Security Rules and Procedures—Merchant Edition • 27 February 2020 2 Contents

Total Page:16

File Type:pdf, Size:1020Kb

Security Rules and Procedures—Merchant Edition • 27 February 2020 2 Contents Security Rules and Procedures Merchant Edition 27 February 2020 SPME Contents Contents Chapter 1: Customer Obligations........................................................................ 8 1.1 Compliance with the Standards....................................................................................9 1.2 Conflict with Law.........................................................................................................9 1.3 The Security Contact.................................................................................................... 9 1.4 Connecting to Mastercard—Physical and Logical Security Requirements....................... 9 1.4.1 Minimum Security Requirements.........................................................................10 1.4.2 Additional Recommended Security Requirements................................................11 1.4.3 Ownership of Service Delivery Point Equipment.................................................. 11 1.4.4 Component Authentication................................................................................ 11 Chapter 2: Cybersecurity Standards and Programs..................................12 2.1 Cybersecurity Standards............................................................................................. 13 Cybersecurity Minimum Requirement.......................................................................... 13 Cybersecurity Best Practice.......................................................................................... 13 2.1.1 Payment Card Industry (PCI) Security Standards.................................................. 14 2.2 Mastercard Site Data Protection (SDP) Program...........................................................16 2.2.1 Customer Compliance Requirements.................................................................. 17 2.2.2 Merchant Compliance Requirements.................................................................. 17 Level 1 Merchants...................................................................................................18 Level 2 Merchants...................................................................................................18 Level 3 Merchants...................................................................................................19 Level 4 Merchants...................................................................................................19 2.2.3 Service Provider Compliance Requirements......................................................... 19 Level 1 Service Providers..........................................................................................20 Level 2 Service Providers..........................................................................................20 2.2.4 Mastercard Cybersecurity Incentive Program (CSIP)............................................. 20 Mastercard PCI DSS Risk-based Approach............................................................... 20 Mastercard PCI DSS Compliance Validation Exemption Program.............................. 21 2.2.5 SDP Program Noncompliance Assessments......................................................... 23 2.2.6 Mandatory Compliance Requirements for Compromised Entities........................ 24 2.4 PIN Security Standards................................................................................................24 2.4.1 PIN Entry Devices (PEDs) and Encrypting PIN Pads (EPPs)......................................25 Secure Deployment and Management of PEDs and EPPs......................................... 25 2.4.2 Software-based PIN Entry using PIN CVM Applications........................................26 Secure Deployment and Management of PIN CVM Applications..............................26 Chapter 3: Card and Access Device Design Standards............................ 28 3.11 Consumer Device Cardholder Verification Methods.................................................. 29 ©1991–2020 Mastercard. Proprietary. All rights reserved. Security Rules and Procedures—Merchant Edition • 27 February 2020 2 Contents 3.11.1 Mastercard Qualification of Consumer Device CVMs.........................................29 3.11.2 CDCVM Functionality....................................................................................... 29 3.11.3 Persistent Authentication..................................................................................31 3.11.4 Prolonged Authentication.................................................................................31 3.11.5 Maintaining Mastercard-qualified CVM Status.................................................. 31 3.11.7 Use of a Vendor................................................................................................32 3.12.4 Acquirer Requirements for CVC 2..........................................................................32 3.13 Service Codes...........................................................................................................32 3.13.2 Acquirer Information........................................................................................ 33 3.13.3 Valid Service Codes...........................................................................................33 3.13.4 Additional Service Code Information.................................................................34 Chapter 4: Terminal and PIN Security Standards....................................... 35 4.1 Personal Identification Numbers (PINs)........................................................................36 4.3 PIN Verification...........................................................................................................36 4.5 PIN Encipherment.......................................................................................................36 4.6 PIN Key Management.................................................................................................37 4.6.1 PIN Transmission Between Customer Host Systems and the Interchange System........................................................................................................................ 37 4.6.2 On-behalf Key Management...............................................................................38 4.7 Terminal Security Standards........................................................................................39 4.8 Hybrid Terminal Security Standards.............................................................................39 4.9 Triple DES Standards...................................................................................................40 Chapter 5: Card Recovery and Return Standards...................................... 