Mastercard SPME §10.6.2 · May 2023 → Sep 2023

Potential Reduction of Financial Responsibility

substantive

The updated section introduces specific criteria for Terminal Servicer-related ADC Events, adding detailed reporting and investigation timing requirements, plus mandatory registration and compliance confirmations. It establishes responsibilities for Terminal Servicers distinct from general customers and emphasizes timely notification and cooperation with Mastercard and law enforcement.

Sources Mastercard SPME · May 2023 · page 129 PDF Mastercard SPME · Sep 2023 · page 119 PDF ATO Detection current
Also in §10.x this release substantive §10 Should the responsible Customer cause a PFI to conduct an examination, the responsible substantive §10.2 Policy Concerning Account Data Compromise Events and Potential Account Data substantive §10.3 Responsibilities in Connection with ADC Events and Potential ADC Events substantive §10.3.1 Time-Specific Procedures for ADC Events and Potential ADC Events substantive §10.3.2 Ongoing Procedures for ADC Events and Potential ADC Events substantive §10.6.5 Determination of Fraud Recovery (FR) substantive §10.7 Assessments and/or Disqualification for Noncompliance
Why these edits? The update introduces specific criteria and added responsibilities for Terminal Servicers related to ADC Events, including PCI DSS compliance validation, forensic investigation timing, and containment, which aligns with ATO detection procedures covering Section 6.2 referenced in Mastercard's rules.
Mastercard SPME §10.6.2
Security Rules and Procedures—Merchant Edition • 1 August 2023 application, notifying all impacted parties of the impending financial obligation or compensation, as applicable. It is the sole responsibility of each Customer, not Mastercard, to include current and complete information in the My Company Manager application. 10.6.2.1 Potential Reduction of Financial Responsibility for Terminal Servicer ADC Events Notwithstanding a Mastercard determination that an ADC Event occurred, Mastercard may consider any the following actions taken by the compromised entity to ¶ TS or the responsible Customer, as applicable, to establish, implement, and maintain procedures and support best practices to safeguard Account data prior to, during, and after the ADC Event or Potential ADC Event, in order to relieve, partially or fully, an otherwise responsible Customer of responsibility for any assessments, ADC operational reimbursement, and/or investigative costs. In determining whether to relieve a responsible Customer of any or all financial responsibility, Mastercard may consider whether the Customer ¶ has Terminal Servicer or the responsible Customer, as applicable, complied with all of the following requirements: • Substantiation to Mastercard from a PCI SSC-approved Qualified Security ¶ Assessor (QSA) of the compromised entity’s TS’s compliance with the PCI DSS at the time of the ADC Event or Potential ADC Event. • Reporting that certifies any MerchantTerminal Servicer(s) associated with the ADC Event or ¶ Potential Potential ADC Event as compliant with the PCI DSS and all applicable ¶ Mastercard Site Data Protection (Mastercard SDP) Program requirements at the time of the ADC Event or Potential ADC Event in accordance with section 2.2.1 2.2.3 of this manual. Such reporting must also affirm that all third party-provided payment applications used by the MerchantTerminal Servicer(s) associated with the ADC Event or Potential ADC Event are compliant with the Payment Card Industry Payment Application Data Security Standard or the Payment Card Industry Secure Software Standard, as applicable. The applicability of the PCI PA-DSS to third party-provided payment applications is defined in the PCI PA-DSS Program Guide and the applicability of the PCI Secure Software Standard to third party- ¶ provided party-provided payment software is defined in the PCI Secure Software Program Guide, found at www.pcisecuritystandards.org. • If the compromised entity is a Europe Region Merchant, a PFI has validated that ¶ the Merchant was compliant with milestones one and two of the PCI DSS ¶ Prioritized Approach at the time of the ADC Event or Potential ADC Event. ¶ • ¶ Registration of any TPP(s) or DSETS(s) associated with the ADC Event through Mastercard Connect, in accordance with Chapter 7 of the Mastercard Rules. Rules, within 10 calendar days of the TS or the responsible Customer being deemed aware of the ADC Event or Potential ADC Event. • Notification of an ADC Event or Potential ADC Event to and cooperation with ¶ Mastercard Mastercard and, as appropriate, law enforcement authorities. Verification that the PFI investigation was initiated within seventy-two (72) hours of the ADC Event or Potential ADC Event and completed as soon as practical. Timely receipt by Mastercard of the unedited (by other than the forensic examiner) forensic examination findings. Confirmation that any TS(s) associated with the ADC Event or Potential ADC Event completed all of the containment recommendations set forth in the forensic report, and that each such TS revalidated its compliance with the PCI DSS to Mastercard within 90 calendar days after the conclusion of the PFI’s investigation and has additionally demonstrated compliance with the DESV appendix of the PCI DSS within twelve (12) months from achieving full compliance with the PCI DSS. Account Data Compromise Events 10.6.2.1 Potential Reduction of Financial Responsibility for Terminal Servicer ADC Events Security Rules and Procedures—Merchant Edition • 1 August 2023 In connection with its evaluation of the Customer’s or its TS’s actions, Mastercard will consider, and may draw adverse inferences from, evidence that a Customer or its TS(s) deleted or altered data. As soon as practicable, Mastercard will contact the Customer’s Security Contact, Principal Contact, or Account Data Compromise Contact as they are listed in the My Company Manager application, notifying all impacted parties of the impending financial obligation or compensation, as applicable. It is the sole responsibility of each Customer, not Mastercard, to include current and complete information in the Company Contact Management application.
Halyard Pay · 2 files
program: ATO Detection
authority: Mastercard SPME §10.6.2.1
risk_threshold_for_3ds_challenge: 0.5
risk_score_range: [0.0, 1.0]
signals:
- geo_anomaly
- device_fingerprint_change
- velocity_breach
- credential_stuffing
challenge_method: 3ds_v2
persistent_risk_escalation_threshold: 3
persistent_risk_lookback_days: 7
agent_owner: ato_agent
 
