PCI guidelines issued for mobile apps

Powered by SC Magazine
 

Developers told to isolate sensitive functions, remove unnecessary access rights.

The Payment Card Industry Security Standards Council (PCI SSC), an industry body which manages payment data security guidelines, released best practices for mobile app developers and device manufacturers.

The main focus of the guidelines is to provide direction on securing mobile device payment processes, as well as the payment environment itself, by educating developers in the emerging mobile app market.

Bob Russo, the general manager of the PCI SSC, told SC the guidelines are particularly relevant today.

“I tell people that convenience trumps security all the time, and people are running quickly to use these new devices and technology, without even thinking about security,” Russo said. “This guidance is actually for the developers of those devices. We are purposely being cautious. It's such a changing market – you'll put something out today and tomorrow people are using it.”

Mobile devices have become payment vehicles and, accordingly, warrant strategies for security, he added.

Key recommendations of the report include isolating sensitive functions and data in trusted environments, implementing secure coding best practices and eliminating unnecessary third-party access and privilege escalation. Developing ways to remotely disable payment functions, in addition to creating tools for mobile apps to monitor and report suspicious activity were also among the recommendations.

The guidelines focus on ways to prevent account data from being intercepted while sent or received on mobile devices or from being compromised while being processed or stored on them.

Troy Leach, the chief technology officer of the council, told SCMagazine.com on Friday that the most recent guidelines reinforce the council's standard payment security goals, while applying them to a mobile space.

“We have a brand new group of developers that aren't of aware of their responsibility,” Leach said. “They are designing good code, but don't know all it's being used for.”

Malware, rootkits used by criminals and jailbreaking vulnerabilities are just some of the threats that can comprise the security of payments transmitted through mobile devices and apps.

David Thiel, the vice president for iSEC Partners, which provides mobile security consulting, told SCMagazine.com on Friday that a common problem in mobile app security is personal data being unintentionally leaked to local storage on devices, which can then be retrieved by attackers using malicious software on jailbroken phones.

“It's still a relatively immature field in terms of security development best practices, so its not quite to the level that a lot of big name software packages have been,” Thiel said of the app development market.  

PCI SSC also recently announced a new qualification program, called the PCI Professional (PCIP) Program, for IT professionals to receive certification for PCI payment security standards.

This article originally appeared at scmagazineus.com

Copyright © SC Magazine, US edition


PCI guidelines issued for mobile apps
 
 
 
Top Stories
NICTA no more as CSIRO takes over
Data61 split out under executive.
 
Inside the stalemate on Australia's piracy code
Still not registered almost five months on.
 
IT staff outline deep anger in Macquarie Uni survey
‘Morale at lowest point in a decade’.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Say goodbye to OneDrive Groups
Aug 28, 2015
If you've a) actually been using OneDrive and b) gone so far as to actually have been using ...
Libreoffice 5 review
Aug 24, 2015
It's free! It's open! But does LibreOffice deliver on its promise of a powerful office suite for ...
How to disable Cortana in Windows 10
Aug 21, 2015
Stop Microsoft's personal assistant snooping around.
Uni is optional: 5 tech leaders without a degree
Aug 17, 2015
Already running a business, but thinking about going back to uni? From Bill Gates to Steve Jobs, ...
New features coming to Xero
Aug 17, 2015
Use Xero? Here are some of the things you can look forward to in the coming months.
Latest Comments
Polls
New Windows 10 users, are you upgrading from...




   |   View results
Windows 8
  46%
 
Windows 7
  44%
 
Windows XP
  5%
 
Another operating system
  3%
 
Windows Vista
  2%
TOTAL VOTES: 726

Vote