PCI/DSS

Course
Time
1 hour 15 minutes
Difficulty
Beginner
CEU/CPE
1

Video Description

In this video series, Kelly Handerhan takes us on a fascinating tour of the Payment Card Industry Data Security Standard. But don't let the title throw you off, this area of IT security affects everyone that's been issued a credit card! The number of data breaches of credit data is quickly becoming legendary. Do Target and Neiman-Marcus ring any bells? They should. The good news for aspiring IT security professionals is industry demand for PCI DSS subject matter experts will only continue to grow. The topics covered in this series revolve around the essential elements of PCI DSS. These are basically the why, what, how, and who and consist of 12 essential requirements. This is a global data security standard and is not limited to just the US. The credit card payments industry is a self-regulated industry, which means the responsibility for monitoring and enforcement falls on its members. These members are the merchants and vendors who process credit card transactions and maintain cardholder data. Along with maintaining such obviously critical data comes a great deal of responsibility and the penalty is the loss of the ability to process credit card payments.

Video Transcription

00:04
Hi. My name is Kelly Hander Han and I will be your subject matter expert on R P C i. D s s class. And that stands for payment card industries, data security standard and what we're gonna be covering today. We're gonna be really focusing in on the most essential elements of P C i. D. S s
00:23
We're gonna look at the y.
00:25
Who, what? Where, When? Why Those sorts of things will start by talking about why p. C i. D. S s is so important. Then we'll talk about who must adhere to the standards set forth in PC. Idea says we'll talk about what those specific standards are and with the requirements basically talking about those 12
00:44
elements that P. C. I. D. S s specifies
00:47
and that will lead into how PC idea says protects our payment card information. I will also just give a quick little word on social engineering because that is one of the more common ways that this information gets disclosed through one form of another
01:04
or another. And of course, we'll do a little wrap up at the end.
01:07
All right, So, talking about why we need payment card industries data security standards. Well, we have to understand that currently certain elements of the payment card industry essentially your self regulated, and it's certainly in their best interest to maintain that self regulation.
01:26
So what they need to do to make sure that they're able to maintain that
01:30
that self regulation is to adhere to certain standards and to make sure that there aren't breaches of large size. Because once those breaches start happening at the lawsuits come once the lawsuits come,
01:45
they're start to be legislative drivers. That will mandate how this information is protected.
01:51
So the PC I counsel essentially got together and came up with some security standards that would be available to vendors and merchants and provide them a framework in some guidance on how to protect that information.
02:07
So that's one of the big reasons why. But the other reasons I don't even have to tell you. Ah, we have seen loss after loss after loss. We'll talk about some of the more common in some of the more recent losses, but it has been estimated somewhere near $14 billion has been lost
02:24
through credit card theft and fraud.
02:28
That's a lot of money and is, we know those companies don't just absorb those costs. They pass it along to the consumers through higher interest rates, higher annual fees and so on. So we, as consumers need to be concerned about that. We also need to be concerned about this. Information being disclosed could lead
02:47
to our identity. Theft could lead to
02:51
bogus charges on our account.
02:53
Lots of issues, um, lost customer confidence from a business standpoint. So we as individuals, care about compromise to payment card information. But we, his businesses have to care a swell. We want our customers to be confident that we understand the significance of the information with which they've entrusted us,
03:13
and also that we inspire confidence that our customers will come back and continue to shop with us.
03:19
When we lose customer confidence that usually turns into lost sales, and that doesn't have the cost of re issuing new payment cards. I know that sounds like small potatoes and in comparison to 4 $14 billion it may be, but when you look at how many times and I think we pause here
03:38
and I'd ask each of you to think about have you ever had an instance where one of your payment cards was compromised.
03:45
I think many people would answer yes to that. So that caused the hassle of re issuing those cards can be quite costly over time.
03:53
Now, also, his vendors or merchants. If we don't adhere to the P C. I. D. S s, we may find that our credentials in order to accept payment cards are revoked and that we're no longer able to do so very difficult to exist in today's economy without accepting payment card. So
04:11
we want to make sure his individual companies that were able to do so
04:15
All right, so who does the data security standard apply? So what is it in a nutshell? You can see that this is for merchants and payment card processors Doesn't matter the size of the business. If you're a merchant that accepts payment card payments,
04:32
uh, you are susceptible to the PC. Idea says
04:36
specifically, there are 12 requirements that businesses must adhere to, and anyone that stores processes or transmits this cardholder information must follow these requirements.
04:50
And this really is a global data security standards. So this isn't something us based.
04:58
This is world wide
05:00
And
05:01
one of the things that I found is a lot of the security practices or common sense, at least the concept behind him. Sometimes implementing them could be a little bit more difficult. But I think when we go through those 12 elements you'll find, yeah, most of these make sense. So the next piece we have to talk about is,
05:20
where is Dad of vulnerable? What? Her Attackers,
05:24
um, looking to compromise. You know, the old joke. Why did you rob the bank?
05:30
Because that's where the money is. So why do Attackers target payment card systems? Because that's where the money is. If I can retrieve your payment card information, think about all the many sources we have today for me to make purchases where that
05:46
physical card does not have to be present. You know, just look att, e commerce and online purchasing and processing
