Mastercard SPME §10.6.1 · Jun 2022 → May 2023

Assessments for PCI Violations in Connection with ADC Events

substantive

The changes update timelines and compliance requirements for Terminal Servicers after an ADC Event. Specifically, PCI DSS revalidation is extended from 60 to 90 days post-investigation, and an additional requirement for compliance with the DESV appendix within 12 months is added, strengthening ongoing security obligations.

Sources Mastercard SPME · Jun 2022 · page 119 PDF Mastercard SPME · May 2023 · page 129 PDF ATO Detection current
Why these edits? The update extends the PCI DSS revalidation timeline for Terminal Servicers from 60 to 90 days and adds a requirement for compliance with the DESV appendix within 12 months, directly affecting Account-Takeover (ATO) Detection obligations by strengthening security and compliance timelines after an Account Data Compromise (ADC) event.
Mastercard SPME §10.6.1
Security Rules and Procedures—Merchant Edition • 22 7 February 2022 2023 • Verification that the PFI investigation was initiated within seventy-two (72) hours of the ADC Event or Potential ADC Event and completed as soon as practical. • Timely receipt by Mastercard of the unedited (by other than the forensic examiner) forensic examination findings. • Evidence that the ADC Event or Potential ADC Event was not foreseeable or preventable by commercially reasonable means and that, on a continuing basis, best security practices were applied. In connection with its evaluation of the Customer’s or its Agent’s actions, Mastercard will consider, and may draw adverse inferences from, evidence that a Customer or its Agent(s) deleted or altered data. As soon as practicable, Mastercard will contact the Customer’s Security Contact, Principal Contact, or Account Data Compromise Contact as they are listed in the My Company Manager application, notifying all impacted parties of the impending financial obligation or compensation, as applicable. It is the sole responsibility of each Customer, not Mastercard, to include current and complete information in the My Company Manager application. 10.6.2.1 Potential Reduction of Financial Responsibility for Terminal Servicer ADC Events Notwithstanding a Mastercard determination that an ADC Event occurred, Mastercard may consider the following actions taken by the compromised TS or the responsible Customer, as applicable, to establish, implement, and maintain procedures and support best practices to safeguard Account data prior to, during, and after the ADC Event or Potential ADC Event, in order to relieve, partially or fully, an otherwise responsible Customer of responsibility for any assessments, ADC operational reimbursement, and/or investigative costs. In determining whether to relieve a responsible Customer of any or all financial responsibility, Mastercard may consider whether the Terminal Servicer or the responsible Customer, as applicable, complied with all of the following requirements: • Substantiation to Mastercard from a PCI SSC-approved QSA of the compromised TS’s compliance with the PCI DSS at the time of the ADC Event or Potential ADC Event. • Reporting that certifies any Terminal Servicer(s) associated with the ADC Event or Potential ADC Event as compliant with the PCI DSS and all applicable Mastercard SDP Program requirements at the time of the ADC Event or Potential ADC Event in accordance with section 2.2.3 of this manual. Such reporting must also affirm that all third party-provided payment applications used by the Terminal Servicer(s) associated with the ADC Event or Potential ADC Event are compliant with the Payment Card Industry Payment Application Data Security Standard or the Payment Card Industry Secure Software Standard, as applicable. The applicability of the PCI PA-DSS to third party- provided payment applications is defined in the PCI PA-DSS Program Guide and Account Data Compromise Events 10.6.2.1 Potential Reduction of Financial Responsibility for Terminal Servicer ADC Events Security Rules and Procedures—Merchant Edition • 22 7 February 2022 2023 the applicability of the PCI Secure Software Standard to third party-provided payment software is defined in the PCI Secure Software Program Guide, found at www.pcisecuritystandards.org. • Registration of any TS(s) associated with the ADC Event through Mastercard Connect, in accordance with Chapter 7 of the Mastercard Rules, within 10 calendar days of the TS or the responsible Customer being deemed aware of the ADC Event or Potential ADC Event. • Notification of an ADC Event or Potential ADC Event to and cooperation with Mastercard and, as appropriate, law enforcement authorities. • Verification that the PFI investigation was initiated within seventy-two (72) hours of the ADC Event or Potential ADC Event and completed as soon as practical. • Timely receipt by Mastercard of the unedited (by other than the forensic examiner) forensic examination findings. • Confirmation that any TS(s) associated with the ADC Event or Potential ADC Event completed all of the containment recommendations set forth in the forensic report, and that each such TS revalidated its compliance with the PCI DSS to Mastercard within 60 90 calendar days after the conclusion of the PFI’s investigation. investigation and has additionally demonstrated compliance with the DESV appendix of the PCI DSS within twelve (12) months from achieving full compliance with the PCI DSS. In connection with its evaluation of the Customer’s or its TS’s actions, Mastercard will consider, and may draw adverse inferences from, evidence that a Customer or its TS(s) deleted or altered data. As soon as practicable, Mastercard will contact the Customer’s Security Contact, Principal Contact, or Account Data Compromise Contact as they are listed in the My Company Manager application, notifying all impacted parties of the impending financial obligation or compensation, as applicable. It is the sole responsibility of each Customer, not Mastercard, to include current and complete information in the Company Contact Management application.
Halyard Pay · 2 files
program: ATO Detection
- authority: Mastercard SPME §6.2
+ authority: Mastercard SPME §10.6.2.1
risk_threshold_for_3ds_challenge: 0.5
risk_score_range: [0.0, 1.0]
signals:
- geo_anomaly
- device_fingerprint_change
- velocity_breach
- credential_stuffing
challenge_method: 3ds_v2
persistent_risk_escalation_threshold: 3
persistent_risk_lookback_days: 7
agent_owner: ato_agent
+
+ # This policy incorporates the updated Mastercard SPME §10.6.2.1 requirements,
+ # including extended timelines for Terminal Servicer compliance revalidation
+ # after an Account Data Compromise Event, emphasizing a 90-day PCI DSS
+ # revalidation period and an added 12-month DESV appendix compliance.
+ # It reinforces timely and comprehensive security procedures to mitigate
+ # Account Takeover risk in line with Mastercard's updated security standards.

