate>Tue, 26 Apr 2011 04:20:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Press]]></category>
		<category><![CDATA[ComplyGuard Networks]]></category>
		<category><![CDATA[Electronic Transaction Association]]></category>
		<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[PCI ToolKit®]]></category>
		<category><![CDATA[Self-assessment questionnaire]]></category>

		<guid isPermaLink="false">http://www.pcitoolkit.com/?p=231</guid>
		<description><![CDATA[Rick Heroux, President of CSRSI, a leader in the field of PCI compliance and data protection, announces the new version 2.0 of the PCI ToolKit®.]]></description>
			<content:encoded><![CDATA[<p>Jensen Beach, FL—April 22, 2011— Rick Heroux, President of CSRSI, a leader in the field of PCI compliance and data protection, announces the new version 2.0 of the PCI ToolKit®, the industry standard in survey-driven services to help merchants complete their mandatory annual Self-Assessment Questionnaires (SAQ) while bank and payment processor administrators monitor and manage their progress.</p>
<p>CSRSI team members will show off the new version in Meeting Room #1524 and Booth #1424 at the annual Electronic Transaction Association (ETA) meeting in San Diego May 10-12.</p>
<p>“The new enhancements increase the ease and speed of completion of the SAQ by merchants while incorporating the fifth and newest SAQ C-VT, which reduces the number of merchants requiring a quarterly system scan. The policies in the system are more detailed with instructions that are easier to follow. The scanning reporting is improved for both merchant and processor. Current users beta-tested this version, providing important feedback,” said Heroux.</p>
<p>“With the PCI Toolkit, we have found, without fail, that our merchants are now embracing these very necessary security measures,” says Abe Maghaguian, President of Atlantic-Pacific Processing Systems, Inc.</p>
<p>The PCI ToolKit® is the only system to provide a self-guided interview system written to the 7<sup>th</sup> grade level of reading, making it very helpful to the average small merchant. It is complete with all the policies and procedures each merchant will need as required by the PCI Security Standards Council. The PCI ToolKit® is integrated with ComplyGuard Network for scanning and single sign-on reporting, however the ToolKit works with all approved scanning vendors. Tens of thousands of merchants use the ToolKit each month.</p>
<p>The new version 2.0 offers greater flexibility to banks and processors who oversee the process to encourage all the merchants in their portfolio to become PCI compliant. Implementation protocols are simpler and expanded. Requirements are presented in even more simpler terms. Greater detail is provided for merchants taking the longer SAQ D allowing workarounds. Overall version 2.0 creates a better experience for bank, payment processor and merchant.</p>
<p>About CSRSI</p>
<p>Reducing risk and liability are core competencies for this consulting team of advocates knowledgeable in privacy legislation, compliance, detecting and protecting personally identifiable information.</p>
<p>In over 1750+ engagements since 1999, CSRSI provides guidance in electronic payments, PCI compliance and security of personal data to companies and institutions. For more information, visit csrsi.com.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pcitoolkit.com/2011/04/26/csrsi-announces-new-and-improved-version-2-0-of-the-pci-toolkit%c2%ae-program-for-pci-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CSRSI Team to Moderate and Participate on Regulatory Update and Interchange Panels at ETA 2011</title>
		<link>http://www.pcitoolkit.com/2011/04/26/csrsi-team-to-moderate-and-participate-on-regulatory-update-and-interchange-panels-at-eta-2011/</link>
		<comments>http://www.pcitoolkit.com/2011/04/26/csrsi-team-to-moderate-and-participate-on-regulatory-update-and-interchange-panels-at-eta-2011/#comments</comments>
		<pubDate>Tue, 26 Apr 2011 00:52:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Press]]></category>
		<category><![CDATA[Anti-Money Laundering]]></category>
		<category><![CDATA[data breach requirements]]></category>
		<category><![CDATA[Durbin Amendment]]></category>
		<category><![CDATA[Electronic Transaction Association]]></category>
		<category><![CDATA[interchange]]></category>
		<category><![CDATA[MasterCard]]></category>
		<category><![CDATA[PCI compliance]]></category>
		<category><![CDATA[personally identifiable information]]></category>
		<category><![CDATA[regulatory update]]></category>
		<category><![CDATA[security of personal data]]></category>

		<guid isPermaLink="false">http://www.pcitoolkit.com/?p=229</guid>
		<description><![CDATA[Ross Federgreen, founder of CSRSI, a leader in payments and data privacy consulting, and Mark Brady, Senior Consultant at CSRSI, will participate in panels covering Regulatory Updates at the ETA annual meeting.]]></description>
			<content:encoded><![CDATA[<p>Jensen Beach, FL—April 22, 2011— Ross Federgreen, founder of CSRSI, a leader in payments and data privacy consulting, and Mark Brady, Senior Consultant at CSRSI, will participate in panels covering Regulatory Updates at the annual Electronic Transaction Association (ETA) meeting in San Diego May 10-12.</p>
<p>Federgreen will moderate Regulatory Update, Part 1: Interchange outlining a status of the Durbin Amendment with commentary on the practical effects and implications on acquiring businesses.</p>
<p>Brady will join the Regulatory Update, Part 2: Market Landscape panel, discussing the new IRS reporting requirements, levy rights on merchants, US Treasury/FINCEN compliance, US Anti-Money Laundering and new data security and breach requirements. Commentary will follow on the challenges presented and response by acquiring community and the ETA.</p>
<p>The Challenges of PCI Compliance panel will also be moderated by Federgreen covering reasonable expectations for these programs, handling merchant resistance, avoiding attrition and a discussion on selection of PCI Compliance vendors.</p>
<p>“We always enjoy the give and take of discussions on compliance topics that affect the payments industry and their merchants. These are interesting times with many forces from Federal, state, judicial and regulatory directions causing bank, acquirers, processors and merchants all alike to make significant changes in how they do business and how they strategize for the future.”</p>