05:53
of payment information. So if I can steal those credit card numbers, it doesn't matter that I don't physically have the card in my hand. So, uh, first of all at the payment card centers, you know your credit card data processing centers, call centers. That information may be present
06:13
in the databases that hold payment card information
06:17
compromise card readers, especially when we have the cards that simply have the magnetic stripe that a magnetic stripe can be siphoned. All can be assigned to a new magnetic strip without the user even knowing. And sometimes we refer
06:34
to these elements that would do so as shims.
06:38
And I've seen this in the I live in the Washington D. C area, and we've had instances of several A T M systems being compromised. They've added a either a hardware or software element again called a shim, that records the transactions going on between the user and the actual A t. M itself.
06:58
So if that information is intercepted,
07:00
it could be applied to a new card
07:03
point of sale systems. We've seen a couple of big compromises in the last few years where the point of sale systems, as in you're at the shop, swipe your card. Those particular systems are compromised themselves. We'll talk a little bit about a technique called Ram scraping
07:21
and anything that resides in memory.
07:26
They're remnants left over. Even when that process is not currently, it's not current or is not being transmitted or at rest. So Ram scrapings gonna take advantage of that
07:39
paper records. Always a vulnerability. You know you have that written copy of information, whether it's handwritten notes, whether it's paper based files, making sure that those files that papers properly stored and, equally important, making sure that once that material is no longer of use,
07:58
that it's destroyed in a
08:00
proper fashion.
08:01
Other ways that data could be compromised. Hidden cameras recording entry of authentication information, you know, think about when you use your A T M or your credit card and you have to punch in a pen or a personal I D number at a store.
08:18
Uh, it doesn't have to be a security camera or hidden camera.
08:22
It could be as basic as somebody looking over your shoulder, but often were typing in these authentication codes unprotected again. If I could get your number or your card. Having that authentication code is just one more step that makes it very likely I can access your information
08:41
secret Tap into your stores, wireless or wired network. So basically the information gets transmitted. Very frequent means of communication used wireless and even wired networks are susceptible,
08:56
and I'll tell you. I think you would be surprised at how very vulnerable
09:01
your information may be for organizations that use wireless communication or again, even wired communications. I was at a shopping mall, and it's probably been six months ago or so, and I was getting some pictures taken of my kids,
09:16
and I asked her to the restroom and went to the rest of the restroom, and their wireless router
09:22
that was connected to their wired network was sitting on top of their toilet in a public restroom.
09:30
Now think about that for just a minute. How very simple it would be for me to have a man in the middle attack insert a device that all the communication goes through that device before being passed along. How very easy it would be for me to substitute a device to tap into that network,
09:48
you know, have was just absolutely stunned because you think about the credit card information
09:52
that you know when you purchased the pictures, you give him the credit card. That information gets transmitted and it's transmitted across that exceedingly vulnerable set of hardware. So, you know we don't take for granted that companies protect our information
10:09
As a matter of fact, what we tend to find is companies protect our information a lot better.
10:13
Once they've had a breach. Because management either gets it or they don't, they either have buy in. They either understand the risks associated with their data or they don't. And when companies have management that doesn't understand and doesn't support the security function,
10:31
it's not gonna happen.
10:31
And when will they support that function after their found liable for millions of credit card numbers? Perhaps being compromised
10:41
is usually when it happens. I mentioned shims with a T. M's residual information stored in RAM, and this was one of the things that happened to Target. We'll talk about that compromise with Target in a few minutes ago,
10:54
but it was a ram scraping attack, so essentially software had gotten installed on their point of sale systems
11:01
and was able to retrieve information that was swiped through the point of sale readers. Other places that data is vulnerable just everywhere. That's all just everywhere. If information about a payment card is stored, its vulnerable, there are no absolute security mechanisms.
11:20
The best that we can hope to do is to do what's right
11:22
to do an industry standard suggest toe, Look at what our competitors are doing to continue to monitor for risks as they occur and as new risks pop up. You know, constant vigilance is the key to protecting our patient card information. So what, We're going to our payment card information.
11:41
So what, we're gonna do what we're going to focus in?
11:45
We're gonna focus in on the framework that P. C. I. D. S s supplies for us now. The reason I call it a framework first of all because it is a frame or but when a framework means is the PC idea says, is not a list of do's and don'ts and specific methodologies,
12:05
essentially what it is and any does address. Do this and don't do certain things. But essentially what it is
12:11
is guidance to provide me with a general instruction set. It doesn't detail specific technologies. It doesn't provide me with the 25 access control list rules that I should have on my firewall.
12:28
But it is a set of general instructions
12:31
and mechanisms that need to be employed to protect payment card information anywhere that it's collected. Process is stored or processed, stored or transmitted. So we'll see that across the upcoming slides

Up Next

PCI/DSS

This series covers the framework governing the self-regulated payment processing industry. Compliance with these standards is critical. Learn the 12 elements of the framework and how they pertain to risk management in relation to cardholder data.

Instructed By

Instructor Profile Image
Kelly Handerhan
Senior Instructor