Mastercard SPME §1.4 · May 2023 → Sep 2023

Connecting to Mastercard—Physical and Logical Security

substantive
⚠ Extraction warning — review against source PDF. One side of the Mastercard SPME text below appears to contain only the page-running header, not body content. This usually means the section heading fell on a page boundary and the body was attributed to a neighbouring section in the source PDF. The AI summary and proposed edit below may be misleading. Verify in: May 2023 · page 11 ↗ · Sep 2023 · page 10 ↗.

The updated section emphasizes the requirement for customers and their agents to prove to Mastercard that they have effective physical and logical security controls in place for any device connecting their processing systems to the Mastercard Network, covering all related components.

Sources Mastercard SPME · May 2023 · page 11 PDF Mastercard SPME · Sep 2023 · page 10 PDF Fraud Monitoring current
Also in §1.x this release substantive §1.4.1 Minimum Security Requirements substantive §1.5 Data Protection substantive §1.5.1 Compliance with Privacy, Data Protection and Information Security Requirements
Why these edits? The updated Mastercard SPME section 1.4 requires customers to demonstrate effective physical and logical security controls for devices connecting to the Mastercard Network, which directly impacts Halyard Pay's fraud monitoring by mandating stronger security assurances.
Mastercard SPME §1.4
This section was substantively restructured between versions (1% text overlap). Compare the texts directly below.
Before · May 2023 · page 11

Security Rules and Procedures—Merchant Edition • 7 February 2023

After · Sep 2023 · page 10

Requirements Each Customer and any agent thereof must be able to demonstrate to the satisfaction of Mastercard the existence and use of meaningful physical and logical security controls for any communications processor or other device used to connect the Customer’s processing systems to the Mastercard Network (herein, “a Mastercard Network Device”) and all associated components, including all hardware, software, systems, and documentation (herein collectively Customer Obligations

Halyard Pay · 2 files
program: Fraud Monitoring
- authority: Mastercard SPME §3.7, §11.1.1
+ authority: Mastercard SPME 73.7, 711.1.1, 71.4
fraud_to_sales_ratio_threshold: 0.015
min_count_per_month: 100
monitoring_cadence: monthly
escalation_actions:
- escalate_to_human_review
- notify_acquirer
lookback_period_months: 1
remediation_review_interval_days: 30
agent_owner: fraud_ops_agent
 
- # MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.
+ # MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME 711.1.1.
# Acquirers may add and search for information on up to five principal owners per Merchant.
# Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.
# Retroactive alert processing is supported for data up to 360 days old.
# Acquirers control receipt and detail of inquiry match information.
# Real-time access via MATCH Online and API, and batch operations remain available.
# Merchant URL information may be added and searched.
- # Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.
+ # After obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.
+ # Additionally, per SPME 71.4, Customers must demonstrate effective physical and logical security controls for devices and systems connecting to the Mastercard Network to support secure fraud monitoring operations.

Fraud Monitoring

Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.

When this policy applies

This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.

  3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.

  4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.

  5. Ensure that all devices connecting to Mastercard network systems comply with Mastercard's requirement for robust physical and logical security controls to safeguard transaction processing.

6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.

6. 7. Track case progress until the account returns to threshold compliance or is terminated.

Source authority: Mastercard SPME §3.7 and §11.1.1.§§1.4, 3.7, and 11.1.1.

policies/fraud_monitoring/policy.md — after applying change

Fraud Monitoring

Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.

When this policy applies

This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.

Required actions

  1. Compute the merchant's rolling fraud-to-sales ratio each calendar month.

  2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.

  3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.

  4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.

  5. Ensure that all devices connecting to Mastercard network systems comply with Mastercard's requirement for robust physical and logical security controls to safeguard transaction processing.

6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.

6. 7. Track case progress until the account returns to threshold compliance or is terminated.

Source authority: Mastercard SPME §3.7 and §11.1.1.§§1.4, 3.7, and 11.1.1.

Source authority: Mastercard SPME §1.4.

--- a/policies/fraud_monitoring/rules.yaml
+++ b/policies/fraud_monitoring/rules.yaml
@@ -1,5 +1,5 @@
 program: Fraud Monitoring
-authority: Mastercard SPME §3.7, §11.1.1
+authority: Mastercard SPME 73.7, 711.1.1, 71.4
 fraud_to_sales_ratio_threshold: 0.015
 min_count_per_month: 100
 monitoring_cadence: monthly
@@ -10,11 +10,12 @@
 remediation_review_interval_days: 30
 agent_owner: fraud_ops_agent
 
-# MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.
+# MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME 711.1.1.
 # Acquirers may add and search for information on up to five principal owners per Merchant.
 # Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.
 # Retroactive alert processing is supported for data up to 360 days old.
 # Acquirers control receipt and detail of inquiry match information.
 # Real-time access via MATCH Online and API, and batch operations remain available.
 # Merchant URL information may be added and searched.
-# Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.
+# After obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.
+# Additionally, per SPME 71.4, Customers must demonstrate effective physical and logical security controls for devices and systems connecting to the Mastercard Network to support secure fraud monitoring operations.
--- a/policies/fraud_monitoring/policy.md
+++ b/policies/fraud_monitoring/policy.md
@@ -12,7 +12,8 @@
 2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
 3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.
 4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted.
-5. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
-6. Track case progress until the account returns to threshold compliance or is terminated.
+5. Ensure that all devices connecting to Mastercard network systems comply with Mastercard's requirement for robust physical and logical security controls to safeguard transaction processing.
+6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
+7. Track case progress until the account returns to threshold compliance or is terminated.
 
-Source authority: Mastercard SPME §3.7 and §11.1.1.
+Source authority: Mastercard SPME §§1.4, 3.7, and 11.1.1.