Telecommunications operators and banks implementing security standards required to protect their networks against hackers can now heave a sigh of relief thanks to the recently released ISACA guidance that simplifies the process.
With a template implementation plan, example self-assessment and an audit/assurance programme, the new guideline makes it easier for implementation of security standards such as PCI DSS version 3.1, COBIT 5 processes among others.
Before the new practical guide, organizations were faced with complex in implementation process that often lead to failure.
The guide solution also provide for mapping of different security standard together which was not in existence before.
Adesanya Ahmed, founder of Petrovice Resources International who was the only Africa appointed expert reviewer for the benchmark said, that a practical guide to the Payment Card Industry Data Security Standard (PCI DSS) explains the security requirements, processes and technologies that are required to implement the Payment Card Industry Data Security Standard (PCI DSS), which is a compliance requirement for all enterprises that process, store, transmit or access cardholder information for any of the major payment brands, such as American Express, Discover, JCB, MasterCard and Visa brands.
Nigeria CommunicationsWeek investigations revealed that the practical guide solution was made available to organizations last month.
He added that the guide provides a comprehensive overview of the PCI DSS and explains how to implement its demanding security requirements.
“The guide also contains a wealth of background information about payment cards and the nature of payment card fraud. The content in this guide goes beyond other sources of information about the PCI DSS by providing the following valued information: Concise summaries of PCI DSS requirements version 3.1, consolidated information from numerous PCI DSS publications background advice on challenging requirements, techniques that are required to scope and implement the requirements, PCI DSS requirements mapped to COBIT 5 processes and International Organization for Standardization (ISO)/International Electrotechnical Commission (IEC) 27001/2 controls as well as detailed explanation of how to design a professional audit /assurance plan,” he said.
Ahmed noted that in order to make compliance easier and to assist organization planning to move to cloud or already in the cloud, Petrovice Resources International is collaborating with Digital Bridge Institute an agency under Nigerian Communication Commission to offer a training on meeting PCI DSS when using a cloud service provider, which has been endorsed by Payment Card Industry Standard Security Council.
PCIDSS is a framework for ensuring that critical information assets are protected from unauthorized access, use, disclosure, disruption, modification, perusal, inspection, recording or destruction.
Oluseyi Akindeinde, chief technical officer, Digital Encode, a company that assist banks and other organisations to achieve PCI DSS, said that, it will be highly beneficial for all banks to get certified to this new standard. “The PCI certification audit is a yearly process and as such it only makes sense to make adjustments where needed as it relates to the new versions,” he said.
He noted that compliance to security standards has helped in reducing fraud committed through external bridges in the system and that focus is now on internal fraud which is committed through the help of bank staff and vendors that compromised on their job.
The major global payment brands require that every entity including financial institutions as well as merchants and service providers stores, processes, or transmits payment card data, in every channel including catalog and online retailers as well as brick-and-mortar businesses -- must be in compliance with the PCI Data Security Standard (PCI DSS).
Telcos, Others Get Impetus to Fight CyberCrime

Telecommunications operators and banks implementing security standards required to protect their networks against hackers can now heave a sigh of relief thanks to the recently released ISACA guidance…
Comms Week
Trained and practicing journalist passionate about telecommunications, fintech, cybersecurity, and digital economy reporting.

Google Issues Urgent Chrome Update to Block Active Attacks

RockPay Launches, Targets Digital Payments through Social Finance

NDIC Still Paying Depositors of 46 Failed MFBs — Sunday

NITDA Inaugurates Taskforce to Drive Sovereign Cloud Implementation

SEC Proposes N2bn Capital Requirement, N30m Registration Fee for Crypto Firms




