Blog Blog http://spva.org/blog.aspx http://backend.userland.com/rss My Data Breach Costs More Than Your Data Breach <p style="line-height: 13.5pt;"><o:p>Earlier this year, the Ponemon Institute released a study (“<a shape="rect" href="http://www.ponemon.org/local/upload/fckjail/generalcontent/18/file/2010 Global CODB.pdf" target="_blank" shape="rect">Five Countries: Cost of Data Breach</a>”), and the results paint a dichotomous picture of security and loss among counties.<br /> <br /> </o:p><o:p>All participating companies experienced one or more data breach incidents over the past year. The companies were based in the United States, the United Kingdom, Germany, France and Australia.<br /> <br /> </o:p><o:p>Right off the bat, one thing stands out. The total cost of a data breach in the US is off the charts ($6.75 million) compared to the study average of $3.55 million. Similarly, the US stands alone in the “lost business cost” results. It is the only one of the five countries above the average of $1.6 million. The US comes in at $4.47 million while its next closest data point is Germany at $1.19 million.<br /> <br /> </o:p><o:p>One immediate question is: why? The root cause of these breaches may be surprising (or maybe not!), but the US had the smallest percentage in the “malicious or criminal attack” category yet the highest in the “system glitch” category and second highest in “negligence” (topped only by the UK).<br /> <br /> </o:p><o:p>With so many compliance standards and rules regarding data security, where is the kink? Are things changing too quickly? Is there a general lack of understanding? Is there a false sense of security among C-level executives? Let us know what you think.<br /> <br /> </o:p><o:p>And here’s hoping you never meet the requirements to participate in next year’s study.</o:p></p> http://spva.org/blog/10-08-27/My_Data_Breach_Costs_More_Than_Your_Data_Breach.aspx Steven Hughes http://spva.org/blog/10-08-27/My_Data_Breach_Costs_More_Than_Your_Data_Breach.aspx 919525c4-38ed-49a9-9b37-014ac6bae35c Fri, 27 Aug 2010 13:44:31 GMT U.S. Credit Cards Not Welcome? <span lang="EN">A number of recent surveys show that anywhere from one-half to two-thirds of people who carry U.S. credit cards experience difficulty when trying to use their cards outside of the United States. The hang-up, as most of you know, is magnetic stripes versus chip-and-PIN technology.<br /> <br /> The perennial question is whether chip-and-PIN will make it to U.S. shores, and what factors will line up to motivate a change. Wal-Mart pulled its weight earlier this year when it announced that it would accept chip-and-PIN in its U.S. stores, and the U.S.’s neighbors to the north and south have also moved to adopt chip technology. Still, it hasn’t taken hold here, maybe due to cost – estimated to be nearly $9 billion.<br /> <br /> But an <a shape="rect" href="http://www.creditcards.com/credit-card-news/future-next-generation-credit-cards-1273.php" shape="rect"><span lang="EN">article</span></a><span lang="EN"> posted Monday on CreditCards.com describes the next generation of payment cards. LCD screens, videos, passwords, voiceover features, etc. In a word – innovative.<br /> <br /> From an aesthetic and interactive standpoint, this new generation of cards will pique interest. From a security perspective, the new cards will help prevent fraud through a password protected feature that allows for safer online and in-store purchases.<br /> <br /> The catch – these cards are only being tested in the European EMV market on cards that use the chip technology. So will interactive cards take off? Are magnetic-stripe cards becoming obsolete? Will interactive cards nudge the public into creating demand? What do you think?<b></b></span> <p>&nbsp;</p> <p> </p> </span> http://spva.org/blog/10-08-11/U_S_Credit_Cards_Not_Welcome.aspx Steven Hughes http://spva.org/blog/10-08-11/U_S_Credit_Cards_Not_Welcome.aspx 914da1ad-7c99-42ac-a3da-d34931833684 Wed, 11 Aug 2010 12:00:47 GMT You Asked, We Answered <p class="MsoNormal"><span style="font-family: candara; ">During my travels –domestic and international – on behalf of the SPVA, I’ve spoken with hundreds of payment industry stakeholders about what our organization is bringing to the table in terms of security compliance and best practices.</span></p><p class="MsoNormal"><span style="font-family: candara; "><br /></span></p><p class="MsoNormal"><span style="font-family: candara; ">Many of you brought up compelling questions about the SPVA and the industry at-large that I thought were worth addressing in a more public, widespread forum, so here we go. You asked, we answered. Below are some of the issues you wanted to know about. And  please keep the questions coming. We’re here to collaborate with the industry’s best and brightest to reduce fraud and lowering risk for all.</span></p><p class="MsoNormal"><span style="font-family: candara; "><br /></span></p><p class="MsoNormal"><span style="font-family: candara; ">Q. Will the SPVA host an annual conference or other face-to-face networking and educational opportunities?</span></p><p class="MsoNormal"><span style="font-family: candara; "><br /></span></p><p class="MsoNormal"><span style="font-family: candara; ">A. The SPVA currently has no plans to host a stand alone annual conference, however we do host bi-annual meetings of the members at other industry conferences around the world.  In addition, the SPVA is partnering with other industry associations to host Webinars and integrate half day to full dayworkshop sessions at their conferences.</span></p><p class="MsoNormal"><span style="font-family: candara; "><br /></span></p><p class="MsoNormal"><span style="font-family: candara; ">Q. Will the SPVA issue additional white papers similar to the SPVA <a href="http://www.spva.org/presse2e.aspx">End-to-End Encryption Security Requirements</a> paper?</span></p><p class="MsoNormal"><span style="font-family: candara; "><br /></span></p><p class="MsoNormal"><span style="font-family: candara; ">A.  Yes, the SPVA is committed to providing educational white papers and presentations to the payments industry.  The SPVA is comprised of four technical working groups and these working groups are the backbone of the SPVA’s knowledge sharing with the industry stakeholders.  