41 5.1 Card Recovery and Return..........................................................................................42 5.1.1 Card Retention by Merchants............................................................................. 42 5.1.1.1 Returning Recovered Cards......................................................................... 42 5.1.1.2 Returning Counterfeit Cards....................................................................... 42 5.1.1.3 Liability for Loss, Costs, and Damages......................................................... 43 Chapter 6: Fraud Loss Control Standards...................................................... 44 6.2 Mastercard Fraud Loss Control Program Standards..................................................... 45 6.2.2 Acquirer Fraud Loss Control Programs................................................................ 45 6.2.2.1 Acquirer Authorization Monitoring Requirements........................................45 6.2.2.1.1 Additional Acquirer Authorization Monitoring Requirements for High-Risk Negative Option Billing Merchants...................................................... 45 6.2.2.2 Acquirer Merchant Deposit Monitoring Requirements................................. 46 6.2.2.3 Acquirer Channel Management Requirements............................................ 47 6.2.2.4 Recommended Additional Acquirer Monitoring...........................................47 6.2.2.5 Recommended Fraud Detection Tool Implementation..................................47 ©1991–2020 Mastercard. Proprietary. All rights reserved. Security Rules and Procedures—Merchant Edition • 27 February 2020 3 Contents 6.2.2.6 Ongoing Merchant Monitoring................................................................... 48 6.3 Mastercard Counterfeit Card Fraud Loss Control Standards........................................ 48 6.3.1 Counterfeit Card Notification..............................................................................48 6.3.1.2 Notification by Acquirer.............................................................................. 48 6.3.1.3 Failure to Give Notice..................................................................................49 6.3.2 Responsibility for Counterfeit Loss...................................................................... 49 6.3.2.1 Loss from Internal Fraud..............................................................................49 6.3.2.3 Transactions Arising from Unidentified Counterfeit Cards............................49 6.3.3 Acquirer Counterfeit Liability Program................................................................ 49 6.3.3.1 Acquirer Counterfeit Liability.......................................................................50 6.3.3.2 Acquirer Liability Period...............................................................................50
Recommended publications
  • Set of Rules for AAU Credit Cards with Corporate Liability - Staff
    Aalborg University Set of rules for AAU credit cards with corporate liability - staff Disclaimer This set of rules for AAU credit cards with corporate liability has been translated into English from the Danish language. However, the original Danish text shall be the governing text for all purposes and in any discrepancies. Finance and Accounts Department Translated into English 28 May 2014 Contents 1. Introduction ..................................................................................................................................................2 2. Who can obtain an AAU credit card with corporate liability? ......................................................................2 3. Application for a credit card with corporate liability ...................................................................................2 4. Personal data ................................................................................................................................................2 5. Receipt of credit card and PIN ......................................................................................................................3 6. Card holder's obligations ..............................................................................................................................3 7. User guide for holders of credit cards with corporate liability ....................................................................3 8. Settlement of e-transactions on credit cards with corporate liability ..........................................................4
    [Show full text]
  • The Millennials Influence
    RESEARCH 2016 THE MILLENNIAL INFLUENCE HOW MILLENNIALS OF THE USA WILL SHAPE TOMORROW’S PAYMENTS LANDSCAPE USA INTRODUCTION CONTENTS INTRODUCTION 3 This research into US millennials’ Millennials are coming of age – the I hope you find these insights and payments behavior is part of our long- oldest of them are hitting the peak of themes both interesting and useful WHAT ARE WE TALKING ABOUT? 4 standing commitment to play a leading their economic productivity and their and encourage you to continue the role in the discussion about the future of greatest purchasing power. Their choices, debate through our online hub OUR AIMS AND APPROACH 5 payments systems. their behaviors and their concerns are Vocalink CONNECT. MILLENNIALS AND THEIR TECH 6 set to profoundly shape developments Having been at the forefront of across every spectrum of business and SOCIAL MILLENNIALS 8 developments in our industry for 60 commerce, and nowhere more so than years, we see proprietary research and in how they access their money. Starting MILLENNIALS AND THEIR MONEY 10 market analysis as a fundamental part in the US, and moving to South East Asia of our offering. As providers of the and Europe, we are taking a close look CARA O’NIONS HOW MILLENNIALS LIKE TO PAY 12 infrastructure through which so much at what millennials are saying about how MARKETING AND CUSTOMER of business and personal commerce INSIGHT DIRECTOR THE MILLENNIAL INFLUENCE 14 they want to pay and what this means for is conducted, we are uniquely well- the next generation of payments. HOW MILLENNIALS LIKE TO BE PAID 16 placed to explore and offer insight on emerging trends and behaviors For us this has already been a MILLENNIALS AND MOBILE PAYMENTS 18 in the way people and organizations fascinating journey, and we’re only want to access and move their money.