<p>Federgreen has personally completed compliance, risk mitigation and liability engagements for companies ranging from the Fortune 100 to start-ups.  His experience includes the hospitality, grocery, e-Commerce and self-storage industries.</p>
<p>Author of over 100 articles appearing in professional and trade journals like Transaction Trends, The Bottom Line, Inside Self-Storage, Grocery Headquarters, Federgreen has authored critical white papers on transaction security compliance and currently serves on the Advisory Board to the “Green Sheet” and is section editor for payments for Inside Self-Storage Magazine.</p>
<p>Brady’s compliance expertise in data protection extends from MasterCard International and as Compliance Officer for EVO Merchant Services. He provides a regulatory perspective to CSRSI clients.</p>
<p>About CSRSI</p>
<p>Reducing risk and liability are core competencies for this consulting team of advocates knowledgeable in privacy legislation, compliance, detecting and protecting personally identifiable information.</p>
<p>In over 1750+ engagements since 1999, CSRSI provides guidance in electronic payments, PCI compliance and security of personal data to companies and institutions. For more information, visit csrsi.com.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pcitoolkit.com/2011/04/26/csrsi-team-to-moderate-and-participate-on-regulatory-update-and-interchange-panels-at-eta-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Dodd-Frank Act: What it might mean for issuers and acquirers</title>
		<link>http://www.pcitoolkit.com/2010/09/20/the-dodd-frank-act-what-it-might-mean-for-issuers-and-acquirers/</link>
		<comments>http://www.pcitoolkit.com/2010/09/20/the-dodd-frank-act-what-it-might-mean-for-issuers-and-acquirers/#comments</comments>
		<pubDate>Mon, 20 Sep 2010 04:47:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Press]]></category>
		<category><![CDATA[American Banker]]></category>
		<category><![CDATA[Dodd-Frank Act]]></category>
		<category><![CDATA[Durbin Agreement]]></category>
		<category><![CDATA[fraud fees]]></category>
		<category><![CDATA[interchange fees]]></category>
		<category><![CDATA[MasterCard]]></category>
		<category><![CDATA[PaymentSource.com]]></category>
		<category><![CDATA[Reasonable Fees for Rules and Payment]]></category>
		<category><![CDATA[Section 1075]]></category>
		<category><![CDATA[The Green Sheet]]></category>
		<category><![CDATA[Visa]]></category>

		<guid isPermaLink="false">http://www.pcitoolkit.com/?p=198</guid>
		<description><![CDATA[While the full effect of the recent passage of the Dodd-Frank Act is yet to be determined, it’s clear that substantial changes are in the offing. Look for changes in interchange rates, possible new fraud fees and new Fed regulations]]></description>
			<content:encoded><![CDATA[<p>This article as it appeared in The Green Sheet, Sept. 13, 2010</p>
<p>By Mark Brady and Ross Federgreen</p>
<p>The <a href="http://en.wikipedia.org/wiki/Dodd-Frank_Wall_Street_Reform_and_Consumer_Protection_Act" target="_blank"><strong>Dodd-Frank Wall Street Reform and Consumer Protection Act</strong></a>, signed by President Obama on July 21, 2010, is now the law of the land. Included in the act is the <a href="http://durbin.senate.gov/showRelease.cfm?releaseId=325810" target="_blank"><strong>Durbin Amendment</strong></a>, a provision in the final bill aimed at debit card interchange fees and other issues to increase competition in payment processing.</p>
<p><a href="http://www.mondaq.com/unitedstates/article.asp?article_id=108256" target="_blank"><strong>Section 1075 of the Act (&#8220;Reasonable Fees for Rules and Payment&#8221;)</strong></a> offers implications for acquirers and issuers. <a href="http://www.federalreserve.gov/" target="_blank"><strong>The Federal Reserve Board</strong></a> still has to write specific rules for implementing the new regulation; the devil will be in the details. The following discusses some of the major points of Section 1075 and provides our take at this point in time. Issuers must provide costs to justify debit interchange rates.</p>
<p>Section 1075 states that &#8220;the amount of any interchange transaction fee that an issuer may receive or charge with respect to an electronic debit transaction shall be reasonable and proportional to the cost incurred by the issuer.&#8221; This is the most far-reaching piece of Section 1075. Experts predict electronic debit may surpass cash in the next few years. According to the <a href="http://www.nrf.com/" target="_blank"><strong>National Retail Federation</strong></a>, merchants pay approximately $20 billion annually in fees for accepting debit cards. American Banker&#8217;s <a href="http://paymentsource.com/" target="_blank"><strong>PaymentSource.com</strong></a> estimates that if debit fees are cut by 50 percent, $4.15 billion in interchange fees for Visa Inc. issuers and $1.45 billion for MasterCard Worldwide issuers would be eliminated. As such, the stakes are significant.</p>
<p>Several years ago MasterCard and Visa justified interchange rates, at least in part, on a cost basis. They now promote their product based on value. For example, in January 2010, The New York Times reported that, according to Visa, merchants&#8217; cost for accepting debit hasn&#8217;t gone down because the cards provide greater value than they did previously and that merchant acceptance has doubled in the last 10 years, so the costs of accepting debit cannot be too onerous.</p>
<p>The article also quoted Elizabeth Buse, Visa&#8217;s Group Executive, International, who said the fees are &#8220;not a cost-based calculation but a value-based calculation&#8221; and William M. Sheedy, Visa&#8217;s President for the Americas, who said, &#8220;Debit has become so mainstream, some of the people who have benefited have lost sight of what their business model was, what their cost structure was.&#8221;</p>
<p>The Fed is requiring issuers to provide information biannually on costs &#8220;in connection with the authorization, clearance or settlement of electronic debit transactions.&#8221; It further stipulates that &#8220;costs incurred by an issuer which are not specific to a particular electronic debit transaction shall not be considered.&#8221;</p>
<p><strong>Fed can allow adjustments for issuer fraud costs</strong></p>
<p>Section 1075 states that the Fed may allow for &#8220;an adjustment to the fee amount received by an issuer if such adjustment is reasonably necessary to make allowance for costs incurred by the issuer in preventing fraud in relation to electronic debit transactions.&#8221;</p>