The SPVA will issue additional White Papers during the coming year, and I encourage you to join the SPVA and participate in the formulation of the forthcoming SPVA implementation guidelines.</span></p><p class="MsoNormal"><span style="font-family: candara; "><br /></span></p><p class="MsoNormal"><span style="font-family: candara; ">Q. How do you see mobile apps for devices such as the iPhone and iPad impacting payment security and compliance?</span></p><p class="MsoNormal"><span style="font-family: candara; "><br /></span></p><p class="MsoNormal"><span style="font-family: candara; ">A. Mobile apps definitely are an interesting emerging technology in the payments industry and an area that has potential for attacks and security breaches.  This is certainly an area that needs attention in assuring environments are secure.</span></p><p class="MsoNormal"><span style="font-family: candara; "><br /></span></p><p class="MsoNormal"><span style="font-family: candara; ">Q. What are the benefits to the labs that join the SPVA’s <a href="http://spva.org/press/pressLabNetwork.aspx">Lab Network</a> ?</span></p><p class="MsoNormal"><span style="font-family: candara; "><br /></span></p><p class="MsoNormal"><span style="font-family: candara; ">A: The benefits of joining the SPVA Lab Network is to assure customers that your Lab is an active participant in the development and implementation of the SPVA’s recommended implementation guidelines.  Labs which participate with the SPVA are interacting with the various stakeholders throughout the entire payments process and are instrumental in defining and developing the best practices around secure environments. <o:p></o:p></span></p> http://spva.org/blog/10-07-29/You_Asked_We_Answered.aspx Steven Hughes http://spva.org/blog/10-07-29/You_Asked_We_Answered.aspx 0266319e-1886-4a8a-a790-4bd2870b69d6 Thu, 29 Jul 2010 12:28:57 GMT Now’s The Time <p style="line-height: 13.5pt;"><strong><span style="font-weight: normal; mso-bidi-font-weight: bold;">Google “PCI compliance” or “payment security” and you’ll always find a long list of news stories, but media is picking up the pace, and there couldn’t be a better time to join the fight for tighter security and a common solution to the various – and constantly shifting – security standards.<br /> <br /> </span></strong><strong><span style="font-weight: normal; mso-bidi-font-weight: bold;">As <i style="mso-bidi-font-style: normal;">Infosecurity Magazine</i> reports, “<a shape="rect" href="http://www.infosecurity-magazine.com/view/10669/new-pci-dss-hurdles-loom/" shape="rect"><span style="color: #800080; mso-bidi-font-weight: normal;">PCI DSS hurdles loom</span></a>,” and the industry is taking note. Every stakeholder in the payment process has an ear to the ground, working to keep up with the ever more complex and shifting set of rules and requirements.<br /> <br /> </span></strong><strong><span style="font-weight: normal; mso-bidi-font-weight: bold;">As these worldwide security threats grow and compliance standards evolve, the SPVA is working to stay one step ahead, working not to add another layer but to create a common understanding of existing and newly released standards. Our member-driven </span></strong><span style="mso-bidi-font-style: italic;"><a shape="rect" href="http://spva.org/technicalWorking.aspx" shape="rect">Technical Working Groups</a></span><strong><span style="font-weight: normal; mso-bidi-font-weight: bold;"> are constantly evaluating the latest information to keep stakeholders informed and one step ahead of what they are reading in the news.<br /> <br /> </span></strong>SPVA members represent all points along the payment continuum, from POS payment terminal vendors to software developers to acquirers and so many more. Before your company gets lost in the payment security news and looming regulations, <span style="mso-bidi-font-style: italic;"><a shape="rect" href="http://spva.org/membershipInfo.aspx" shape="rect">join us</a></span> and stay ahead of the game, ultimately keeping your clients and consumers safe from security compromise.<br /> <br /> Steven<br /> <a shape="rect" href="mailto:steven.hughes@spva.org" shape="rect">steven.hughes@spva.org</a></p> <p style="line-height: 13.5pt;">&nbsp;</p> http://spva.org/blog/10-07-12/Now’s_The_Time.aspx Steven Hughes http://spva.org/blog/10-07-12/Now%e2%80%99s_The_Time.aspx bb3ba3c3-c4ba-4540-9281-173279874f81 Mon, 12 Jul 2010 12:49:00 GMT Interview With The Chairman <p><em>In case you missed our most recent </em><a shape="rect" href="http://spva.org/newsletter_v4.aspx" shape="rect"><em>newsletter</em></a><em>, we wanted to share this interview with our new chairman, <st1:PersonName w:st="on">T.K. Cheung</st1:PersonName>.<o:p></o:p></em></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><o:p> </o:p></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><strong>SPVA Welcomes T.K. Cheung as new Chairman of the Board</strong><br /> Hypercom’s vice president global quality &amp; security takes the helm of the SPVA as the founding members rotate leadership positions heading into the organization’s second year. T.K. Cheung talks SPVA accomplishments and goals.</p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"> </p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><strong>What were the most important accomplishments of the SPVA in its inaugural year?</strong><br /> I think our membership numbers (20) speak for themselves and not only the quantity of our members – but the quality. Our members represent the leading companies in the industry. In addition, the establishment of our <a shape="rect" href="http://spva.org/technicalWorking.aspx" shape="rect">Technical Working Groups</a> and the work that is being shared is significant and stands to have a lasting impact on the industry, garnering widespread recognition of our organization.</p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"> </p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><strong>What is your vision for year two?</strong> <br /> I would like to continue to grow the organization and double our numbers this year. In addition, we look forward to the publication of more white papers from the other TWGs, that will be just as impactful as the recent <a shape="rect" href="http://www.spva.org/Files/E2E_EncryptionSecurityRequirements_WP10_May27.pdf" target="_blank" shape="rect">End-to-End Encryption Security Requirements</a> document.