Silicus sets up a short term special purpose ODC staffed with secure programming experts to successfully achieve PCI DSS application compliance for a Fortune 500 Financial Services Company
About the Client
The client is a provider of financial electronic commerce services, products. The client’s solutions power electronic billing and payment, while automating financial transactions and streamlining regulatory reporting. The client’s solution portfolio includes a membership software solution for the health and fitness club industry.
Challenge
The client needed to get its membership solution certified for PA-DSS Compliance in accordance with regulations from Credit Card merchants. The PCI Data Security Standard (DSS) is a set of comprehensive requirements for enhancing payment account data security, and was developed by the founding payment brands of the PCI Security Standards Council (including American Express, Discover Financial Services, JCB International, MasterCard Worldwide and Visa International) to help facilitate the adoption of consistent data security measures.
Making web applications PA-DSS compliant includes checking the applications against OWASP top 10 vulnerabilities. These are a set of architectural and usage scenarios considerations: web based multi-tier, smart client and thick client meant for internal and public use. This includes use of web services, complex third party integrations with multiple payment gateways.
The project was kick-started with a training session on OWASP vulnerabilities, PCI & PA-DSS requirements and secure coding practices for all the Microsoft.NET developers who would be working on the project. The online training was conducted by IBM and subsequently PCI DSS & PA-DSS requirements overview training by Control Case. The QA team also went through a special training of the IBM Appscan tool. This tool provides web applications security vulnerability scanning, testing and reporting.
After the training, the first task the developers undertook was to develop a Common Security Framework. This was essentially a generic security framework/accelerator in .NET to address common security concerns like:
With the framework in place, the team set about re-engineering the software application to adhere to PA-DSS requirements. The changes included:
Parts of the software re-engineering effort were avoided through the use of pre-built .NET assemblies that make use of industry standards like:
The team engaged in rigorous Code Review sessions, including implementation of checklist based comprehensive, effective security code review methodology.
During the development, the QA team was involved in extensive testing using security test cases, AppScan tool (web applications), SoapUI tool (web services).
PCI Compliance expertise delivered from a low cost location
PCI compliance software re-engineering services are fairly niche, with only PCI certified companies offering these services. By partnering with an offshore company, the client was able to gain access to niche software engineering expertise at a fraction of the cost
Software Engineering Risk Mitigation
Failure to get the application ready for PA-DSS compliance within the deadline would have resulted in loss of business. A strong set of software engineering practices, processes ensured that risks, challenges were understood upfront and addressed without adversely impacting the project timelines
To meet the deadline, Silicus responded by quickly ramping up a team of 10 individuals ranging from Architects, developers, QA engineers and PCI experts to complete the exercise in 6.5 months and within the stipulated deadline