Posted on 14 September 2012.
The PCI Security Standards Council (PCI SSC), a global, open industry standards body providing management of the Payment Card Industry Data Security Standard (PCI DSS), PINTransaction Security (PTS) requirements and the Payment Application Data Security Standard (PA-DSS), released best practices for mobile payment acceptance security.
The PCI Mobile Payment Acceptance Security Guidelines
offer software developers and mobile device manufacturers guidance on designing appropriate security controls to provide solutions for merchants to accept mobile payments securely.
The guidance supports the need for more secure development practices for mobile payment acceptance solutions. According to security experts Trustwave SpiderLabs, that specialize in data breach investigations and malware analysis, mobile computing, commerce, and malware are still in their infancy. Existing platforms limit users’ ability to ensure the security of transactions conducted on mobile technology.
The document organizes the mobile payment-acceptance security guidance into two categories: best practices to secure the payment transaction itself, which addresses cardholder data as it is entered, stored and processed using mobile devices; and guidelines for securing the supporting environment, which addresses security measures essential to the integrity of the broader mobile application platform environment.
Key recommendations include:solate sensitive functions and data in trusted environmentsImplement secure coding best practicesEliminate unnecessary third-party access and privilege escalationCreate the ability to remotely disable payment applicationsCreate server-side controls and report unauthorized access.PCI SSC Chief Technology Officer Troy Leach said: “Applications are going to market so quickly – anyone can design their own app today that can be used to accept payments tomorrow. It’s our hope that in educating this new group of developers, as well as device vendors on what they can do to build security into their design process, that we’ll start to see the market drive more secure options for merchants to protect their customers’ data.”