September 2023 Summaries
6 posts from Basis Theory
Filter
Month:
Year:
Post Summaries
Back to Blog
PCI DSS Requirement 7 focuses on protecting cardholder data by enforcing least-privilege, need-to-know access to systems and data. It requires organizations to document and maintain access-control policies, define staff responsibilities, assign permissions according to job functions, obtain authorized approval for privileges, and review user and third-party access at least every six months. System and application accounts must receive only the access needed for operation, while direct access to stored cardholder-data repositories is generally limited to responsible administrators. Access-control systems should enforce role-based permissions across all components and default to denying access unless it is explicitly granted. The passage also presents Basis Theory as a PCI Level 1-compliant provider that offers an assessed cardholder data environment and tokenization tools intended to help businesses secure payment data while reducing the scope, cost, and operational burden of PCI DSS compliance.
Sep 29, 2023
858 words in the original blog post.
Risk assessment for payment merchants is an ongoing process of identifying and evaluating threats to card transactions, customer data, and payment infrastructure, with particular attention to chargeback abuse, identity theft involving stolen or fabricated card details, and system intrusions aimed at stealing personally identifiable information. Suggested safeguards include transaction and volume limits for suspicious customer activity, Address Verification Service, CVV checks, and 3-D Secure for card fraud, along with firewalls, multifactor authentication, prompt software updates, encryption, secure key management, and third-party tokenization vaults to protect sensitive data. Effective assessments should combine frequent internal scans and penetration tests with independent white-hat testing, monitoring of emerging vulnerabilities, access-control hygiene, log analysis, and employee training against phishing and other human-focused attacks. Because payment threats continually evolve, regular assessment and mitigation are presented as essential for maintaining security beyond annual compliance audits.
Sep 19, 2023
901 words in the original blog post.
PCI DSS Requirement 6 establishes controls for developing and maintaining secure systems and software to protect account data from vulnerabilities, attacks, and insecure changes. Its five sections require organizations to document security policies and responsibilities, embed secure coding practices throughout custom software development, train developers annually, conduct independent code reviews, and use techniques that address common attack types. Organizations must identify, rank, track, and remediate vulnerabilities in custom and third-party software, maintain component inventories, install critical patches within one month, and apply other updates within risk-appropriate timeframes. Public-facing applications must undergo periodic security assessments or be protected by automated web-attack defenses, while payment-page scripts require authorization, integrity verification, and documented inventories. Secure change management includes approval, security-impact analysis, testing, rollback procedures, separation of production and pre-production environments, and restrictions on live cardholder data and test accounts. The text also presents Basis Theory as a PCI Level 1-compliant provider that can help customers reduce their PCI scope by securing card data within its assessed cardholder data environment.
Sep 18, 2023
1,544 words in the original blog post.
Malware is software designed to damage systems or bypass security controls, with threats including viruses, ransomware, spyware, keyloggers, and phishing-delivered code that can enter organizations through email, web use, removable media, and exploited vulnerabilities. PCI DSS Requirement 5 addresses these risks through four areas: documenting and assigning security policies and responsibilities; deploying anti-malware protections on at-risk systems while periodically reassessing exemptions; keeping protections updated, continuously or periodically scanning systems and removable media, retaining logs, and restricting unauthorized disabling of controls; and implementing automated processes to detect and protect personnel from phishing, potentially using DMARC, SPF, and DKIM. The material also states that Basis Theory, a PCI Level 1 compliant provider, offers a platform intended to help organizations secure and tokenize cardholder data while reducing the scope, cost, and operational burden of PCI DSS compliance, though readers are directed to the PCI Security Standards Council for authoritative and current requirements.
Sep 12, 2023
993 words in the original blog post.
Basis Theory’s August updates introduce a BIN details service that lets customers enrich card or card-number tokens with Standard information such as bank, card brand, funding type, issuing country, and account-updater status, or Enhanced data including transaction costs, card segment, Level 2 and 3 eligibility, authentication, and other risk-related attributes to support payment routing, analytics, authorization rates, and fraud reduction. The company also expanded its enterprise Whitelabel Proxy to support path-based routing, allowing selected routes under a customer’s existing API domain to pass through Basis Theory while other traffic continues directly to backend servers. Additional improvements include API fixes for response transformations and forwarded IP headers, new numeric keyboard and read-only options in Elements JS, faster conceal-font loading, lower iOS version requirements and added focus and blur events in Elements iOS, plus clearer documentation on access rules and approved Reactor code libraries.
Sep 08, 2023
562 words in the original blog post.
PCI DSS Requirement 4 addresses the protection of cardholder data, especially primary account numbers (PAN), while transmitted across open or public networks, where outdated wireless encryption and authentication protocols may expose data to interception. It requires organizations to document, maintain, communicate, and assign responsibility for policies and procedures governing transmission security, while ensuring PAN is protected through strong cryptography. Key controls include using trusted and valid certificates and keys, avoiding insecure protocol versions and configurations, maintaining an inventory of trusted cryptographic assets, applying industry-standard wireless encryption where networks transmit PAN or connect to the cardholder data environment, and encrypting PAN sent through end-user messaging technologies. The text also presents Basis Theory as a PCI Level 1 compliant provider that offers an externally assessed cardholder data environment and tokenization tools intended to help businesses secure payment data while reducing the systems and PCI DSS obligations that fall within their direct scope.
Sep 05, 2023
749 words in the original blog post.