Moving towards PCI DSS 3.0 compliance: A case study of credit card data security audit in an online payment company

M. R. Shihab, Febriana Misdianti
{"title":"Moving towards PCI DSS 3.0 compliance: A case study of credit card data security audit in an online payment company","authors":"M. R. Shihab, Febriana Misdianti","doi":"10.1109/ICACSIS.2014.7065872","DOIUrl":null,"url":null,"abstract":"E-commerce industry in Indonesia has grown rapidly since 2012. This development is also in line with the number of transactions that uses credit cards. Unfortunately, this phenomenon is followed by credit card frauds as well. Therefore, there is an urge for a standard to be used as a main reference in protecting the security of information. Visa and MasterCard have issued an international standard to ensure the security of credit card data, namely, PCI DSS. It emphasizes the importance of protecting cardholder information in one's daily business processes. On December 2013, the latest version of this standard was released, and brought about difficulties, even to those organizations that are already compliant to previous versions of the same standard. The aim of this research is to be able to identify the changes brought about by the latest PCI DSS, namely, version 3.0. Furthermore, this research is intended to implement that very standard to measure an organization's compliance level. This research uses a case study approach in Indonesia largest company in online payment services. The results of this research are the summation of 182 new controls that are simplified for use by organizations that have complied with PCI DSS 2.0 and are preparing for PCI DSS 3.0. Additionally, we found that Company X, the object of our case study, is compliant towards 77.43% of PCI DSS 3.0 requirements. Payment card industry data security standard is considered at its earlier stages. We believe that this research is one of the first in observing the changes brought about by PCI DSS 3.0 as well as in implementing it to measure an organization's compliance level.","PeriodicalId":443250,"journal":{"name":"2014 International Conference on Advanced Computer Science and Information System","volume":"16 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2014-03-23","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"4","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2014 International Conference on Advanced Computer Science and Information System","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICACSIS.2014.7065872","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 4

Abstract

E-commerce industry in Indonesia has grown rapidly since 2012. This development is also in line with the number of transactions that uses credit cards. Unfortunately, this phenomenon is followed by credit card frauds as well. Therefore, there is an urge for a standard to be used as a main reference in protecting the security of information. Visa and MasterCard have issued an international standard to ensure the security of credit card data, namely, PCI DSS. It emphasizes the importance of protecting cardholder information in one's daily business processes. On December 2013, the latest version of this standard was released, and brought about difficulties, even to those organizations that are already compliant to previous versions of the same standard. The aim of this research is to be able to identify the changes brought about by the latest PCI DSS, namely, version 3.0. Furthermore, this research is intended to implement that very standard to measure an organization's compliance level. This research uses a case study approach in Indonesia largest company in online payment services. The results of this research are the summation of 182 new controls that are simplified for use by organizations that have complied with PCI DSS 2.0 and are preparing for PCI DSS 3.0. Additionally, we found that Company X, the object of our case study, is compliant towards 77.43% of PCI DSS 3.0 requirements. Payment card industry data security standard is considered at its earlier stages. We believe that this research is one of the first in observing the changes brought about by PCI DSS 3.0 as well as in implementing it to measure an organization's compliance level.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
向PCI DSS 3.0遵从性迈进:在线支付公司信用卡数据安全审计的案例研究
自2012年以来,印尼的电子商务行业发展迅速。这一发展也与使用信用卡的交易数量一致。不幸的是,这种现象也随之而来的是信用卡欺诈。因此,迫切需要一个标准作为保护信息安全的主要参考。Visa和MasterCard已经发布了一个确保信用卡数据安全的国际标准,即PCI DSS。它强调了在日常业务流程中保护持卡人信息的重要性。2013年12月,该标准的最新版本发布,甚至对那些已经遵循同一标准的先前版本的组织也带来了困难。本研究的目的是能够识别最新的PCI DSS,即3.0版本所带来的变化。此外,本研究的目的是实现非常标准,以衡量组织的法规遵循水平。本研究采用印度尼西亚最大的在线支付服务公司的案例研究方法。这项研究的结果是182项新控制的总结,这些控制被简化了,供已经遵守PCI DSS 2.0并正在准备PCI DSS 3.0的组织使用。此外,我们发现我们案例研究的对象X公司符合77.43%的PCI DSS 3.0要求。支付卡行业数据安全标准尚处于早期阶段。我们相信,这项研究是第一次观察PCI DSS 3.0带来的变化,并实施它来衡量组织的合规水平。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Model prediction for accreditation of public junior high school in Bogor using spatial decision tree Campaign 2.0: Analysis of social media utilization in 2014 Jakarta legislative election Performance of robust two-dimensional principal component for classification Extending V-model practices to support SRE to build secure web application A comparison of backpropagation and LVQ: A case study of lung sound recognition
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1