</p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"> </p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><strong>What do you see as the biggest challenges for the SPVA?</strong><br /> Hands down, the adoption of SPVA guidelines and recommendations as well as attracting retailers and the card associations to join the SPVA is one of the biggest challenges. This will be a critical step for us as their input is valuable and will help shape our future.</p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"> </p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><strong>What are three things that are not generally known about you?</strong> <br /> I built my first computer from a kit in 1977. It was called a <a shape="rect" href="http://en.wikipedia.org/wiki/Nascom" target="_blank" shape="rect">Nascom 1</a>, and I still have it. My accent is English, not Australian, and I’m fluent in Cantonese.</p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"> </p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><strong>Current personal goal?</strong></p> <p style="line-height: 13.5pt;">To break 100 playing golf. </p> http://spva.org/blog/10-06-17/Interview_With_The_Chairman.aspx Steven Hughes http://spva.org/blog/10-06-17/Interview_With_The_Chairman.aspx 5c7976c3-aeda-43a8-820c-77ebc620f18d Thu, 17 Jun 2010 09:11:36 GMT From End to End – A Guideline is Born <p class="MsoNormal" style="margin: 0in 0in 0pt;">After a year of collaboration and research from our End-to-End Encryption Technical Working Group, I am pleased to announce the release of SPVA’s first white paper, the <a shape="rect" href="http://spva.org/whitePapers.aspx" shape="rect"><em>End-to-End Encryption Security Requirements</em></a>.</p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><o:p> </o:p></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;">This guideline represents SPVA’s commitment to strengthening global payment security standards and creating a common understanding of best practices. The insight and thoroughness with which this framework has been prepared is a testament to our members and to the Technical Working Groups.</p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><o:p> </o:p></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;">The <em>End-to-End Encryption Security Requirements</em> sets a baseline for the industry, and focuses on:</p> <p class="MsoNormal" style="margin: 0in 0in 0pt;">&nbsp;</p> <ul> <li> <p class="MsoNormal" style="margin: 0in 0in 0pt;">Data to be encrypted during transmission</p> </li> <li> <p class="MsoNormal" style="margin: 0in 0in 0pt;">Key management</p> </li> <li> <p class="MsoNormal" style="margin: 0in 0in 0pt;">Physical and logistical security of the TRSM and key components</p> </li> <li> <p class="MsoNormal" style="margin: 0in 0in 0pt;">Encryption monitoring and management systems requirements </p> </li> </ul> <p class="MsoNormal" style="margin: 0in 0in 0pt;">We invite you to <a shape="rect" href="http://spva.org/whitePapers.aspx" shape="rect">download</a> the <em>End-to-End Encryption Security Requirements</em>. We welcome your thoughts and feedback.<o:p></o:p></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><o:p> </o:p></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;">If you are interested in contributing to our next white paper, <a shape="rect" href="http://spva.org/membershipInfo.aspx" shape="rect">membership</a> in the SPVA allows you to join any of our four <a shape="rect" href="http://spva.org/technicalWorking.aspx" shape="rect">Technical Working Groups</a>.</p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><o:p> </o:p></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;">Steven</p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><a shape="rect" href="mailto:steven.hughes@spva.org" shape="rect">steven.hughes@spva.org</a> </p> http://spva.org/blog/10-05-27/From_End_to_End_–_A_Guideline_is_Born.aspx Steven Hughes http://spva.org/blog/10-05-27/From_End_to_End_%e2%80%93_A_Guideline_is_Born.aspx 987ff87a-16db-463a-8e73-a44842e91eef Thu, 27 May 2010 09:59:31 GMT “On the Road Again…” <p>Disclaimer: The following information is subject to change (but hopefully it won’t!).<br /> <br /> But having officially given that disclaimer, it looks like the SPVA’s event schedule is taking shape. We’ve got our eye on four shows in 2010.</p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><a shape="rect" href="http://www.midwestacquirers.com/next_event.php" shape="rect">Midwest Acquirers Association (MWAA)</a><o:p></o:p></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;">July 21-23</p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><st1:place w:st="on"><st1:City w:st="on">Schaumburg,</st1:City> <st1:State w:st="on">IL</st1:State></st1:place></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;">8th Annual MWAA Conference – “Changing Times…Changing Visions”</p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><o:p> </o:p></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><o:p></o:p><a shape="rect" href="http://www.terrapinn.com/2010/cla/" shape="rect">Cards Latin America</a><o:p></o:p></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;">October 4-6</p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><st1:place w:st="on"><st1:City w:st="on">Coral Gables</st1:City>, <st1:State w:st="on">FL</st1:State></st1:place></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><o:p> </o:p></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><a shape="rect" href="http://www.electran.org/content/category/6/75/123/" shape="rect">ETA Strategic Leadership Forum</a><o:p></o:p></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;">October 27-29</p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><st1:place w:st="on"><st1:City w:st="on">Palm Beach</st1:City>, <st1:State w:st="on">FL</st1:State></st1:place></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><st1:place w:st="on"><st1:State w:st="on">"Business Intelligence for a Rising Economy"</st1:State></st1:place></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><o:p> </o:p></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><a