Account-Takeover (ATO) Detection

Account-takeover fraud occurs when a malicious actor gains unauthorized access to

a cardholder's account and initiates transactions without the cardholder's consent.

Halyard Pay implements real-time risk scoring on authentication events and enforces a

mandatory 3DS (3-D Secure) challenge for any session where the computed risk score

meets or exceeds the defined threshold.

Detection signals

The risk model incorporates multiple behavioral signals: geographic anomalies

inconsistent with a cardholder's established pattern, changes to device fingerprint,

transaction velocity breaches, and indicators of credential-stuffing activity.

Required actions

  1. Evaluate each authentication event against the defined signal list in real time.

  2. Compute a normalized risk score between 0.0 and 1.0.

  3. If the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before

authorizing the transaction.

  1. Log all ATO signals and outcomes in the case management system.

  2. Escalate persistent high-risk accounts to the ATO response team for manual review.

6. In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer

involved revalidates PCI DSS compliance within 90 calendar days after the forensic

investigation concludes, and demonstrate compliance with the PCI DSS Data

Encryption and Software Validation (DESV) appendix within 12 months, consistent

with Mastercard requirements (SPME §10.6.2.1).

Source authority: Mastercard SPME §6.2.§6.2, §10.6.2.1.

policies/ato_detection/policy.md — after applying change

Account-Takeover (ATO) Detection

Account-takeover fraud occurs when a malicious actor gains unauthorized access to

a cardholder's account and initiates transactions without the cardholder's consent.

Halyard Pay implements real-time risk scoring on authentication events and enforces a

mandatory 3DS (3-D Secure) challenge for any session where the computed risk score

meets or exceeds the defined threshold.

Detection signals

The risk model incorporates multiple behavioral signals: geographic anomalies

inconsistent with a cardholder's established pattern, changes to device fingerprint,

transaction velocity breaches, and indicators of credential-stuffing activity.

Required actions

  1. Evaluate each authentication event against the defined signal list in real time.

  2. Compute a normalized risk score between 0.0 and 1.0.

  3. If the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before

authorizing the transaction.

  1. Log all ATO signals and outcomes in the case management system.

  2. Escalate persistent high-risk accounts to the ATO response team for manual review.

6. In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer

involved revalidates PCI DSS compliance within 90 calendar days after the forensic

investigation concludes, and demonstrate compliance with the PCI DSS Data

Encryption and Software Validation (DESV) appendix within 12 months, consistent

with Mastercard requirements (SPME §10.6.2.1).

Source authority: Mastercard SPME §6.2.§6.2, §10.6.2.1.

Source authority: Mastercard SPME §10.6.1.

--- a/policies/ato_detection/rules.yaml
+++ b/policies/ato_detection/rules.yaml
@@ -1,5 +1,5 @@
 program: ATO Detection
-authority: Mastercard SPME §6.2
+authority: Mastercard SPME §10.6.2.1
 risk_threshold_for_3ds_challenge: 0.5
 risk_score_range: [0.0, 1.0]
 signals:
@@ -11,3 +11,10 @@
 persistent_risk_escalation_threshold: 3
 persistent_risk_lookback_days: 7
 agent_owner: ato_agent
+
+# This policy incorporates the updated Mastercard SPME §10.6.2.1 requirements,
+# including extended timelines for Terminal Servicer compliance revalidation
+# after an Account Data Compromise Event, emphasizing a 90-day PCI DSS
+# revalidation period and an added 12-month DESV appendix compliance.
+# It reinforces timely and comprehensive security procedures to mitigate
+# Account Takeover risk in line with Mastercard's updated security standards.
--- a/policies/ato_detection/policy.md
+++ b/policies/ato_detection/policy.md
@@ -20,5 +20,10 @@
    authorizing the transaction.
 4. Log all ATO signals and outcomes in the case management system.
 5. Escalate persistent high-risk accounts to the ATO response team for manual review.
+6. In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer
+   involved revalidates PCI DSS compliance within 90 calendar days after the forensic
+   investigation concludes, and demonstrate compliance with the PCI DSS Data
+   Encryption and Software Validation (DESV) appendix within 12 months, consistent
+   with Mastercard requirements (SPME §10.6.2.1).
 
-Source authority: Mastercard SPME §6.2.
+Source authority: Mastercard SPME §6.2, §10.6.2.1.