As indicated by the PCI SSC in its current version “Best Practices for Implementing PCI DSS into Business-as-Usual Processes” and based on the premise that Security is something that degrades over time, as well as the fact that complying with PCI DSS does not end with its implementation but implies continuous work to manage ongoing compliance.
Internet Security Auditors, through its PCI DSS Technical Office (OTP) proposal, provides its clients with a service to ensure continuity in maintaining the standard in a practical and effective way, integrated within their technological and security operations.
Among others, the activities carried out by the OTP include:
- Initial implementation.
- Maintaining PCI DSS compliance when the following are incorporated into the environment:
- New systems, networks, applications/developments or changes to existing ones.
- New processes/services or changes to existing ones.
- Newly acquired companies.
- New service providers.
- New staff or changes in roles.
- Managing changes in the standard and/or validation requirements.
- Continuous updating of the Documentation Framework.
- Ongoing training: Knowing at all times the changes to the PCI DSS standard and validation requirements.
- Monitoring third parties:
- Service providers on behalf of merchants and financial institutions.
- Merchants on behalf of financial institutions.
- Other third parties on behalf of service providers.
- Validating compliance with security requirements:
- Quarterly ASV and internal vulnerability scans.
- Review and update of SAQ questionnaires.
- Annual QSA compliance audits.
- Internal/external penetration tests.
- Code reviews, quarterly WiFi analyses, etc.
- Reporting to brands and financial institutions.
- Review of controls and risks.
The OTP provides the necessary services to implement and maintain PCI DSS compliance with:
- Expert personnel, with regular training from the card brands themselves, working as part of the client’s staff.
- Tools best suited to manage compliance.
- Methodologies aligned with standards.
- Training/knowledge transfer that makes it possible to maintain control.
All this allows Internet Security Auditors, through the OTP, to offer outsourced centralization of PCI DSS management to financial institutions, merchants and service providers, enabling:
- Reduced costs in resources and time for implementing and maintaining PCI DSS.
- For OTP clients to focus their effort on their business without completely detaching from PCI DSS.
- Having centralized support by phone, email and onsite as a single point for resolving questions and incidents related to compliance.
How financial institutions benefit from the OTP services to manage their merchants and service providers:
- Continuous control of the compliance status of the institution itself and its merchants, managing risk more efficiently.
- Simplification of reporting to the brands on the compliance of their merchants.
- Loyalty-building for existing merchants and added value for new merchants.
How merchants and service providers benefit from the OTP services:
- Continuous management of compliance.
- Simplification of reporting to entities.
- Offering a higher level of confidence to entities and card brands regarding compliance.