shape="rect" href="http://www.cartes.com/ExposiumCms/do/admin/visu?reqCode=accueil" shape="rect">CARTES &amp; IDentification</a><o:p></o:p></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;">December 7-9</p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><st1:place w:st="on"><st1:City w:st="on">Paris</st1:City>, <st1:country-region w:st="on">France</st1:country-region></st1:place></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;">“Digital Security – Smart Technologies – Payment – Mobility”</p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><o:p> </o:p></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;">So if we haven’t met in person or you haven’t had a chance to learn about the <a shape="rect" href="http://spva.org/PDF/SPVA_Top5Reasons_Oct09.pdf" shape="rect">benefits of joining</a> the SPVA, this is a great place to start. Visit us at one (or all) of these shows to see the great work we’ve been doing and talk to us about what our plans are for the future.</p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><o:p> </o:p></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;">There you have it. I wanted you to hear it here first. I encourage you to check our <a shape="rect" href="http://spva.org/events.aspx" shape="rect">events page</a> regularly as we confirm the shows in which the SPVA will be exhibiting, speaking and hosting workshops. Hope to see you on the road in the coming year. Wheels up!</p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><o:p> </o:p></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;">Steven</p> <p><a shape="rect" href="mailto:steven.hughes@spva.org" shape="rect">steven.hughes@spva.org</a></p> <p> </p> http://spva.org/blog/10-05-07/“On_the_Road_Again…”.aspx Steven Hughes http://spva.org/blog/10-05-07/%e2%80%9cOn_the_Road_Again%e2%80%a6%e2%80%9d.aspx 3d750553-46ab-4265-906b-b05dc98f8477 Fri, 07 May 2010 14:36:15 GMT Lights Up on the Lab Network <span style="font-family: times new roman; font-size: 12pt;"> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: verdana; font-size: 9pt;">I don’t think I’ve given our Lab Network its due spotlight on the blog. No excuses since it’s a fantastic opportunity for labs and SPVA members alike. <br /> <br /> <o:p></o:p></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><v:shapetype id="_x0000_t75" path="m@4@5l@4@11@9@11@9@5xe" stroked="f" filled="f" o:preferrelative="t" o:spt="75" coordsize="21600,21600"><v:stroke joinstyle="miter"></v:stroke><v:formulas><v:f eqn="if lineDrawn pixelLineWidth 0"></v:f><v:f eqn="sum @0 1 0"></v:f><v:f eqn="sum 0 0 @1"></v:f><v:f eqn="prod @2 1 2"></v:f><v:f eqn="prod @3 21600 pixelWidth"></v:f><v:f eqn="prod @3 21600 pixelHeight"></v:f><v:f eqn="sum @0 0 1"></v:f><v:f eqn="prod @6 1 2"></v:f><v:f eqn="prod @7 21600 pixelWidth"></v:f><v:f eqn="sum @8 21600 0"></v:f><v:f eqn="prod @7 21600 pixelHeight"></v:f><v:f eqn="sum @10 21600 0"></v:f></v:formulas><v:path o:connecttype="rect" gradientshapeok="t" o:extrusionok="f"></v:path><o:lock aspectratio="t" v:ext="edit"></o:lock></v:shapetype><v:shape id="_x0000_s1026" style="z-index: -1; position: absolute; margin-top: 2.4pt; width: 99pt; height: 89.25pt; margin-left: -9pt;" type="#_x0000_t75" wrapcoords="7467 740 2533 888 2533 3551 0 4142 -133 5918 -133 9912 267 10208 2800 10208 4533 12575 2133 12871 2267 14055 10800 14942 -133 14942 -133 19973 1333 21452 1600 21452 19867 21452 20133 21452 21600 19973 21600 14942 16133 14942 19467 14055 18133 10208 21200 10208 21600 9912 21600 4142 18933 3551 12667 3107 13733 2219 13600 740 7467 740" alt="SPVA Lab Network Logo"><v:imagedata o:href="http://spva.org/Images/Logo_SPVA_LabNetworkMember_.png" src="file:///C:\DOCUME~1\LindsayD\LOCALS~1\Temp\msohtml1\01\clip_image001.png"></v:imagedata><w:wrap type="tight"></w:wrap></v:shape><span style="font-family: verdana; font-size: 9pt;"><o:p></o:p></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: verdana; font-size: 9pt;">For anyone who doesn’t know what I’m referring to, the elevator pitch about SPVA’s <a shape="rect" href="http://spva.org/labnetwork.aspx" target="_blank" shape="rect">Lab Network</a> is this: It’s a group of participating labs that work with our <a shape="rect" href="http://spva.org/members.aspx" target="_blank" shape="rect">members</a> and <a shape="rect" href="http://spva.org/technicalWorking.aspx" target="_blank" shape="rect">Technical Working Groups</a> on security evaluations and implementation guidelines. Ultimately, the Lab Network will work with its peers and with other members to share best practices and improve security throughout the POS industry.<o:p></o:p></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: verdana; font-size: 9pt;"><o:p> </o:p></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: verdana; font-size: 9pt;">So what are the benefits? Here are five reasons why a lab would want to join:<o:p></o:p></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: verdana; font-size: 9pt;"><o:p> </o:p></span></p> <p class="MsoNormal" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; tab-stops: list .5in;"><span style="font-family: symbol; font-size: 9pt; mso-list: ignore; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;">·<span style="font: 7pt 'times new roman';">          </span></span><span style="font-family: verdana; font-size: 9pt;">Recognition throughout the industry as a qualified and effective lab, operating on the forefront of security<o:p></o:p></span></p> <p class="MsoNormal" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; tab-stops: list .5in;"><span style="font-family: symbol; font-size: 9pt; mso-list: ignore; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;">·<span style="font: 7pt 'times new roman';">          </span></span><span style="font-family: verdana; font-size: 9pt;">Access to SPVA’s Technical Working Groups and committee members representing leading payment companies<o:p></o:p></span></p> <p class="MsoNormal" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; tab-stops: list .5in;"><span style="font-family: symbol; font-size: 9pt; mso-list: ignore; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;">·<span style="font: 7pt 'times new roman';">          </span></span><span style="font-family: