If you came this far you did one of the following when you read the title:

1. Scoffed;

2. Screwed up your forehead in confusion, or;

3. Laughed.

Good, these all mean you’re cynical and therefore a perfect audience, so let me put you out of your misery; this is a story of unintentional cause and effect, and has started a trend that will not stop until credit cards as we know them are dead and buried.

About time too. 60+ year old technology in payments is akin to leaches in medicine (no offence card brands, but this analogy is particularly relevant).

When PCI was first drafted, it was very clear for whom it was geared; e-commerce organisations running Windows. How do you translate the configuration standard requirements (for example) to someone working on a mainframe. For Windows, you take out what you don’t need (hardening), for zOS, you build in only what you need. What about logging? Can syslog record everything you need in 10.2.X?

This is one of the most minor issues that drove organisations to seek alternatives to compliance, cost / effort / ROI, you name it, PCI is a burden any way you look at it. Yes, cardholder data should be protected, but enforcement of a single standard across all industry sectors and business types was never going to work.

At first, organisations became VERY creative in making their PCI burden go away. From outsourcing, to revamping all business processes in favour of truncated card numbers (except authorisation of course), to going back to cash only (not kidding). While almost EVERY merchant organisation should consider the first 2 anyway, it really didn’t help either retail, or e-commerce.

So the first foray into a technical ‘innovation’ was to make PCI go away for areas where they could not fix their systems to a degree that supported PCI compliance. Organisations started looking for alternatives to processing the full cardholder data; tokenisation was born (poetic licence, we’ve had forms of tokenisation for centuries). But this does nothing for authentication traffic which requires the fill account number.

Then came my personal favourite; Point to Point Encryption (P2PE), a.k.a. – and before the SSC decided to kibosh it – End to End Encryption (E2EE). The theory is very sound; encrypt the data for the point of interaction (usually a Pin Entry Device, or PED) all the way to the point of decryption, but the eventual PCI-approved solution is as complex as the DSS, limited (currently) to approved hardware devices, and requires a degree of certification few have even looked at.

A lot of organisations put their entire PCI programme on hold until such times as the P2PE standards were defined, and now that the first one (hardware/hardware) cannot apply to them, they continue to do nothing until such times as a hybrid standard is released.

So what you have here is; PCI forced the innovation, which in turn caused a justifiable delay in doing anything at all, which means that cardholder data is no better protected. Brilliant.

So P2PE, which had so much promise, is now stagnant. Organisations SHOULD have developed software solutions for legacy PEDs 3 years ago, which would have almost forced acceptance. But no-one did, and now it’s too late. How do you standardise a P2PE solution for an infinite number of scenarios? You don’t obviously, but with the advent of the next innovation, even PEDs themselves are becoming redundant…

We have the ultimate PCI and card brand killer; Mobile Applications / Mobile Payments. Still fairly new, growing exponentially – and to add the ultimate piece of irony – but cannot be PCI complaint unless the device was built for purpose. In other words, smart phones and tablets, by themselves, can never be PCI compliant. Not that this will stop their use.

Mobile payments, in all its forms, is already forcing the CARD BRANDS to innovate, or in the case of Visa, buy interest in vendors like The Square. But the SSC, as a standards only body, can never keep up. Eventually, as credit card numbers decline, so will the SSC and ALL it’s standards, and a replacement will be formed when people realise this massive drive for innovation has set us BACK in security…again.

That’s my final point of this blog; unless security is built in from the ground floor of this wave of innovation, the innovators will be directly responsible for the impossible-to-follow standards of the future.

As long as there are profit drivers, and Windows OS, I will always have a job…

 

In my White Paper on Selecting the Right QSA, I liken security to the law, in that it is becoming increasingly complicated, specialised, and inaccessible to businesses too small to afford in-house expertise. Unless you’re Fortune/FTSE 100, this is most likely your business.

I also introduce these core concept in the form of a highly artistic and creative Word table (what’s the punctuation for irony?).