<p>Given that fraud rates for signature debit are much higher than for PIN debit, it will be interesting to see how issuers and the Fed deal with that aspect of the law. Will the Fed address the issuer promotion of signature debit versus PIN debit due to higher fraud rates for signature? Or will the Fed disallow a portion of signature debit fraud from issuer&#8217;s cost calculations?</p>
<p>Also, Section 1075 states &#8220;any fraud-related adjustment of the issuer &#8230; takes into account any fraud-related reimbursements (including amounts from chargebacks) received from consumers, merchants or payment card networks in relation to electronic debit transactions.&#8221; This appears to say fraud-related chargebacks issuers return to merchants (and are not successfully represented back to issuers) must be removed from the issuers&#8217; interchange cost workups. Many fraud related chargebacks are not returnable to issuers per MasterCard and Visa rules. Will the Fed require issuers to eliminate these chargebacks from their cost workups?</p>
<p>Finally, the law allows issuers to include data security costs in their fraud calculations. While issuers certainly incur costs for data security, it is the acquiring side of the business that is responsible for data security breaches. These acquiring costs include reimbursement to issuers for new card reissuance in the event of data security breaches. Will the Fed consider these acquiring data security costs in the issuer interchange cost calculations?</p>
<p>The cost data will provide the Fed significant information about this market &#8211; information issuers may not be happy to provide. In 2009 the <a href="http://www.gao.gov/" target="_blank"><strong>Government Accountability Office</strong></a> requested some of these costs and had a difficult time obtaining this information.</p>
<p>The Fed intends to prescribe the new regulations no later than nine months after the law was signed. This means the new interchange rates will probably be determined in the first quarter of 2011 or early second quarter.</p>
<p><strong>Regulation is limited to the largest U.S. banks</strong></p>
<p>Section 1075 states that the regulations will not apply to any issuer that, together with its affiliates, has assets of less than $10 billion. As such, most U.S. banks will be exempt from Dodd-Frank, even with their affiliates included. How will these banks react to their exemption? How will it affect their merchant business? Will they be helped or hurt?</p>
<p><strong>Government programs are exempt</strong></p>
<p>Governments appear to have exempted themselves from the interchange transaction fee regulation for &#8220;a debit card or general-use prepaid card that has been provided to a person pursuant to a federal, state or local government-administered payment program.&#8221; The U.S. government was obviously concerned about the debit card issuing impact on its own government card programs.</p>
<p><strong>Issuer network fee increases are restricted</strong></p>
<p>The regulators appear to be concerned that the card companies will substitute increased network fees for interchange rate decreases. As such, the Fed will &#8220;prescribe regulations to ensure that a network fee is not used to directly or indirectly compensate an issuer with respect to an electronic debit transaction, and a network fee is not used to circumvent or evade the restrictions of the regulation.&#8221;</p>
<p>Also, issuers may not restrict the number of payment card networks on which an electronic debit transaction may be processed. This may help MasterCard, which trails Visa significantly in debit card transaction volume. Concern also exists among issuers that the United States will further pressure MasterCard and Visa to lower network fees.</p>
<p><strong>Merchants can set minimum or maximum amounts for credit card transactions</strong></p>
<p>The law allows merchants to establish minimum and maximum dollar values for credit card transactions: &#8220;A payment card network shall not, directly or through any agent, processor, or licensed member of the network, by contract, requirement, condition, penalty, or otherwise, inhibit the ability &#8230; to set a minimum or maximum dollar value for the acceptance of credit cards.&#8221; Merchants may not differentiate between issuers or between payment card networks, and the minimum dollar value may not exceed $10.</p>
<p>Minimums at the POS are much more pervasive than maximums and are bound to confuse merchants, as the new rule does not apply to debit card transactions. Many transactions under $10 involve signature debit cards. Clerks at the POS are going to have a difficult time distinguishing between debit and credit cards; they will understandably think the $10 minimum applies to all cards. It&#8217;s bound to result in confusion at the cash register.</p>
<p>The regulation also allows maximum limits to be set by merchants, specifically citing &#8220;institutions of higher education.&#8221; Colleges and universities have been among the most likely entities to set maximums. Again, maximums may not differentiate between issuers or between payment card networks and apply to credit card transactions only.</p>
<p><strong>Merchants&#8217; ability to establish discounts is expanded</strong></p>
<p>The regulation stipulates that networks may not &#8220;inhibit the ability of any person to provide a discount or in-kind incentive for payment by the use of cash, checks, debit cards or credit cards to the extent that &#8211; the discount does not differentiate on the basis of the issuer or the payment card network.&#8221; The discount must be applied to the advertised price of the item or service. As such, a &#8220;card price&#8221; cannot be added to the regular price of an item in the form of a surcharge.</p>
<p>The card brands and issuers appear to have given up little here, except that merchants can now offer a discount for, say, PIN debit. As the MasterCard and Visa rules are now written, discounts for cash are allowed under these conditions. These cash discounts have been common in gas stations for several years.</p>
<p>It&#8217;s difficult to predict whether the new discount provisions will be utilized by a significant number of merchants, especially small merchants. Many big-box and wholesale or warehouse merchants do not offer discounts for entering a PIN at the POS, but they make sure a PIN pad is right in front of the customer at checkout.</p>
