New security standard for CHAPS who have your CREDIT CARD data
From: The Register
Did you know small merchants can self-assess? Read on for more shockers
By John Leyden
A new version of the PCI-DSS payment card industry standard was published yesterday, and is due to come into effect at the start of January.
The new rules place a greater emphasis on promoting improved security rather than complying with pre-set rules.
PCI DSS 3.0 is designed to “help organisations take a proactive approach to protect cardholder data that focuses on security, not compliance”, according to the PCI Security Standards Council*.
The key aim of PCI DSS 3.0 is to change merchants’ “mentality”, so that good compliance disciplines are adopted operationally as part of their normal business practices rather than treated as a hurdle to get over every year – like taking a car for an annual MOT (government traffic inspection) test.
Many infosec pros have historically criticised PCI as simply offering a minimal security baseline, containing such advice as “use an antivirus” and “protect cardholder data”, rather than adopting a more risk- or business-focused approach.
A common finding to emerge from analysis of data breaches among merchants is that although they are often compliant at the time of their annual PCI DSS assessment, they are no longer compliant at the time of the data breach.
According to SureCloud, a UK-based provider of cloud-based IT governance services, many e-commerce merchants choose a “cram for the exam” approach that focuses only on being ready for the day of the assessment.
“Often, PCI DSS compliance is treated a bit like the annual MOT on your car,” explained Richard Hibbert, chief exec of SureCloud. “You only fix the issues needed to pass the test instead of taking good care of your car all year round.”
PCI DSS specifies the “security rules” under which merchants and banks are supposed to process credit card transactions. Merchants are obliged to adopt the standard if they don’t want to face higher card processing fees in general and tougher fines in the case of problems. Continual non-compliance by merchants can result in payment processors pulling the plug on e-commerce outfits, leaving businesses without the ability to take e-commerce payments. The standard was placed on a three-year refresh cycle back in 2011.
Small merchants can self-assess
Compliance for small merchants can be achieved through self-assessment but larger outfits are obliged to hire independent Qualified Security Assessor to run independent audits, a potentially costly exercise.
Transforming PCI DSS from an assessment-centric activity to a security programme would represent a major sea change. In addition, the latest version of the guidelines aim to a greeter emphasis on the importance of staff security training
Tightening up poor password security practices is among the key objectives of the revised standard. The PCI DSS update clarifies the importance of changing default passwords for application/service accounts, as well as user accounts, to address gaps in basic password security practices that are leading to compromises.
Matt Middleton-Leal, regional director for UK & Ireland at security tools firm CyberArk, commented: “It’s extremely encouraging that the latest revision of PCI DSS is moving away from focusing solely on compliance, and moving towards best-practice security.
“As we continue to see privileged account credentials and passwords as primary targets in almost all major breaches, it’s great that this latest version of the standard is taking steps towards addressing this crucial part of the problem.”
Biz bods will have to change password policy… Are you also praying your local grocer doesn’t use 123456?
“The proposed changes state that revised password policies should include guidance on ‘choosing strong passwords, protecting their credentials, changing passwords on suspicion of compromise’. While this is certainly a step in the right direction, I would argue that we need to go further in order to adequately protect these extremely powerful credentials.
| Print article |