With the plethora (one for you Three Amigos fans) of regulations, enforcement bodies, and good practice standards out there, it’s no surprise organisations are stuck in the mode of analysis paralysis. Every requirement for data protection cares only for their specific data type / jurisdiction / use / retention etc, so who is supposed to make sense of this for a business that just wants to sell their widgets?

Unfortunately, only the business concerned can put the necessary commercial perspective on this. However, seeing as ALL security boils down to the same core concepts or common denominators, this is likely easier than you think. Yes, you may still need professional help, but if all you are doing is talking about your business goals, you can leave the security part up to your consultant.

In my experience, there are only 6 security program core concepts:

1. Risk Assessment (RA) & Business Impact Analysis (BIA) – If you can’t (in some form) qualify/quantify your business risks related to your sensitive data, and then determine an estimated cost-of-loss related to data theft or unavailability, how will you know how much to spend on security? Put simply; if the cost of security outweighs the value of the data, don’t do it (this includes compliance). This does NOT mean you should do nothing at all, it just means you need to re-evaluate how you perform some of your business functions. The first question is not “How do I protect it?”, it’s “Do I need it?”

2. Security Control Selection & Implementation – The RA, done correctly, will show you where you can make improvements in your security posture. This does not necessarily involve capital expenditure – which should always be the LAST resort – it can be something as simple as destroying every instance of redundant data. Regardless, at some point you will probably purchase technology, but even here you should be careful (In Security, Technology is Always the Last Resort) and ensure that this new technology meets all of the business needs defined in the RA.

3. Security Management Systems – There’s not much point putting security controls in place if you don’t manage them properly to keep them in place. This is where standards like ISO 2700X come into play. This includes the day-to-day procedures used to maintain the operational aspect of your security infrastructure. Obviously this will vary dramatically by organisation; from a simple check-list for your corner sandwich shop, to a full time job for larger more complex organisations. The trick is doing only what’s appropriate without going overboard.

4. Governance & Change Control – Ask 100 people what Governance is, and you’ll get 105 different answers. I believe governance provides a function that trumps all others; it allows the business side of an organisation to talk to the IT side in the same language. Business: “I want this new functionality.”, IT: “Sure, but do it this way.” is the perfect conversation. IT, and especially IT security, are typically seen as roadblocks, but this is just a symptom of immature Governance processes. As for change control, that’s just common sense. If things don’t change, the only increase in security risk is from external sources. The threat landscape changes almost daily, why make things worse by screwing up internally as well?

5. Incident Response (IR) & Disaster Recovery (DR) – Fairly self-explanatory; what’s the point of being in business if you don’t intend staying in business? For example; if you are an e-comm company, you should know from the RA what your maximum downtime is, and both your security controls and IR & DR processes need to fit according.

6. Business Continuity Management (BCM) & Business As Usual (BAU) – You may ask why this is broken out from IR & DR. I do this because BCP and BAU are more related to the business side of the table, and IR & DR are on the IT side. IT never leads, IT enables, it’s the business side that needs to lay down the plans for staying in business, as well as how to do so efficiently, and cost effectively.

I know its a bold statement, but if you follow these core concepts, it won’t matter the compliance regime, the data type, of even the type / location you’re business is in, you’ll be covered …mostly. These are the concepts on which I founded Core Concept Security, Ltd.

Yes, this is a lot of work, and the up-front costs in both capital and resource terms can be significant, but it’s a damned sight cheaper than the cost of non-compliance, fines, and particularly; being breached. In the extreme, what if it’s the difference between you being in business at all?

As the Americans say, it’s a no-brainer.

[If you liked this article, please share! Want more like it, subscribe!]

In recent months, I have had time to reflect on many things, one of which was my career choices over the course of the last 12+ years.

I came to the conclusion that loyalty, while absolutely critical, can potentially put you in a tough position should you ever decide on a change. Your organisation must also match your degree of loyalty, or the negative effect on your motivation / morale is the same.

