There seems to be quite a bit of confusion about the ‘new’ requirements for service provider contracts. I say ‘new’ sarcastically because this should have been part of your vendor due diligence processes from the beginning.

From a merchant’s perspective, unless they have hired a QSA (or other PCI expert) to help define the service requirements and contractual obligation, it’s very difficult for them to ask the right questions. From a  service providers perspective, I’ve seen the gamut from complete ignorance of their obligations, to out-and-out lies in terms of what they are and are not providing.

The DSS v3.0 requirements of 12.8.X go a long way to resolve this, but not far enough in my opinion. The bottom line is that someone has to be responsible for each requirement, and there are only the following choices;

  1. SP agrees to be fully responsible for the requirement;
  2. SP agrees to be partially responsible, and;
  3. SP pushes the entire requirement back on you.

That’s it.

The above list is fairly obvious, but for the service provider’s clients the challenges are now twofold:

  1. If the service provider accepts full responsibility, are they PCI compliant for the service(s)?
  2. If they are only partially responsible, EXACTLY what part of the requirement is left?

Does the service provider need to be fully PCI compliant for you to achieve compliance? The answer is no, but if they are not, you have just doubled your assessment scope. Again, someone has to answer the questions, so if your service provider has not validated compliance for the services they are offering, you need to add them to your validation efforts.

As for the partial responsibility, that’s easy, get your service provider to tell you what they’re doing. For example;

DSS Req. #

Description

Service Provider Responsibility Client Responsibility
1.1.3

Examine data-flow diagram and interview personnel to verify the diagram:

*  Shows all cardholder data flows across systems and networks.

*  Is kept current and updated as needed upon changes to the environment.

SP will provide initial diagrams in Visio format for the pre-production environment but will not own, manage, or keep up-to-date the data-flow diagrams post-production.

 This requirement is not part of SP PCI Report on Compliance dated [Mmm dd, yyyy]

Client must own, manage, and keep up-to-date all data-flow diagrams for inclusion into their own PCI compliance efforts once services have reached a production state.

You must repeat the above for EVERY requirement in the PCI DSS v3.0, then add this as an addendum or annex to your signed service contract. This applies not only for the services they are providing DIRECTLY, but the SP has a responsibility for any SUB-contractor they may bring in, and so on down the line.

Again, SOMEONE has to answer the questions!

However, let’s back up a bit and handle each DSS Requirement in turn:

12.8.1 Maintain a list of service providers

Easy, just maintain a list of Service Providers, with – at a minimum – the following detail;

  • Company Name
  • Service Description
  • Is [CONFIDENTIAL] Data Shared?
  • Regulatory Compliance Date
  • Status Verified By

12.8.2 Maintain a written agreement that includes an acknowledgement that the service providers are responsible for the security of cardholder data the service providers possess or otherwise store, process or transmit on behalf of the customer, or to the extent that they could impact the security of the customer’s cardholder data environment.

Even easier, they wrote it down for you!! Include – again, at a minimum – the language in red in your contracts. You will likely want significantly more than this as there is no declaration of LIABILITY, or even SLAs.

12.8.3 Ensure there is an established process for engaging service providers including proper due diligence prior to engagement.

If you don’t have robust vendor due diligence and vendor on-boarding/off-boarding processes you are really asking for trouble. For PCI services, if you have not ensured they are PCI compliant for the services they are providing AND you have the full details written into contact, then you have created a world of pain for yourself.

12.8.4 Maintain a program to monitor service providers’ PCI DSS compliance status at least annually.

Does this say anything about the service providers actually working towards PCI compliance? No, it doesn’t, so the status could be; “They will never achieve PCI compliance.” and this is good enough for PCI. This should NEVER be good enough for you.

12.8.5 Maintain information about which PCI DSS requirements are managed by each service provider, and which are managed by the entity.