    [Show full text]
  • Introduction: History
    Introduction: "Key to the global village", that is how the Smart Card has been described. Smart Cards will bring big changes to the way people provide and receive information and the way they spend money. They will have a profound impact on retailing and service delivery. A Smart Card is like an "electronic wallet". It is a standard credit card-sized plastic intelligent token within which a microchip has been embedded within its body and which makes it 'smart'. It provides not only memory capacity, but computational capability as well and thus the chip is capable of processing data. It has gold contacts that allow other devices to communicate with it. This chip holds a variety of information, from stored (monetary) value used for retail and vending machines to secure information and applications for higher-end operations such as medical/healthcare records. New information and applications can be added depending on the chip capabilities. Smart Cards can store several hundred times more data than a conventional card with a magnetic stripe and can be programmed to reveal only the relevant information. For example, it could tell a device in a store that there is sufficient balance in an account to pay for a transaction without revealing the balance amount. The marriage between a convenient plastic card and a microprocessor allows information to be stored, accessed and processed either online or offline. Therefore, unlike the read-only plastic card, the processing power of Smart Cards gives them the versatility needed to make payments, to configure your cell phones, TVs and video players and to connect to your computers via telephone, satellite or the Internet anytime, anywhere in the world.
    [Show full text]
  • EMF Implementing EMV at The
    Implementing EMV®at the ATM: Requirements and Recommendations for the U.S. ATM Community Version 2.0 Date: June 2015 Implementing EMV at the ATM: Requirements and Recommendations for the U.S. ATM Community About the EMV Migration Forum The EMV Migration Forum is a cross-industry body focused on supporting the EMV implementation steps required for global and regional payment networks, issuers, processors, merchants, and consumers to help ensure a successful introduction of more secure EMV chip technology in the United States. The focus of the Forum is to address topics that require some level of industry cooperation and/or coordination to migrate successfully to EMV technology in the United States. For more information on the EMV Migration Forum, please visit http://www.emv- connection.com/emv-migration-forum/. EMV is a trademark owned by EMVCo LLC. Copyright ©2015 EMV Migration Forum and Smart Card Alliance. All rights reserved. The EMV Migration Forum has used best efforts to ensure, but cannot guarantee, that the information described in this document is accurate as of the publication date. The EMV Migration Forum disclaims all warranties as to the accuracy, completeness or adequacy of information in this document. Comments or recommendations for edits or additions to this document should be submitted to: ATM- [email protected]. __________________________________________________________________________________ Page 2 Implementing EMV at the ATM: Requirements and Recommendations for the U.S. ATM Community TABLE OF CONTENTS
    [Show full text]
  • POS Interface Specifications ISO 8583 (1987 Version)
    POS Interface Specifications ISO 8583 (1987 version) Prepared by: Nigeria Inter – Bank Settlement System (NIBSS) Version: 1.16 August 07, 2018 Page 1 of 64 POS ISO 8583 Interface Specification TABLE OF CONTENTS POS INTERFACE SPECIFICATIONS .................................................................................... 1 ISO 8583 (1987 VERSION) ............................................................................................... 1 DOCUMENT CONTROL .................................................................................................... 3 1. INTRODUCTION ....................................................................................................... 4 2. EXTERNAL MESSAGE TYPES ........................................................................................ 5 2.1 PROTOCOL ............................................................................................................ 5 2.2 BITMAP .................................................................................................................... 5 2. 3 SUPPORTED MESSAGE TYPE ......................................................................................... 5 3. EXTERNAL MESSAGE TYPE LAYOUTS ........................................................................... 6 3.1 AUTHORIZATION REQUEST/REPEAT (0100) ..................................................................... 6 3.2 AUTHORIZATION REQUEST RESPONSE (0110) .................................................................. 7 3.3 FINANCIAL REQUEST/REPEAT (0200) ..........................................................................