Like people, organisations change over time. What was once a place that deserved, and even earned your continued efforts, can change into something that is best left behind. Nothing nefarious, or even negative, it’s just not right for you, and if you’re not paying close attention, you may not notice this deviation until it’s too late. Or the decision is made for you of course

Everyone needs to develop their personal career vision statement, and list the corresponding values. If the organisation for whom you work does not mostly mirror these values, it may be time to re-evaluate. This evaluation exercise should be repeated often, and especially if there is a significant event on either side of the table.

My vision statement would read something like; “Security before regulation, service before profit.”, and my values would include: integrity, hard work, and enablement (I teach, I don’t just consult). Do you know yours? Does your company post theirs on their website for all to see? Do they live and breathe them?

Companies are the communities of old, where you should feel part of something bigger than yourself, that you are making a positive difference, and maybe – just maybe – receive a little bit of appreciation. This feeling of belonging cannot be attained if your values are different from theirs.

As a manager of a very disparate and diverse group of consultants across 14 time zones, I tried to guide my guys into a little introspection. Whether it was about their own strengths, career progression, or even the organisation for whom we worked, I was never going to get the best out of them unless they truly wanted to be there. This comes from shared vision, and matching values, not from a salary.

So finally, I’m not saying quit if things aren’t perfect, they never will be, but where previously you would not entertain calls from recruiters, take the calls. Where you think you’re underpaid / under-appreciated, go find out if other companies can provide more of what you are looking for.

Above all, know what’s important to you, and don’t be taken by surprise!!

[If you liked this article, please share! Want more like it, subscribe!]

Finally, some common sense is starting to prevail;

http://www.huntonprivacyblog.com/2013/06/articles/hunton-webinar-on-the-proposed-eu-regulation-developing-a-more-creative-approach/

Detractors say that this is diluting the original intent of the directive, but as I have seen so many times in PCI, if you don’t make it achievable, you cannot enforce it fairly.

Risk based approach is always the way…

Anyone who’s worked in PCI for more than 5 minutes knows it has serious limitations with regard security. Even security of cardholder data, which is the only type of date to which it relates!

That’s because PCI DSS was not written with comprehensive security in mind, or would not start and end where it does.  It was designed to be security-enough to keep the US Federal Government off Visa/MC/Amex/et al backs.  You would not be surprised to hear that things like this generally happen when someone important is inconvenienced.  In this case, a couple of senators were the victims of credit card breach.

Good security never ends, but it almost always starts with a business need, followed by a Risk Assessment.  The end of a security life cycle instance is when the business continuity plan has been updated, and security processes become business as usual.  PCI builds in the Risk Assessment (that’s what the 260-odd controls are), does not allow for residual risk, and stops at Incident Response.

In other words, and if you take the PCI DSS to the negative extreme, neither the card brands nor the SSC care if compliance fits your business needs, nor does it care if you even stay in business (as long as the cardholder data is safe).

Clearly this is not the case, they do care (to a point), but the issue is that the majority of organisations working towards compliance either do not care about security themselves (it’s just another cost of doing business), or they do care and just don’t know how to go about it.

So where is the good in PCI?  It’s twofold (for the purposes of this post);

1. It has significantly raised the profile of security in general as a business necessity, and;

2. It has driven innovation to an amazing degree into a SIXTY+ year old payment technology …the credit card number (blog pending on this).

OK, so the PCI DSS is limited, but at least they did what NO-ONE has done before, or since; actually defined what they consider to be a minimum standard of data protection.  Every other standard says things like ‘appropriate’, or ‘reasonable’.  Appropriate and reasonable to whom?  The PCI DSS says you must have a firewall capable of stateful packet inspection, you must have up to date configuration standards, encryption, logging, POLICIES and so on.  The way to compliance is WRITTEN DOWN FOR YOU!

Of course, it’s not that easy, and the confusion is where to start, and how to implement compliance in a way that suits the business, not the other way around.  A good QSA can help (White Paper:  Selecting the Right QSA), but the assessment process starts with the CEO and a culture of security.

The PCI DSS has, and continues to change the security climate for the better, all you need is the right perspective, and the right guidance.