This we’ve already covered, all you need is a table, like the above, of every PCI requirement handled by each of your service providers and their sub-contractors. Your QSA can then tell you precisely what is left for you to cover for full compliance.

Whether you’re assessing for the first time, or re-assessing under v3.0, you need to start these conversation with your service providers NOW, as while this may be simple, it is not easy.

Advice for Merchants:

  • Only choose PCI compliant service providers (start here; Visa Europe Merchant Agent List)
  • Only choose service providers who have already addressed 12.8.2 and 12.8.5 up-front. You should not have to ask for this from SP worth their salt
  • If you have existing SPs and don’t know where to start, hire a decent consultant who is familiar with the PCI DSS to help

Advice for Service Providers:

  • Get your responsibility mappings and your contract language sorted out now, BEFORE you are asked
  • If you need help, ask for it, ignorance is not an excuse your clients can accept, nor can the card schemes

Easy huh?

[Apologies for the blank post yesterday, here is the real one]

The timing for this part of the Going Beyond the Standard series is almost perfect given the SSC’s release of their ‘Information Supplement: Third-Party Security Assurance‘. Which, despite it’s gratuitous use of the word ‘may’, and the ongoing generic-ness of the SSC supplements, is actually pretty good.

It has always irritated me that the phrase ‘third parties’ is now the established norm in these scenarios, when it’s actually SECOND parties that create the most challenges;

third party
[noun]
1. a person or group besides the two primarily involved in a situation

So third parties are the service providers that YOUR service provider hires to do [part of] the work for which you (the first party) hired the original provider. Third parties are fairly common, but not as common as second parties, and while third parties ARE an issue, they should be addressed in the same way as any other outsourced service; with proper due diligence.

Unfortunately, this due diligence is almost universally performed badly, or there would be no need for the SSC to issue an information supplement in the first place. Or course, if the requirements in the PCI DSS were written better perhaps there would be less confusion, but it’s too late now.

Because the supplement is quite good, I’ll not go into the nitty gritty of vendor management, but it is important to realise that the choice of an outsourced service does not start with vendor due diligence, it starts with a business need that has been PROPERLY analysed, and a risk assessment performed.

PCI itself has driven an enormous growth in outsourcing, and not because there was suddenly a need for more services, but because so many organisation wanted PCI to just go away. The thought was if you outsourced, you could just point at them and shirk all further responsibility.

In reality, you can outsource almost every function relevant to PCI, but you can NEVER outsource the responsibility for the protection of the cardholder data. Yes, you can throw financial liabilities into the contract, you can buy cyber-insurance, you can even drag your service provider down with you if things go horribly wrong, but it’s going to be YOUR name in the papers.

The other big mistake organisations make at the beginning phases of outsourcing is, as always, asking the wrong questions. While a service provider does not have to BE PCI compliant for the service they are providing, their services have to SUPPORT yours. Not only that, if they do not have a Report on Compliance backing up their services, they will have to be fully assessed and validated against yours.

I’ve had small clients whose PCI assessment costs and effort increased FIVE fold because they had not performed the correct due diligence.

Even if I assumed you are outsourcing for the right reasons, CHOOSING vendors is next step where things go wrong. DSS v3.0 has built in the requirement for  ‘third parties’ to qualify their services with detailed analysis of EXACTLY what is being provided against the requirements themselves. This was always a requirement in my mind, but rarely followed, and has led to significant gaps based on assumptions.

However, if if your chosen service provider is PCI compliant for the services, there is surprisingly little they can do in terms of reducing your effort;

1. DSS Requirement 1.x – You can outsource management, but you will always own the policies, the final configuration standard(s), and of course, the ruleset(s). About the only things that can be 100% outsourced is stageful packet inspection.

2. DSS Requirement 2.x – Again, you can have a service provider put together configuration standards for you, but you will always own them, the business justifications for every available service and listening port is yours to document, and insecure protocols are yours to fix or compensate for.

