Home > Financial Services Information Security Tips > Compliance and Governance Digest > PCI DSS 3.1 best practices
Financial Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE AND GOVERNANCE DIGEST

PCI DSS 3.1 best practices


Roger Nebel, Contributor
12.02.2008
Rating: -4.20- (out of 5)


GRC in the financial services industry
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Requirement 3.1 of the Payment Card Industry Data Security Standard (PCI DSS) requires merchants keep cardholder data storage to a minimum. Develop a data retention and disposal policy. Limit storage amount and retention time to that which is required for business, legal, and/or regulatory purposes, as documented in the data retention policy.

To keep, or not to keep -- that is the question. Whether it is nobler in the eyes of your acquiring bank to retain your transaction data, and risk a breach, or to take arms against the conventional wisdom that the merchant must retain massive amounts of private data in order to fend off the odd contested transaction. Ay, there's the rub.

Many banks insist that their merchants retain complete records of all credit card transactions in case there is a disputed transaction. However, all the merchant needs is the authorization number from the processor, the dollar amount and to have checked the customer's identification for a card present transaction, or to get the card verification value code and billing zip code for a card not present at the transaction.

Yet this topic comes back to haunt us. The National Retail Federation wants the acquiring banks to store the data and provide a code to the merchant which would relieve the merchants of their burden to store the data. But that's just what already exists in the form of the authorization code! One merchant insisted that they must retain the full transaction data -- credit card number, expiration date, etc. -- for seven years. Unless there's been fraud, not even the IRS requires that.

So are there valid reasons to store the data? Possibly. Customers lea


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
PCI DSS compliance
Download presentations from Financial Information Security Decisions 2009
Two conversations about risk assessment
Why financials should pay attention to NERC CIP
Infosecurity pro pitfalls
RBS WorldPay regains spot on Visa's PCI compliance list
Tokenization and PCI compliance
Heartland breach cost $12.6 million, CEO says
PCI certification isn't always the right answer
Heartland gains PCI compliance from Visa
The PCI compliance case for source code review

Compliance and Governance Digest
Red Flags Rule compliance
How AML compliance applies to remote deposit capture
Tokenization and PCI compliance
Data governance and classification
The PCI compliance case for source code review
Identity management for financial firms in turbulent times
PCI DSS: Best practices for compliance
Red Flag Rules compliance demands a risk-based approach
Understanding the impact of new state data protection laws
Understanding the FFIEC remote deposit capture guidance

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
CISP-PCI  (SearchFinancialSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


ve their credit card data at Amazon or PayPal, and the benefits to those merchants are clear -- ease of future transactions which presumably increase sales. There are other valid reasons, such as recurring payments. If a merchant does decide to store the data for a legitimate business reason then they are required to protect it.

What then is the merchant to do?

-- First, have a good set of policies and well-documented business practices. Also encrypt or otherwise protect the data (if the entire card number is stored).
-- Second, have those policies and practices reviewed on a periodic basis (annually at a minimum) by one or more experts in the field. These include law, privacy and security experts.
-- Finally, question yourself over retention in the first place. Is the risk and cost of retention worth the benefits of having the data on hand?

See sidebar for testing procedures.

A merchant should store the minimum necessary to meet the documented business needs for cardholder data. In addition, ensure that any storage is done securely and in compliance with all statutes, regulations, contractual obligations, and in accordance with your privacy policy.

About the author:
Roger Nebel, CISSP, CISA, works with FTI Consulting, specializing in forensic and litigation consulting. He is based in Washington DC where he leads the Strategic Security practice. Nebel also teaches at the University of Virginia in the graduate information security program. He can be reached at roger.nebel@fticonsulting.com. The views expressed in the article are held by the author and are not necessarily representative of FTI Consulting.


Rate this Tip
To rate tips, you must be a member of SearchFinancialSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Finance Sector Security - Anti-Phishing, Remote Access Security, Firewall Systems
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts