Mastercard SPME §10.6.2 · May 2023 → Sep 2023
Potential Reduction of Financial Responsibility
The updated section introduces specific criteria for Terminal Servicer-related ADC Events, adding detailed reporting and investigation timing requirements, plus mandatory registration and compliance confirmations. It establishes responsibilities for Terminal Servicers distinct from general customers and emphasizes timely notification and cooperation with Mastercard and law enforcement.
program: ATO Detectionauthority: Mastercard SPME §10.6.2.1risk_threshold_for_3ds_challenge: 0.5risk_score_range: [0.0, 1.0]signals:- geo_anomaly- device_fingerprint_change- velocity_breach- credential_stuffingchallenge_method: 3ds_v2persistent_risk_escalation_threshold: 3persistent_risk_lookback_days: 7agent_owner: ato_agent- # This policy incorporates the updated Mastercard SPME §10.6.2.1 requirements,- # including extended timelines for Terminal Servicer compliance revalidation- # after an Account Data Compromise Event, emphasizing a 90-day PCI DSS- # revalidation period and an added 12-month DESV appendix compliance.- # It reinforces timely and comprehensive security procedures to mitigate- # Account Takeover risk in line with Mastercard's updated security standards.+ # This policy update reflects the expanded requirements in Mastercard SPME §10.6.2.1 for Terminal Servicers in Account Data Compromise (ADC) events,+ # including mandated PCI DSS compliance verification at event time, timely forensic investigations, and enforced containment measures with+ # a 90-day PCI DSS revalidation and a further 12-month PCI DESV appendix compliance period. These detailed steps support risk mitigation+ # aligned with Mastercard’s enhanced responsibility reductions during ADC events, reinforcing rigorous security controls within the ATO detection program.
Account-Takeover (ATO) Detection
Account-takeover fraud occurs when a malicious actor gains unauthorized access to ¶ a cardholder's account and initiates transactions without the cardholder's consent. ¶ Halyard Pay implements real-time risk scoring on authentication events and enforces a ¶ mandatory 3DS (3-D Secure) challenge for any session where the computed risk score ¶ meets or exceeds the defined threshold.
Detection signals
The risk model incorporates multiple behavioral signals: geographic anomalies ¶ inconsistent with a cardholder's established pattern, changes to device fingerprint, ¶ transaction velocity breaches, and indicators of credential-stuffing activity.
Required actions
-
Evaluate each authentication event against the defined signal list in real time.
-
Compute a normalized risk score between 0.0 and 1.0.
-
If the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before
¶authorizing the transaction. -
Log all ATO signals and outcomes in the case management system.
-
Escalate persistent high-risk accounts to the ATO response team for manual review.
-
In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer
¶(TS) involved revalidates PCI DSS compliance within 90 calendar days afterthecompletion of a forensic¶ investigation concludes, and demonstrateinvestigation, demonstrates compliance with the PCI DSS Data¶Encryption and Software Validation (DESV) appendix within 12 months, and cooperates fully with Mastercard and law enforcement, consistent¶ withwith the requirements outlined in Mastercardrequirements (SPME§10.6.2.1).§10.6.2.1.
7. Require prompt initiation and timely completion of forensic investigations by a PCI Forensic Investigator (PFI) within 72 hours of the ADC or Potential ADC Event.
8. Confirm that all identified containment actions from forensic reports have been completed by involved Terminal Servicers.
These enhanced controls align with Mastercard's comprehensive approach to minimizing the risk and impact of ADC events through stringent compliance and timely response protocols.
Source authority: Mastercard SPME §6.2, §10.6.2.1.
Account-Takeover (ATO) Detection
Account-takeover fraud occurs when a malicious actor gains unauthorized access to ¶ a cardholder's account and initiates transactions without the cardholder's consent. ¶ Halyard Pay implements real-time risk scoring on authentication events and enforces a ¶ mandatory 3DS (3-D Secure) challenge for any session where the computed risk score ¶ meets or exceeds the defined threshold.
Detection signals
The risk model incorporates multiple behavioral signals: geographic anomalies ¶ inconsistent with a cardholder's established pattern, changes to device fingerprint, ¶ transaction velocity breaches, and indicators of credential-stuffing activity.
Required actions
-
Evaluate each authentication event against the defined signal list in real time.
-
Compute a normalized risk score between 0.0 and 1.0.
-
If the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before
¶authorizing the transaction. -
Log all ATO signals and outcomes in the case management system.
-
Escalate persistent high-risk accounts to the ATO response team for manual review.
