Few months after money deposit banks in the country completed certification of Payment Card Industry Data Security Standards (PCI DSS) version 2, they are now faced with new task of complying with the next upgrade which is version 3.
PCIDSS is a framework for ensuring that critical information assets are protected from unauthorized access, use, disclosure, disruption, modification, perusal, inspection, recording or destruction.
The major global payment brands require that every entity including financial institutions as well as merchants and service providers store, process, or transmit payment card data, in every channel including catalogue and online retailers as well as brick-and-mortar businesses -- must be in compliance with the PCI Data Security Standard (PCI DSS).
Nigeria CommunicationsWeek investigations revealed that PCI DSS version 2 the one Central Bank of Nigeria (CBN) mandated banks to comply with by November 30, 2014, ended in December last year, and version 3 was released in January this year.
Some Nigerian banks have already commenced efforts towards compliance to this new version.
Oluseyi Akindeinde, chief technical officer, Digital Encode, a company that assist banks and other organizations to achieve PCI DSS certification, said, PCI DSS Version 3.0 is just an update to the already existing PCI DSS version 2.
“It was brought about by the ever evolving and changing sphere of information security. It has updated a few of the objectives and added new controls in line with the current landscape of payment systems threats and risks. There are quite a number of advantages. One now is that it makes application security testing a very key component of the overall process. Other key advantages include systems component inventory, third party and vendor relationships, advanced persistent threats and malware as well as physical access and point of sale security,” he stated.
He added that, it will be highly beneficial for all banks to get certified to this new standard.
“The PCI certification audit is a yearly process and as such it only makes sense to make adjustments where needed as it relates to the new version,” he said.
Ahmed Adesanya, IT Security and Connectivity consultant, said that version 3 compliance extends to merchants, payment application providers, communications service providers as well as cloud service providers.
He said that the new version has 12 requirements and over 200 control processes.
“Banks need to show a report of compliance, covering all the processes of security control that applied to them. If any bank doesn’t meet up with this version 3 compliance, payment card brands such as Visa and MasterCard will sanction such bank,” he noted.
He added that such sanctions include fine of $450 per card bridge recorded by the bank that did not comply to this version 3.
He pointed out that the tedious process of compliance to PCI DSS has led to some banks to outsource some of the process to cloud services providers that have met the requirement.
Banks Race to Comply with PCI DSS Version 3

Few months after money deposit banks in the country completed certification of Payment Card Industry Data Security Standards (PCI DSS) version 2, they are now faced with new task of complying with…
Comms Week
Trained and practicing journalist passionate about telecommunications, fintech, cybersecurity, and digital economy reporting.

NAICOM Dismisses Allegations of $100Bn Fraud in Recapitalisation Exercise

Yellow Card Financial Gets SEC’s ARIP Recognition

NPF-NCCC @ CIBN Conference, Urges Banks to Set up eFraud Response Teams

Dangote Refinery IPO Opens Banks, Fintechs, Apps for Share Purchase

CBN Warns Banks, Says A Bank’s Cyber Weakness Could Trigger System-Wide Crisis