- # This policy incorporates the updated Mastercard SPME §10.6.2.1 requirements,
- # including extended timelines for Terminal Servicer compliance revalidation
- # after an Account Data Compromise Event, emphasizing a 90-day PCI DSS
- # revalidation period and an added 12-month DESV appendix compliance.
- # It reinforces timely and comprehensive security procedures to mitigate
- # Account Takeover risk in line with Mastercard's updated security standards.
+ # This policy update reflects the expanded requirements in Mastercard SPME §10.6.2.1 for Terminal Servicers in Account Data Compromise (ADC) events,
+ # including mandated PCI DSS compliance verification at event time, timely forensic investigations, and enforced containment measures with
+ # a 90-day PCI DSS revalidation and a further 12-month PCI DESV appendix compliance period. These detailed steps support risk mitigation
+ # aligned with Mastercard’s enhanced responsibility reductions during ADC events, reinforcing rigorous security controls within the ATO detection program.

Account-Takeover (ATO) Detection

Account-takeover fraud occurs when a malicious actor gains unauthorized access to a cardholder's account and initiates transactions without the cardholder's consent. Halyard Pay implements real-time risk scoring on authentication events and enforces a mandatory 3DS (3-D Secure) challenge for any session where the computed risk score meets or exceeds the defined threshold.

Detection signals

The risk model incorporates multiple behavioral signals: geographic anomalies inconsistent with a cardholder's established pattern, changes to device fingerprint, transaction velocity breaches, and indicators of credential-stuffing activity.

Required actions

  1. Evaluate each authentication event against the defined signal list in real time.

  2. Compute a normalized risk score between 0.0 and 1.0.

  3. If the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before authorizing the transaction.

  4. Log all ATO signals and outcomes in the case management system.

  5. Escalate persistent high-risk accounts to the ATO response team for manual review.

  6. In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer (TS) involved revalidates PCI DSS compliance within 90 calendar days after the completion of a forensic ¶ investigation concludes, and demonstrate investigation, demonstrates compliance with the PCI DSS Data Encryption and Software Validation (DESV) appendix within 12 months, and cooperates fully with Mastercard and law enforcement, consistent ¶ with with the requirements outlined in Mastercard requirements (SPME §10.6.2.1). §10.6.2.1.

7. Require prompt initiation and timely completion of forensic investigations by a PCI Forensic Investigator (PFI) within 72 hours of the ADC or Potential ADC Event.

8. Confirm that all identified containment actions from forensic reports have been completed by involved Terminal Servicers.

These enhanced controls align with Mastercard's comprehensive approach to minimizing the risk and impact of ADC events through stringent compliance and timely response protocols.

Source authority: Mastercard SPME §6.2, §10.6.2.1.

policies/ato_detection/policy.md — after applying change

Account-Takeover (ATO) Detection

Account-takeover fraud occurs when a malicious actor gains unauthorized access to a cardholder's account and initiates transactions without the cardholder's consent. Halyard Pay implements real-time risk scoring on authentication events and enforces a mandatory 3DS (3-D Secure) challenge for any session where the computed risk score meets or exceeds the defined threshold.

Detection signals

The risk model incorporates multiple behavioral signals: geographic anomalies inconsistent with a cardholder's established pattern, changes to device fingerprint, transaction velocity breaches, and indicators of credential-stuffing activity.