verdana; font-size: 9pt;">Ability to share best practices and navigate through challenges with PCI’s top players <o:p></o:p></span></p> <p class="MsoNormal" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; tab-stops: list .5in;"><span style="font-family: symbol; font-size: 9pt; mso-list: ignore; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;">·<span style="font: 7pt 'times new roman';">          </span></span><span style="font-family: verdana; font-size: 9pt;">Promotion through SPVA’s website, newsletter, press releases and social media channels<o:p></o:p></span></p> <p class="MsoNormal" style="text-indent: -0.25in; margin: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1; tab-stops: list .5in;"><span style="font-family: symbol; font-size: 9pt; mso-list: ignore; mso-fareast-font-family: symbol; mso-bidi-font-family: symbol;">·<span style="font: 7pt 'times new roman';">          </span></span><span style="font-family: verdana; font-size: 9pt;">Permission to download and use the SPVA Lab Network logo<o:p></o:p></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: verdana; font-size: 9pt;"><o:p> </o:p></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: verdana; font-size: 9pt;">And we’re not letting just anyone in. There are requirements to meet and applications to fill out. For more details about the details, I’m your guy. Email or call – or both!<o:p></o:p></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: verdana; font-size: 9pt;"><o:p> </o:p></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: verdana; font-size: 9pt;">Steven<o:p></o:p></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: verdana; font-size: 9pt;"><a shape="rect" href="mailto:steven.hughes@spva.org" shape="rect"><span style="color: #0000ff;">steven.hughes@spva.org</span></a> </span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="font-family: verdana; font-size: 9pt;">404-760-4223<o:p></o:p></span></p> <p> </p> </span> <p><span style="font-family: times new roman; font-size: 12pt;"></span></p> http://spva.org/blog/10-04-21/Lights_Up_on_the_Lab_Network.aspx Steven Hughes http://spva.org/blog/10-04-21/Lights_Up_on_the_Lab_Network.aspx b10d5fac-ed05-4640-9d70-6afedb485e61 Wed, 21 Apr 2010 09:18:44 GMT SPVA Value to Industry: Questions for Bob Carr <p style="margin-top: 0in; margin-right: 0in; margin-bottom: 0pt; margin-left: 0in; ">I sat down with our newest board member, Bob Carr, CEO of Heartland Payment Systems and SPVA associate member director, to get his perspective on how the SPVA is impacting the world of payments.</p><p style="margin-top: 0in; margin-right: 0in; margin-bottom: 0pt; margin-left: 0in; "> </p><p style="margin-top: 0in; margin-right: 0in; margin-bottom: 0pt; margin-left: 0in; ">Read on for his take on how the organization is helping members protect their data and reputations while staying one step ahead of cunning cybercriminals. This week, he outlines a few key initiatives for us that the SPVA is proud of and talks about recent successes.</p><p style="margin-top: 0in; margin-right: 0in; margin-bottom: 0pt; margin-left: 0in; "><span style="font-family: arial; font-size: 10pt; "> </span></p><p style="margin-top: 0in; margin-right: 0in; margin-bottom: 0pt; margin-left: 0in; "><span style="font-family: arial; font-size: 10pt; "> </span></p><p style="margin-top: 0in; margin-right: 0in; margin-bottom: 0pt; margin-left: 0in; "><strong>Why is the SPVA important to the world of payments?  </strong></p><p style="margin-top: 0in; margin-right: 0in; margin-bottom: 0pt; margin-left: 0in; ">The SPVA is important because it can lead the way in taking valuable digital data out of the POS systems of business owners.  This removal will make merchants, consumers and all stakeholders in the payments infrastructure less vulnerable to cyber criminals.</p><p style="margin-top: 0in; margin-right: 0in; margin-bottom: 0pt; margin-left: 0in; "> </p><p style="margin-top: 0in; margin-right: 0in; margin-bottom: 0pt; margin-left: 0in; "><strong>What’s your long-term vision for the organization?   </strong></p><p style="margin-top: 0in; margin-right: 0in; margin-bottom: 0pt; margin-left: 0in; ">The SPVA can make the break through changes to POS devices, define the standards for those devices, and continue to refine their solutions.</p><p style="margin-top: 0in; margin-right: 0in; margin-bottom: 0pt; margin-left: 0in; "> </p><p style="margin-top: 0in; margin-right: 0in; margin-bottom: 0pt; margin-left: 0in; "><strong>How has Heartland benefitted from membership?  </strong></p><p style="margin-top: 0in; margin-right: 0in; margin-bottom: 0pt; margin-left: 0in; ">The very existence of SPVA has provided proof that TRSM encryption at the POS is a valuable solution in the fight against cybercrime.</p><p style="margin-top: 0in; margin-right: 0in; margin-bottom: 0pt; margin-left: 0in; "> </p><p style="margin-top: 0in; margin-right: 0in; margin-bottom: 0pt; margin-left: 0in; "><strong>What is your advice to prospective member companies with regard to membership, involvement with the SPVA?  </strong></p><p style="margin-top: 0in; margin-right: 0in; margin-bottom: 0pt; margin-left: 0in; ">Any manufacturer or user of POS equipment should support the mission of the SPVA to remove valuable digital data from merchant systems.</p><p style="margin-top: 0in; margin-right: 0in; margin-bottom: 0pt; margin-left: 0in; "> </p><p style="margin-top: 0in; margin-right: 0in; margin-bottom: 0pt; margin-left: 0in; "><strong>What trends are you seeing in the payments industry?  </strong></p><p style="margin-top: 0in; margin-right: 0in; margin-bottom: 0pt; margin-left: 0in; ">A more intense focus on creating real solutions to security breach concerns.</p> http://spva.org/blog/10-03-29/SPVA_Value_to_Industry_Questions_for_Bob_Carr.aspx Steven Hughes http://spva.org/blog/10-03-29/SPVA_Value_to_Industry_Questions_for_Bob_Carr.aspx 3ddfcb63-f6d7-4a28-885c-be1cac3cd2c7 Mon, 29 Mar 2010 14:44:01 GMT Good News/Bad News <p style="margin: 0in 0in 0pt;">Don’t worry. The “bad” news isn’t all that bad. You could say that the good news is the excuse for the bad news. Confused? I’ll explain. The bad news is that I’ve been remiss in posting a blog entry as frequently as I had planned. The “good” news is that the reason for the radio silence is due to the hectic event schedule SPVA has committed to.