    [Show full text]
  • Mastercard Frequently Asked Questions Platinum Class Credit Cards
    Mastercard® Frequently Asked Questions Platinum Class Credit Cards How do I activate my Mastercard credit card? You can activate your card and select your Personal Identification Number (PIN) by calling 1-866-839-3492. For enhanced security, RBFCU credit cards are PIN-preferred and your PIN may be required to complete transactions at select merchants. After you activate your card, you can manage your account through your Online Banking account and/or the RBFCU Mobile app. You can: • View transactions • Enroll in paperless statements • Set up automatic payments • Request Balance Transfers and Cash Advances • Report a lost or stolen card • Dispute transactions Click here to learn more about managing your card online. How do I change my PIN? Over the phone by calling 1-866-297-3413. There may be situations when you are unable to set your PIN through the automated system. In this instance, please visit an RBFCU ATM to manually set your PIN. Can I use my card in my mobile wallet? Yes, our Mastercard credit cards are compatible with PayPal, Apple Pay®, Samsung Pay, FitbitPay™ and Garmin FitPay™. Click here for more information on mobile payments. You can also enroll in Mastercard Click to Pay which offers online, password-free checkout. You can learn more by clicking here. How do I add an authorized user? Please call our Member Service Center at 1-800-580-3300 to provide the necessary information in order to qualify an authorized user. All non-business Mastercard account authorized users must be members of the credit union. Click here to learn more about authorized users.
    [Show full text]
  • STATE of MICHIGAN CENTRAL PROCUREMENT SERVICES Department of Technology, Management, and Budget 525 W
    STATE OF MICHIGAN CENTRAL PROCUREMENT SERVICES Department of Technology, Management, and Budget 525 W. ALLEGAN ST., LANSING, MICHIGAN 48913 P.O. BOX 30026 LANSING, MICHIGAN 48909 CONTRACT CHANGE NOTICE Change Notice Number 1 to Contract Number 200000002198 Program Fidelity Information Services, LCC Manager Various MDHHS CONTRACTOR 601 Riverside Avenue STATE Jacksonville, FL 32204 Administrator Kim Bynan Contract Joy Nakfoor DTMB 414-577-9861 (517) 249-0481 [email protected] [email protected] VC0006630 CONTRACT SUMMARY ELECTRONIC BENEFITS TRANSFER (EBT) FOR SNAP AND WIC PROGRAMS INITIAL EFFECTIVE DATE INITIAL EXPIRATION DATE INITIAL AVAILABLE OPTIONS EXPIRATION DATE BEFORE November 1, 2020 September 14, 2027 1 - 3 Year September 14, 2027 PAYMENT TERMS DELIVERY TIMEFRAME N/A ALTERNATE PAYMENT OPTIONS EXTENDED PURCHASING ☐ P-Card ☐ PRC ☐ Other ☐ Yes ☒ No MINIMUM DELIVERY REQUIREMENTS N/A DESCRIPTION OF CHANGE NOTICE OPTION LENGTH OF OPTION EXTENSION LENGTH OF EXTENSION REVISED EXP. DATE ☐ ☐ September 14, 2027 CURRENT VALUE VALUE OF CHANGE NOTICE ESTIMATED AGGREGATE CONTRACT VALUE $22,655,691.55 $0.00 $22,655,691.55 DESCRIPTION Effective August 24, 2021, the new Go Live date is August 29, 2021. As of the Go Live, pricing is updated to: - SNAP CSR Cost per Minute is $0.699 (per the attached Schedule B – MDHHS SNAP Pricing, II. Call Center/Telecommunication). - WIC Cost per Case Month is $0.414 (per the attached Schedule B – MDHHS WIC Pricing, A. Cost Per Case Month). All other terms, conditions, specifications and pricing remain the same. Per contractor and agency agreement, and DTMB Central Procurement approval. CHANGE NOTICE NO. 1 TO CONTRACT NO.