<p>MasterCard, Visa and card issuers may have successfully avoided repeating their Australian experience several years ago when courts in that country allowed merchants to surcharge transactions. Over the next several months, as the Fed issues drafts of the new regulations, there will be more to say about the Dodd-Frank Act and it&#8217;s implications for the major card brands, issuers and acquirers.</p>
<p>Stay tuned.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pcitoolkit.com/2010/09/20/the-dodd-frank-act-what-it-might-mean-for-issuers-and-acquirers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The PA-DSS Deadline Looms</title>
		<link>http://www.pcitoolkit.com/2010/06/30/the-pa-dss-deadline-looms/</link>
		<comments>http://www.pcitoolkit.com/2010/06/30/the-pa-dss-deadline-looms/#comments</comments>
		<pubDate>Wed, 30 Jun 2010 16:28:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[CSRSI]]></category>
		<category><![CDATA[PA-DSS]]></category>
		<category><![CDATA[Payment Application Data Security Standard deadline]]></category>
		<category><![CDATA[The Green Sheet]]></category>

		<guid isPermaLink="false">http://www.pcitoolkit.com/?p=195</guid>
		<description><![CDATA[Payments industry expert Ross Federgreen comments on the July 1 deadline for PA-DSS, when all payment applications need to be compliant. All payment processors need to ensure that their merchants are using compliant software. ]]></description>
			<content:encoded><![CDATA[<p>Payments industry expert Ross Federgreen in an interview by The Green Sheet comments on the July 1 deadline for PA-DSS, when all payment applications need to be compliant. All payment processors need to ensure that their merchants are using compliant software: <a href="http://j.mp/GS1000">http://j.mp/GS1000</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pcitoolkit.com/2010/06/30/the-pa-dss-deadline-looms/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Live Demo Right Column Text</title>
		<link>http://www.pcitoolkit.com/2010/06/22/live-demo-right-column-text-2/</link>
		<comments>http://www.pcitoolkit.com/2010/06/22/live-demo-right-column-text-2/#comments</comments>
		<pubDate>Tue, 22 Jun 2010 21:26:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[LiveDemo]]></category>

		<guid isPermaLink="false">http://www.pcitoolkit.com/?p=191</guid>
		<description><![CDATA[&#160;
&#160;
&#160;
&#160;
Thank you for your interest in the PCI ToolKit®, a service sold to banks, acquirers and payment processors (ISOs). Merchants should contact their processor or banking relationship for instructions. If you represent a bank, acquirer or payments processor, fill out the form to schedule your demo.
]]></description>
			<content:encoded><![CDATA[<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>Thank you for your interest in the PCI ToolKit®, a service sold to banks, acquirers and payment processors (ISOs). Merchants should contact their processor or banking relationship for instructions. If you represent a bank, acquirer or payments processor, fill out the form to schedule your demo.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pcitoolkit.com/2010/06/22/live-demo-right-column-text-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CSRSI Announces Enhancements to the PCI ToolKit® Web Application</title>
		<link>http://www.pcitoolkit.com/2010/04/30/csrsi-announces-enhancements-to-the-pci-toolkit%c2%ae-web-application/</link>
		<comments>http://www.pcitoolkit.com/2010/04/30/csrsi-announces-enhancements-to-the-pci-toolkit%c2%ae-web-application/#comments</comments>
		<pubDate>Fri, 30 Apr 2010 17:17:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Press]]></category>

		<guid isPermaLink="false">http://www.pcitoolkit.com/?p=174</guid>
		<description><![CDATA[CSRSI unveiled a more user-friendly interface for the PCI ToolKit® survey-based system for merchants to complete their required annual Self-Assessment Questionnaire and become PCI compliant as mandated by the PCI Standards Council.  ]]></description>
			<content:encoded><![CDATA[<p>IMMEDIATE RELEASE</p>
<p>Jensen Beach, FL-April 15, 2010- CSRSI, a leading electronics payments consulting firm, proudly announced several new enhancements to their PCI ToolKit® web application at a Client Appreciation Dinner for 60 clients attending the Electronic Transaction Association’s Annual Meeting and Expo in Las Vegas April 14th. The dinner, held at Smith &amp; Wollensky’s restaurant, highlighted a new look and feel and a more user-friendly interface for its survey-based system for merchants to complete their required annual Self-Assessment Questionnaire as mandated by the PCI Standards Council.</p>
<p><a title="PCIToolKit" href="http://www.pcitoolkit.com" target="_blank">The PCI ToolKit®</a> is a broadly used web-based, comprehensive system for merchants processing credit cards to become compliant with the Payment Card Industry’s Data Security Standard (PCI-DSS). Introduced in 2005, the ToolKit also provides an interface to CSRSI’s clients composed of member banks, payment processors and ISOs to administer oversight of merchants’ progress.</p>
<p>Ross Federgreen, one of CSRSI’s founders, in appreciation of the moment, summed up the milestone event: “We continue to listen to our clients’ feedback and incorporate their requests for advancements in our development stages. We’re thrilled to see how many of our long term client/friends were present to show their confidence in and support of the PCI ToolKit®, representing many well-known member banks, processors and ISOs.</p>
<p>About CSRSI</p>
<p>CSRSI provides electronic payment consultation and management. Our areas of focus include PCI, PII (personally identifiable information), risk, liability, compliance, systems selection and vendor selection. Our expertise includes merchant services, ACH, SWIFT, IBAN and all other electronic formats. For more information, visit www.csrsi.com.</p>
<p>For further information, contact: <a href="mailto:jcarroza@csrsi.com">jcarroza@csrsi.com</a>.</p>
<p>Twitter: @pcitoolkit</p>
<p>Twitter: @csrsi</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pcitoolkit.com/2010/04/30/csrsi-announces-enhancements-to-the-pci-toolkit%c2%ae-web-application/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Top Five Data Security Trends Impacting Franchise Operators</title>
		<link>http://www.pcitoolkit.com/2010/04/30/top-five-data-security-trends/</link>
		<comments>http://www.pcitoolkit.com/2010/04/30/top-five-data-security-trends/#comments</comments>
		<pubDate>Fri, 30 Apr 2010 17:02:02 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.pcitoolkit.com/?p=172</guid>
