'Aussie merchant card security standards a sham'

Australian retailers are sluggishly adopting credit card security standards, according to Citrix chief security officer, Kurt Roemer, but competing standards and proposed amendments to the Privacy Act will cause even greater confusion for them.

PCI DSS (Payment Card Industry Data Security Standard) is a set of 12 requirements for securing credit card information whenever it is stored, processed or transmitted by a merchant. The industry-wide effort is aimed at reducing credit card fraud.

The standard covers basic aspects of security such as firewalls, passwords, data storage protection, antivirus and encryption, and were originally developed by Visa before being adopted late last year by all of the major credit card providers including Mastercard and American Express.

Roemer said that Australian retailers remain "behind the rest of the world" in terms of awareness and adoption of the PCI DSS standard -- a task the PCI Standards Council has handed to banks, which regulate it on a contractual basis with merchants.

However Roemer said there "doesn't appear to be an acceptable level of awareness" in Australia.

This is despite credit card companies providing both incentives for PCI-compliant customers and penalties for those merchants that haven't made the effort.

Incentives include savings on the transaction rates offered by the credit card companies. Penalties for those companies that are not compliant include unfavourable transaction rates and the levying of fines of up to AU$50,000.

Roemer said credit card issuers in other countries, such as banks, have made direct contact with merchants to warn them of the consequences -- but he doubts such an effort has been made in Australia.

Conflicting standards confuse retailers
Retailers can expect the challenge to comply with payment card security standards to become more complex in the near future.

According to Ajoy Ghosh, a security executive with Logica CMG, planned amendments to the Commonwealth Privacy Act as well as Visa's announcement of new security standards for card payment software used by merchants will add further complexity for merchant compliance.

"There is a new scenario emerging. Visa have sponsored another organisation which have come up with PA DSS [Payment Application Data Security Standard]. Visa is now requiring Visa merchants to comply with that," said Ghosh.

"On top of that, [proposed] amendments to the Privacy Act broadly extend the scope of 'personal data' to include IP and e-mail addresses. On the other hand PCI DSS and PA DSS require merchants to keep certain things such as originating IP addresses, yet under the privacy act that's considered a piece of personal data, which means a merchant needs to consider how that is captured and stored," he added.

In other words, to comply with the PCI and PA DSS standards, retailers will need to capture an IP address from a transaction, which forms part of an audit record, yet to comply with proposed amendments to the Privacy Act, retailers will need to gain the consent of their customers to collect this data.

"At the moment, if you're just capturing an IP address you can't attach that to a person, but if it's matched to a transaction that becomes personal data," explained Ghosh.

Despite the potential confusion, Citrix's Roemer said retailers should, at a minimum, understand their duties under PCI standards while those responsible for awareness of the standard should do more.

"If you deal with credit card information in any way and you haven't been told about the PCI DSS standard, somebody has tremendously failed you," Roemer said. -You definitely need to be aware of this."

The risk, he says, is that companies that are unaware of their need to be compliant will be scrambling to do so in less time as deadlines for compliance approach.

The first auditable deadline already passed at the start of the year. A second deadline around applications, firewalls and scanning is due in mid-2008, before several more rolling deadlines come up in 2008, 2009 and beyond.

A breach, in most cases, can be more disastrous than a fine.

Take the recent theft of credit card data from online florist, Roses Only, for example.

An estimated 20,000 Australians had their credit card details exposed by the e-tailer in September, which has since become the subject of Police and Privacy Commission investigations.

"My number one recommendation is to know when and how credit card information is used in your organisation," Roemer said.

"I would then recommend you read the PCI DSS specification and have it read by anybody relevant to your dealings with that information."

"Third, I would recommend that instead of taking a reactionary approach to credit card security, that you be more progressive. Virtualise access to credit card applications in a way that is centralised, authenticated, available only to those who require the application, and auditable."

Payment Application Data Security Standard
PA DSS compliance will mean retailers also need to ensure the technology they are using meets the additional compliance measures which Visa recently announced.

Visa's Payment Application Best Practices (PABP) require that retail software applications do not store credit card information after the transaction is completed.

Roemer said that in many retail configurations, the credit card swipe is hooked into the keyboard input of a PC. Retailers often have "little idea" about how much of a customer's information is stored on the machine as a result, he said.

