SlideShare a Scribd company logo
Payment Card Industry Data Security StandardBy: Sally ChiuACC 626 Section 002
What is PCI DSS?Is it effective?Impact on the auditing professionOverview
“Payment Card Industry Data Security Standard”industry-wide framework for developing a robust payment card data security processaims to protect cardholder data What is PCI DSS?
response to the growing misuse of payment card informationPayment Card Industry (PCI) Security Standards Council - 5 global payment card companies: American Express, Discover, JCB International, MasterCard, and Visaapplies to entities that store, process or transmit cardholder information Retailers, on-line merchants, payment processing companiesHistory and Origins
6 principles, 12 major requirements, many sub-requirements and detailed requirements, and testing procedures 6 objectives:Build and Maintain a Secure NetworkProtect Cardholder DataMaintain a Vulnerability Management ProgramImplement Strong Access Control MeasuresRegularly Monitor and Test NetworksMaintain an Information Security PolicyComponents of PCI DSS:
PCI Security Standards Council sets the overall high level requirementseach card issuer enforces the standard, sets validation requirements and penaltiesdifferent merchant / service provider levels, and requirements for each levelEg: Level 1 – merchants with 6M+ transactions annually most stringent requirements ASV scans, QSA auditsmost recent version - PCI DSS v.2.0continuously updated to as new threats emergePCI DSS Logistics
Is PCI DSS Effective?Effectiveness of PCI DSS2011Ponemon Institute & Imperva study:64% of compliant firms had no breaches over the past two years, vs only 38% of non-compliant firms  2011 Cisco study:70% feel that their organizations are more secure 87% feel that PCI compliance is necessary60% are using PCI compliance to drive other security network projectsappears that most organizations regard PCI DSS as an effective tool in improving cardholder security
Ineffectiveness of PCI DSSPCI DSS compliant firms still experience security breachesEg: Hannaford Bros, breach in 2008:  theft of 4.2 million customer card numbers Eg: Heartland Payment Systems, breach in 2008: 130 million credit card numbers exposedCritics: PCI DSS ineffective as it has failed to prevent data breach incidents Is PCI DSS Effective?
Is PCI DSS Effective?Ineffectiveness of PCI DSSdeveloped by card companies to shift blame to retailers rather than actually preventing cybercrimelack of standardizationhigh cost of compliance - $3.8M implementation cost for Level 1 merchantsExecutives see PCI DSS as a burden, not an investment  ROI unknown
PCI DSS: Effective guideline, but does not guarantee security Breaches of PCI DSS compliant firms show that even compliance does not guarantee protection against security breachesPCI DSS -  only a framework for protecting cardholder data – will not 100% guarantee securityEffective from aspect of laying the groundwork for a secure systemForces entities to be continuously compliant
Canadians are among the most frequent users of debit and credit cards Canada seen as vulnerable to hackers and data thieves due to:lack of strong Canadian privacy legislation inadequate IS security at Canadian SMEslag in adopting Chip & PIN technology on credit cards Canada has relied upon PCI DSS to improve cardholder data securityPCI DSS and Canada
Impact of PCI DSS on the Accounting Professionopens numerous opportunities for the accounting profession CAs can act as consultants to businesses CAs can act as QSAs to assess PCI DSS complianceCAs can work together with the PCI to achieve greater protection of cardholder data
Impact of PCI DSS on the Accounting ProfessionCAs acting as QSAs can offer integrated services to clients PCI compliance & S. 5970 audit efficiencies can be gainedHowever, should be aware of differences:FrameworkTesting periodScope
PCI DSS is a critical step towards improving the security of cardholder data in Canada and worldwidepresents new opportunities for the accounting professionConclusion

More Related Content

PPTX
Is your business PCI DSS compliant? You’re digging your own grave if not
PPTX
PCI DSS Slidecast
PDF
Reduce PCI Scope - Maximise Conversion - Whitepaper
PPT
PCI DSS Certification
PPT
Evolution Pci For Pod1
PDF
Introduction to the Payment Card Industry Data Security Standard (PCI DSS) - ...
PDF
PCI_Presentation_OASIS
DOCX
PCI DSS | PCI DSS Training | PCI DSS AWARENESS TRAINING
Is your business PCI DSS compliant? You’re digging your own grave if not
PCI DSS Slidecast
Reduce PCI Scope - Maximise Conversion - Whitepaper
PCI DSS Certification
Evolution Pci For Pod1
Introduction to the Payment Card Industry Data Security Standard (PCI DSS) - ...
PCI_Presentation_OASIS
PCI DSS | PCI DSS Training | PCI DSS AWARENESS TRAINING

What's hot (20)

