Get a reputable firm to conduct a full-blown SAQ audit & confirm gaps
CIOREVIEW >> Cyber Security >> NEWS

The Avon

Michael P. O’Hara, Information Security Principal

Get a reputable firm to conduct a full-blown SAQ audit & confirm gaps

Michael P. O’Hara, Information Security Principal
Michael P. O’Hara, Information Security Principal, <a href='https://www.avonworldwide.com/' rel='nofollow' target='_blank' style='color:blue !important'>The Avon</a>

Due to our Merchant Level & lack of a QSA (qualified security assessor), we appointed a business partner who had the resources to spend 8 weeks running through a formalized SAQ. The QSAs spent a few hundred hours collecting/compiling the info, working with several stakeholders in digital & IT. Interviews were recorded & logged along with all other collateral generated during the process.

Their findings were around the same, but with the gravitas of formal artifacts – we would never become PCI-DSS in our current setup without ripping out & starting all over again. They also reinforced my original guesstimate around costs to avoid by rebuilding on-prem.

Note this is not an inexpensive exercise – but money well-spent. Having clarified around where you are for such a critical business process pays for itself many times over. You will not achieve that if you try to do this on your own – stay in your lane. Let the experts draw the picture.

Decide on a platform that can support the crown jewels:

As all revenues flow from our digital properties, the decision to move to a top-shelf cloud provider was easy – as it happened, we were able to piggyback off our parent company’s existing agreement. I will take economies of scale when possible.

Reduce the cost/complexity around your payment channel:

This is a great time to review your existing payment channel; as noted earlier, how/where credit-card data hits your infrastructure has an enormous impact on your obligations under PCI – as was the case with my company.   There was A) no tokenization done & B) even if the data was traversing physically/logically on our network. BAM – you’re SAQ-D & cannot escape that unless you consider the options available.

Another outcome that saved tons of time & funding was the decision to change providers & use an iFrame. This action drastically reduced your obligations – all the way down to SAQ-A, the lowest set of obligations (23 questions vs. the nearly 290 for SAQ-D).   The real heavy lifting for PCI-DSS was magically removed – a case study in Risk Transfer.

THE MIGRATION PROJECT

I will not go through this as it constitutes an entirely separate article on its own, involving many other groups. I can say it’s on a far better infrastructure that can grow easily.   Save yourselves the anguish of building on-prem… 95% of everyone will be up on AWS, Azure, or GCP in 10 years.

FINAL STEPS – THE QSA REVIEW & ATTESTATIONS

Once the site went live, I jumped at the opportunity to engage with our third-party vendor to have the SAQ-A reviewed.   In terms of time/effort involved, it was about 4 days of work with the QSA to prove our 23 questions were all answered in the affirmative…. That is as opposed to the ten weeks we burned (with more resources dedicating time from their day job) while doing our SAQ-D.   If you put a per-hour cost to these, it’s clear the annual costs between D & A are quite significant.

The QSA reviewed all the collateral from those 4 days & signed off on two documents affirming our attestation:

AoC                       Attestation of Compliance, which you have to provide to your payment providers.

RoC                       Report on Compliance (all the dirty details behind how they could sign off on AoC).

And that was that – the company achieved PCI-DSS for the first time.   It is a major milestone for both the company & those who led the project.   Come to the renewal – yes, this isn’t something you have in perpetuity – I will be ready & totally know what the process looks like.

LESSONS LEARNED ON THE PCI CERT JOURNEY:

1. It provides opportunities for public relations.   Customers/businesses are more likely to trust & do business with e-commerce sites that have the seal of approval.

2. Being able to hassle your credit-card companies on any fraud that may happen on their systems makes for recovery of lost funds far, far easier.   Without certification, they will say have a nice day – and no funds returned.

3. You can make this an opportunity to shore up your cyber defenses on your e-comm platform; the SAQ

4. You can GREATLY ease the burden of PCI-DSS with one simple stroke – change to an iFrame that sits totally outside your network.   And like magic, your obligations go from D à A (which is all of 23 questions, most of which are Mickey Mouse).   You pay for it but are handing over the truly heavy lifting to your provider.

5. Do not give these solutions a second thought. Do them & don’t look back. The more levels of anti-fraud you drop in, the better your customer experience:

a. MFA… put this in NOW. If you were ever curious how pervasive personal account breaches were, look at www.haveibeenpwned.com. ‘Nuff said.  

b. Tokenization combined with an iFrame from a reputable provider (CyberSource, Chase, etc.) should also be a hill to die on.   If you farm this out, you avoid the nasty parts of the SAQ.

c. Use device fingerprinting. Bots & bad actors will weasel their way onto your site – they will likely fail if the black box chews on customer history (who, where, when, how) and finds anomalies.

d. Get OUT of your on-premise. The cloud provider infrastructures are insanely scalable & available.

The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.