首页> 外文会议>International Conference on Financial Cryptography and Data Security >STE Is the Most Cost Effective Measure for Comply with Payment Card Industry (PCI) Data Security Standard
【24h】

STE Is the Most Cost Effective Measure for Comply with Payment Card Industry (PCI) Data Security Standard

机译:ST&E是符合支付卡行业(PCI)数据安全标准的最具成本效益的措施

获取原文

摘要

In September of 2006, the five leading payment brands formed an independent council to manage the Payment Card Industry (PCI) Data Security Standard (DSS). American Express, Discover Financial Services, JCB, MasterCard Worldwide and Visa International saw the need to secure payment account data in a globally consistent manner. As such, the financial institutions which store, process and transact the credit card must comply with the PCI/DSS. The Noncompliance fines can reach up to USD500,000 per incident including the public disclosure of breaches. Financial Institution can implement very broad security controls to comply with the PCI/DSS standard. The cost can be prohibitive. This poster argues that the most cost effective security measure is to conduct a Security Testing and Evaluation (ST&E) project before the expensive auditing performed by a PCI DSS Qualified Security Assessor (QSA) Company. We have proposed 5 distinct phases of ST&E, and what it means to the CIO/CTO of the financial institutions. The five phases of ST&E are 1) Planning, 2) Develop Evaluation Methods and Tool Selection, 3) Test Execution and Reporting, 4) Corrective Measures Recommendation and 5) Re-Testing.
机译:2006年9月,五个领先的支付品牌组建了一个独立的理事会,以管理支付卡行业(PCI)数据安全标准(DSS)。美国运通,探索金融服务,JCB,万事达卡全球和Visa International认为需要以全球一致的方式确保支付帐户数据。因此,存储,流程和交易信用卡的金融机构必须符合PCI / DSS。非融合罚款可以每次事件达到500,000美元,包括公开披露违规行为。金融机构可以实施非常广泛的安全控制,以遵守PCI / DSS标准。成本可能是禁止的。这张海报认为,最具成本效益的安全措施是在由PCI DSS合格安全评估员(QSA)公司执行的昂贵审计之前进行安全测试和评估(ST&E)项目。我们提出了5个不同的ST&E阶段,以及金融机构的CIO / CTO意味着什么。 ST&E的五个阶段为1)规划,2)开发评估方法和工具选择,3)测试执行和报告,4)纠正措施建议和5)重新测试。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号