Home > Ask the Information Security Experts > Questions & Answers > What should be the fraud and risk assessment policy for organizations that deal with consumer banking card sales?
Ask The Security UK Expert: Questions & Answers
EMAIL THIS

What should be the fraud and risk assessment policy for organizations that deal with consumer banking card sales?

Mike Rothman EXPERT RESPONSE FROM: Mike Rothman

Pose a Question
Other Security UK Categories
Meet all Security UK Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 19 August 2007
What should be the fraud and risk assessment policy at consumer banking cards' sales end?

>
EXPERT RESPONSE
Fraud mitigation and risk assessment are different things. I am interpreting this question to ask about policies that retailers and other merchants should be implementing relative to consumer banking cards. Many of the requirements for protecting cardholder information are specified in the Payment Card Industry Data Security Standard, commonly known as PCI DSS.

PCI DSS specifies 12 different requirements to secure cardholder data and requires a qualified assessor to examine a merchant's environment to ensure compliance. Penalties for non-compliance range from small fines to the inability to use a specific type of credit or debit card.

Specific to risk assessment, the PCI DSS standard requires that "security controls, limitations, network connections and restrictions" are tested at least annually. It also mandates quarterly use of a wireless analyzer to see if your Wi-Fi networks are vulnerable. Additionally, the regulation requires quarterly vulnerability scans to ensure that no known vulnerabilities put cardholder data at risk.

I strongly recommend that organizations also conduct a more formal penetration test, ideally performed by outside resources, at least once a year, and also use automated pen testing tools internally more often. Why? Because the bad guys are testing your network and applications every day. They are performing risk assessments all the time, trying to figure out how to compromise your systems, so you should use their same tools and techniques to find and remediate problems.

For more information:

  • In this tip, contributor Khalid Kark defines the framework that makes organizational risk management work in your enterprise.
  • In this expert response, Joel Dubin discusses whether or not tokenization can meet PCI DSS standards for storing credit card data.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Compliance Regulations
    The power of the ICO: Liabilities for a data security breach
    Privacy, data protection must be built into system design, says ICO
    Using ISO 27000 to comply with Data Protection Act principles
    Latest U.K. data security laws get tough on fines, PETs and policies
    Will the Data Handling Review improve government security practices?
    The 'appropriate' way to comply with Data Protection Act 1998
    Best practices: Handling compliance during a corporate merger
    Information Commissioner turns up the heat on data breach culprits
    Email confusion could look bad in court
    Firms aim to achieve PCI compliance deadline, despite the cost

    Risk Assessment Analysis
    Reports show security awareness and training are still lagging
    Data threats: Insiders vs. outsiders
    Managed services company finds way to automate support
    RSA gets control of security, risk with Agiliance compliance solution
    Database patch denial: How 'critical' are Oracle's CPUs?
    Is personal Internet usage acceptable for employees in the workplace?
    Windows registry forensics guide: Investigating hacker activities
    Security strategy research seeks to plug weaknesses
    Bank security chief explains how to avoid internal threats
    Data loss prevention doesn't come in a pill

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    Basel II  (SearchSecurityUK.com)
    EU Data Protection Directive  (SearchSecurityUK.com)
    Financial Services Authority  (SearchSecurityUK.com)
    UK Identity Cards Act  (SearchSecurityUK.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts