Home / Companies / Basis Theory / Blog / October 2023

October 2023 Summaries

7 posts from Basis Theory

Filter
Month: Year:
Post Summaries Back to Blog
PCI DSS Requirement 11 establishes controls for regularly testing the security of systems and networks that handle cardholder data, aiming to identify and remediate weaknesses before attackers exploit them. It requires documented policies, assigned responsibilities, wireless access-point inventories and monitoring, quarterly internal and external vulnerability scans, authenticated scans where feasible, and additional scans after significant changes. Organizations must also conduct independent internal and external penetration tests at least annually, validate network segmentation controls, correct exploitable findings, and retain testing and remediation records. The requirement further calls for intrusion-detection or prevention capabilities, weekly critical-file change detection, and mechanisms to identify unauthorized modifications to payment-page content and HTTP headers that could indicate web-skimming attacks. The text also presents Basis Theory, a PCI Level 1 compliant service provider, as a platform intended to help organizations reduce the scope and operational burden of handling cardholder data by using its independently assessed cardholder data environment.
Oct 30, 2023 1,842 words in the original blog post.
Gift card authorization rates are estimated to be 5–10% lower than those for standard credit cards, largely because branded gift cards have fixed balances that can be exceeded by taxes, shipping, pre-authorizations, or tip allowances. Store, or closed-loop, gift cards are managed entirely by individual merchants and provide full program control and potential revenue benefits, but also require the merchant to handle fraud prevention, administration, and outstanding-card liability. Branded cards operate through major payment networks, giving merchants less control but reducing operational responsibility and offering access to network marketing, partnership incentives, and revenue-sharing opportunities. Authorization failures for branded gift cards commonly stem from customers not knowing their remaining balances, purchases exceeding loaded funds, and temporary authorization holds at gas stations, hotels, restaurants, and similar businesses. Merchants can reduce customer friction by clearly communicating total costs, explaining insufficient-funds declines, and considering follow-up outreach when otherwise viable purchases fail solely because of a low gift card balance.
Oct 23, 2023 1,078 words in the original blog post.
PCI DSS Requirement 10 establishes logging and monitoring controls intended to prevent, detect, and investigate compromises involving cardholder data environments, applying to activities performed by employees and third parties alike. Its seven sections require documented policies and assigned responsibilities; comprehensive audit logging of user access, administrative actions, failed access attempts, credential changes, log-management events, and system-object changes; and event records that identify users, affected resources, timing, origin, and outcomes. The requirement also calls for protections against log alteration or destruction, including restricted access, secure centralized backups, and file-integrity monitoring, alongside daily reviews of critical logs, risk-based periodic reviews of other logs, and prompt investigation of anomalies. Organizations must retain log history for at least 12 months, with three recent months readily available, synchronize system clocks through controlled time sources, and promptly detect, alert on, remediate, and document failures of critical security controls. The text also promotes Basis Theory, a PCI Level 1-compliant provider that offers an assessed cardholder data environment and tokenization tools intended to reduce customers’ PCI DSS scope and infrastructure burden.
Oct 17, 2023 1,549 words in the original blog post.
Payment Account Reference (PAR) is a globally unique identifier developed by EMVCo and card schemes to connect different representations of a card account, including PANs, network tokens, PSP tokens, DPANs, and FPANs, without being intended to track consumers. It can help merchants and fintechs recognize the same payment account across in-store, online, and digital-wallet transactions, supporting more complete purchase histories, cross-channel loyalty programs, personalized offers, reporting, and fraud prevention. PAR may identify account-linking fraud and promotion abuse by revealing when one payment account is associated with multiple user profiles, especially when combined with device, IP, or other risk signals. Accessing PAR through card-network APIs generally requires PCI Level 1 compliance or a third-party tokenization platform that securely collects and stores PAN data independently of payment service providers. Basis Theory presents its tokenization platform, API tools, Reactors, proxies, and Terraform example as a way for payment teams to access PAR while maintaining PCI compliance and control over payment data.
Oct 16, 2023 733 words in the original blog post.
PCI DSS Requirement 9 focuses on protecting cardholder data through physical security controls that limit and monitor access to cardholder data environments, systems, media, and payment devices. It requires documented policies, assigned responsibilities, facility-entry controls, monitoring of sensitive areas, restrictions on network equipment and consoles, and prompt revocation of access for departing personnel. Organizations must also authorize, identify, escort, and track visitors, while securing cardholder-data media throughout its storage, transport, inventory, and destruction lifecycle. Payment point-of-interaction devices must be inventoried, inspected for tampering or replacement, and supported by employee training to recognize suspicious activity and verify third-party repair personnel. The passage also presents Basis Theory as a PCI Level 1-compliant provider that can help organizations use an externally managed cardholder data environment to reduce their PCI DSS scope and associated implementation effort.
Oct 13, 2023 1,538 words in the original blog post.
Basis Theory’s October update introduces enhancements for card issuance, data management, API transparency, and regional data handling. Mobile SDKs now support copying revealed card details, intended to reduce payment friction and help issuers increase card usage, while a KnotAPI integration enables customers to move recurring subscription payments from older cards to newly issued ones without requiring the issuer to attain PCI Level 1 compliance. The platform also announced Payment Account Reference (PAR) connections, allowing merchants and fintechs to identify cards across payment methods such as card-not-present transactions, digital wallets, network tokens, and Click to Pay, with applications in fraud prevention and loyalty programs. Additional updates include an Apple Pay guide for decrypting and routing DPANs, fixes for tokenization using BIN enrichment and deduplication, new proxy status headers that distinguish third-party failures from Basis Theory errors, enterprise TCP connection-management headers, and an EU instance designed to store and process customer data in European data centers.
Oct 11, 2023 841 words in the original blog post.
PCI DSS Requirement 8 establishes identity and authentication controls intended to protect cardholder data environments by assigning unique user identifiers, verifying users through authentication factors, and maintaining accountability for system actions. Its six sections require documented policies and responsibilities, lifecycle management for user and administrator accounts, strong authentication controls, multi-factor authentication for access to the cardholder data environment and remote connections, safeguards against MFA misuse, and strict management of application and system accounts. Key measures include promptly revoking terminated-user access, disabling inactive accounts within 90 days, re-authenticating idle sessions after 15 minutes, encrypting authentication factors, limiting failed login attempts, enforcing password complexity and reuse restrictions, and preventing shared or interactive system-account use except under approved, traceable exceptions. The material notes alignment with established security practices and NIST identity guidance, while advising readers to consult PCI SSC’s current official requirements. It also promotes Basis Theory’s PCI Level 1-compliant platform as a way for businesses to secure and use card data while reducing the systems they must bring into PCI scope.
Oct 09, 2023 1,901 words in the original blog post.