</p> <p style="margin: 0in 0in 0pt;"> </p> <p style="margin: 0in 0in 0pt;">Having said that, I hope you can join us at some of our upcoming shows. We’ll be at EPCA in Paris and then ETA in Las Vegas (celebrating our one-year anniversary). In between the two dates, we’re participating in a PCI Compliance webinar panel, hosted by BrightTALK.</p> <p style="margin: 0in 0in 0pt;"> </p> <p style="margin: 0in 0in 0pt;">Take a look at some of our upcoming plans. If you’ll be there, please drop me a line – I’d enjoy the chance to meet you.</p> <p style="margin: 0in 0in 0pt;"> </p> <p style="margin: 0in 0in 0pt;"><strong>EPCA Payment Conference</strong> </p> <p style="margin: 0in 0in 0pt;">Bonjour!  Wheels down in Paris on Sunday, March 21. We’ll have a booth set up at the 2010 <a shape="rect" href="http://www.epcaconference.com/index.php/2010/2010/home" shape="rect">EPCA Payment Conference</a> March 22-24. Stop by and say hello.</p> <p style="margin: 0in 0in 0pt;"> </p> <p style="margin: 0in 0in 0pt;"><strong>BrightTALK</strong></p> <p style="margin: 0in 0in 0pt;">If you’re sitting at your computer on March 25 1 p.m. GMT, tune in to this free webinar. The <a shape="rect" href="http://www.brighttalk.com/summit/pcicompliance3" shape="rect">PCI Compliance Summit</a> will be a day-long event, but if you can catch our time slot, we’re sharing the “stage” with SPVA member Witham Labs and the CTO of SecureWorks.</p> <p style="margin: 0in 0in 0pt;"> </p> <p style="margin: 0in 0in 0pt;"><strong>ETA Annual Meeting &amp; Expo</strong></p> <p style="margin: 0in 0in 0pt;">April marks the one-year anniversary of the SPVA. We’ll be back at the place of our launch to hold our annual members’ meeting and board meeting. If you will be in Las Vegas April 13-15, let’s talk.</p> <p style="margin: 0in 0in 0pt;"> </p> <p style="margin: 0in 0in 0pt;">See you on the road.</p> <p style="margin: 0in 0in 0pt;"> </p> <p style="margin: 0in 0in 0pt;">Steven</p> <p style="margin: 0in 0in 0pt;"><a shape="rect" href="mailto:steven.hughes@spva.org" shape="rect">steven.hughes@spva.org</a> </p> <span style="font-family: candara;"> <p style="margin: 0in 0in 0pt;"> </p> </span> http://spva.org/blog/10-03-04/Good_News_Bad_News.aspx Steven Hughes http://spva.org/blog/10-03-04/Good_News_Bad_News.aspx 382ca1d4-6c8e-445c-97fe-6b9e84dbe0a6 Thu, 04 Mar 2010 10:37:24 GMT Expanding Connections <p class="MsoNormal"><span style="font-family: candara; "></span></p><span><p></p><p class="MsoNormal"><span style="font-family: candara; "></span></p><p class="MsoNormal" style="margin-bottom: 7.5pt; "><span style="font-family: arial; font-size: 10pt; color: black; ">The past two weeks have brought significant andexciting changes to the Secure POS Vendor Alliance. <span class="apple-converted-space"> </span>When the SPVA launched less than ayear ago, the founding members – Hypercom, Ingenico and <span class="apple-converted-space"> </span>VeriFone -always had the vision that the organization would not simply be a soapbox for the “big three,” but rather a more inclusive entity that provided a collaborative environment and a stronger voice for ensuring payments security. The 15 additional members that have joined the SPVA over the past eight months agreed, committing their time and resources in return for the value this organization could provide. With two recent developments, we’ve come even further in realizing our vision.<o:p></o:p></span></p><p class="MsoNormal" style="margin-bottom: 7.5pt; "><span style="font-family: arial; font-size: 10pt; color: black; ">Bob Carr, CEO of Heartland Payment Systems, was elected to the 2010 SPVA<span class="apple-converted-space"> </span><a href="http://spva.org/board.aspx">Board of Directors<span class="apple-converted-space" style="text-decoration: none; color: windowtext; "> </span></a>as our Associate Member Director.We are honored to have Bob take on this leadership position and feel there is currently no one better for this role. Bob expressed his commitment to 'bringing POS hardware and software vendors together for the good of all the stakeholders in the payments domain.” I look forward to working with Bob in continued support of our mission.<o:p></o:p></span></p><p class="MsoNormal" style="margin-bottom: 7.5pt; "><span style="font-family: arial; font-size: 10pt; color: black; ">In case you missed it, the SPVA also launched a new involvement opportunity – the<span class="apple-converted-space"> </span><a href="http://www.spva.org/labnetwork.aspx">Lab Network</a>. Our <a href="http://spva.org/OLDtechnicalWorking.aspx" title="Find out more about our Technical Working Groups" target="_blank">Technical Working Groups</a> have been working diligently in the development of implementation guidelines related to end-to-end encryption, payments lifecycle management protocols and other pressing industry needs. Members of theLab Network, including authorized QSA labs, will be given the opportunity to conduct<span class="apple-converted-space"> </span>security evaluations of our implementation guidelines and connect with our other members in sharing best practices and raising the security level within the POS industry.<span class="apple-converted-space"> </span> <o:p></o:p></span></p><p class="MsoNormal" style="margin-bottom: 7.5pt; "><span style="font-family: arial; font-size: 10pt; color: black; ">So as you can see, we’ve been busy around here! We’re convinced that the strides we are making to expand our connections will help to further our goals. If you want to know more about what’s going on at SPVA,<span class="apple-converted-space"> </span><a href="mailto:steven.hughes@spva.org">reach out</a> to me at any time. <o:p></o:p></span></p></span><p></p><p></p><p class="MsoNormal"><span style="font-family: candara; "></span></p> http://spva.org/blog/10-02-11/Expanding_Connections.aspx Steven Hughes http://spva.org/blog/10-02-11/Expanding_Connections.aspx 32205673-83c6-441d-bb86-ae850b1585f6 Thu, 11 Feb 2010 14:35:32 GMT SPVA Attracts More Members <p class="MsoNormal"><span style="font-family: verdana; font-size: 9pt; color: black; ">Elavon, GHL Systems, ID TECH, Independent Purchasing Cooperative, Inc. (IPC) and<span class="apple-converted-space"> </span>Voltage Security<span class="apple-converted-space"> </span>joined the SPVA, bringing our membership total to more than a dozen elite organizations. Following through on their new year’s resolutions to help the SPVA achieve its mission to increase awareness of security issues, each new member is committed to providing the safest operating environment for their partners and customers.