Securetrust Service Description Web Risk Monitoring
Total Page:16
File Type:pdf, Size:1020Kb
SecureTrust Service Description Web Risk Monitoring Copyright © 2018 Trustwave Holdings, Inc. All rights reserved. 1 SecureTrust WRM Service Description - January 27, 2021 WEB RISK MONITORING (WRM) ................................................................................................................ 3 SERVICE DESCRIPTION ................................................................................................................................. 3 BASE SERVICE FEATURES ............................................................................................................................. 3 WRM Overview ....................................................................................................................................... 3 Content Monitoring ................................................................................................................................. 5 Merchant Intelligence.............................................................................................................................. 5 Malware Monitoring ................................................................................................................................ 7 Custom Monitoring.................................................................................................................................. 8 Transaction Laundering Detection (TLD) ............................................................................................... 8 Merchant MCC Code Matching .............................................................................................................. 8 WRM Additional Paid Services ............................................................................................................... 9 DELIVERY AND IMPLEMENTATION ................................................................................................................... 9 Service Initiation ..................................................................................................................................... 9 Phase I: Merchant Onboarding............................................................................................................... 9 Phase 1a: Card brand service provider registration ............................................................................. 10 Phase II: Transaction Laundering Preparation ..................................................................................... 10 Phase IIIa: Merchant Monitoring........................................................................................................... 10 Phase IIIb: Transaction Laundering Detection Monitoring ................................................................... 10 Phase IV: Merchant cancellation .......................................................................................................... 11 Phase V: Card Brand Violation Notifications ........................................................................................ 11 Merchant Discovery Process ................................................................................................................ 11 Invoice Calculation................................................................................................................................ 12 SECURETRUST RESPONSIBILITIES ................................................................................................ 12 CLIENT RESPONSIBILITIES ............................................................................................................... 12 Copyright © 2020 SecureTrust, Inc. All rights reserved. 2 SecureTrust WRM Service Description - January 27, 2021 Web Risk Monitoring (WRM) SERVICE DESCRIPTION The SecureTrust WRM solution (“WRM”) offers acquirers and independent sales organizations a full suite of protection for monitoring and reducing risk, to help reduce costs and increase revenues. WRM supports compliance with card brand monitoring requirements, detects merchant violations, reduces risks, and simplifies the delivery of additional services (e.g. web malware monitoring, which adds value to merchant programs). The WRM process is managed through the SecureTrust web portal (the “Portal”). SecureTrust will set the parameters for the identification of questionable and illegal content and malware scanning. BASE SERVICE FEATURES Clients can purchase each of the WRM features described below separately or in a bundle. WRM Overview Analysis WRM analyzes e-commerce websites (provided by SecureTrust’s partners as URLs) by applying SecureTrust’s patented automated content-analysis techniques, which reviews standard categories identified as being critical to risk management and brand protection programs. SecureTrust’s Web Risk Analysis Team (each member shall be referred to herein as an “Analyst”) utilizes the WRM Analyst Workstation, a data and evidence collection platform, to review all websites identified by the automated analysis system as potentially violating card brand rules or Client Terms of Service, including the content and links of such websites. This analysis process provides a multi-tier workflow, in which an Analyst may escalate a finding to a Senior Analyst for review. All suspected website findings are reviewed by a Senior Analyst prior to being reported to the Client. This process produces more thorough results and reduces false positive cases. WRM also performs automated website security analysis using industry leading vulnerability and security scanning systems. Reporting and Data Access All WRM components produce data that is available either in reports or through the online data explorers in the Client’s Portal account. These reports and data are intended to provide a detailed look into a specific merchant or trends affecting the merchant portfolio. WRM allows automated reporting to card brand protection programs such as the MasterCard MMP. The MasterCard MMP Reporting Tool allows Client to review an automatically generated report that meets MasterCard’s specification within the Portal, send the report on-demand, or enlist the tool to automatically send the report securely to MasterCard on a monthly basis. This tool is designed to allow the Client a simple and effective way to meet MasterCard MMP’s requirements after Client has registered SecureTrust as Client’s Merchant Monitoring Service Provider (MMSP) per MasterCard MMP program requirements. Copyright © 2020 SecureTrust, Inc. All rights reserved. 3 SecureTrust WRM Service Description - January 27, 2021 Portal Access WRM provides a modern, user-friendly Portal which provides access for Client’s users. The information available includes a top-level summary dashboard covering the types of violations found on merchant websites which allows the Client to view the evidence needed to make educated decisions regarding each violation. The evidence gathered and stored with each violation can be downloaded in a PDF report and used when following up with the merchant involved. The URL of the Portal is: https://portal.securetrust.com/. Sponsor Hierarchy WRM features a multi-tiered Sponsor View hierarchy set-up, allowing a global view for Clients with disparate entities that want to have a single view into the overall merchant risk of their organization. Each Client sponsor in the hierarchy will have its own merchants, scan schedules, and users defined. Users at the top sponsor level will have visibility into their sub-sponsors. The WRM dashboard provides aggregate summary information across the current sponsor and any sub- sponsors. Client may also select specific sponsors for concentrated analysis. Scan Types and Frequency WRM offers three types of merchant website scanning for Clients who purchase Content Monitoring, Merchant Intelligence, Malware Monitoring, and/or Custom Monitoring services. Each scan of a merchant website follows a similar process, detailed as follows: • Test that the website is valid and is available via IPV4 on the public internet • Crawl the first 100 pages of the website and store the HTML code in temporary storage • Analyze the content of the HTML code that was retrieved by the crawler • Content violations detected are reported for Analyst review • SecureTrust Web Risk Analyst team reviews and classifies potential violations or clears them • Results of each scan are made available in the Portal for review by Client Onboarding Scan: A Onboarding Scan assists the Client with onboarding and underwriting online merchants. Client may submit scans to the Portal at any time and receive a result within minutes. Results are aggregated in a Score Card Report to identify a merchant’s areas of risk. Automated Routine Scan: The content analysis engine will scan merchant websites on an automated routine schedule. The most common frequency for scanning of merchant websites is once per month; however, the frequency can be adjusted to match specific program goals for additional services fees. Different merchant portfolios may be scanned at varying frequencies. Client will be billed for each successful scan of a merchant website. On-Demand Scan: An On-Demand Scan can be submitted by the Client via the Portal at any time for any active merchant in the portfolio to assist with investigations outside of the Automated Routine Scan schedule. Copyright © 2020 SecureTrust, Inc. All rights reserved. 4 SecureTrust WRM Service Description - January 27, 2021 Content Monitoring Card Brand Program Specification Content Monitoring in WRM is designed to monitor the content