		<description><![CDATA[Cyber criminals continue to target retail and hospitality industries, intercepting cardholder data in transit. PCI DSS compliance should mitigate vulnerabilities that contribute to data breaches. ]]></description>
			<content:encoded><![CDATA[<p>Cyber criminals continue to target retail and hospitality industries, intercepting cardholder data in transit. PCI DSS compliance should mitigate vulnerabilities that contribute to data breaches. What weaknesses are hackers looking for?  What to do if compromised&#8230;  <a href="http://usa.visa.com/download/merchants/Top5DataSecurityTrends_FranchiseOperators_092909.pdf">More&#8230;</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pcitoolkit.com/2010/04/30/top-five-data-security-trends/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Aberdeen report shows firms using PCI-DSS can halve costs</title>
		<link>http://www.pcitoolkit.com/2009/12/31/aberdeen-report-shows-firms-using-pci-dss-can-halve-costs/</link>
		<comments>http://www.pcitoolkit.com/2009/12/31/aberdeen-report-shows-firms-using-pci-dss-can-halve-costs/#comments</comments>
		<pubDate>Thu, 31 Dec 2009 13:01:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Press]]></category>

		<guid isPermaLink="false">http://www.pcitoolkit.com/?p=162</guid>
		<description><![CDATA[Aberdeen report shows firms using PCI-DSS can halve costs]]></description>
			<content:encoded><![CDATA[<p>The Aberdeen group&#8217;s third annual study into Payment Card Industry Data Security Standard (PCI-DSS) issues claims to show that a growing number of companies are saving up to 55% on maintaining their compliance by adopting best practices.</p>
<p>The <a href="http://research.aberdeen.com/index.php/-information-technology/54-business- intelligence/1011-5892">report</a>  &#8211; which is offered free until the end of January &#8211; also says that companies adopting PCI-DSS compliance can save up to 45% on their costs by adopting a best practice strategy.</p>
<p>The study, which is billed as providing year-over-year insights into the progress that affected organizations have made in achieving and sustaining compliance with PCI-DSS <https://www.pcisecuritystandards.org/> , found that adopting a best-in-class approach can halve a company&#8217;s compliance costs.</p>
<p>On top of this, the report notes that best-in-class companies can divert the PCI-DSS compliance savings into other areas, such as sustainable programs and continuous improvement.</p>
<p>According to the research firm, best-in-class companies were found to have reduced their deficiencies related to PCI-DSS compliance by 7.5% on a year-over-year basis, when compared to `laggards.&#8217;</p>
<p>The conclusions of the security analysis show how companies can reduce the scope of their PCI-DSS compliance, as well as `map and adapt&#8217; to better security practices.</p>
<p>One of the most interesting conclusions of the report is the need for managers to assign clear ownership of the PCI-DSS issues and so achieve better PCI-DSS efficiencies.</p>
<p>Source: Infosecurity Magazine</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pcitoolkit.com/2009/12/31/aberdeen-report-shows-firms-using-pci-dss-can-halve-costs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI Breach Costs</title>
		<link>http://www.pcitoolkit.com/2009/10/29/pci-breach-costs/</link>
		<comments>http://www.pcitoolkit.com/2009/10/29/pci-breach-costs/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 16:26:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Costs of A Breach]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.pcitoolkit.com/?p=133</guid>
		<description><![CDATA[Total direct cost to a merchant from a PCI event]]></description>
			<content:encoded><![CDATA[<p>Total direct cost to a merchant from a PCI event include:</p>
<ul>
<li> Card replacement costs now averaging about $4 per item</li>
<li>Compliance fines now ranging from about $5,000 to $50,000<br />
per event for a small merchant (III, IV)</li>
<li>Cost of forensic examination averaging between $25,000 		and $35,000 per event for Level III and IV  merchants</li>
<li>Additional fines for actual fraudulent utilization of stolen PAN 		varies</li>
</ul>
<p><span style="text-decoration: underline;">Case Study:</span></p>
<ul>
<li><span style="font-family: Arial; color: black;">A small carp present retailer was breached. The retailer had filled out a self assessment form and attested that the information was true and correct to the acquirer. </span></li>
<li><span style="font-family: Arial; color: black;">The merchant was found to have stored over 2,000 credit card numbers in an accounting system for “reference” and to bill clients “if they forgot there credit card number”. </span></li>
<li><span style="font-family: Arial; color: black;">The file was accessed and the credit card numbers were stolen when during the course of a robbery the CPU was stolen. A CPP (common point of purchase) analysis of credit cards revealed the location of the theft.</span></li>
</ul>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;">Replacement Cost                 $ 5,000</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;"> Compliance Fine                   $ 12,500</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;"> Forensic Examination            $ 25,000</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;"> Card Utilization Fines </span><span style="text-decoration: underline;"><span style="font-family: Arial; color: black;">$ 74,398.47</span></span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;"> </span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;"> TOTAL $116,898.47</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;"> </span></p>
<ul>
<li><span style="font-family: Arial; color: black;">The merchant also sustained significant reputational cost due to adverse publicity, legal fees, loss of business and other expenses.</span></li>
<li><span style="font-family: Arial; color: black;">The merchant filed for protection under bankruptcy</span></li>
<li><span style="font-family: Arial; color: black;">The amounts due were assessed to the ISO by the acquirer.</span></li>
<li><span style="font-family: Arial; color: black;">Visa fined the ISO additional fees following an examination of ISO practices as it relates to PCI adoption and plan for portfolio under VBR 07508 after the initial event.</span></li>