</span></p><p class="MsoNormal"><span style="font-family: verdana; font-size: 9pt; color: black; ">These companies are leaders in their respective fields and will bring a high level of expertise to the SPVA effort. We look forward to their involvement and hope to engage all<span class="apple-converted-space"> </span><a href="http://spva.org/members.aspx" target="_blank" style="outline-style: none; outline-width: initial; outline-color: initial; "><span style="color: rgb(43, 57, 60); ">our members</span></a> in the important work of our technical working groups this year.</span></p><p class="MsoNormal"><span style="font-family: verdana; font-size: 9pt; color: black; ">Here’s what some of our current members are saying about SPVA involvement:</span></p><p class="MsoNormal"><span style="font-family: verdana; font-size: 12px; ">“<em>I am very excited to be involved with SPVA, an organization that provides strong support and guidance to the merchant community around security and specifically PCI compliance. In this confusing and everchanging compliance environment, merchants need a trusted and reliable sourcefor information and solutions. The Secure POS Vendor Alliance is focused on bringing answers to the merchant community and supporting their interests when it comes to consumer payment information security.</em>”<span class="apple-converted-space"> <br /></span><strong><span style="font-family: verdana; ">– Doug Dwyre, VP, Business Development, Voltage Security<br /></span></strong></span></p><p class="MsoNormal"><span style="font-family: verdana; font-size: 9pt; color: black; "><strong><span style="font-weight: normal; line-height: 15px; font-family: verdana; font-size: 13px; ">“<em>Heartland has benefited from our membership in SPVA in several ways. The SPVA creates an environment conducive to moving important industry ideas forward – such as improving security of cardholder data from global payment industry participants. The SPVA also provides a forum for participating member companies to demonstrate their commitment to payments security and re-imagine what is possible within the payments ecosystem and set new standards to help move forward on shared security goals.</em>”<span class="apple-converted-space"> <br /></span><strong><span style="font-family: verdana; ">– Bob Carr, Chairman and CEO,</span></strong><span class="apple-converted-space"><strong> </strong></span><strong><span style="font-family: verdana; ">Heartland Payment Systems</span></strong></span></strong></span></p><p class="MsoNormal"><span style="font-family: verdana; font-size: small; line-height: 15px; "><br /></span></p><p class="MsoNormal"><span style="line-height: 15px; font-family: verdana; font-size: small; ">Please join us as we continue to rapidly expand and transform the world of secure payments in 2010 and <strong>don’t forget to vote</strong> by tomorrow, January 22, as the SPVA elects two new board of directors. Contact me at steven.hughes@spva.org to find out about <a href="http://spva.org/membershipInfo.aspx" target="_blank"><span style="color: rgb(43, 57, 60); ">membership opportunities</span></a>. Happy New Year!</span></p><p class="MsoNormal"><span style="line-height: 15px; font-family: verdana; font-size: 13px; "><br /></span></p> http://spva.org/blog/10-01-21/SPVA_Attracts_More_Members.aspx Steven Hughes http://spva.org/blog/10-01-21/SPVA_Attracts_More_Members.aspx e705276e-ce97-48d0-9cdd-9f2ceac545e3 Thu, 21 Jan 2010 09:23:57 GMT Five Good Reasons <p style="margin: 0in 0in 0pt;">As we head (or sprint) toward the finish line that will bring an end to 2009, 2010 promises to be an even more exciting year in the payment processing world. The rapidly-changing mobile marketplace, increasing scrutiny of payment standards, and continuing economic uncertainty are sure to play a role in our industry in the coming year. As you look ahead at ways to grow your business, might I suggest putting “<a shape="rect" href="http://spva.org/welcome.aspx" shape="rect">join SPVA</a>” at the top of the list?</p> <p style="margin: 0in 0in 0pt;"> </p> <p style="margin: 0in 0in 0pt;">Here are my top five reasons you should join: </p> <p style="margin: 0in 0in 0pt;"> </p> <p style="margin: 0in 0in 0pt 0.5in;">1)       Work with leading POS vendors to enrich and develop security guidelines</p> <p style="margin: 0in 0in 0pt 0.5in;">&nbsp;</p> <p style="margin: 0in 0in 0pt 0.5in;">2)       Acquire first-hand knowledge of current security threats and ways to mitigate them</p> <p style="text-align: left; margin: 0in 0in 0pt 0.5in;">&nbsp;</p> <p style="text-align: left; margin: 0in 0in 0pt 0.5in;">3)       Cultivate a common interpretation of existing security standards and public collective implementation guidelines</p> <p style="margin: 0in 0in 0pt 0.5in;">&nbsp;</p> <p style="margin: 0in 0in 0pt 0.5in;">4)       Develop end-to-end lifecycle security guidelines</p> <p style="margin: 0in 0in 0pt 0.5in;">&nbsp;</p> <p style="margin: 0in 0in 0pt 0.5in;">5)       Create industry encryption framework of cardholder data</p> <p style="margin: 0in 0in 0pt;"> </p> <p style="margin: 0in 0in 0pt;">I hope you’ll take the opportunity to <a shape="rect" href="http://spva.org/management.aspx" shape="rect">contact me</a> for more details on what the SPVA is bringing to the industry and what we can bring to your business. </p> <p style="margin: 0in 0in 0pt;"> </p> <p style="margin: 0in 0in 0pt;">I look forward to talking to you.