PCI guidelines issued for mobile apps

Powered by SC Magazine
 

Developers told to isolate sensitive functions, remove unnecessary access rights.

The Payment Card Industry Security Standards Council (PCI SSC), an industry body which manages payment data security guidelines, released best practices for mobile app developers and device manufacturers.

The main focus of the guidelines is to provide direction on securing mobile device payment processes, as well as the payment environment itself, by educating developers in the emerging mobile app market.

Bob Russo, the general manager of the PCI SSC, told SC the guidelines are particularly relevant today.

“I tell people that convenience trumps security all the time, and people are running quickly to use these new devices and technology, without even thinking about security,” Russo said. “This guidance is actually for the developers of those devices. We are purposely being cautious. It's such a changing market – you'll put something out today and tomorrow people are using it.”

Mobile devices have become payment vehicles and, accordingly, warrant strategies for security, he added.

Key recommendations of the report include isolating sensitive functions and data in trusted environments, implementing secure coding best practices and eliminating unnecessary third-party access and privilege escalation. Developing ways to remotely disable payment functions, in addition to creating tools for mobile apps to monitor and report suspicious activity were also among the recommendations.

The guidelines focus on ways to prevent account data from being intercepted while sent or received on mobile devices or from being compromised while being processed or stored on them.

Troy Leach, the chief technology officer of the council, told SCMagazine.com on Friday that the most recent guidelines reinforce the council's standard payment security goals, while applying them to a mobile space.

“We have a brand new group of developers that aren't of aware of their responsibility,” Leach said. “They are designing good code, but don't know all it's being used for.”

Malware, rootkits used by criminals and jailbreaking vulnerabilities are just some of the threats that can comprise the security of payments transmitted through mobile devices and apps.

David Thiel, the vice president for iSEC Partners, which provides mobile security consulting, told SCMagazine.com on Friday that a common problem in mobile app security is personal data being unintentionally leaked to local storage on devices, which can then be retrieved by attackers using malicious software on jailbroken phones.

“It's still a relatively immature field in terms of security development best practices, so its not quite to the level that a lot of big name software packages have been,” Thiel said of the app development market.  

PCI SSC also recently announced a new qualification program, called the PCI Professional (PCIP) Program, for IT professionals to receive certification for PCI payment security standards.

This article originally appeared at scmagazineus.com

Copyright © SC Magazine, US edition


PCI guidelines issued for mobile apps
 
 
 
Top Stories
NBN Co names first 140 FTTN sites
National trial extended.
 
Cloud, big data propel bank CISOs into the boardroom
And this time, they are welcome.
 
Photos: A tour of CommBank's new innovation lab
Oculus Rift, Kinect and more.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Do you direct debit customers? Read this
Oct 10, 2014
Authorities have been targeting direct debit practices with iiNet and Dodo receiving formal ...
Optus expands 4G coverage
Oct 10, 2014
If you rely on an Optus phone for work you might be interested to know that there are now 200 ...
Microsoft Office is now free for some charities
Oct 10, 2014
Microsoft has announced that eligible Australian non-profit organisations and charities can now ...
Vodafone lights up 4G in Adelaide
Oct 9, 2014
Live and work in Adelaide? Vodafone has switched on its 4G network in the city and suburbs.
Next year tradies will be able to take payments using ingogo
Oct 3, 2014
Ingogo is going to provide a card payment service for Xero users.
Latest Comments
Polls
In which area is your IT shop hiring the most staff?




   |   View results
IT security and risk
  25%
 
Sourcing and strategy
  12%
 
IT infrastructure (servers, storage, networking)
  23%
 
End user computing (desktops, mobiles, apps)
  12%
 
Software development
  27%
TOTAL VOTES: 224

Vote
Would your InfoSec team be prepared to share threat data with the Australian Government?

   |   View results
Yes
  63%
 
No
  37%
TOTAL VOTES: 67

Vote