<li><span style="font-family: Arial; color: black;">ISO sustained a financial loss of </span><span style="font-family: Arial; color: black; font-weight: bold;">$189,354.45</span></li>
</ul>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black; font-weight: bold;">Study: Maine Bureau of Financial Institutions January 2009</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="text-decoration: underline;"><span style="font-family: Arial; color: black;">Study design</span></span><span style="font-family: Arial; color: black;">: Cost of TJX and Hannaford breach borne by Maine chartered banks and credit unions</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;"><strong>TJX<br />
</strong></span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;">52 Institutions</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;">64,825 Accounts</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;">$485,000 Recovery*</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;"><strong>Hannaford</strong></span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;">71 Institutions</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;">243.599 Accounts</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;">$4,500,000 Recovery*</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;">*</span><span style="font-family: Arial; color: black; font-style: italic;">Recovery cost: investigation, communication, reissuance and net fraud</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black; font-style: italic;"><br />
</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="text-decoration: underline;"><span style="font-family: Arial; color: black;">Study Design</span></span><span style="font-family: Arial; color: black;">: Cost of compromise to 43 companies in 2008. Each company volunteered under the condition of anonymity.</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p><!-- tr 	{mso-height-source:auto;} col 	{mso-width-source:auto;} td 	{padding-top:1.0px; 	padding-right:1.0px; 	padding-left:1.0px; 	mso-ignore:padding; 	color:windowtext; 	font-size:18.0pt; 	font-weight:400; 	font-style:normal; 	text-decoration:none; 	font-family:Arial; 	mso-generic-font-family:auto; 	mso-font-charset:0; 	text-align:general; 	vertical-align:bottom; 	border:none; 	mso-background-source:auto; 	mso-pattern:auto;} .oa1 	{border-top:.75pt solid black; 	border-right:none; 	border-bottom:.75pt solid black; 	border-left:.75pt solid black; 	background:black; 	mso-pattern:auto none; 	text-align:center; 	vertical-align:top; 	padding-bottom:3.6pt; 	padding-left:7.2pt; 	padding-top:3.6pt; 	padding-right:7.2pt;} .oa2 	{border-top:.75pt solid black; 	border-right:none; 	border-bottom:.75pt solid black; 	border-left:none; 	background:black; 	mso-pattern:auto none; 	text-align:center; 	vertical-align:top; 	padding-bottom:3.6pt; 	padding-left:7.2pt; 	padding-top:3.6pt; 	padding-right:7.2pt;} .oa3 	{border-top:.75pt solid black; 	border-right:.75pt solid black; 	border-bottom:.75pt solid black; 	border-left:none; 	background:black; 	mso-pattern:auto none; 	text-align:center; 	vertical-align:top; 	padding-bottom:3.6pt; 	padding-left:7.2pt; 	padding-top:3.6pt; 	padding-right:7.2pt;} .oa4 	{border-top:.75pt solid black; 	border-right:none; 	border-bottom:.75pt solid black; 	border-left:.75pt solid black; 	text-align:center; 	vertical-align:top; 	padding-bottom:3.6pt; 	padding-left:7.2pt; 	padding-top:3.6pt; 	padding-right:7.2pt;} .oa5 	{border-top:.75pt solid black; 	border-right:none; 	border-bottom:.75pt solid black; 	border-left:none; 	text-align:center; 	vertical-align:top; 	padding-bottom:3.6pt; 	padding-left:7.2pt; 	padding-top:3.6pt; 	padding-right:7.2pt;} .oa6 	{border-top:.75pt solid black; 	border-right:.75pt solid black; 	border-bottom:.75pt solid black; 	border-left:none; 	text-align:center; 	vertical-align:top; 	padding-bottom:3.6pt; 	padding-left:7.2pt; 	padding-top:3.6pt; 	padding-right:7.2pt;} --></p>
<table style="border-collapse: collapse; height: 149px;" border="0" cellspacing="0" cellpadding="0" width="853">
<col style="width: 120pt;" span="4" width="160"></col>
<tbody>
<tr>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="color: #000000;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; text-transform: none; font-weight: bold; font-style: normal; vertical-align: baseline;">YEAR</span></span></p>
</td>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="color: #000000;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; text-transform: none; font-weight: bold; font-style: normal; vertical-align: baseline;">Cost per Breach</span></span></p>
</td>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="color: #000000;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; text-transform: none; font-weight: bold; font-style: normal; vertical-align: baseline;">Cost per record</span></span></p>
</td>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="color: #000000;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; text-transform: none; font-weight: bold; font-style: normal; vertical-align: baseline;">External Third Party</span></span></p>
</td>
</tr>
<tr>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; color: black; text-transform: none; font-weight: normal; font-style: normal; vertical-align: baseline;">2008</span></p>
</td>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; color: black; text-transform: none; font-weight: normal; font-style: normal; vertical-align: baseline;">$6.6 million</span></p>
</td>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; color: black; text-transform: none; font-weight: normal; font-style: normal; vertical-align: baseline;">$202</span></p>
</td>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; color: black; text-transform: none; font-weight: normal; font-style: normal; vertical-align: baseline;">44%</span></p>
</td>
</tr>
<tr>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; color: black; text-transform: none; font-weight: normal; font-style: normal; vertical-align: baseline;">2007</span></p>
</td>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; direction: ltr; unicode-bidi: embed; vertical-align: baseline; text-align: center;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; color: black; text-transform: none; font-weight: normal; font-style: normal; vertical-align: baseline;">$6.3 million</span></p>
</td>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; color: black; text-transform: none; font-weight: normal; font-style: normal; vertical-align: baseline;">$193</span></p>
