ETA Website Compliance Portal Home News & Commentary Links & Information
NEWS & COMMENTARY
IRS Revises 1099K form PDF Print E-mail

The Internal Revenue Service has revised the form 1099K that merchant acquirers must use when reporting merchant card transactions, beginning in January 2012. The new form includes a box for each merchant's IRS merchant category code (MCC). The newly required code is an IRS code and is not the MCC codes used by card companies to classify merchants. A copy of the new form and a list of IRS MCCs can be found at:

 

Form 1099K

MCC List

 

PULSE Network Releases New Debit, ATM Transaction Pricing PDF Print E-mail
PULSE announced new network pricing to its participants this morning.
Following is a brief statement from the network to all affected ETA members:
"PULSE announced revisions to its network pricing on August 30, 2011. The
revisions include changes to PIN Debit and ATM pricing. All changes take
effect on the settlement day of October 1, 2011. For more information,For
more information, contact your PULSE account manager or call the PULSE
office at 800-410-2122
."
Homeland Security Department: Humans Are Weak Link in Data Security Chain PDF Print E-mail

It won’t surprise many computer security experts, but the U.S. Homeland Security Department (DHS) has proven again that humans are the “weak link” in the data security chain.

 

In an effort to test computer security in federal agencies, DHS dropped thumb drives and CDs in the parking lots of various federal buildings and office buildings housing government contractors. Among the people who picked up the devices and disks,, 60 percent plugged the them into office computers. If the drive or CD case had an official logo, 90 percent were plugged in. Had they carried auto-loading malware, entire government networks might have been compromised.

 

A full report on the Homeland Security study will be published this year, according to Sean McGurk, director of the department’s National Cybersecurity and Communications Integration Center.

FTC Commissioner Joins Call for Federal Data Security Law PDF Print E-mail

The drumbeat for Congress to adopt a federal data security law got a little louder when Federal Trade Commissioner  Edith Ramirez told a House subcommittee that Congress should pass a federal data security law during hearings on Wednesday.

 

Read more...
PCI Security Standards Council Offers Update On Virtualization Rules PDF Print E-mail

Virtualization, which allows a single computer to run multiple copies of an operating system or multiple operating systems in parallel, has sometimes been touted as a way to add security to systems that handle payment data, but last Fall’s release of the updated PCI Data Security Standard only touched on virtualization and left many questions unanswered.

 

Tuesday, the PCI Council’s special interest group that deals with the issue released a much welcomed “information supplement” that aims to clarify outstanding issues. The 39-page document is not officially part of PCI DSS, but its recommendations likely will  eventually be part of the rules in the future.

??More than 30 so-called participating organizations of vendors, merchants, processors, and others working with the PCI Council developed the guidelines, which do not endorse any specific technology or provider, according to the PCI Council.

Citi Breach Reflects Changing Hacker Patterns PDF Print E-mail
 The Citi data breach revealed last week is yet another piece of evidence pointing to a shift in behavior on the part of sophisticated hackers, one that many current security policies aren’t always prepared to handle.
 

The Data Security/Compliance firm Trustwave has circulated a mini-Q&A which notes that the Citi breach likely was accomplished by someone who gained access to the Citi customer portal with valid credentials, the took advantage of flaws in the web application to gain access to the records of other customers. While the stolen data did include card account  numbers, that was probably the least valuable part of the electronic haul.

 

According to Trustwave: “The real concern is have the Citi customers been targeted with other types of attacks using the name, addresses, email, etc, info that was breached.”

 

Combined with a card number, this information could be used for targeted “spear-phishing” ploys that persuade customers to volunteer additional data that can be used to gain access to bank accounts and other lucrative information.

 

The targeting of non-card data (as in the Sony and Epsilon breaches earlier this year), the use of valid customer credentials to hack into customer records through web applications for the purpose of spear-phishing attacks, represent a distinct shift in tactics on the part of hackers, who are acting on a common weakness in web based applications, like customer portals.

 

Says Trustwave: “Credential attackers are becoming the new way that attackers are getting access to the real data they are looking for. As companies are only testing their systems for security issues from an unauthenticated point of view, they are not identifying critical vulnerabilities that an attacker with a user name and password to a customer portal can exploit.”

PCI-Compliant Merchants Fare Better, but 36% Still Report Breaches Over 2-Year Span PDF Print E-mail

Despite the fact that 36% of PCI DSS-compliant merchants reported data breaches in the past 24 months, those who met the data security standard still fared better than non-compliant merchants, according to a new report. The document also said the number of merchants reporting a data breach in the previous 24 months rose 7.6% from 79% in 2009 to 85% this year. The report, “2011 PCI DSS Compliance Trends Study,” was produced by the market research firm Ponemon Institute and commissioned by data security firm Imperva.

 

Based on a survey of 670 U.S. and multinational information technology professionals, the report found that 64% of PCI-compliant merchants said they did not suffer a data breach involving credit card data over the past two years, compared to 38% of non-compliant businesses.

Links & Information PDF Print E-mail
Read more...
 
 
COMPLIANCE LINKS & INFORMATION
 
INDUSTRY
DATA SECURITY
 
 
Visa Data Security Information
MasterCard Worldwide Data Security Rules
NACHA Rules
PCI SSC Website
PCI Data Security Standard
OCI DSS Quick Reference Guide
 
  More Industry... More Data Security...  
       
 
GOVERNMENT
ETA RESOURCES
 
 
Regulations.gov
FFIEC Retail Payments Examination Guide
Federal Reserve Payment Card Center
Risk Management Whitepaper
Data Security Whitepaper
ETA University
 
  More Government... More ETA Resources...  
       
 
ETA Members Only
Login to access:
member information
membership status
member-only content
Upcoming Events
2012 STRATEGIC LEADERSHIP FORUM
October 16-18, 2012
The Breakers
Palm Beach, FL
 
2013 ANNUAL
MEETING & EXPO
April 30-May 2, 2013
New Orleans
Convention Center
New Orleans, LA
 
   
   
   
   
 

 
Electronic Transactions Association  |  1101 16th Street NW, Washington, DC 20036
202.828.2635  |  800.695.5509
Privacy Statement  |  Antitrust Laws & Trade Associations
© 2012 ETA The Electronic Transactions Association. All rights reserved.