BankInfoSecurity.com - Banking Information Security News, Regulations, & Education
BankInfoSecurity.com Banking Information Security Careers Banking Information Security Training Banking Information Security Blogs

Username:
Password:
Remember Username?
Register | Help
Agency Releases
Articles
Handbooks
Podcasts
Webinars
White Papers

Take the 2010 Banking Information Security Today Survey

Results to be Unveiled at RSA Conference on March 2
Bank Information Security RSS Syndication Bank Information Security Articles

Credit
Eligible
As a BankInfoSecurity.com annual member, this content can be used toward your membership credits and transcript tracking. Click For More Info
Heartland Back on Visa's List as PCI Compliant
RBS WorldPay Still Not Recertified After Data Breach
May 6, 2009 - Linda McGlasson, Managing Editor


Comment on this article

Heartland Payment Systems (HPY) has made it back onto Visa's list of PCI DSS Validated Service Providers. The announcement comes almost six weeks after the credit card payment processor was taken off the list and four months since it announced its networks had been breached and credit card information stolen.

Calling the recertification its "annual PCI DSS assessment," Heartland says it was put back on the list on May 4. VeriSign was the company hired to do the recertification work, says Jason Maloni, Heartland's spokeperson. The list, www.visa.com/cisp, says Heartland was recertified on April 30, and VeriSign is listed as the Qualified Security Assessor (QSA).

Visa requires all service providers that store, process or transmit Visa account data to validate PCI DSS compliance every 12 months. Businesses that validate their PCI DSS compliance utilizing a qualified security assessor (QSA) are listed on Visa's List of Compliant Service Providers.

"Earlier this year, Heartland Payment Systems publicly disclosed unauthorized access to their systems resulting in the compromise of card account information from all major card brands. Based on compromise event findings, Visa removed Heartland from its list of PCI DSS compliant service providers," says Eduardo Perez, head of global data security at Visa

Perez says that since January 20, when Heartland first announced the data breach publicly, Heartland worked with a QSA (VeriSign) to revalidate and submit a Report on Compliance. "Visa has reviewed their report and is satisfied that previous deficiencies have been addressed," Perez states.

Click to Get Updates on the Latest Information Security News

Perez says Visa is pleased that Heartland has been committed to working diligently to improve its systems and meet the PCI DSS requirements. "It's essential that every business that handles payment card information adhere to the highest standards to protect the security and privacy of their customers' financial information. The PCI DSS remains an effective security tool when implemented properly - and remains the best defense for businesses against the loss of sensitive data."

The other company that was removed from the list during the same time period, RBS WorldPay, has not yet received recertification and is not back on the list. RBS WorldPay announced its computer systems were hacked in November 2008 and sent out notification letters (PDF) to affected cardholders beginning on December 23, 2008.





Question
Question
?What difference does it make to your institution that Heartland is once again PCI compliant?
Here's your chance to be heard by your peers in the banking and finance industry! Your comments will be kept anonymous. Just enter your comment to the right and click submit to send it to our Editor.
Please login if you would like to post a comment on this question.

"The PCI DSS are based on a common book of knowledge for information security best practices.

They are valid "standards" just as the FFIEC standards are valid.

The problem is most of these card processors were trying to pull a fast one and claim they had compensating controls that addressed those standards, when in reality they did not.

You must take a security approach to compliance. You waste more money chasing after a checkbox versus simply building a strong security program that as a byproduct easily demonstrates compliance.
"My question is: do PCI checks and audits really serve the security cause?
Whyever Heatland was on the PCI compliant list before being compromised? This states the PCI audit or the PCI standard itself is not sufficient to preserve cardholders data.
Now that Heartland is on the PCI compliant list again doesn't ensure the data could not be compromised, as it has been before.

Search for Articles
in

 More on this Topic:

  Recent   Popular   Research  



Blogs Related Blog Entries
Tom FieldNew Information Security Survey - Why it Matters
"If trust and security are big parts of your equation, then there's a lot to learn from this survey's results"



BankInfoSecurity.com is your one-stop portal for the latest news, insights and education on the top information security issues facing U.S. financial institutions today. Through articles, webinars, podcasts, customized training and sponsored content, our team is committed to providing up-to-date information on the security regulations, threats, solutions, training and career trends that most impact banks, credit unions and other related enterprises. Also, please check out our companion site, CUInfoSecurity.com.
Terms of Service | Advertise | Archive | Site Map | Contact | Bank Information Security RSS Syndication RSS Syndication
Copyright © 2010 BankInfoSecurity.com an ISMG Corp. company.