3. DSS Requirement 6.x – Outsourced development is great, but unless their SDLC supports your compliance, YOU won’t be.

4. DSS Requirement 10.x – The most egregiously overstated service provider coverage of them all. The issue is rarely in the collection of the events, it’s what events should be logged in the first place and how. And how ANY service provider dares to say they can cover a daily review without establishing a baseling is beyond me.

5. …and so on.

I’m already ay 700 words and I’ve barely starched the surface, but that should be an indication of just how messy this topic can be. It deserves a white paper, but that will have to wait.

Bottom line; If you don’t have a program for vendor selection and vendor management, get one, and make it retroactive. Get help if you need it, but in the end, if your service providers fail, YOU fail, and deservedly so.

Read the SSC supplement, implement what it says, they have not missed much.

Who has seen a “Zero Malware Guarantee“, or something like it?

More to the point; who saw this and thought what a load of bull$#@?

Anyone who knows even the most basic aspects of information security knows that the ONLY guarantee is that nothing is safe. Ever. To throw out a word like guarantee is nothing except the most despicable attempt to drive business in a field where the experts are SUPPOSED to be trusted!

What is the guarantee?; “…to detect and stop 100 percent of malware that propagates over the web and is scanned by the [blah blah] Managed Anti-Malware Service“. Could this ‘guarantee’ be any more pointless? Who wrote this? Lawyers?

What’s worse, here’s what you get if they fail to detect and stop 100% of the malware; “…one-month extension of the service at no cost, up to four times per year.“.

Seriously? It didn’t work, but you get one more month for free? And why would you possibly need to do this FOUR times in a year? Would you seriously still pay for the service after a second failure, let alone a third?!

Doctor to dying patient: “The drugs we gave you aren’t working, but here, have some more on the house.”

Surely if the product is that good, this vendor and vendors like them (there are many) should WARRANTEE their products. “If we screw up we’ll pay for the fix AND give you your money back.” Now THAT’S something I can get behind!

You can guess how often that will happen.

The reason this is so offensive to me is that security is already seen as something to spend money on only because you have to. Like insurance. And this crass commercialisation of yet another security PRODUCT just makes everyone in the information security field look like ambulance chasers. Incompetent ones at that.

Eradication of malware (as in the above example) STARTS with policy and procedures, continues on with parallel efforts in security awareness training and control definition, and is maintained by a security program done well. Just like every other aspect of security. So the only reason security companies keep coming up with these snake oil ads is because people keep buying stuff from them.

Don’t. Do. It.

I can empathise with organisations struggling to understand security and buying what they think is the right thing for their business. What I cannot even begin to condone is any organisation selling something TO those organisations when the seller damned well DOES know better!

You never need guarantees in security, you only need appropriate security. You can start by avoiding any organisation that begins with making empty promises.

[If you liked this article, please share! Want more like it, subscribe!]

[blank] as a Service. There are so many XaaS services available now that we are running out of letters:

  • AaaS – Authentication as a Service
  • BaaS – Back-End as a Service
  • CaaS – Communication as a Service`
  • DaaS – Desktop or Data as a Service
  • EaaS – Encryption as a Service
  • FaaS – Failure as a Service [I know, couldn’t believe this one myself]
  • …and so on.

As much as I have an issue with buzz-words and inventing acronyms, I cannot deny the trend that; Unless it’s a core function, don’t do it yourself.

Retailers should outsource payment acceptance, insurance companies should outsource cyber due diligence, and every business should outsource some of its security risk management.

Sure you can change the oil in your own car, you may even be able to perform some basic plumbing, but why would you? There’s an excellent chance that a professional can do it better, and in the long-run cheaper, than you. What’s more important; saving money, or saving your time? I guess the answer is different for everyone, but a business does not have the luxury of experimentation to the degree we do. False economy, while relatively trivial for us, can be make or break to a business.

