advertisement
advertisement

This is page 2 of:

PA-DSS Reduces Your Scope Less Than You Think

February 24th, 2011

Not one of these is a valid reason to store cardholder data today. Communications are reliable and timeouts are infrequent. When you have a problem, re-swipe the card. If your acquirer loses your transactions and can’t reconstruct them from its own records, get a new acquirer. And if you think you are required to keep the data to process exception items, see Visa’s recent guidance, which makes the point that storing cardholder data is the acquirer’s job, not the merchant’s.

Today, the only way to tell if a payment application stores cardholder data is to ask the vendor. I personally wish the PCI Council would add a column to the PA-DSS listings to indicate which of the following three conditions exist: “Yes,” the app stores cardholder data; “no,” it does not; or “configurable,” meaning the merchant has the option. My suggestion does not require any change to the PA-DSS or the validation process, and it would not cost anything. Unfortunately, this change is not likely to happen anytime soon.

I raised the issue recently with a senior executive of the PCI Council. The response was that reporting this information was not a role that made sense for the Council. Instead, it should be “left to the market,” meaning it should be the merchants’ responsibility. I respect the Council’s position; it is a standards body, after all. But I wish its mission could also include making scope reduction a little bit easier for merchants.

Therefore, because “the market” will have to be responsible, I would like to encourage all those vendors whose application does not store cardholder data to shout that fact on their Web sites and in their sell sheets. Believe me, your customers and potential customers want to know this fact. You provide a merchant benefit that goes beyond PA-DSS validation. Merchants who want to minimize their PCI scope or qualify for a simplified SAQ can make a clear choice.

In the same way, software vendors who re-write their applications so they no longer store cardholder data should highlight the benefits of simplified compliance to their merchants.

Although the functionality of the payment application will be critical, whether that application also stores cardholder data should be part of your cost equation along with price and maintenance.

I want to make it clear that merchants may store electronic cardholder data. My professional opinion is that it does not make sense in most cases (“We always did it this way” is neither a justification nor a compensating control). But if a merchant wants to keep the data, it is permitted. Just understand the result is that you will have a new hobby: PCI DSS.

Did you ever get half the story? Have you ever had what a friend in Texas calls “one of them sales critters” rattle on about how they are compliant, while carefully ignoring the fact that their application increases your PCI scope?

What do you think? I’d like to hear your thoughts and experiences. Either leave a comment or E-mail me at wconway@403labs.com.


advertisement

2 Comments | Read PA-DSS Reduces Your Scope Less Than You Think

  1. jml Says:

    Strong second on extending the PA-DSS listings to include information relevant to persisting CHD after authorization.

    I have a whole series of war stories about vendors flat out lying about whether their POS systems persist cardholder data after authorization.

    In some cases we’ve had to dive into the databases themselves and print out what we find in order for the vendor representative to acknowledge that, well, yes, they do store CHD.

    Even better are the vendor reps of a Validation Type 5 (persists CHD after authorization) POS system who loudly trumpeted that a number of his customers were “compliant at the SAQ-C” like that was a good thing, in order to assuage a new customers’ concerns about having to maintain SAQ-D compliance around the application.

    It’s a really ugly mess out there.

  2. Ernie Floyd Says:

    Good points Walt. I think more attention needs to be paid to Visa’s guidance. The acquirers have not been rushing to update their specs and usually send the PAN back to the merchant in the response message which is then encrypted and stored by the payment application. In other cases, the PAN must be sent back to the acquirer, post authorization, when doing adjustments such as tips. Payment application vendors may not be able to make much headway on the issue of stored cardholder data until the acquirers change. Perhaps Visa’s guidance should become a mandate.

    I’ve said this before: it feels like we are just adjusting the deck chairs. If merchants respond to SAQ C, they still must comply with the full standard. Unfortunately, merchants most likely, and wrongly, get the impression they only have comply with the requirements listed on SAQ C. Doing so will still leave them open to vectors permitting memory parsers or key loggers to enter the CDE. Whether or not the payment application stores encrypted PAN is irrelevant at that point.

    We need more focus on core security best practices such as implementing a managed hardware firewall to protect from external threats and deploying whitelisting and anti-malware applications to protect from internal threats. Pushing merchants to complete an SAQ isn’t improving the overall security position when we know merchants aren’t really doing most of what they are attesting to.

Newsletters

StorefrontBacktalk delivers the latest retail technology news & analysis. Join more than 60,000 retail IT leaders who subscribe to our free weekly email. Sign up today!
advertisement

Most Recent Comments

Why Did Gonzales Hackers Like European Cards So Much Better?

I am still unclear about the core point here-- why higher value of European cards. Supply and demand, yes, makes sense. But the fact that the cards were chip and pin (EMV) should make them less valuable because that demonstrably reduces the ability to use them fraudulently. Did the author mean that the chip and pin cards could be used in a country where EMV is not implemented--the US--and this mis-match make it easier to us them since the issuing banks may not have as robust anti-fraud controls as non-EMV banks because they assumed EMV would do the fraud prevention for them Read more...
Two possible reasons that I can think of and have seen in the past - 1) Cards issued by European banks when used online cross border don't usually support AVS checks. So, when a European card is used with a billing address that's in the US, an ecom merchant wouldn't necessarily know that the shipping zip code doesn't match the billing code. 2) Also, in offline chip countries the card determines whether or not a transaction is approved, not the issuer. In my experience, European issuers haven't developed the same checks on authorization requests as US issuers. So, these cards might be more valuable because they are more likely to get approved. Read more...
A smart card slot in terminals doesn't mean there is a reader or that the reader is activated. Then, activated reader or not, the U.S. processors don't have apps certified or ready to load into those terminals to accept and process smart card transactions just yet. Don't get your card(t) before the terminal (horse). Read more...
The marketplace does speak. More fraud capacity translates to higher value for the stolen data. Because nearly 100% of all US transactions are authorized online in real time, we have less fraud regardless of whether the card is Magstripe only or chip and PIn. Hence, $10 prices for US cards vs $25 for the European counterparts. Read more...
@David True. The European cards have both an EMV chip AND a mag stripe. Europeans may generally use the chip for their transactions, but the insecure stripe remains vulnerable to skimming, whether it be from a false front on an ATM or a dishonest waiter with a handheld skimmer. If their stripe is skimmed, the track data can still be cloned and used fraudulently in the United States. If European banks only detect fraud from 9-5 GMT, that might explain why American criminals prefer them over American bank issued cards, who have fraud detection in place 24x7. Read more...

StorefrontBacktalk
Our apologies. Due to legal and security copyright issues, we can't facilitate the printing of Premium Content. If you absolutely need a hard copy, please contact customer service.