    [Show full text]
  • Smart Cards Vs Mag Stripe Cards
    Benefits of Smart Cards versus Magnetic Stripe Cards for Healthcare Applications Smart cards have significant benefits versus magnetic stripe (“mag stripe”) cards for healthcare applications. First, smart cards are highly secure and are used worldwide in applications where the security and privacy of information are critical requirements. • Smart cards embedded with microprocessors can encrypt and securely store information, protecting the patient’s personal health information. • Smart cards can allow access to stored information only to authorized users. For example, all or portions of the patient’s personal health information can be protected so that only authorized doctors, hospitals and medical staff can access it. The rules for accessing medical information can be enforced by the smart card, even when used offline. • Smart cards support strong authentication for accessing personal health information. Patients and providers can use smart health ID cards as a second factor when logging in to access information. In addition, smart cards support personal identification numbers and biometrics (e.g., a fingerprint) to further protect access. • Smart cards support digital signatures, which can be used to determine that the card was issued by a valid organization and that the data on the card has not been fraudulently altered since issuance. • Smart cards use secure chip technology and are designed and manufactured with features that help to deter counterfeiting and thwart tampering. • Smart cards can help to reduce healthcare fraud by providing strong identity authentication of patients and providers. The use of secure smart chip technology, encryption and other cryptography measures makes it extremely difficult for unauthorized users to access or use information on a smart card or to create duplicate cards.
    [Show full text]
  • 2020 Annual Report Discover Card • $71 Billion in Loans a Leading • Leading Cash Rewards Program
    2020 Annual Report Discover Card • $71 billion in loans A Leading • Leading cash rewards program Student Loans Digital Bank • $10 billion in student loans and Payments • Offered at more than 2,400 colleges Personal Loans • $7 billion in loans • Debt consolidation and major purchases Partner Home Loans • $2 billion in mortgages Discover is one of the largest digital banks in the United • Cash-out refinance and home loans States, offering a broad array of products, including credit cards, personal loans, student loans, deposit products Deposit Products and home loans. • $63 billion in direct-to-consumer deposits • Money market accounts, certificates The Discover brand is known for rewards, service and of deposit, savings accounts and checking value. Across all digital banking products, Discover seeks accounts to help customers meet their financial needs and achieve brighter financial futures. Discover Network Discover Global Network, the global payments brand of • $181 billion volume Discover Financial Services, strives to be the most flexible • 20+ network alliances and innovative payments partner in the United States and around the world. Our Network Partners business provides payment transaction processing and settlement services PULSE Debit Network on the Discover Network. PULSE is one of the nation’s • $212 billion volume leading ATM/debit networks, and Diners Club International is a global payments network with acceptance around Diners Club International the world. • $24 billion volume To my fellow shareholders, A year has passed since our world changed virtually overnight as we faced the greatest public health crisis in a century and the resulting economic contraction. We remain grateful to those on the front lines of this battle, including healthcare and emergency workers, and everyone who has taken personal risk to make sure the essential services of our society keep running.
