Online Payments Blog

Industry News and discussions relating to Online Payments and Application Security.
Tags >> security
Aug 31
2010

Visa release Top 10 Best Practices for Securing Payment Applications

Posted by Dave in web development , Visa , security , PCI DSS , payment processing , passwords , online payments , news

credit card data securityVisa have published a set of 10 best practices for application vendors, integrators and resellers that implement, install or manage payment-related systems on behalf of merchants. The best practices are set to compliment the Payment Card Industry (PCI) Payment Application Data Security Standard (PA-DSS). The PA-DSS was originally developed by Visa before being embraced by the industry as the PA-DSS.

"The PA-DSS provides guidance for developing secure software, while Visa's Best Practices for Payment Application Companies represents a natural companion, providing guidance on how to securely install that piece of software," said Eduardo Perez, Head of Global Payment System Security, Visa Inc.

The 10 best practices are as follows:

  • Perform background checks on new employees and contractors prior to hire.
  • Maintain an internal and external software security training and certification curriculum.
  • Adhere to a common software development life cycle across payment applications.
  • Ensure that newly released payment application versions are Payment Application Data Security Standard (PA-DSS) compliant.
  • Conduct application vulnerability detection tests and code reviews against common vulnerabilities and weaknesses prior to sale or distribution.
  • Actively identify payment application versions that store sensitive authentication data and/or retain critical security vulnerabilities, and notify all affected customers.
  • Maintain customer service level agreements stating that only PA-DSS compliant payment application versions will be sold and supported.
  • Implement an installer, integrator and reseller training and certification program that enforces adequate data security processes when supporting customers.
  • Adhere to industry guidelines for data field encryption and tokenization and PAN elimination across payment applications that use these technologies.
  • Support capability of dynamic data solutions across payment applications


You can find more information over on the on Visa website.

 

Dave

--

If you liked this article then you can:

 

Related Blog Posts:

Nov 19
2009

Serious osCommerce vulnerability exposed

Posted by Dave in web development , security , e-commerce , Application Security

oscommerce logoA very serious vulnerability in osCommerce was brought to our attention on November 13th. The vulnerability allows an attacker to bypass the authentication mechanism and gain access to the admin pages.

I have held off on blogging about this until now as I did not feel it was appropriate. It was a difficult decision to make, on one hand I want to inform those running osCommerce so they can secure their systems but by blogging about the issue I am also highlighting it to potential attackers.



I would like to discuss the vulnerability and how it works but we'll leave that for another time. For those of you running osCommerce you can find information about the vulnerability on the osCommerce forums and also on the powersellers forum.

There are a number of suggested solutions and patches but based on my research the simplest thing to do is to protect the admin directory using .htaccess-based authentication.

Dave

--

If you liked this article then you can:


Related Blog Posts:

<< Start < Prev 1 2 3 4 5 6 7 8 9 10 Next > End >>
Tag Cloud