Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cloud
    • Cloud
    • Cybersecurity
    • Mobile

    PCI Security Standards Council Issues Guidance for Mobile Payment Industry

    Written by

    Brian Prince
    Published September 14, 2012
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The PCI Security Standards Council (PCI SSC) is unveiling a set of best practices for mobile payment acceptance security.

      The standards, announced Sept. 13, follow predictions by analysts that the global mobile payment market will continue to grow. According to Gartner, worldwide mobile payment transaction values will surpass $171.5 billion in 2012, a roughly 62 percent increase from the $105.9 billion in 2011. The firm also predicts the number of mobile payment users will reach 212.2 million by the end of the year, up from 160.5 million in 2011.

      “The trend in mobile payments is to utilize consumer grade devices for operations that were historically performed by hardened hardware terminals,” Nicholas J. Percoco, senior vice president at Trustwave’s SpiderLabs, told eWEEK. “The challenges are broad and many but some of the top issues revolve around management/control over the device, the integrity of the payment applications, and the security of the payment process.”

      The best practices were announced at the PCI SSC’s North America Community Meeting. Dubbed the PCI Mobile Payment Acceptance Security Guidelines, the best practices are meant to offer software developers and mobile device manufacturers guidance on how to include security controls in solutions for merchants to accept mobile payments safely. The guidelines are focused on securing the payment transactions as well as the broader mobile application platform environment.

      Recommendations include:

      • Isolate sensitive functions and data in trusted environments

      • Implement secure coding best practices

      • Eliminate unnecessary third-party access and privilege escalation

      • Create the ability to remotely disable payment applications

      • Create server-side controls and report unauthorized access

      According to the guidance, developers should ensure that a trusted path exists between the data-entry mechanism (e.g., manual key entry or entry via a card reader) and the mobile device so that account data cannot be intercepted by an unauthorized party. This can be accomplished using a trusted execution environment that restricts access between the mechanism receiving account data and secured memory located inside the device. As an alternative, account data can be encrypted appropriately before it is entered into the mobile device.

      “Applications are going to market so quickly-anyone can design their own app today that can be used to accept payments tomorrow,” PCI SSC CTO Troy Leach said in a statement. “It’s our hope that in educating this new group of developers, as well as device vendors on what they can do to build security into their design process, that we’ll start to see the market drive more secure options for merchants to protect their customers’ data.”

      In the short-term, security will probably not hurt the adoption of mobile payment technologies because many small businesses are not aware of the current risks, said Percoco.

      “Long-term, as criminals begin to focus more on capitalizing on the flaw in current mobile solutions, there could be impacts to organization successfully utilizing mobile as a payment platform,” he said. “PCI SCC rolled out their best practice guide as a step in the right direction for educating the mobile payment application development community.”

      Brian Prince
      Brian Prince

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.