Visa Program to Fight Online Fraud Debuts
Computerworld -
Amid increasing concerns about online credit-card fraud rates, Visa International Inc. is addressing the problem with a two-part plan.
The first part, a payment- authentication program, was launched late last month. The second part, a series of security standards that merchants will be asked to follow, is slated to take effect in September, according to Brian Buckley, vice president of product risk and analysis at the Foster City, Calif.-based company.
The initiatives are expected to reduce Internet transaction disputes by as much as 50%.
However, Avivah Litan, an analyst at Gartner Group Inc. in Stamford, Conn., said Visa's new security measures aren't much better than its old certificate-based Secure Electronic Transaction model.
"It was complicated. No one understood it, and no one wanted to use it," Litan said.
According to a recent survey by Gartner Group, credit-card fraud is 12 times more common for online merchants than their off-line counterparts. Credit-card fraud contributed to about $230 million in losses last year, said Litan. That number could go as high as $500 million this year, she added.
The Visa program provides merchants with options to authenticate payments online, protect privacy and ensure that data in transmission is unchanged. The model was designed to work with chip cards, mobile phones, personal digital assistants and set-top boxes.
According to Buckley, this model lets different regions and credit-card issuers select the most appropriate authentication procedures. "This has opened up options," he said.
The voluntary standards will address problems such as those recently faced by Wallingford, Conn.-based CD Universe, where hackers were able to look at buyers' credit-card numbers.
"There are instances where consumer information is held on merchant Web sites or on servers that are accessible via the merchant's Web site and is inadequately protected," Buckley said.
Under the new best practices rules, merchants will be required to install firewalls or keep customer credit-card data in a segregated environment.
"The emphasis is on logical data security," Buckley said.
Additional Resources


White Papers & Webcasts
Sustaining SOX Compliance: Best Practices to Mitigate Risk, Automate Compliance, and Reduce Costs
Since the adoption of SOX, much has been learned about IT compliance. Discover how to make SOX efforts more effective in "Sustaining Sox...
Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....
IDC White Paper: CCM for IT Compliance and Risk Management
Learn from industry analysts how IT organizations are using configuration management to meet compliance requirements and instill best practices. Find out how these...
The Value of Real SaaS at Workday
Cost savings, speed to value, and innovation brought to the enterprise by Workday's software-as-a-service solutions for HR and Payroll....
Keep it Clean: Maintaining the Integrity of your CMDB through Change Detection
Learn how configuration drift can challenge configuration management database (CMDB) integrity and how a configuration audit tool and an effective change management process...
SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....
The Tripwire HIPAA Solution: Meeting the Security Standards Set Forth in Section 164
HIPAA requires businesses that handle personal health information (PHI) to set up strong controls to ensure the security and integrity of that information....
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
Configuration Assessment: Choosing the Right Solution
Configuration assessment lets businesses proactively secure their IT infrastructure and achieve compliance with important industry standards and regulations. Learn why configuration assessment is...
Agile Enterprise Content Management (ECM) for Rapid ROI
Find out how combining ECM and BPM will help adress issues about content rich business processes....
Subscribe to Computerworld
