date: 3/28/2014 getting started with the integrity easy pci program presenter : integrity payment...

33
DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

Upload: elizabeth-collins

Post on 11-Jan-2016

216 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

DATE: 3/28/2014

GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM

Presenter : Integrity Payment Systems

Title: Easy PCI Program

Page 2: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

1. Integrity Easy PCI Program

2. About Trustwave

3. PCI Basics

4. The Risk of Non-Compliance

5. Using TrustKeeper PCI Manager

AGENDA

Page 3: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

Who We AreWHO IS TRUSTWAVE?Company facts and figures

ESTABLISHED

TRUSTED

GLOBAL

GROWING

INNOVATING

1995BY OVER 2.5 MILLION BUSINESSES

NOW OVER 1,200 EMPLOYEESCUSTOMERS IN 96 COUNTIRES

OVER 50 PATENTS & COUNTING

Global Threat Database feeds technologies and services with threat intelligence

Selected by more enterprises for compliance – chosen more often than the next 10 service providers combined

Industry’s most holistic portfolio of security technologies delivered through TrustKeeper®

Page 4: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

PCI BASICS

• The Payment Card Industry Data Security Standard (PCI DSS) is a set of 12 requirements designed to protect cardholder data

• It is applied to all merchants, systems, networks and applications that process, store, and/or transmit card numbers

PCI DSS Defined

Page 5: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

PCI BASICS

• Cardholder data is any personally identifiable data associated with a cardholder, including:– Primary Account Number– Expiry Date– Name

• All merchants accepting debit/credit cards must comply with the PCI DSS at all times.

PCI DSS Defined

Page 6: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

PCI DSS

• Self-Assessment Questionnaire (SAQ)– A questionnaire designed to assist organizations in self-evaluating

their IT and payment processing environment

• Vulnerability Scanning– Helps secure your business by identifying weaknesses in your

network and applications

• Qualified Security Assessor (QSA)– Certified to validate that a company is compliant with the PCI DSS

• Approved Scanning Vendor (ASV)– Certified to perform vulnerability scanning

Key Terms

Page 7: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

THE RISK OF NON-COMPLIANCE

• Large corporations that have been breached make the news daily• What doesn’t make the news is that small merchants are at the

greatest risk of a data breach

Trustwave found that 90% of merchants that have data stolen are small businesses

Page 8: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

PCI DSS COMPLIANCE

• Fundamental Best Security Practices– Avoid fraud– Helps to understand own system better– Clarifies where data is stored

• Upholds Brand Name– Adds value to name– Increases consumer confidence

• Non-compliant, compromised business could expect:– Damage to their brand/reputation– Investigation costs– Remediation costs– Fines and fees

Sound Business Practice

Page 9: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

Integrity Data Breach Protection

• Data Breach Coverage is a new and unique indemnification program designed specifically to meet the expenses resulting from a suspected or actual breach of credit card data.

• Audit Costs – Employee Theft, Fraud, Stolen Computers, Hacked Networks, etc.

• Why do I need Data Breach Coverage?If you suffer a suspected or actual data breach, you could incur thousands upon thousands of dollars of unexpected costs in the form of audit expenses, card monitoring and replacement expenses, and fines. These costs could significantly affect revenue... and even jeopardize the existence of your business. This inexpensive program reduces your monetary exposure when a presumed or actual data compromise occurs, thus providing peace of mind!

$100,000 in Protection for Your Merchant

Page 10: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

Other Data Breach FAQ’s

• 85% of Data Breaches happen in small, level 4 merchant locations.• No deductible on the $100,000 Insurance Policy• Even if you are compliant, a data breach can still happen!• Claims are processed quickly, within 30 days.• You will have an insurance company working to reduce the fees.

How big a problem is this?

Page 11: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

GETTING STARTED WITH TRUSTKEEPER PCI MANAGER

Page 12: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

USING TRUSTKEEPER PCI MANAGER

Page 13: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

REGISTRATION – THREE EASY STEPS Step 1: Enter merchant information

Page 14: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

REGISTRATION – THREE EASY STEPS Step 2: How does your business accept credit cards?

Page 15: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

REGISTRATION – THREE EASY STEPS Step 3: Create User Account and Register

Page 16: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

SAQ OR PCI WIZARD?Simplify completion by selecting the Step-By-Step Wizard

Page 17: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

USING THE PCI WIZARD

Page 18: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

USING THE PCI WIZARD

Page 19: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

PCI WIZARD (INET-PA)

Page 20: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

PCI WIZARD Click the “?” icon for help

Page 21: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

PCI WIZARD Click the “i” icon to learn why it’s important

Page 22: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

PCI WIZARD Answer a question wrong . . .

Page 23: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

PCI WIZARD A task is added to the To Do List

Page 24: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

SCAN SETUP Add a scan location

Page 25: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

SCAN SETUP E-commerce website or physical location?

Page 26: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

SCAN SETUPEnter information about the scan location

Page 27: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

CERTIFICATE OF COMPLIANCE

Page 28: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

TRUSTED COMMERCE SEAL

Page 29: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

SECURITY POLICY ADVISOR Sample security policies and supporting documents

Page 30: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

SECURITY AWARENESS EDUCATION Select training based on different industries and employee roles

Page 31: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

RESOURCES

• PCI Security Standards Council:– https://www.pcisecuritystandards.org

• VISA CISP:– http://www.visa.com/cisp

• MasterCard SDP:– http://www.mastercard.com/sdp

• Discover DISC– http://www.discovernetwork.com/disc

• American Express– www.americanexpress.com/datasecurity

Page 32: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

QUESTIONS?

• Integrity Easy PCI Starting Page:– https://pci.trustwave.com/integrity – Have your Merchant ID handy

• Customer Support – Trustwave– [email protected]– (877) 417-2186

We’re here to help!

Page 33: DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program

THANK YOU