-
In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer
¶(TS) involved revalidates PCI DSS compliance within 90 calendar days afterthecompletion of a forensic¶ investigation concludes, and demonstrateinvestigation, demonstrates compliance with the PCI DSS Data¶Encryption and Software Validation (DESV) appendix within 12 months, and cooperates fully with Mastercard and law enforcement, consistent¶ withwith the requirements outlined in Mastercardrequirements (SPME§10.6.2.1).§10.6.2.1.
7. Require prompt initiation and timely completion of forensic investigations by a PCI Forensic Investigator (PFI) within 72 hours of the ADC or Potential ADC Event.
8. Confirm that all identified containment actions from forensic reports have been completed by involved Terminal Servicers.
These enhanced controls align with Mastercard's comprehensive approach to minimizing the risk and impact of ADC events through stringent compliance and timely response protocols.
Source authority: Mastercard SPME §6.2, §10.6.2.1.
Source authority: Mastercard SPME §10.6.2.
--- a/policies/ato_detection/rules.yaml +++ b/policies/ato_detection/rules.yaml @@ -12,9 +12,7 @@ persistent_risk_lookback_days: 7 agent_owner: ato_agent -# This policy incorporates the updated Mastercard SPME §10.6.2.1 requirements, -# including extended timelines for Terminal Servicer compliance revalidation -# after an Account Data Compromise Event, emphasizing a 90-day PCI DSS -# revalidation period and an added 12-month DESV appendix compliance. -# It reinforces timely and comprehensive security procedures to mitigate -# Account Takeover risk in line with Mastercard's updated security standards.+# This policy update reflects the expanded requirements in Mastercard SPME §10.6.2.1 for Terminal Servicers in Account Data Compromise (ADC) events, +# including mandated PCI DSS compliance verification at event time, timely forensic investigations, and enforced containment measures with +# a 90-day PCI DSS revalidation and a further 12-month PCI DESV appendix compliance period. These detailed steps support risk mitigation +# aligned with Mastercard’s enhanced responsibility reductions during ADC events, reinforcing rigorous security controls within the ATO detection program. --- a/policies/ato_detection/policy.md +++ b/policies/ato_detection/policy.md @@ -1,29 +1,23 @@ # Account-Takeover (ATO) Detection -Account-takeover fraud occurs when a malicious actor gains unauthorized access to -a cardholder's account and initiates transactions without the cardholder's consent. -Halyard Pay implements real-time risk scoring on authentication events and enforces a -mandatory 3DS (3-D Secure) challenge for any session where the computed risk score -meets or exceeds the defined threshold. +Account-takeover fraud occurs when a malicious actor gains unauthorized access to a cardholder's account and initiates transactions without the cardholder's consent. Halyard Pay implements real-time risk scoring on authentication events and enforces a mandatory 3DS (3-D Secure) challenge for any session where the computed risk score meets or exceeds the defined threshold. ## Detection signals -The risk model incorporates multiple behavioral signals: geographic anomalies -inconsistent with a cardholder's established pattern, changes to device fingerprint, -transaction velocity breaches, and indicators of credential-stuffing activity. +The risk model incorporates multiple behavioral signals: geographic anomalies inconsistent with a cardholder's established pattern, changes to device fingerprint, transaction velocity breaches, and indicators of credential-stuffing activity. ## Required actions 1. Evaluate each authentication event against the defined signal list in real time. 2. Compute a normalized risk score between 0.0 and 1.0. -3. If the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before - authorizing the transaction. +3. If the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before authorizing the transaction. 4. Log all ATO signals and outcomes in the case management system. 5. Escalate persistent high-risk accounts to the ATO response team for manual review. -6. In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer - involved revalidates PCI DSS compliance within 90 calendar days after the forensic - investigation concludes, and demonstrate compliance with the PCI DSS Data - Encryption and Software Validation (DESV) appendix within 12 months, consistent - with Mastercard requirements (SPME §10.6.2.1). +6. In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer (TS) involved revalidates PCI DSS compliance within 90 calendar days after completion of a forensic investigation, demonstrates compliance with the PCI DSS Data Encryption and Software Validation (DESV) appendix within 12 months, and cooperates fully with Mastercard and law enforcement, consistent with the requirements outlined in Mastercard SPME §10.6.2.1. + +7. Require prompt initiation and timely completion of forensic investigations by a PCI Forensic Investigator (PFI) within 72 hours of the ADC or Potential ADC Event. +8. Confirm that all identified containment actions from forensic reports have been completed by involved Terminal Servicers. + +These enhanced controls align with Mastercard's comprehensive approach to minimizing the risk and impact of ADC events through stringent compliance and timely response protocols. Source authority: Mastercard SPME §6.2, §10.6.2.1.