Security Rules and Procedures 30 July 2015 Summary of Changes, 30 July 2015
Total Page:16
File Type:pdf, Size:1020Kb
Security Rules and Procedures 30 July 2015 Summary of Changes, 30 July 2015 Summary of Changes, 30 July 2015 This manual reflects changes associated with announcements in MasterCard bulletins from 15 September 2014 to 15 July 2015, and additional terminology changes. To locate the changes listed below online, on the Adobe toolbar, click Find. In the Find box, type >> and then press ENTER. To move to the next change, press ENTER again. Description of Change Where to Look Removed definitions of the following terms: Dual Interface Hybrid POS Appendix F Terminal. Updated definitions of the following terms: Interregional Transaction; Appendix F Intraregional Tranaction. Added definitions of the following terms: Digital Goods; Dual Interface; Appendix F Identification & Verification (ID&V); Multi-Account Chip Card. NOTE: The changes to Appendix F (Definitions) cannot be located online using the Find box. Please scroll to Appendix F at the end of the manual to locate these changes. Added access instructions for the Card Production Physical Security 2.4 Requirements and the Card Production Logical Security Requirements. Clarified the CVC 2 value verification requirements for Issuers. 3.9.2 Clarified the CVC 2 value provision requirements for Acquirers. 3.9.4 Added section 6.2.1.4—Product Portfolio Management. 6.2.1.4 Updated the recommended additional monitoring parameters for Issuers. 6.2.1.5 (renumbered) Added section 6.2.1.6—Additional Prepaid Monitoring Requirements. 6.2.1.6 Added section 6.2.1.7—Fraud Detection Tool Implementation. 6.2.1.7 Added section 6.2.1.8—Cardholder Communication Strategy. 6.2.1.8 Clarified the Merchant deposit monitoring parameters for Acquirers. 6.2.2.2 Moved the 150 percent threshold recommendation for Acquirer fraud loss 6.2.2.3 control monitoring reports from section 6.2.2.2—Acquirer Merchant Deposit Monitoring Requirements to section 6.2.2.3. Updated the recommended additional monitoring parameters for 6.2.2.3 Acquirers. ©1991–2015 MasterCard. Proprietary. All rights reserved. Security Rules and Procedures • 30 July 2015 2 Summary of Changes, 30 July 2015 Description of Change Where to Look Updated references from website monitoring to Merchant monitoring. 6.2.2.3 7.2 13.2.2 Added MATCH compliance requirements for Acquirers. 7.1.2 NOTE: The MATCH compliance requirements added to section 7.1.2 were inadvertently omitted from the article, "Revised Standards for the Payment Facilitator and Service Provider Programs," published in Global Security Bulletin No. 10, 15 October 2014. Removed MCC 9754 from the types of non-face-to-face gambling 9.1 Merchants required to be registered using the MRP. 9.4.2 Added MCCs 7801 and 7802 to the types of non-face-to-face gambling 9.1 Merchants required to be registered using the MRP. 9.4.2 Removed MCC 9399 from the types of state lottery Merchants required to 9.1 be registered using the MRP. 9.4.4 Added MCC 7800 to the types of state lottery Merchants required to be 9.1 registered using the MRP. 9.4.4 Added website URL to the information requested for each Merchant, 9.2 Submerchant, or other entity required to be registered through the MRP system. Updated applicable references from MasterCard POS Transaction to Chapter 10 MasterCard Transaction. Updated applicable references from Maestro POS Transaction to Maestro Chapter 10 Transaction. Removed the definition of Point-of-Sale (POS) Transaction from the list of 10.2 Account Data Compromise Event terminology. Updated the ADC FR determination process. 10.2.5.5 Added references of fraudulent inter-European Maestro POS Transactions 12.2 to references of fraudulent intra-European Maestro POS Transactions. 12.6 Added section 12.8—Digital Goods Transactions. 12.8 ©1991–2015 MasterCard. Proprietary. All rights reserved. Security Rules and Procedures • 30 July 2015 3 Summary of Changes, 30 July 2015 Description of Change Where to Look Removed section 13.1.1.1—Merchant Risk Review Offering. 13.1.1.1 (deleted) ©1991–2015 MasterCard. Proprietary. All rights reserved. Security Rules and Procedures • 30 July 2015 4 Contents Contents Summary of Changes, 30 July 2015....................................................................2 Chapter 1: Customer Obligations...................................................................... 13 1.1 Compliance with the Standards..................................................................................14 1.2 Conflict with Law.......................................................................................................14 1.3 The Security Contact.................................................................................................. 14 Chapter 2: Card Production Standards............................................................15 2.1 Compliance with Card Production Standards..............................................................16 2.2 Monitoring of Personnel.............................................................................................16 2.3 Contracting with Card Registration Companies.......................................................... 17 2.4 Working with Vendors............................................................................................... 18 2.4.1 Order Request Required to Produce Cards...........................................................19 2.4.2 Stockpiling Plastics..............................................................................................19 2.5 Cards Without Personalization................................................................................... 19 2.6 Card Count Discrepancies.......................................................................................... 19 2.7 Reporting Card Loss or Theft......................................................................................19 2.8 Disposition of Unissued Cards and Account Information.............................................20 Chapter 3: Card and TID Design Standards.................................................. 21 3.1 Principles of Standardization...................................................................................... 22 3.2 MasterCard Account Number.....................................................................................22 3.3 Maestro and Cirrus Account Numbers........................................................................23 3.4 Signature Panel.......................................................................................................... 24 3.5 Magnetic Stripe or MasterCard HoloMag Encoding.................................................... 24 3.5.1 Card Validation Code 1 (CVC 1)......................................................................... 24 3.5.2 Service Code...................................................................................................... 24 3.5.3 Cardholder Name............................................................................................... 24 3.5.4 Expiration Date...................................................................................................26 3.6 Chip Cards.................................................................................................................26 3.6.1 Chip Card Applications.......................................................................................28 3.6.2 Multiple Application Chip Cards......................................................................... 28 3.6.3 Use of M/Chip Card Application Specifications....................................................29 3.7 Contactless Cards and Payment Devices..................................................................... 29 3.8 Mobile Payment Devices.............................................................................................30 3.9 Card Validation Code (CVC)....................................................................................... 30 3.9.1 Issuer Requirements for CVC 1........................................................................... 31 3.9.2 Issuer Requirements for CVC 2........................................................................... 32 ©1991–2015 MasterCard. Proprietary. All rights reserved. Security Rules and Procedures • 30 July 2015 5 Contents 3.9.3 Issuer Requirements for CVC 3........................................................................... 32 3.9.4 Acquirer Requirements for CVC 2....................................................................... 32 3.9.5 CVC Calculation Methods.................................................................................. 33 3.10 Service Codes...........................................................................................................34 3.10.1 Issuer Information.............................................................................................35 3.10.2 Acquirer Information........................................................................................ 35 3.10.3 Valid Service Codes...........................................................................................36 3.10.4 Additional Service Code Information.................................................................37 3.11 Transaction Information Documents (TIDs)................................................................37 3.11.1 Formset Contents............................................................................................. 38 3.11.2 POS Terminal Receipt Contents.........................................................................38 3.11.3 Primary Account Number Truncation and Expiration