190 likes | 383 Views
PCI DSS for Retail Industry. March 21, 2014. Agenda. Threat Landscape Payment Ecosystem Overview of PCI DSS Bank’s Approach for PCIDSS Compliance. Threat Landscape. Increased focus at compromising POS systems at retail outlets
E N D
PCI DSS for Retail Industry March 21, 2014
Agenda • Threat Landscape • Payment Ecosystem • Overview of PCI DSS • Bank’s Approach for PCIDSS Compliance
Threat Landscape • Increased focus at compromising POS systems at retail outlets • Successful data breaches resulting in leakage of millions of cardholder data • Sophisticated attack vectors being used to breach the security controls
Merchant Levels Payment Brand reserves the right to deem the level irrespective of transaction volume
Merchant Reporting Requirements OA: Onsite Assessment R: Recommended IA: Internal Auditor
Service Provider Levels TPP: Third Party Processors Payment Brand reserves the right to deem the level irrespective of transaction volume
Service Provider Reporting Requirements OA: Onsite Assessment IA: Internal Auditor
Bank’s Approach for PCIDSS Compliance Two streams of compliance program HDFC Bank has taken the initiative to share the data security alerts and advisories received from Payment brands with all its merchants. Take these alerts/advisories seriously. If not actioned on time you will get hit – as a target or by a random attack.
Thank You Manish Pal, Information Security Group