"Criminals are targeting certain versions of software because of their known security gaps," said Michael Smith, Visa's senior vice president of payment system risk in a statement last week. "Some versions of software in use today are known to store the full content of the magnetic stripe, PIN data or security codes contrary to Visa rules and the PCI Data Security Standard."

This new requirement, again pioneered by Visa, has been accepted by Visa's credit card peers and in early 2008 will be released as an industry-wide standard called the Payment Application Data Security Standard (PA-DSS).

Roemer said that most credit card applications were written well before authentication and audit controls were available. When these new application requirements are made universal, he anticipates a need for a "great deal of upgrades" in retail technology.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

US, Australia team up on cybersecurity: http://t.co/OCFR5khp

Security services provider Earthwave reports 700% rise in DDoS on clients in Q1. http://t.co/LOBC8NOo

Dynamics CRM saves email-drowned utility http://t.co/S5rvxbcU

RT @MSDynamicsCRM: Great article on ZDNet - Microsoft #Dynamics #CRM saves email-drowned Australian Power and Gas http://t.co/LKjZzQcR #msdyncrm #crm2011 ^pb

Tech News: Mac OS users on security: No worries - The Mac users that ZDNet Asia spoke to regarding Flashback and oth... http://t.co/fhw6gJ0T

RT @msdynamicscrm: Great article on ZDNet - Microsoft #Dynamics #CRM saves email-drowned Australian Power and Gas http://t.co/B5logcak...

First off, Bitcoin is not a virus. Second off, the only way to generate Bitcoins, is by using a Bitcoin miner. More information on this h...

56 minutes ago by rizowski on ABC's Bitcoin miner tackled in minutes

Vic councils tender for VMware partner - ZDNet Australia: Vic councils tender for VMware partnerZDNet Australia#... http://t.co/V9rukN7Q

Cybercrime golden age over in two years?
http://t.co/qdeIhHXP #techwd #Tech_ar #reversing

US, Australia team up on #cybersecurity http://t.co/AKDgHpmB

Microsoft's So.cl network launched amid Facebook press http://t.co/MkUizROL

Students create "v'ideo parties" with MSFT new social service http://t.co/uH9ffvLa

RT @zdnetaustralia: Melbourne City Council pulls parking fine cameras. Turns out Melbournites park too close together: http://t.co/pqbJbeJy

Vic councils tender for VMware partner - ZDNet Australia http://t.co/eTTZFXVG #australia #technews

@Microsoft So.cl combines search and social media, designed to aid students networking and sharing information ZDNet http://t.co/zQW8Zecr

Google's Chrome vs. Microsoft's IE: How's that halo effect? http://t.co/xz2YGQMU

When an operating system is sold it should not launch until an approved security service is purchased online with a list of approved supp...

1 hour ago by Kevin Cobley on National Botnet Network coming: Earthwave

Windows Phone: Photography the key to its success? http://t.co/14swIy1J

National Botnet Network coming: Earthwave http://t.co/BsCUwtGW via @zdnetaustralia

Windows Phone: Photography the key to its success? http://t.co/CBVdS9f7

RT @MicrosoftNZCRM: Great article on ZDNet - Microsoft #Dynamics #CRM saves email-drowned Australian Power and Gas http://t.co/51PgGxkW #msdyncrm #crm2011 ^pb

RT @MicrosoftNZCRM: Great article on ZDNet - Microsoft #Dynamics #CRM saves email-drowned Australian Power and Gas http://t.co/51PgGxkW #msdyncrm #crm2011 ^pb

Windows Phone: Photography the key to its success?: I tend to do a bit of digital photography when I go on trips... http://t.co/lAYofzgi

CASE STUDY: using #msdyncrm to cope with growing number of client comms http://t.co/qA1SxZLO #personalinjury #legaluk #solicitors #lawyers

Windows Phone: Photography the key to its success? - ZDNet (blog): ZDNet (blog)Windows Phone: Photography the ke... http://t.co/HPArdCe0

One of Windows Server 2012's secret weapons: Hyper-V Replica http://t.co/F8nJ7xK6

“@ZDNet: One of Windows Server 2012's secret weapons: Hyper-V Replica http://t.co/oAE1ifmp”....a DR solution, that is for the little guys.