</td>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; color: black; text-transform: none; font-weight: normal; font-style: normal; vertical-align: baseline;">40%</span></p>
</td>
</tr>
<tr>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; color: black; text-transform: none; font-weight: normal; font-style: normal; vertical-align: baseline;">2006</span></p>
</td>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; color: black; text-transform: none; font-weight: normal; font-style: normal; vertical-align: baseline;">$4.7 million</span></p>
</td>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; color: black; text-transform: none; font-weight: normal; font-style: normal; vertical-align: baseline;">$186</span></p>
</td>
<td style="width: 120pt;" width="160">
<p style="margin: 0pt 0in; line-height: normal; text-indent: 0in; direction: ltr; unicode-bidi: embed; vertical-align: baseline; text-align: center;"><span style="font-size: 18pt; font-family: Arial; font-variant: normal; color: black; text-transform: none; font-weight: normal; font-style: normal; vertical-align: baseline;">29%</span></p>
</td>
</tr>
</tbody>
</table>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;"><br />
</span></p>
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;">
<p style="margin-top: 0pt; margin-bottom: 0pt; text-align: left; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"><span style="font-family: Arial; color: black;"><br />
</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pcitoolkit.com/2009/10/29/pci-breach-costs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Visa Announces New Payment Application Security Mandates</title>
		<link>http://www.pcitoolkit.com/2009/10/29/visa-announces-new-payment-application-security-mandates/</link>
		<comments>http://www.pcitoolkit.com/2009/10/29/visa-announces-new-payment-application-security-mandates/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 15:55:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Alerts]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.pcitoolkit.com/?p=106</guid>
		<description><![CDATA[Beginning January 1, 2008, Visa will implement a series of mandates to eliminate the use of
non-secure payment applications from the Visa payment system. These mandates require
acquirers to ensure their merchants and agents do not use payment applications known to
retain prohibited data elements and require the use of payment applications that adhere to
Visa’s Payment Application Best Practices (PABP).]]></description>
			<content:encoded><![CDATA[<p>CISP BULLETIN<br />
Visa Announces New Payment Application Security Mandates<br />
October 23, 2007<br />
</br><br />
Beginning January 1, 2008, Visa will implement a series of mandates to eliminate the use of  non-secure payment applications from the Visa payment system. These mandates require  acquirers to ensure their merchants and agents do not use payment applications known to  retain prohibited data elements and require the use of payment applications that adhere to  Visa’s Payment Application Best Practices (PABP). PABP-compliant applications help  merchants and agents mitigate compromises, prevent storage of prohibited data and support  overall compliance with the Payment Card Industry Data Security Standard (PCI DSS) and the  Visa U.S.A. Inc. Operating Regulations. A list of PABP-validated applications is available at  www.visa.com/pabp.<br />
</br><br />
Vulnerable payment applications have proved to be the leading cause of compromise incidents,  particularly among small merchants. Visa U.S.A. Inc. Operating Regulations prohibit the  storage of the full content of any magnetic-stripe, CVV2 or PIN data and require compliance  with the PCI DSS. Merchants and agents that use payment applications that store prohibited  data or have inherent security weaknesses will not be compliant with the PCI DSS and are at  high risk of being compromised.<br />
</br><br />
In light of the criticality of promoting payment application security and merchant dependence on  secure payment applications to achieve compliance, Visa will implement a series of mandates,  beginning January 1, 2008, to eliminate the use of vulnerable payment applications from the  Visa payment system. These mandates support compliance with the Visa U.S.A. Inc. Operating<br />
</br><br />
Regulations, which prohibit the storage of magnetic-stripe, CVV2 and PIN data. Further, the  Operating Regulations require that acquirers comply — and ensure that their merchants and agents comply — with the requirements of the Cardholder Information Security Program (CISP).  These mandates are intended to prevent cardholder data compromises and thereby help mitigate the risk of associated financial losses such as liability from the Account Data  Compromise Recovery (ADCR) program. Additionally, Visa’s payment application security  mandates reinforce acquirer compliance efforts and create a level playing field by preventing  merchants from migrating from one acquirer to another in attempt to avoid security requirements.<br />
</br><br />
Outlined below are each of the five mandates, which will take effect over the next three years.<br />
</br><br />
Phase 1 &#8211; Effective Date &#8211; 1/1/08<br />
Newly boarded merchants must not use known vulnerable payment applications, and VisaNet Processors (VNPs) and agents must not certify new payment applications<br />
</br><br />
Phase 2 &#8211; Effective Date &#8211; 7/1/08<br />
VNPs and agents must only certify new payment applications to their platforms that are PABP-compliant<br />
</br><br />
Phase 3 &#8211; Effective Date &#8211; 10/1/08<br />
Newly boarded Level 3 and 4 merchants must be PCI DSS compliant or use PABP-compliant applications<br />
</br><br />
Phase 4  &#8211; Effective Date &#8211; 10/1/09<br />
VNPs and agents must decertify all vulnerable payment applications<br />
</br><br />
Phase 5  &#8211; Effective Date &#8211; 7/1/10<br />
Acquirers must ensure their merchants, VNPs and agents use only PABP-compliant applications<br />
</br><br />
</br></p>
<h3><span style="color: #0000ff;">Phase I – January 1, 2008</span></h3>
<p></br><br />
Acquirers must not board new merchants that use known vulnerable payment applications. Furthermore, VNPs and agents must not certify new applications to their platforms that are known vulnerable payment applications. A list of vulnerable payment applications is updated quarterly and is available on Visa Online at <a href="www.us.visaonline.com/us_riskmgmt/cisp" target="_blank"><span style="color: #0000ff;">www.us.visaonline.com/us_riskmgmt/cisp</span></a>.<br />