PDF
Tripwire pci basics_wp
PPTX
What Everybody Ought to Know About PCI DSS and PA-DSS
PPS
P0 Pcidss Overview
PDF
Pcidss qr gv3_1
PDF
PCI-DSS for IDRBT
PDF
PCIDSS compliance made easier through a collaboration between NC State and UN...
DOCX
Pci dss compliance
PPTX
Introduction to PCI DSS
PPTX
Webinar: Protect Your Customers, Protect Yourself Learn How to Take Precautio...
PDF
Alcumus ISOQAR PCIDSS Compliance Presentation
PDF
Senate_2014_Data_Breach_Testimony_Richey
PDF
Pci dss v3-2-1
PDF
Visa Compliance Mark National Certification
PPT
ECMTA 2009 PCI Compliance and the Ecommerce Merchant
PDF
Pcidss
PPTX
Payment Card Industry Introduction CMTA APR 2010
PDF
Whitepaper - Application Delivery in PCI DSS Compliant Environments
PDF
Quick Reference Guide to the PCI Data Security Standard
PDF
PCI Compliance - How To Keep Your Business Safe From Credit Card Criminals
PPTX
Reducing cardholder data footprint with tokenization and other techniques
Tripwire pci basics_wp
What Everybody Ought to Know About PCI DSS and PA-DSS
P0 Pcidss Overview
Pcidss qr gv3_1
PCI-DSS for IDRBT
PCIDSS compliance made easier through a collaboration between NC State and UN...
Pci dss compliance
Introduction to PCI DSS
Webinar: Protect Your Customers, Protect Yourself Learn How to Take Precautio...
Alcumus ISOQAR PCIDSS Compliance Presentation
Senate_2014_Data_Breach_Testimony_Richey
Pci dss v3-2-1
Visa Compliance Mark National Certification
ECMTA 2009 PCI Compliance and the Ecommerce Merchant
Pcidss
Payment Card Industry Introduction CMTA APR 2010
Whitepaper - Application Delivery in PCI DSS Compliant Environments
Quick Reference Guide to the PCI Data Security Standard
PCI Compliance - How To Keep Your Business Safe From Credit Card Criminals
Reducing cardholder data footprint with tokenization and other techniques
Ad

Similar to Payment card industry data security standard (20)

PPTX
Payment Card Industry Security Standards
PDF
Credit Card Processing for Small Business
PDF
PCI DSS: What it is, and why you should care
PDF
PCI-DSS_Overview
PDF
Pci ssc quick reference guide
PDF
MTBiz May-June 2019
DOCX
PCI DSS 6 Key Objectives You Must Know for Compliance.docx
PDF
Pci standards, from participation to implementation and review
PDF
Best Practices to Protect Cardholder Data Environment and Achieve PCI Compliance
PDF
Adventures in PCI Wonderland
PDF
a Guide for quick pci dss and payment security
PPTX
Payment Card Industry CMTA NOV 2010
PPTX
PruebaJLF.pptx
PPT
pci-comp pci requirements and controls.ppt
DOCX
Online_Transactions_PCI
PPT
PCI DSS
PDF
Understanding Your PCI DSS Guidelines: Successes and Failures
PPT
PCI Compliance Seminar
PPTX
PCI DSS Compliance Readiness
PPTX
PCI Compliance for Community Colleges @One CISOA 2011
Payment Card Industry Security Standards
Credit Card Processing for Small Business
PCI DSS: What it is, and why you should care
PCI-DSS_Overview
Pci ssc quick reference guide
MTBiz May-June 2019
PCI DSS 6 Key Objectives You Must Know for Compliance.docx
Pci standards, from participation to implementation and review
Best Practices to Protect Cardholder Data Environment and Achieve PCI Compliance
Adventures in PCI Wonderland
a Guide for quick pci dss and payment security
Payment Card Industry CMTA NOV 2010
PruebaJLF.pptx
pci-comp pci requirements and controls.ppt
Online_Transactions_PCI
PCI DSS
Understanding Your PCI DSS Guidelines: Successes and Failures
PCI Compliance Seminar
PCI DSS Compliance Readiness
PCI Compliance for Community Colleges @One CISOA 2011
Ad

Recently uploaded (20)

PDF
Nidhal Samdaie CV - International Business Consultant
PDF
Roadmap Map-digital Banking feature MB,IB,AB
PPTX
AI-assistance in Knowledge Collection and Curation supporting Safe and Sustai...
PPTX
The Marketing Journey - Tracey Phillips - Marketing Matters 7-2025.pptx
PPTX
ICG2025_ICG 6th steering committee 30-8-24.pptx
PDF
WRN_Investor_Presentation_August 2025.pdf
PDF
Training And Development of Employee .pdf
PDF
Types of control:Qualitative vs Quantitative
PPTX
Business Ethics - An introduction and its overview.pptx
PDF
COST SHEET- Tender and Quotation unit 2.pdf
PDF
Ôn tập tiếng anh trong kinh doanh nâng cao
PDF
Traveri Digital Marketing Seminar 2025 by Corey and Jessica Perlman
PDF
Deliverable file - Regulatory guideline analysis.pdf
PPTX
job Avenue by vinith.pptxvnbvnvnvbnvbnbmnbmbh
PPT
Chapter four Project-Preparation material
PDF
How to Get Funding for Your Trucking Business
PDF
A Brief Introduction About Julia Allison
PPTX
CkgxkgxydkydyldylydlydyldlyddolydyoyyU2.pptx
PPTX
Lecture (1)-Introduction.pptx business communication
PPTX
Dragon_Fruit_Cultivation_in Nepal ppt.pptx
Nidhal Samdaie CV - International Business Consultant
Roadmap Map-digital Banking feature MB,IB,AB
AI-assistance in Knowledge Collection and Curation supporting Safe and Sustai...
The Marketing Journey - Tracey Phillips - Marketing Matters 7-2025.pptx
ICG2025_ICG 6th steering committee 30-8-24.pptx
WRN_Investor_Presentation_August 2025.pdf
Training And Development of Employee .pdf
Types of control:Qualitative vs Quantitative
Business Ethics - An introduction and its overview.pptx
COST SHEET- Tender and Quotation unit 2.pdf
Ôn tập tiếng anh trong kinh doanh nâng cao
Traveri Digital Marketing Seminar 2025 by Corey and Jessica Perlman
Deliverable file - Regulatory guideline analysis.pdf
job Avenue by vinith.pptxvnbvnvnvbnvbnbmnbmbh
Chapter four Project-Preparation material
How to Get Funding for Your Trucking Business
A Brief Introduction About Julia Allison
CkgxkgxydkydyldylydlydyldlyddolydyoyyU2.pptx
Lecture (1)-Introduction.pptx business communication
Dragon_Fruit_Cultivation_in Nepal ppt.pptx