TechnologyOne keeps profits growing: http://t.co/A7J5uDlT

“@btviewpoint: #Cybercrime golden age over in two years? - #Security - #News - http://t.co/ZEmny2dI

“@ZDNet: Can Windows 8 tablet be priced low enough to compete with iPad, Kindle Fire? http://t.co/b7n4Wb7C” .....unlikely, and disappointing

#Cybercrime golden age over in two years? - #Security - #News - http://t.co/Mvc37WAr

RT @MicrosoftNZCRM: Great article on ZDNet - Microsoft #Dynamics #CRM saves email-drowned Australian Power and Gas http://t.co/51PgGxkW #msdyncrm #crm2011 ^pb

United States, Australia team up on cybersecurity http://t.co/41IYTcDx

$50m to Medicare locals for eHealth http://t.co/VM5ts5lf

RT @adrianbritton: Goodbye Friending #Facebook: We only part to meet again http://t.co/gXZEKtEE #socialmedia

RT @stilgherrian: RT: Me at @zdnetaustralia: "NSA, FBI split on comms intercepts" http://t.co/Y32rF8Gz #AusCERT

Microsoft admits Vista was 'cheesy' http://t.co/Yd6fSLyx

We Are Specialty Supply Miu Miu Handbags, Miu Miu Pocketbook, Miu Miu Sunglasses And So On. Miu Miu Car-boot sale Online Strapping Reduct...

5 hours ago by ExedegamEmodo on Reservoir blogs: Fan fakes Tarantino diary

5 hours ago by forporoExpoxy on Reservoir blogs: Fan fakes Tarantino diary

Goods Shopping Location Diminish Of Japan's Largest Overseas Train Brands. Coach Outlet Recover 89% Off.We Entertain Stuffed Items Such A...

5 hours ago by MentIdott on Reservoir blogs: Fan fakes Tarantino diary

Our Stow away Tender Exercise Bags Of The Cheapest Quotation, 50-75% OFF. Secured Shipping To Japan. Detailed Inferior Instructor Handbag...

5 hours ago by Hieffiftsoinc on Reservoir blogs: Fan fakes Tarantino diary

1963年ナイキの創業者フィル・ナイトが訪日、オニツカ(現アシックス)の経営陣を訪問。 最新の機...

5 hours ago by Scafthapthinc on Reservoir blogs: Fan fakes Tarantino diary

5 hours ago by antaftilk on Reservoir blogs: Fan fakes Tarantino diary

Our Aggregate Wholesale Trainer Bags Of The Cheapest Consequence, 50-75% OFF. Self-indulgent Shipping To Japan. Exquisite Worthless Drill...

5 hours ago by meltygypent on Reservoir blogs: Fan fakes Tarantino diary

Celine belongings,Celine case,purse Celine,CELINE Celine is synonymous with je sais quoi and faultlessness prevalent since founding in 19...

5 hours ago by dendyBymNTedo on Reservoir blogs: Fan fakes Tarantino diary

6 hours ago by Fedaupdat on Reservoir blogs: Fan fakes Tarantino diary

Admits? Don't fall for their marketing. Vista was beautiful. Microsoft has a history of trashing their older OSes.

7 hours ago by anonymuos on Microsoft admits Vista was 'cheesy'

Gotta agree. For our Burnie, Tas. internet, we have a 1.5MB download speed adls connection through exetel using testra copper line. ADS...

7 hours ago by brozza on Broadband Speedtest

Well the message certainly is clear. Never do anything because something might happen. Seriously it seems to me "Earthwave" just want to...

9 hours ago by Hubert Cumberdale on National Botnet Network coming: Earthwave

you really think it's going to be such a grim future? looking at South Korea, Japan, even Czech Republic - I haven't seen either emit mo...

11 hours ago by romant on National Botnet Network coming: Earthwave

No... they'll just blame the NBN for that too ;-)

11 hours ago by Beta on National Botnet Network coming: Earthwave

It seems that some of the people who set up ACCAN (not staff members) took the view that it would somehow be against their view of 'consu...

12 hours ago by socrates on ACCAN gets govt tick amid industry criticism

Don't laugh, Mr Turnbull is dumb enough to try and use this against the NBN. I'm sure the noallitions magical FTTN will be impervious to ...

12 hours ago by Jingles on National Botnet Network coming: Earthwave

OMG, the sky will fall if we get NBN - it must be cancelled immediately! Sorry; was just channelling Malcolm Turnbull there for a moment...

12 hours ago by socrates on National Botnet Network coming: Earthwave

Thats just stupid.. what else is the NBN going to get blamed for? People die crossing the road, are you going to ban cars or police it b...

13 hours ago by fibretech on National Botnet Network coming: Earthwave

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar