Having an additional security layer assists in preventing unauthorized card-not-present transactions and protects the merchant from exposure to fraud. There are three (3) domains within the standard, consisting of the merchant/acquirer, issuer, and interoperability domain (e.g. payments systems). Schellman 3DS assessors can assist in navigating Parts 1 and 2 of a customer's 3DE (3DS environment) and assessing the appropriate requirements.
The PCI 3DS Program is designed to be a set of procedural and security requirements supporting the 3-D Secure - Protocol and Core Functions Specification requirements set forth by EMVCo. The goal of 3DS is to support app-based authentication and integration with digital wallets and traditional browser-based e-commerce transactions. Consisting of Parts 1 and 2, the PCI 3DS Program supports the security requirements and assessment procedures for a customer's 3DE (3DS environment) that may consist of one or more of the following: the Access Control Server (ACS), Directory Server (DS), and 3DS Server. Part 1: The Baseline Security Requirements looks and feels similar to a PCI DSS assessment, while Part 2: 3DS Security Requirements looks at the specific functionality of the 3DS components and their interworkings.
After the agreement is executed, the first phase of the engagement is planning. This is to ensure that Schellman and the Client are fully aware of the what, who, when, why, and how prior to the beginning of testing.
Proper planning is imperative to the success of a project. Schellman has standard processes to cover the important pieces of the engagement.
The kickoff is considered the start of the engagement. If needed, Schellman will schedule a call at the beginning of, or just prior to, the kickoff to finalize any outstanding items. Schellman will be available to the client with any questions.
By including communication prior to starting, Schellman ensures that no last -minute changes to the project or team have occurred and the Client has the plan prior to the testing and on-site visit.
Testing and gathering is the core of the compliance engagement. Due to the planning and understanding processes, this phase will be an accumulation of gathering the evidence needed for the objectives discussed.
Schellman provides comprehensive solutions for all PCI standards including PCI DSS, which can be used in place of Part 1 if the 3DS environment is physically and logically located within a customer's CDE. If we are performing the DSS and 3DS assessments in tandem, we can help identify areas and provide guidance as to where we can leverage information from DSS.
Schellman’s testing methodology ends with reporting, but the entire assessment is focused on creating a deliverable that is clear, concise, and accurate.
Schellman’s report takes into account the entire process and customizes a report for each Client. The draft report will be provided within 2 weeks of the last day of testing and gathering phase, and a final report will be provided within 30 days. This timing is unsurpassed by the industry.
Joe O'Donnell is a Manager with Schellman mainly dedicated to the PCI and PCI specialty service lines. Before focusing his career on IT auditing services, Joe worked as an Enterprise Operations Computing Analyst where he gained experience in IT systems analysis and data center operations.
Whether it is an ISO 27001 certification, SOC 2 examination or a FedRAMP assessment, companies are often challenged by the need to address customer requirements while ensuring a return on compliance investment.
The most important factor in scoping a potential assessment is understanding what deliverable the recipient (i.e. your customer or partner) is expecting.
Once we have scoped your environment and needs, there are several factors that contribute to Schellman’s pricing: