0 Comments
LONDON - The ATM Industry Association's Debit Council says it is renewing its push for better security best practices at POS terminals, as criminals continue to compromise cardholder information by targeting out-of-date or improperly configured POS hardware and software.
 
According to Fair Isaac, more than 90 percent of card and PIN compromises in 2006 took place either inside outdated POS terminals or through improperly configured POS software coupled with poor key management practices. 
 
"All parties in the electronic payments value chain must be vigilant in the protection of our customers' data," said Mike Urban, a member of the Debit Council and Fair Isaac's senior director of fraud solutions. "The compromise of cardholder data is one of the biggest security risks retailers face. States (in the United States) are moving forward with legislation placing liability on merchants who are not appropriately safeguarding cardholder information."
 
An estimated 20 million POS devices are installed worldwide. The automation of credit and debit card transactions at the point of sale has been growing since the early 1980s.
 
In response to growing fraud trends, ATMIA has published Best Practices for Protecting the Point of Sale Lifecycle. According to ATMIA, the best-practices manual includes collaboration from both the ATM and POS industries - and represents the first time the two industries have worked together to produce security best practices for the entire POS lifecycle. The lifecycle model defines and addresses eight phases: cardholder security, compliance to existing industry standards, secure deployment of devices, physical security, PIN and encryption security, software security and security during the final de-commissioning process.
 
"The beauty of the lifecycle model is that it helps security practitioners to identify possible security vulnerabilities throughout the life of each POS device," said Mike Lee, ATMIA's chief executive and founder of ATMIA's Global ATM Security Alliance.
 
This manual is intended for retailers, POS processors, encryption service organizations, auditors, and security personnel and managers who have responsibility for securing POS installations and for meeting network and PCI requirements.
 
ATMIA expects to host a Debit Council meeting during its ATM Security in the Americas 2007 conference, which runs from Sept. 11 through Sept. 13, in Las Vegas.
 
For more information, contact Mike Lee.

Related Content

Reader Comments

Add a Comment

We welcome your thoughtful comments. All comments will display your real name.

Want to participate in the discussion?

Or log in for complete access.

  • Clear
  • Post
Be the first to post a comment for this story.
Products & Services

Training and Support

http://global2.networldalliance.com/new/images/products/training_7.jpg

132/Training-and-Support

KAL Software

http://global1.networldalliance.com/new/images/products/KAL_Logo_SF100.gif

885/KAL-Software

ATMeye.iQ

http://global1.networldalliance.com/new/images/products/4226.png

4226/ATMeye-iQ

KAL Check 21 Solutions

http://global2.networldalliance.com/new/images/products/KAL_Logo_SF100.gif

843/KAL-Check-21-Solutions

KingTeller -A8 Standard Lobby ATM

http://global1.networldalliance.com/new/images/products/1149.png

1149/KingTeller-A8-Standard-Lobby-ATM

PAI Secure for PCI Compliance

http://global1.networldalliance.com/new/images/products/4651.png

4651/PAI-Secure-for-PCI-Compliance

OptiVLM

http://global2.networldalliance.com/new/images/products/Optivlm100.gif

1239/OptiVLM

Casino and Gaming Solutions

http://global1.networldalliance.com/new/images/products/Casino_100.gif

334/Casino-and-Gaming-Solutions

ATM, EFT and POS Simulation and Testing Software - FASTest™

http://global2.networldalliance.com/new/images/products/Fastest_100.gif

864/ATM-EFT-and-POS-Simulation-and-Testing-Software-FASTest

PAI Wireless

http://global1.networldalliance.com/new/images/products/4657.png

4657/PAI-Wireless

Diebold Incorporated
Customer Experience Technology Buyer
Request Information From Suppliers
Save time looking for suppliers. Complete this form to submit a Request for Information to our entire network of partners.