    [Show full text]
  • V PAY Card Disclosure, Terms and Conditions
    account information V PAY Card Disclosure, Terms and Conditions Table of Contents I. Types of Payments or Transfers ......................................... 2 II. General Rules .................................................................... 2 III. Fees and Limits on Transfer Amount ............................... 4 IV. Account Holder’s Liability for Unauthorized Charges ...... 4 V. Special Rules for Other Uses ............................................. 5 VI. Other Disclosures and Information ................................. 5 V PAY Disclosure, Terms, and Conditions The following information is being provided to you in accordance with Regulation E and the Electronic Funds Transfer Act, and German law. Service Federal Credit Union (Service CU) intends the V PAY Card for use in Europe only. NOTE: The Service CU V PAY Card (formerly, Girocard) will be activated only in support of point-of-sale (POS) debit transactions, to include contactless transactions. Uses of this card for ATM withdrawals, as a chip-based purse (GeldKarte), or to support third party applications are not authorized. I. TYPES OF PAYMENTS OR TRANSFERS The cardholder may use the Service CU V PAY Card (hereinafter referred to as “Card”), for the following payment services. A. In combination with the Personal Identification Number (PIN), which includes Contactless Payment, in German debit card systems: For use at retailers and service companies at POS terminals operated under the German electronic cash system identified by the V PAY logo. B. In combination with the PIN, which includes Contactless Payment, in foreign debit card systems: For use at retailers and service companies at POS terminals operated under a foreign system, provided that the Card is issued with the corresponding functions. In some countries, a signature may be requested instead of a PIN, depending on the system.
    [Show full text]
  • Pre-Solicitation Instructions
    CALIFORNIA DEPARTMENT OF TECHNOLOGY PRE-SOLICITATION INSTRUCTIONS TO: All Interested Bidders RE: Pre-Solicitation Feedback DATE: November 9, 2016 The California Department of Technology (CDT) requests feedback and/or questions on the following Pre- Solicitation documents. FOR: ELECTRONIC WOMEN, INFANT AND CHILDREN MANAGEMENT INFORMATION SYSTEMS (eWIC MIS) PRE-SOLICITATION REVIEW 1. eWIC MIS Project Request for Proposal (RFP) in its entirety a. Part 1 – Bidders Instructions b. Part 2 – Bidders Response 2. Exhibit 22 – Cost Workbook Please note these documents are drafts and are subject to change. GENERAL QUESTIONS If the answer is yes to any of the questions below, please explain. 1. Are there any requirements for which assumptions are required to be made to provide a response? 2. Are there areas in the Statement of Work (SOW) that you believe are not clear? 3. Are there any Sections which are inconsistent and/or contradictory? 4. Is any additional information needed to prepare a response? REQUIREMENTS 1. Are there any requirements too onerous or which may result in unnecessary costs or risks to the State? If so, please indicate which ones and explain why. 2. Are there any requirements which may prevent you from submitting a response? If so, what are they, and why would they prevent you from responding? 3. Are there any requirements which may make it difficult to implement the solution by April 1, 2020? If yes, why? OTHER 1. Please provide a Rough Order of Magnitude (budgetary estimate) of the total costs for the solution required by this RFP. 2. Please review Section 5, Cost (Part 2) and Exhibit 22, Cost Worksheet, of the RFP and provide input on whether the Section and worksheet(s) are clear, concise, complete, and easy to use.
    [Show full text]
  • Centurion® Cardmember Agreement Table of Contents
    CENTURION® CARDMEMBER AGREEMENT TABLE OF CONTENTS CARDMEMBER AGREEMENT Language .............................................................................10 Introduction .......................................................................... 2 Changes ...............................................................................10 Use of your Account and Codes ........................................... 2 Assignment ..........................................................................11 Permitted Uses ...................................................................... 3 Severability ..........................................................................11 Prohibited Uses ..................................................................... 3 Suspension ...........................................................................11 Statements ............................................................................. 4 Default .................................................................................11 Charge Card / Interest Charges ........................................... 4 Cancelling This Agreement/Closing The Account ........... 12 No Pre-set Spending Limit .................................................. 5 Communicating with You ...................................................12 Fees and Commissions ......................................................... 5 No Waiver of our Rights ......................................................13 Liability................................................................................
    [Show full text]