Understanding PCIDSS Part 2: Roles and Responsibilities within the PCIDSS and Card Payment Circle.
Adewale Adeife, CISM
Cyber Risk Management and Technology Consultant || GRC Professional || PCI-DSS Consultant || I help keep top organizations, Fintechs, and financial institutions secure by focusing on People, Process, and Technology.
The PCI DSS was created by 5 founding payment brands namely Visa, Mastercard, American Express, Discover, and JCB. In November 2020 a new member called Union Pay was added. Each founding member has an internal compliance program. It secures against threats and secures other elements in the payment system. If data is outsourced to a third party, the organization is responsible for ensuring that the third party protects the Cardholder's data. The PCI DSS does not supersede local or regional laws.
The PCI DSS provides a baseline of technical and operational requirements designed to protect account data. it applies to all entities that store, process, transmits, or impact the security of? cardholders' data which includes;
What is Sensitive Authentication Data?
Sensitive Authentication Data (SAD) is a data which cannot be stored after authorization but issuers or entities providing issuing services can store SAD after authorization if there is a legitimate business justification.
Merchant Levels
Each payment brand defines its merchant level which is based on the volume of transactions per year.?
PCI DSS Levels
The PCI DSS standard recognizes that not all organizations have equal risk factors or equal capability to roll out security infrastructure. The specific requirements for meeting the standard that your organization will need to meet will depend on your company’s level, which is in turn determined by how many credit card transactions you process annually:
Level 1
This assessment is done by a QSA company that delivers the ROC at the end of the assessment. After the ROC is complete, they would need to provide an attestation of compliance AOC to the acquirer. They also need to provide an Approved Scanning Vendor (ASV). This is a report that shows that the environment in the scope of the PCI DSS is scanned quarterly for vulnerabilities.??
Level 2, 3, 4?
They usually complete a SELF-ASSESSMENT QUESTIONAIRE (SAQ)
Roles and Responsibilities within the PCIDSS
Internal Security assessor-ISA
The ISA is the subject matter expert from the organization who leads the engagement and is the main point of contact for all the activities regarding PCI.
Responsibilities
领英推荐
Qualified Security Assessor- QSA
Merchants and Service Providers
Acquirers
Payment Brands
The card payment cycle
Whenever you make payment with a card for any good or service, it goes through three payment circles namely;
1. Authorization?
2. Clearing
3. Settlement?
Authorization
Clearing
Duration: One day
Settlement
Duration:2 Days
Kindly read and share.
Product Experience and User Engagement Leader | Founder, Brave Achievers | Forging creative pathways and next generation of Product experts
8 个月As an Identity Product Design leader, understanding PCI DSS roles and responsibilities is crucial for my work. @Adewale Adeife's insights highlight how key players—merchants, service providers, acquirers, and PCI-SSC—ensure the security of cardholder data. I believe that this framework is essential for maintaining trust and compliance in financial transactions. Staying informed about these responsibilities helps us design more secure, user-centric identity solutions. #PCIDSS #IdentityDesign #SecurityByDesign
Head of Audit | Cybersecurity & Compliance Leader | Experienced Lawyer (LL.M) | ISO 27001, PCI DSS, SOC 2, GDPR | Third-Party Risk | Information Security Awareness Trainer | Data Privacy & Regulatory Compliance
8 个月Great write up Adewale Adeife . It is very easy to read and understand. In addition, there is this fact about the Levels that is usually not emphasized....The levels depend on the payment brands. For example, Level 1 for Visa is different for Level 1 for Discover or JCB.