|
Links Related to this Story: |
Article published in Issue Number: 070502Visa identifies apps storing sensitive data
In April, Visa identified applications from six vendors needing attention: ICVerify Inc., Menusoft Systems Corp., Micros Systems Inc., Posera Software, Radiant Systems Inc. and Southern DataComm Inc. The products are considered risky because they store prohibited cardholder data - such as full magnetic stripe (tracks 1 and 2), CVV2 (card verification value) and PIN data - after a transaction authorization occurs. Visa said unscrupulous hackers will seek out such systems and exploit vulnerabilities to access the data. Noncompliant payment applications are "an unacceptable risk to ... the entire payment system," Visa stated. "When driving merchants toward payment applications, agents should ensure the application has been validated against Visa's PABP [Payment Application Best Practices]." The PABP, released in 2005, is a set of requirements for developing secure products that support compliance with the Payment Card Industry Data Security Standard and do not store prohibited data. Visa advised merchants and service providers using any of the applications listed to install a vendor-supplied patch or to upgrade to a Visa-approved application (a list is posted at www.visa.com/cisp). The card Association also warned that merchants should wipe "from all systems immediately" any stored full track data. |
![]() |
![]() |
![]() |
© 2007, The Green Sheet, Inc. |