PCI 3DS
OVERVIEW
The PCI Security Standards Council (PCI SSC) announced two new security standards to support secure implementation of EMVCo's EMV 3-D Secure (3DS) protocol. EMV® 3DS helps prevent unauthorized card-not-present (CNP) transactions. It protects merchants from exposure to CNP fraud by enabling consumers to authenticate themselves with their card issuers when making online purchases through web browsers or via mobile applications. Together the work of EMVCo and PCI SSC ensures an agile and workable framework is established for both functional testing and security evaluation of EMV® 3DS solutions.
More About PCI SSCStandard
The PCI Security Requirements and Assessment Procedures for EMV® 3-D Secure Core Components: ACS, DS, and 3DS Server (referred to as PCI 3DS Core Security Standard) and the PCI Security Requirements and Assessment Procedures for EMV® 3-D Secure SDK (referred to as PCI 3DS SDK Security Standard) focus on securing the EMV® 3DS infrastructure that supports 3DS transactions:
The PCI 3DS Core Security Standard supports the EMV® 3-D Secure Protocol and Core Functions Specification, and is for entities that manage, provide or assess 3DS Access Control Server (ACS), Directory Server (DS), and 3DS Server components. The PCI 3DS Core Security Standard defines appropriate security controls to protect these specific 3DS environments, which are critical to the 3DS transaction process. Training will be available for eligible Qualified Security Assessors (QSA) to support assessments of these PCI 3DS environments to the PCI 3DS Core Security Standard.
The PCI 3DS SDK Security Standard supports the EMV® 3-D Secure SDK Specification, which defines EMV® 3DS requirements for entities developing 3DS Software Development Kits (SDK) for use in mobile-based 3DS transactions. The standard is for developers and vendors of 3DS SDK products, and it is focused on ensuring the SDK has been designed and developed with security in mind.
The PCI SSC is also developing a supporting validation program for early 2018, which it had first test as a pilot program in 2017. The final program will include a PCI SSC listing of SDK solutions that meet the PCI 3DS SDK Security Standard.
Consulting Service
One of the first certified PCI 3DS QSA in the world that makes us the first company to obtain 3DS qualification, as well as a leading company to provide both PCI DSS and 3DS consulting and assessment service, we have established a comprehensive and streamlined process to ensure your data security and achieve compliance.
Since the establishment of Secure Vectors, professional teams have been recognized by the market, and many corporate compliance experience will reflect the professional knowledge of the company's professional team behind the process. It may affect the 3D security environment or the security of the third party provider, and can assist the compliance and complete compliance with the standard consultant through the professional team of our company.
In addition to the first part of the benchmark security demands strict firewalls, network security, the implementation of manufacturers must accept external vulnerability scanning four times a year (Vulnerability Scan), external penetration testing (Penetration Test), the external and internal weaknesses of scanning each year, and to establish a strict monitoring, 24 hours of incident response and other information security requirements. After completing the first part “benchmark safety requirements”, the second part will assist in the import, “3DS safety requirements”, focusing on the 3DS data, technology and processes, and provide safety control measures for these functions.
In addition to the PCI SSC standard of payment card industry related safety standards, there are other related services:
- PCI DSS Compliance Assessment (Level 1-4) compliance review service.
- PCI 3DS compliance review service.
- PCI DSS and PCI 3DS consulting services.
- PCI DSS and PCI 3DS technical services, including vulnerability scanning, ASV scanning services, penetration testing (PT), and source code review.
- Payment card collection business system construction consulting (with system builder or software supplier).
- Training service of external card receiving management personnel (all kinds of operation management personnel required by the training and payment card industry).
- Safety management personnel training (training safety technical engineer, network management engineer, database security management engineer, etc.).