Merchants 5 Step Guide
To PCI Compliance







 ISO / Acquirers 5 Step Guide
To PCI Compliance









 PCI COMPLIANCE
INFO









 PCI COMPLIANT
VENDORS


 About Us











Step One: Spot/investigate the breach

The PCI DSS Self Assessment Questionnaire is an excellent way to spot or investigate a data breach, whether or not your organization is currently PCI compliant.

In the case of Bananas.com, it was months before they realized that a breach had taken place.

For TJX, it took several years after the breach for the company to realize that 45.7 million credit card numbers had been compromised. The company is still reeling from paying out settlements, upwards of 40 million dollars, for class-action suits against them.

If your organization is hit by a data breach, the first thing to do is to detect where the breach occurred, by looking at all of the IT departments, including network and systems, Internet activity or whether there has been a physical theft of a computer or computer hard drive. Additionally, utilizing and monitoring intrusion detection systems (IDS) can give vital information on data breaches.

Once your organization has determined the type of breach and what sector it affects, it's time to determine the scope and size of the damage from the data breach.

This data breach assessment includes:
  • The number of customers affected.
  • Systems that are damaged or infected by malicious intrusions, if applicable.
  • The exact type of data breach-Was it credit card numbers? Social Security Numbers? Vital statistic information? Address and telephone numbers?
  • Projected amount of cost to repair the damage from the organization perspective and, most importantly, the customer aspect.
  • A complete list of compromised accounts
  • Decisions as to whether to monitor, freeze or close affected accounts, if applicable.
  • Blocking and reissuing credit cards, if needed
  • Monitoring and studying affected accounts
  • Determining fraud patterns


pci compliance                      pci compliance asv


pci compliancePrint this page

Send this page to a friend

Data Breaches Part I
- Is it possible to prevent the inevitable?

Introduction

Step 1: A Good Defense is an Offense

Step 2: Perform a company-wide risk assessment/inventory

Step 3: Educate employees on breach/data security

Step 4: Create a pre-breach containment and communication plan

Step 5: Create a rapid response and internal audit/compliance team

Epilogue: Spend now or pay later

Introduction

New changes to PCI DSS Self Assessment Questionnaire

Step 1: Spot/investigate the breach

Step 2: Circle the wagons: Deploy the rapid response team

Step 3: Create a Notification Plan

Step 4: Implement the Notification/Communications Plan

Step 5: Perform a response audit after the event

Navigating state disclosure laws

Outsourcing data breach response to a third-party

Recommended reading
PCI Compliance Polls

Are you currently PCI Compliant?
Yes
No
Working towards compliance

Why are you looking at PCI Compliance
Required By Credit Card Processor
Required By Bank
Want to meet industry standards
Looking to secure network

What merchant level do you fall under for PCI Compliance?
Level 1
Level 2
Level 3
Level 4
I have no idea
View PCI Merchant Level Results
View All PCI Compliance Poll Results

EV SSL Certificate Guide

Sponsored Listing:

|  Home  |  About PCI Compliance |  For Acquirers |  Find PCI Compliance Solutions | 
|  Preventing Data Breaches |  Managing Data Breaches |  Contact Us |    EV SSL Certificate Guide | 
© 2008 PCI Compliance Guide.org
   All right reserved - do not copy any material without written permission.