Home > Ask the Security Experts > Security Management Questions & Answers > What should be the fraud and risk assessment policy for organizations that deal with consumer banking card sales?
Ask The Security Expert: Questions & Answers
EMAIL THIS

What should be the fraud and risk assessment policy for organizations that deal with consumer banking card sales?

Mike Rothman EXPERT RESPONSE FROM: Mike Rothman

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 19 August 2007
What should be the fraud and risk assessment policy at consumer banking cards' sales end?

>
EXPERT RESPONSE
Fraud mitigation and risk assessment are different things. I am interpreting this question to ask about policies that retailers and other merchants should be implementing relative to consumer banking cards. Many of the requirements for protecting cardholder information are specified in the Payment Card Industry Data Security Standard, commonly known as PCI DSS.

PCI DSS specifies 12 different requirements to secure cardholder data and requires a qualified assessor to examine a merchant's environment to ensure compliance. Penalties for non-compliance range from small fines to the inability to use a specific type of credit or debit card.

Specific to risk assessment, the PCI DSS standard requires that "security controls, limitations, network connections and restrictions" are tested at least annually. It also mandates quarterly use of a wireless analyzer to see if your Wi-Fi networks are vulnerable. Additionally, the regulation requires quarterly vulnerability scans to ensure that no known vulnerabilities put cardholder data at risk.

I strongly recommend that organizations also conduct a more formal penetration test, ideally performed by outside resources, at least once a year, and also use automated pen testing tools internally more often. Why? Because the bad guys are testing your network and applications every day. They are performing risk assessments all the time, trying to figure out how to compromise your systems, so you should use their same tools and techniques to find and remediate problems.

For more information:

  • In this tip, contributor Khalid Kark defines the framework that makes organizational risk management work in your enterprise.
  • In this expert response, Joel Dubin discusses whether or not tokenization can meet PCI DSS standards for storing credit card data.


  • Sound Off! -   Be the first to post a message to Sound Off!


    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Security Management
    Is it against HIPAA regulations to permanently store sensitive information?
    Two-tier distributed systems vs. three-tier distributed systems
    How to prevent software piracy
    How do ISO 17799 and SAS 70 differ?
    Has FFIEC made any VoIP-specific mandates?
    What is the best way to administer exams to students via computer?
    Should computer exams be transmitted as PDF files or Word files?
    Is it against HIPAA regulations to display client names?
    Getting started on a career in penetration testing
    Are there security management products that can track compliance objectives?

    Risk Assessment and Analysis
    Security data lapses hamper researchers
    Panel: IT governance, risk and compliance program helps reduce expenses
    Like MLB scouts, IT security pros are turning to metrics
    Google shares struggle to manage security complexities
    GRC Tools Help Manage Regulations
    Interview: Financial Services CISO David Pollino
    The New School of Information Security
    Penetration testing: Helping your compliance efforts
    Failure mode and effects analysis: Process and system risk assessment
    The pros and cons of data breach insurance

    PCI Data Security Standard
    PCI Requirement 6.6 has merchants gearing up
    PCI compliance extends to car washes, quick lubes
    PCI council to launch assessor quality assurance program
    The 'security standards dilemma': Network segmentation and PCI Compliance
    NSS Labs to focus research on PCI technologies
    PCI Confusion
    Trio indicted in restaurant data security breach
    PCI portal aims compliance guidance at smaller merchants
    PCI compliance and Web applications: Code review or firewalls?
    How to test the security of personal details submitted to a website

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    risk analysis  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts