Sunday, October 14, 2007

PCI Compliance

My article discussed PCI compliance. The main topics it covered were; 1. Remote Access Security 2. Host Security 3. Network security. The old cash registers with the bells are out of date. Now almost everyone has a POS terminal hooked up to modem. POS machines are now essentially computers. However, the fact that these terminals are hooked up to the internet leaves the companies' POS systems vulnerable to attack by computer hackers. A virtual treasure trove of information is held in the POS systems, including credit card data and personal information. That is everything one would need to steal someone's identity.

Many vendors have remote access links set up for the terminals they sell for trouble shooting purposes. This is a very at-risk back door if you will. "The exploitation of improperly configured and unpatched remote management software tools is the most frequent method of attack used by hackers against POS payment systems."

The second security issue faced by new POS terminals is Host Security. The host is where everything is. Everything from authorization functionality to data back up takes place on the Host Server. “ Because so much information is stored or transmitted there, the host is considered to be the coveted “crown jewel” among hackers. A merchant must ensure that its host software does not store any prohibited data elements such as full magnetic stripe data or PIN data.”

The third security issue is network security. Many POS terminals are connect through a network via either high speed wireless, or wired. For this reason individual usernames and restricted access must be utilized, so as to know who did what where and when. One of the main problems is that many of the wireless routers that come from the store come out of the box containing default IDs and passwords that are supplied by the vendor. If a property is not careful to change the username and password that would leave the network wide open to attack. In fact, many default and IDs and passwords are available to criminals via the internet. Another vulnerability is physical attack. Devices can be placed on the terminals that catch and cop swiped credit cards.

I think this article is a good tool for any establishment. I received an email from Doubletree corporate office about the card catching devices that are being installed on the computers. People will work at a property for less than thirty days with the sole purpose of installing these gadgets and stealing credit card information. Now that we know where and what to look for management has to physically inspect all the terminals once or twice per week. I also know that not being PCI compliant can end up costing you a lot of money. A gentleman I met at a conference, works for a PCI compliance firm, and when he checked into his hotel in Orlando the hotel imprinted his card on the back of his registration card which had his address and other personal information. He is now suing that hotel and expects to win somewhere in the neighborhood of twenty-five thousand dollars.