</br><br />
Phase I will deter vendors from introducing new vulnerable payment applications into the payment system, and will reinforce acquirer compliance efforts by preventing merchants from migrating from one acquirer to another in an attempt to avoid upgrading a vulnerable payment application.<br />
</br><br />
</br></p>
<h3><span style="color: #0000ff;">Phase II – July 1, 2008</span></h3>
<p></br><br />
VNPs and agents must only certify new payment applications to their platforms that are PABPcompliant. A list of payment applications that have been validated against Visa’s PABP is available at www.visa.com/pabp.<br />
</br><br />
Phase II promotes the use of payment applications that adhere to PABP and support merchant PCI DSS compliance. This phase will also further prevent vendors from introducing new vulnerable payment applications into the payment system.<br />
</br><br />
</br></p>
<h3><span style="color: #0000ff;">Phase III – October 1, 2008</span></h3>
<p></br><br />
Acquirers must only board new Level 3 and Level 4 merchants that are PCI DSS compliant or utilize  PABP-compliant applications. PABP does not apply to applications developed for inhouse use only or to  hardware terminals.<br />
</br><br />
Phase III mitigates acquirer risk associated with boarding new merchants that are not PCI DSS compliant or that rely on payment applications that are not PABP-compliant. Further, Phase III reinforces acquirer compliance efforts by preventing merchants from migrating from one acquirer to another in an attempt to avoid compliance requirements.<br />
</br><br />
</br></p>
<h3><span style="color: #0000ff;">Phase IV – October 1, 2009</span></h3>
<p></br><br />
VNPs and agents must decertify all known vulnerable payment applications, including those published on Visa’s quarterly list of vulnerable payment applications. As future vulnerable payment applications are identified, VNPs and agents must decertify these applications within 12 months.<br />
Phase IV is intended to eliminate the continued use of vulnerable payment applications by acquirers, merchants and agents within the payment system.<br />
</br><br />
</br></p>
<h3><span style="color: #0000ff;">Phase V – July 1, 2010</span></h3>
<p></br><br />
Acquirers must ensure their merchants and agents use only PABP-compliant applications. A list of payment applications that have been validated against Visa’s PABP is available at www.visa.com/pabp.<br />
</br><br />
Phase V mandates the use of payment applications that support PCI DSS compliance, requiring acquirers, merchants and agents to use only those payment applications that can be validated as  PABP-compliant. It is important to note that the deadline for Phase V is aligned with the Triple Data Encryption Standard (TDES) usage mandate for all point-of-sale (POS) PIN-entry devices (PEDs) to be using TDES to protect PINs. Additionally, all attended POS PEDs must be evaluated by a Visa-recognized laboratory and approved by Visa prior to this same date.<br />
</br><br />
</br></p>
<h3><span style="color: #0000ff;">Vulnerable Payment Applications</span></h3>
<p></br><br />
As a result of an increasing number of merchant compromises, Visa has identified that certain payment applications are designed to store prohibited data, including full magnetic-stripe, CVV2 or PIN data, subsequent to transaction authorization. Storage of these data elements is in violation of the PCI DSS and Visa U.S.A. Inc. Operating Regulations. Hackers are targeting merchants and agents using vulnerable payment applications and exploiting vulnerabilities to find this data. It is critical for acquirers to ensure that their merchants and agents do not use payment applications known to retain prohibited data elements and to take corrective actions to address any identified deficiencies. Acquirers, merchants and agents should ask all of their payment application vendors, resellers or system integrators to confirm that software versions used do not store magnetic-stripe, CVV2 or PIN data.<br />
</br><br />
Recently, Visa alerted acquirers of an updated list of vulnerable payment applications that retain prohibited data. Visa will continue to proactively alert acquirers as vulnerable payment applications are identified. The vulnerable payment application list is available on Visa Online at <a href="www.us.visaonline.com/us_riskmgmt/cisp" target="_blank">www.us.visaonline.com/us_riskmgmt/cisp</a>.<br />
</br><br />
</br></p>
<h3><span style="color: #0000ff;">Summary</span></h3>
<p></br><br />
<strong> </strong> To enforce the payment application security mandates, Visa will continue to identify payment applications used by Level 1 and 2 merchants through the PCI Compliance Acceleration Program, monitor acquirers’ Level 4 merchant compliance plans and determine payment applications certified by VNPs. Visa may also consider a compromised entity’s use of vulnerable payment applications or PABP-validated applications in fine and ADCR determinations.<br />
</br><br />
Visa will continue to work with all key stakeholders — acquirers, processors, merchants, agents and payment application vendors — to raise security awareness and promote the use of payment  applications validated against the PABP. In many cases, acquirers, processors and agents have indicated that they already have more aggressive plans in place to support these mandates. It is critical for acquirers and processors to begin integrating these mandates into their processes. Acquirers should also revisit their Level 4 merchant compliance plans and adjust accordingly to support these  candates. In an effort to mitigate the risk of compromise, acquirers must take prompt action to ensure that merchants and agents discontinue use of vulnerable payment applications and begin moving merchants and agents toward using only PABP-compliant applications.<br />
</br><br />
For more information on Visa’s PABP, please visit <a href="http://www.visa.com/pabp" target="_blank">http://www.visa.com/pabp</a>. Questions about this bulletin may be directed to CISP@visa.com. For the complete VBR, Visa acquirers may refer to the Visa Business Review article, “Visa Announces New Payment Application Security Mandates,” October 2007; Issue 07100902.<br />
</br><br />
© 2007 Visa Inc., all rights reserved.<br />
</br><br />
CISP BULLETIN – 102307</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pcitoolkit.com/2009/10/29/visa-announces-new-payment-application-security-mandates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

