22 September 2012

Visa Europe Mobile Security Best Practices

Further to my last post about the guidance on developing mobile applications that accept payments from the PCI SSC, Visa Europe has also published updated guidance concerning mobile payment acceptance solutions.

Partial view of the security best practice advice within Visa Europe's document 'Mobile Payment Acceptance Solutions' version 2, September 2012

Mobile Payment Acceptance Solutions, version 2, September 2012, includes guidance for payment solution developers (in-house or on behalf of another organisation), and merchants, acquirers and payment service providers (PSPs) using Mobile Payment Acceptance Solutions. Developers, merchants and acquirers must follow all Visa requirements for magnetic stripe, chip and contactless acceptance (where supported) as well as the guidance in this document. Visa Europe also state mobile payment solutions should also adhere to the principles set out in the Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS).

Additionally the guidance document provides three security goals each for vendors, merchants and acquirers/PSPs:

  • Mobile Payment Acceptance Solution Vendors
    • Design and implement secure Mobile Payment Acceptance Solutions
    • Ensure the secure use of Mobile Payment Acceptance Solutions
    • Limit exposure of account data that could be used to commit fraud
  • Merchants
    • Ensure the secure use of Mobile Payment Acceptance Solutions
    • xLimit the exposure of account data that may be used to commit fraud
    • Prevent software attacks on Consumer Mobile Devices
  • Acquirers & Payment Service Providers (PSPs)
    • Design and deploy robust Mobile Payment Acceptance Solutions
    • Design and Implement appropriate controls when on-boarding merchants
    • Ensure proper monitoring of Mobile Payment Acceptance Solutions

Best practices are then defined for each security goal. So there is some overlap, and some merchants might also be considered vendors (if they develop their own payment applications), and some might also conceivably be PSPs.

Posted on: 22 September 2012 at 19:42 hrs

Comments Comments (0) | Permalink | Send Send | Post to Twitter

Comments

Comments are filtered automatically and should appear shortly after they been checked.

Post a comment
Confirm acceptance and understanding of the terms of use
New posts to this thread will be sent to your email address
Visa Europe Mobile Security Best Practices
http://www.clerkendweller.com/2012/9/22/Visa-Europe-Mobile-Security-Best-Practices
ISO/IEC 18004:2006 QR code for http://clerkendweller.com

Page http://www.clerkendweller.com/2012/9/22/Visa-Europe-Mobile-Security-Best-Practices
Requested by 54.242.233.11 on Wednesday, 19 June 2013 at 10:24 hrs (London date/time)

Please read our terms of use and obtain professional advice before undertaking any actions based on the opinions, suggestions and generic guidance presented here. Your organisation's situation will be unique and all practices and controls need to be assessed with consideration of your own business context.

Terms of use http://www.clerkendweller.com/page/terms
Privacy statement http://www.clerkendweller.com/page/privacy
© 2012-2013 clerkendweller.com