</p> http://spva.org/blog/09-12-28/Five_Good_Reasons.aspx Steven Hughes http://spva.org/blog/09-12-28/Five_Good_Reasons.aspx f188fb56-e146-4071-8af8-d18206c3f1a1 Mon, 28 Dec 2009 10:31:52 GMT Election Day <p class="MsoNormal"><span style="font-family: arial; font-size: 10pt; "></span></p><span><p></p><p class="MsoNormal"><span style="font-family: arial; font-size: 10pt; "></span></p><p></p><p class="MsoNormal"><span style="font-family: arial; font-size: 13px; "></span></p><p class="MsoNormal"><span style="font-family: verdana; font-size: 10pt; color: rgb(102, 102, 102); ">After a successful whirlwind trip to CARTES, we’re settling in but still just as busy on the home front. The SPVA continues to build momentum as new members come onboard, our <a href="http://spva.org/technicalWorking.aspx" target="_blank">technical working groups</a> </span><span style="font-family: verdana; font-size: 10pt; color: rgb(102, 102, 102); ">prepare to release their first whitepapers, and…drumroll…it’s time for us to elect two candidates to the SPVA board of directors.<o:p></o:p></span></p><p class="MsoNormal"><span style="font-family: verdana; font-size: 13px; color: rgb(102, 102, 102); ">For some quick background, the SPVA board is comprised of five directors. Three seats belong to the founding members (VeriFone, Ingenico and Hypercom), and the other two are open to a representative of our general members and a representative of our associate members.</span></p><p class="MsoNormal"><span style="font-family: verdana; font-size: 10pt; color: rgb(102, 102, 102); "><o:p>So who will it be? We have to keep you in suspense until January 6, when the results of the election are made public. Right now, the call for candidates is out, and we’re anticipating strong nominees to emerge over the course of the next few weeks.</o:p></span></p><p class="MsoNormal"><span style="font-family: verdana; font-size: 10pt; color: rgb(102, 102, 102); ">I’ll also take this opportunity to mention again that it’s never too late to <a href="http://spva.org/welcome.aspx" target="_blank">join SPVA</a></span><span style="font-family: verdana; font-size: 10pt; "><span style="color: rgb(102, 102, 102); ">. Take a look at some of the <a href="http://spva.org/benefits.aspx" target="_blank">benefits</a></span><span style="color: rgb(102, 102, 102); ">, and if you act quickly, you may be able to run for a 2010 board seat. And if you’re already a member and wondering what else you can do to help (besides voting, of course), I’d ask that you help us spread theword about SPVA. The larger our membership base, the stronger we’ll be.</span></span></p><p class="MsoNormal"><span style="font-family: verdana; font-size: 13px; color: rgb(102, 102, 102); ">Our plates are full in 2010, so have your say in our strategic direction, policy formation, administration and all matters regarding SPVA’s work scope and mission.</span></p><p class="MsoNormal"><span style="font-family: verdana; font-size: 10pt; color: rgb(102, 102, 102); ">Don’t forget. Only our members are eligible to run for the board and cast a ballot. And as always, please feel free to <a href="http://spva.org/management.aspx" target="_blank">contact me</a></span><span style="font-family: verdana; font-size: 10pt; color: rgb(102, 102, 102); "> if you have any questions.</span></p><p class="MsoNormal"><span style="font-family: verdana; font-size: 13px; color: rgb(102, 102, 102); ">Good luck to all the candidates…</span></p></span><p></p><p></p><p class="MsoNormal"><span style="font-family: arial; font-size: 10pt; "></span></p><p></p><p class="MsoNormal"><span style="font-family: arial; font-size: 10pt; "><o:p></o:p></span></p> http://spva.org/blog/09-12-08/Election_Day.aspx Steven Hughes http://spva.org/blog/09-12-08/Election_Day.aspx 214c4c6d-021b-4288-8fec-34246a8c543f Tue, 08 Dec 2009 13:07:40 GMT Bonjour de Paris! <span style="font-size: 13px; "><p>Hot on the heels of CARTES &amp; IDentification 2009, SPVA members gathered last week for the first official <a shape="rect" href="http://spva.org/members.aspx" title="See the growing SPVA membership" target="_blank">members</a> meeting. Joined by the SPVA board and myself, more than 20 representatives from leading payment industry companies assembled to discuss where SPVA has gone in its short existence and where it is headed. </p><p><em>So why SPVA and why now</em>? </p></span><p><span style="font-size: 13px; ">You don’t have to look much further than the recent data breaches (Radisson Hotels &amp; Resorts, TJX Companies, Network Solutions, etc.) to know that payment security is not where it needs to be. What better way to contribute to the understanding and compliance of existing security standards than to utilize the knowledge of some of the biggest players in the industry. Ingenico, Hypercom and VeriFone are opening the door for an industry-wide meeting of the minds. </span></p><p><span style="font-size: 13px; ">With the creation of four <a shape="rect" href="http://spva.org/technicalWorking.aspx" title="Find out more about SPVA TWGs" target="_blank">Technical Working Groups</a>, SPVA members have the opportunity to affect the future of PCI compliance. One representative from each member company is allowed to sit on a TWG committee. The four TWGs address distinct and critical areas of payment security: </span> </p><ul> <li><strong><span style="font-size: 13px; ">Security Standards</span> </strong></li> <li><strong><span style="font-size: 13px; ">Payment Device Lifecycle</span> </strong></li> <li><strong><span style="font-size: 13px; ">Threat Analysis and Intelligence</span> </strong></li> <li><span style="font-size: 13px; "><strong>E</strong></span><span style="font-size: 13px; "><strong>nd-to-End Encryption</strong> </span></li></ul><p><span style="font-size: 13px; ">One important note is that <em>SPVA does not endorse any one solution over another</em>. Its impartiality allows that any and all retailers, acquirers, POS vendors/supplies and card brands are welcome to <a shape="rect" href="http://spva.org/levels.aspx" title="SPVA membership levels" target="_blank">join the conversation</a> </span><span style="font-size: 13px; ">and share best practices. </span></p><p><span style="font-size: 13px; ">Our TWGs are already in action, and we anticipate the release of an end-to-end encryption implementation guideline in early 2010. Stay tuned for details because we’re not wasting any time getting moving or making our mark on the industry.</span></p><p> </p><p></p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p><p> </p> http://spva.org/blog/09-11-23/Bonjour_de_Paris.aspx Steven Hughes http://spva.org/blog/09-11-23/Bonjour_de_Paris.aspx 05233ddd-83f5-4e51-9489-dff474914bf9 Mon, 23 Nov 2009 15:12:28 GMT