{"id":2902,"date":"2022-06-16T11:00:14","date_gmt":"2022-06-16T08:00:14","guid":{"rendered":"https:\/\/www.endpointprotector.com\/blog\/?p=2902"},"modified":"2022-06-16T11:48:54","modified_gmt":"2022-06-16T08:48:54","slug":"pci-dss-compliance-and-remote-work","status":"publish","type":"post","link":"https:\/\/www.endpointprotector.com\/blog\/pci-dss-compliance-and-remote-work\/","title":{"rendered":"PCI DSS Compliance and Remote Work"},"content":{"rendered":"<p>Starting with the coronavirus (COVID-19) pandemic, companies across the world that wanted to maintain business operations and abide by new government-mandated regulations concerning the movement of individuals, have widely adopted remote work models. And while for certain types of jobs and sectors, this posed no great problems, others faced the danger of non-compliance with data protection regulations and industry standards.<\/p>\n<p>The\u00a0<a href=\"https:\/\/www.pcisecuritystandards.org\/pci_security\/\" target=\"_blank\" rel=\"noopener\">Payment Card Industry Data Security Standard<\/a> (PCI DSS) has long been considered a hurdle to remote work as compliance is hard to achieve in an uncontrolled environment such as an employee\u2019s home. PCI DSS is a set of 12 security requirements that helps businesses protect their payment systems from breaches, fraud, and theft of cardholder data. They include, among others, the need to implement strong access control measures, protect cardholder data and maintain an information security policy.<\/p>\n<p>While not legally binding, PCI DSS was adopted globally as a general standard by financial institutions, most notably banks, and is required for all companies that process, store or transmit credit card information from the world\u2019s biggest card schemes: American Express, Discover, JCB, MasterCard, and Visa.<\/p>\n<p>Non-compliance comes at a high price: organizations face fines of up to $100,000\/month and increased transaction fees and risk having their relationship with their bank terminated. Worse still, they can find themselves on the dreaded\u00a0<a href=\"http:\/\/www.mastercard.com\/elearning\/match\/story.html\" target=\"_blank\" rel=\"noopener\">MATCH<\/a> (Merchant Alert to Control High-Risk) list, which will ensure they will never be allowed to process card payments again.<\/p>\n<h2>PCI DSS Compliance in WFH environments<\/h2>\n<p>The PCI Security Standards Council (PCI SSC) has recognized the extraordinary circumstances companies around the world face and has issued <a href=\"https:\/\/blog.pcisecuritystandards.org\/protecting-payments-while-working-remotely\" target=\"_blank\" rel=\"noopener\">guidance<\/a> for remote work while stressing the need to maintain cybersecurity practices to protect payment card data. These best practices for work from home (WFH) environments, however, do not replace PCI DSS requirements but are meant to support companies to meet compliance while their employees work from home.<\/p>\n<p>According to the guidance, one of the best ways to guarantee continued compliance is to create and maintain a culture of security within the organization. This can be achieved through a security-awareness program that informs employees about a business\u2019s security policies and procedures and helps them understand their importance both for data security and compliance. If companies were PCI compliant prior to the ongoing health crisis, they should already have such a program in place as it is part of PCI DSS Requirement 12.6.<\/p>\n<p>In the case of remote work, the need to inform and educate employees increases: they must be made aware of the risks posed by working from home to <a href=\"https:\/\/www.endpointprotector.com\/blog\/5-best-practices-for-pci-dss-compliance\/\" target=\"_blank\" rel=\"noopener\">PCI DSS compliance<\/a> and what they need to do to ensure the continued security of systems, processes, and equipment supporting the processing of payment card data.<\/p>\n<p>While this can be challenging outside of the office, employees must know that the most essential requirement is that any systems used to process account data are securely maintained and not accessible to any unauthorized individual. This means protection against outside interference and any carelessness on the part of the employees themselves and blocking physical access to the place where their work is conducted. Employees should, therefore, maintain a home working environment where other members of their household cannot enter.<\/p>\n<h2>Securing Processes<\/h2>\n<p>The physical space where an employee is working remotely and processing card payments must be effectively monitored and access to it controlled at all times. Locking a home office space is one-way employees can prevent physical access to any systems that process account data. However, it is also essential that multi-factor authentication processes be put in place to make sure that, should someone gain physical access to the home office space, they will still not be able to access account data.<\/p>\n<p>Data transfer can also be controlled through <a href=\"https:\/\/www.endpointprotector.com\/solutions\/finance\" target=\"_blank\" rel=\"noopener\">Data Loss Prevention (DLP) tools<\/a> that allow companies to monitor credit card information transfers through predefined policies and block its transfer through insecure exit points such as file-sharing services or instant messaging applications, which employees might be tempted to use while working remotely.<\/p>\n<p>Any printed account data must also be securely stored, preferably under lock and key, and shredded or otherwise destroyed when it is no longer needed.<\/p>\n<h2>Limiting Data Exposure<\/h2>\n<p>Remote workers should only use company-approved hardware: whether it\u2019s laptops, phones, or removable devices. In this way, companies can maintain control of systems and the technology supporting payment processing. Organizations can ensure that no unauthorized devices are connected to work computers by the application of DLP <a href=\"https:\/\/www.endpointprotector.com\/solutions\/device-control\" target=\"_blank\" rel=\"noopener\">device control policies<\/a> on the endpoint which limit or block USB and peripheral ports altogether whether a device is online or not.<\/p>\n<p>It is also recommended that all company computers being used remotely have up-to-date firewalls, corporate antivirus solutions, and security patches installed. These security controls need to be configured in such a way that users cannot disable them.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Starting with the coronavirus (COVID-19) pandemic, companies across the world that wanted to maintain business operations and abide by new government-mandated regulations concerning the movement of individuals, have widely adopted remote work models. And while for certain types of jobs and sectors, this posed no great problems, others faced the danger of non-compliance with data &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/www.endpointprotector.com\/blog\/pci-dss-compliance-and-remote-work\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;PCI DSS Compliance and Remote Work&#8221;<\/span><\/a><\/p>\n","protected":false},"author":12,"featured_media":5865,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[162,115,1,156],"tags":[],"class_list":["post-2902","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-banking-financial-institutions","category-compliance","category-data-loss-prevention","category-work-from-home","entry"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/2902","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/comments?post=2902"}],"version-history":[{"count":13,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/2902\/revisions"}],"predecessor-version":[{"id":4990,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/posts\/2902\/revisions\/4990"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media\/5865"}],"wp:attachment":[{"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/media?parent=2902"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/categories?post=2902"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.endpointprotector.com\/blog\/wp-json\/wp\/v2\/tags?post=2902"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}