HOME

TheInfoList



OR:

The Payment Application Data Security Standard (PA-DSS), formerly referred to as the Payment Application Best Practices (PABP), is the global security standard created by the
Payment Card Industry Security Standards Council The Payment Card Industry Security Standards Council (PCI SSC) was formed by American Express, Discover Financial Services, JCB International, MasterCard and Visa Inc. on September 7, 2006, with the goal of managing the ongoing evolution of the ...
(PCI SSC). PA-DSS was implemented in an effort to provide the definitive data standard for
software Software is a set of computer programs and associated software documentation, documentation and data (computing), data. This is in contrast to Computer hardware, hardware, from which the system is built and which actually performs the work. ...
vendors that develop payment applications. The standard aims to prevent developed payment applications for third parties from storing prohibited secure data including
magnetic stripe The term digital card can refer to a physical item, such as a memory card on a camera, or, increasingly since 2017, to the digital content hosted as a virtual card or cloud card, as a digital virtual representation of a physical card. They share ...
, CVV2, or
PIN A pin is a device used for fastening objects or material together. Pin or PIN may also refer to: Computers and technology * Personal identification number (PIN), to access a secured system ** PIN pad, a PIN entry device * PIN, a former Dutch ...
. In that process, the standard also dictates that software vendors develop payment applications that are compliant with the Payment Card Industry Data Security Standards (
PCI DSS The Payment Card Industry Data Security Standard (PCI DSS) is an information security standard used to handle credit cards from major card scheme, card brands. The standard is administered by the Payment Card Industry Security Standards Council a ...
). Ultimately PA-DSS and its validation program will be incorporated into the PCI Software Security Framework. It is planned that PA-DSS will be retired in late 2022 once the expiry dates of payment applications validated to PA-DSS v3.2 is reached.


Requirements

For a payment application to be deemed PA-DSS compliant, software vendors must ensure that their software includes the following fourteen protections: # Do not retain full track data, card verification code or value (CAV2, CID, CVC2, CVV2), or PIN block data. # Protect stored cardholder data. # Provide secure authentication features. # Log payment application activity. # Develop secure payment applications. # Protect wireless transmissions. # Test payment applications to address vulnerabilities and maintain payment application updates. # Facilitate secure network implementation. # Cardholder data must never be stored on a server connected to the Internet. # Facilitate secure remote access to payment application. # Encrypt sensitive traffic over public networks. # Secure all non-console administrative access. # Maintain a PA-DSS Implementation Guide for customers, resellers, and integrators. # Assign PA-DSS responsibilities for personnel, and maintain training programs for personnel, customers, resellers, and integrators.


Governance and enforcement

PCI SSC has compiled a list of payment applications that have been validated as PA-DSS compliant, with the list updated to reflect compliant payment applications as they are developed. Creation and enforcement of these standards currently rests with PCI SSC via Payment Application- Qualified Security Assessors (PA-QSA). PA-QSAs conduct payment application reviews that help software vendors ensure that applications are compliant with PCI standards.


History

Governed originally by
Visa Inc. Visa Inc. (; stylized as ''VISA'') is an American multinational financial services corporation headquartered in San Francisco, California. It facilitates electronic funds transfers throughout the world, most commonly through Visa-branded cred ...
, under the PABP moniker, PA-DSS was launched on April 15, 2008 and updated on October 15, 2008. PA-DSS then became retroactively distinguished as "version 1.1" and "version 1.2". In October 2009, PA-DSS v1.2.1 was released with three noted changes: # Under “Scope of PA-DSS,” align content with the PA-DSS Program Guide, v1.2.1, to clarify applications to which PA-DSS applies. # Under Laboratory Requirement 6, corrected spelling of “OWASP.” # In the Attestation of Validation, Part 2a, update “Payment Application Functionality” to be consistent with the application types listed in the PA-DSS Program Guide, and clarify annual re-validation procedures in Part 3b. In October 2010, PA-DSS 2.0 was released, indicating: ''Update and implement minor changes from v1.2.1 and align with new PCI DSS v2.0. For details, please see PA-DSS – Summary of Changes from PA-DSS Version 1.2.1 to 2.0.'' In November 2013, PA-DSS 3.0 was released, indicating: ''Update from PA-DSS v2. For details of changes, please see PA-DSS – Summary of Changes from PA-DSS Version 2.0 to 3.0.'' In May 2015, PA-DSS 3.1 was released indicating:''Update from PA-DSS v3.0. See PA-DSS – Summary of Changes from PA-DSS Version 3.0 to 3.1 for details of changes.Summary of Changes from PA-DSS Version 3.0 to 3.1
/ref> In May 2016, version 3.2 of the PA-DSS Program Guide and Standards were released. For details, see ''Summary of Changes from PA-DSS Version 3.1 to 3.2.''


Congressional attention

On March 31, 2009, the
United States House of Representatives The United States House of Representatives, often referred to as the House of Representatives, the U.S. House, or simply the House, is the lower chamber of the United States Congress, with the Senate being the upper chamber. Together they ...
’ Committee on
Homeland Security Homeland security is an American national security term for "the national effort to ensure a homeland that is safe, secure, and resilient against terrorism and other hazards where American interests, aspirations, and ways of life can thrive" t ...
convened to discuss the current
PCI DSS The Payment Card Industry Data Security Standard (PCI DSS) is an information security standard used to handle credit cards from major card scheme, card brands. The standard is administered by the Payment Card Industry Security Standards Council a ...
requirements. Representatives such as
Yvette Clarke Yvette Diane Clarke (born November 21, 1964) is an American politician serving as the U.S. representative for New York's 9th congressional district since 2013. A member of the Democratic Party, she first entered Congress in 2007, representing ...
(D-NY) expressed interest in increasing the strength of standards while others, such as Bennie Thompson (D-Miss.) expressed doubt that industry created standards would be sufficient in the future. While Congressional attention was focused largely on
PCI DSS The Payment Card Industry Data Security Standard (PCI DSS) is an information security standard used to handle credit cards from major card scheme, card brands. The standard is administered by the Payment Card Industry Security Standards Council a ...
, the criticism of card-issuer standards could eventually bring Congressional or legal focus on PA-DSS and on PCI SSC as an entity.


Future

The future of these standards is somewhat vague, with Congressional attention giving rise to the possibility of governmental intervention. Regardless, meeting standards can prove expensive and time consuming for software vendors, with the current expense of PA-DSS certification outpacing other methods of compliance. Given the cost of compliance and certification, current or yet-undetermined alternatives could emerge in the PCI standards compliance market. Visa USA announced a more aggressive push into such technology (chip and pin) in August 2011.


Supplemental information

The PCI SSC has published additional materials that further clarify PA-DSS, including the following: *PA-DSS Requirements and security assessment procedures. *Changes from past standards. *General program guide for QSAs.PA-DSS 3.2 Program Guide
/ref>


References

Financial routing standards Payment systems {{PCISSC