I see a time where the economies of scale, combined with the abundance of competition will enable service providers to give far better service at a much lower price-tag that you could possibly hope to achieve in-house. Doing one thing and doing it well should automatically provide the necessary scalability of service, appropriate innovation and business transformation capability necessary to run a competitive venture in the 2010s and beyond.

Even in the cybersecurity industry, there is significant confusion on how to choose the right vendor or technology, and this will only increase exponentially in the era of The Outsourcing of Everything. Inevitably there will come along a new type of service provider; the Service Provider Integrator. In the same way you cannot manage your security if you have 15 different management stations, you cannot run your business if your service providers are not performing seamlessly, and in full support of your business goals.

In the Information Age, where entire businesses can be run in the virtual world, a competitive edge lasts weeks, not years, and only the organisations who can effective balance risk and innovation, and then transform their business processes in support of that innovation, will succeed. And with everything outsourced, only the companies who are best able to chose, then integrate the most effective and flexible services, can hope to compete. The best Service Provider Integrators will be able to create entire white-labeled businesses from any concept.

In one of my earlier blogs; How Information Security Enables Transformational Change, I made the statement; “Information in context is knowledge, success however is in the correct application of that knowledge.”. The drive towards specialisation will accelerate in every service to be provided. It will be the organisations that are best able to correlate both the management information gathered over years of providing a specific services to multiple organisations, along with the ability to apply those skills to prospective clients, who will run away with the business. This will eventually create new Googles and Amazons, but they are where they are for a reason;

Good service.

[If you liked this article, please share! Want more like it, subscribe!]

========================

Update 22-Oct-13 09:23: Don’t normally add bad language to my posts, but this is too funny not to; www.foaas.com. My thanks to Steve R!

While this is most likely true in every industry, it is VERY true in cybersecurity.

Most organisations above the ‘corner store’ size have some form of ‘in-house’ IT support, even if it’s just the CEO’s brother-in-law, but only the larger organisation will have dedicated in-house security expertise. It’s simply too expensive.

However, most organisations need security expertise – usually when it’s too late unfortunately – so it’s crucial that they are able to define their specific needs in such a way as to attract the right suppliers of those services. Unfortunately, and all too often, the wrong questions lead to the wrong suppliers who provide the wrong services. If they gave you what you asked for, whose fault is it?

Instead, it makes sense to outsource the choice of your security services to someone best placed to judge; a security expert unhindered by organisational or employment commitments. i.e. they are not employed by a security company and are 100% ‘vendor neutral’ in terms of service or product ‘recommendations’.

Of course, you still have the problem of where to find this person, and ensure that they are the right person to make these choices on your behalf, and the responsibility for this due diligence must begin with the person most accountable. Whether this is the CEO, COO, or IT Manager or whatever, the individual who understands the business goals of the organisation needs to be the one asking the questions.

Many large organisations make the curious choice of allowing their purchasing departments to run the vendor selection process, often without specialist security input beyond the most basic of initial requirement definitions. This leads to an RFP that not only asks all the wrong questions, but also to reviews of the responses by people who don’t understand the answers. The choice is then often based on price and not capability turning the whole thing in a debacle.

You don’t allow your dentist to choose which law firm you use to represent you, why would you have anyone other than a security expert define your security solutions?

Even your in-house security team is under certain limitations, and cannot be truly objective with regard their choices. Whether it be pressure from above, fear of making a mistake, or vendor preference / bias, the choices are rarely the optimal result for the organisation. Nothing nefarious, just human nature.

The development of an overarching security program has many moving parts, and every step must be with a view to the end goals, the current needs (risk priorities), and the bit that’s often neglected; how each piece integrates with the next. The purchase of security services, and especial products/technology must be based on not only cost, but of how it will be installed, maintained, managed, monitored, and measured.

This can only be performed by a Governance function that has access to, and guidance from, a true security expert.

I can’t say that I’ve come across a service like this, perhaps I’ll start my own…

[If you liked this article, please share! Want more like it, subscribe!]