Required actions

  1. Evaluate each authentication event against the defined signal list in real time.

  2. Compute a normalized risk score between 0.0 and 1.0.

  3. If the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before authorizing the transaction.

  4. Log all ATO signals and outcomes in the case management system.

  5. Escalate persistent high-risk accounts to the ATO response team for manual review.

  6. In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer (TS) involved revalidates PCI DSS compliance within 90 calendar days after the completion of a forensic ¶ investigation concludes, and demonstrate investigation, demonstrates compliance with the PCI DSS Data Encryption and Software Validation (DESV) appendix within 12 months, and cooperates fully with Mastercard and law enforcement, consistent ¶ with with the requirements outlined in Mastercard requirements (SPME §10.6.2.1). §10.6.2.1.

7. Require prompt initiation and timely completion of forensic investigations by a PCI Forensic Investigator (PFI) within 72 hours of the ADC or Potential ADC Event.

8. Confirm that all identified containment actions from forensic reports have been completed by involved Terminal Servicers.

These enhanced controls align with Mastercard's comprehensive approach to minimizing the risk and impact of ADC events through stringent compliance and timely response protocols.

Source authority: Mastercard SPME §6.2, §10.6.2.1.

Source authority: Mastercard SPME §10.6.2.

--- a/policies/ato_detection/rules.yaml
+++ b/policies/ato_detection/rules.yaml
@@ -12,9 +12,7 @@
 persistent_risk_lookback_days: 7
 agent_owner: ato_agent
 
-# This policy incorporates the updated Mastercard SPME §10.6.2.1 requirements,
-# including extended timelines for Terminal Servicer compliance revalidation
-# after an Account Data Compromise Event, emphasizing a 90-day PCI DSS
-# revalidation period and an added 12-month DESV appendix compliance.
-# It reinforces timely and comprehensive security procedures to mitigate
-# Account Takeover risk in line with Mastercard's updated security standards.+# This policy update reflects the expanded requirements in Mastercard SPME §10.6.2.1 for Terminal Servicers in Account Data Compromise (ADC) events,
+# including mandated PCI DSS compliance verification at event time, timely forensic investigations, and enforced containment measures with
+# a 90-day PCI DSS revalidation and a further 12-month PCI DESV appendix compliance period. These detailed steps support risk mitigation
+# aligned with Mastercard’s enhanced responsibility reductions during ADC events, reinforcing rigorous security controls within the ATO detection program.

--- a/policies/ato_detection/policy.md
+++ b/policies/ato_detection/policy.md
@@ -1,29 +1,23 @@
 # Account-Takeover (ATO) Detection
 
-Account-takeover fraud occurs when a malicious actor gains unauthorized access to
-a cardholder's account and initiates transactions without the cardholder's consent.
-Halyard Pay implements real-time risk scoring on authentication events and enforces a
-mandatory 3DS (3-D Secure) challenge for any session where the computed risk score
-meets or exceeds the defined threshold.
+Account-takeover fraud occurs when a malicious actor gains unauthorized access to a cardholder's account and initiates transactions without the cardholder's consent. Halyard Pay implements real-time risk scoring on authentication events and enforces a mandatory 3DS (3-D Secure) challenge for any session where the computed risk score meets or exceeds the defined threshold.
 
 ## Detection signals
 
-The risk model incorporates multiple behavioral signals: geographic anomalies
-inconsistent with a cardholder's established pattern, changes to device fingerprint,
-transaction velocity breaches, and indicators of credential-stuffing activity.
+The risk model incorporates multiple behavioral signals: geographic anomalies inconsistent with a cardholder's established pattern, changes to device fingerprint, transaction velocity breaches, and indicators of credential-stuffing activity.
 
 ## Required actions
 
 1. Evaluate each authentication event against the defined signal list in real time.
 2. Compute a normalized risk score between 0.0 and 1.0.
-3. If the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before
-   authorizing the transaction.
+3. If the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before authorizing the transaction.
 4. Log all ATO signals and outcomes in the case management system.
 5. Escalate persistent high-risk accounts to the ATO response team for manual review.
-6. In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer
-   involved revalidates PCI DSS compliance within 90 calendar days after the forensic
-   investigation concludes, and demonstrate compliance with the PCI DSS Data
-   Encryption and Software Validation (DESV) appendix within 12 months, consistent
-   with Mastercard requirements (SPME §10.6.2.1).
+6. In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer (TS) involved revalidates PCI DSS compliance within 90 calendar days after completion of a forensic investigation, demonstrates compliance with the PCI DSS Data Encryption and Software Validation (DESV) appendix within 12 months, and cooperates fully with Mastercard and law enforcement, consistent with the requirements outlined in Mastercard SPME §10.6.2.1.
+
+7. Require prompt initiation and timely completion of forensic investigations by a PCI Forensic Investigator (PFI) within 72 hours of the ADC or Potential ADC Event.
+8. Confirm that all identified containment actions from forensic reports have been completed by involved Terminal Servicers.
+
+These enhanced controls align with Mastercard's comprehensive approach to minimizing the risk and impact of ADC events through stringent compliance and timely response protocols.
 
 Source authority: Mastercard SPME §6.2, §10.6.2.1.