Payment card industry data security standard

  • 1. Payment Card Industry Data Security StandardBy: Sally ChiuACC 626 Section 002
  • 2. What is PCI DSS?Is it effective?Impact on the auditing professionOverview
  • 3. “Payment Card Industry Data Security Standard”industry-wide framework for developing a robust payment card data security processaims to protect cardholder data What is PCI DSS?
  • 4. response to the growing misuse of payment card informationPayment Card Industry (PCI) Security Standards Council - 5 global payment card companies: American Express, Discover, JCB International, MasterCard, and Visaapplies to entities that store, process or transmit cardholder information Retailers, on-line merchants, payment processing companiesHistory and Origins
  • 5. 6 principles, 12 major requirements, many sub-requirements and detailed requirements, and testing procedures 6 objectives:Build and Maintain a Secure NetworkProtect Cardholder DataMaintain a Vulnerability Management ProgramImplement Strong Access Control MeasuresRegularly Monitor and Test NetworksMaintain an Information Security PolicyComponents of PCI DSS:
  • 6. PCI Security Standards Council sets the overall high level requirementseach card issuer enforces the standard, sets validation requirements and penaltiesdifferent merchant / service provider levels, and requirements for each levelEg: Level 1 – merchants with 6M+ transactions annually most stringent requirements ASV scans, QSA auditsmost recent version - PCI DSS v.2.0continuously updated to as new threats emergePCI DSS Logistics
  • 7. Is PCI DSS Effective?Effectiveness of PCI DSS2011Ponemon Institute & Imperva study:64% of compliant firms had no breaches over the past two years, vs only 38% of non-compliant firms 2011 Cisco study:70% feel that their organizations are more secure 87% feel that PCI compliance is necessary60% are using PCI compliance to drive other security network projectsappears that most organizations regard PCI DSS as an effective tool in improving cardholder security
  • 8. Ineffectiveness of PCI DSSPCI DSS compliant firms still experience security breachesEg: Hannaford Bros, breach in 2008: theft of 4.2 million customer card numbers Eg: Heartland Payment Systems, breach in 2008: 130 million credit card numbers exposedCritics: PCI DSS ineffective as it has failed to prevent data breach incidents Is PCI DSS Effective?
  • 9. Is PCI DSS Effective?Ineffectiveness of PCI DSSdeveloped by card companies to shift blame to retailers rather than actually preventing cybercrimelack of standardizationhigh cost of compliance - $3.8M implementation cost for Level 1 merchantsExecutives see PCI DSS as a burden, not an investment ROI unknown
  • 10. PCI DSS: Effective guideline, but does not guarantee security Breaches of PCI DSS compliant firms show that even compliance does not guarantee protection against security breachesPCI DSS - only a framework for protecting cardholder data – will not 100% guarantee securityEffective from aspect of laying the groundwork for a secure systemForces entities to be continuously compliant
  • 11. Canadians are among the most frequent users of debit and credit cards Canada seen as vulnerable to hackers and data thieves due to:lack of strong Canadian privacy legislation inadequate IS security at Canadian SMEslag in adopting Chip & PIN technology on credit cards Canada has relied upon PCI DSS to improve cardholder data securityPCI DSS and Canada
  • 12. Impact of PCI DSS on the Accounting Professionopens numerous opportunities for the accounting profession CAs can act as consultants to businesses CAs can act as QSAs to assess PCI DSS complianceCAs can work together with the PCI to achieve greater protection of cardholder data
  • 13. Impact of PCI DSS on the Accounting ProfessionCAs acting as QSAs can offer integrated services to clients PCI compliance & S. 5970 audit efficiencies can be gainedHowever, should be aware of differences:FrameworkTesting periodScope
  • 14. PCI DSS is a critical step towards improving the security of cardholder data in Canada and worldwidepresents new opportunities for the accounting professionConclusion