Mastercard SPME §10.2 · Feb 2024 → Sep 2024
Policy Concerning Account Data Compromise Events and Potential Account Data
The section content has been removed entirely with no replacement text in the August 2024 edition, indicating a full deletion of the previous policy on account data compromise events.
Compromise Events Security Rules and Procedures—Merchant Edition • 6 February 2024
is in the best position to safeguard its systems, to require and monitor the safeguarding of its Agents’ systems, and to insure against, and respond to, ADC Events and Potential ADC Events. Mastercard requires that each Customer apply the utmost diligence and forthrightness in protecting against and responding to any ADC Event or Potential ADC Event. Each Customer acknowledges and agrees that Mastercard has both the right and need to obtain full disclosure (as determined by Mastercard) concerning the causes and effects of an ADC Event or Potential ADC Event as well as the authority to impose assessments, recover costs, and administer compensation, if appropriate, to Customers that have incurred costs, expenses, losses, and/or other liabilities in connection with ADC Events and Potential ADC Events. Except as otherwise expressly provided for in the Standards, Mastercard determinations with respect to the occurrence of and responsibility for ADC Events or Potential ADC Events are conclusive and are not subject to appeal or review within Mastercard. Any Customer that is uncertain with respect to rights and obligations relating to or arising in connection with the Account Data Compromise Event Standards and Programs set forth in this Chapter 10 should request advice from Mastercard. Notwithstanding the generality of the foregoing, the relationship of network, system, and environment configurations with other networks, systems, and environments will often vary, and each ADC Event and Potential ADC Event tends to have its own particular set of circumstances. Mastercard has the sole authority to interpret and enforce the Standards, including those set forth in this chapter. Consistent with the foregoing and pursuant to the definitions set forth in section 10.1 above, Mastercard may determine, as a threshold matter, whether a given set of circumstances constitutes a single ADC Event or multiple ADC Events. In this regard, and by way of example, where a Customer or Merchant connects to, utilizes, accesses, or participates in a common network, system, or environment with one or more other Customers, Merchants, Service Providers, or third parties, a breach of the common network, system, or environment that results, directly or indirectly, in the compromise of local networks, systems, or environments connected thereto may be deemed to constitute a single ADC Event.
Compromise Events Security Rules and Procedures—Merchant Edition • 6 August 2024
program: BRAM- authority: Mastercard SPME 8.6.2, 10.2, 12+ authority: Mastercard SPME 8.6.2, 12 # Removed reference to section 10.2 due to its deletion in the latest SPME updateresponse_window_days: 180required_evidence:- transaction_monitoring_records- corrective_action_plan- police_report # Mandatory inclusion per updated SPME 8.6.2halt_actions:- halt_new_merchant_onboardinginternal_notification_hours: 24agent_owner: bram_response_agent- # Includes updated police report requirement per SPME 8.6.2 and affirms Mastercard's exclusive authority in determining ADC Event responsibility (SPME 10.2).- # Added policy note on consequences for failure to provide complete responses by deadlines, including escalating Category C noncompliance assessments as specified in SPME 12.- # Allows for potential additional time granted by Mastercard upon Acquirer's confirmation of cessation of violating activity.+ # Updated policy to reflect deletion of Mastercard SPME section 10.2 that previously governed ADC Event responsibilities and determinations.+ # This policy no longer cites section 10.2 and focuses on continuity of response obligations under sections 8.6.2 and 12.+ # Retains police report requirements and escalation provisions per remaining applicable SPME sections.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
notice for one of our merchants, the acquirer must halt new merchant onboarding
immediately and submit an evidence package within one hundred eighty (180) days
of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
investigation period at its discretion. At least one claim must include a police report from the Cardholder.
Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,
though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
merchant within the investigation period to prompt claim submissions.
Mastercard's Authority and Determinations on ADC Events
Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Note that the obligations and authorities related to Account Data Compromise (ADC) Events or Potential ADC Events, Events previously described in Mastercard SPME section 10.2 have been removed by Mastercard as of August 2024. Therefore, this policy no longer includes requirements or guidance pertaining to ADC Event investigations or determinations. All other referenced sections, including the consolidation of related incidents into single or multiple events where 3.9 and the BRAM process, remain applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.
Source authority: Mastercard SPME ������8.6.2, ������10.2, 12.0, and section 3.9.§§3.9, 8.6.2, and 12.0.
BRAM Investigation Response
When Mastercard issues a Business Risk Assessment and Mitigation (BRAM) investigation
notice for one of our merchants, the acquirer must halt new merchant onboarding
immediately and submit an evidence package within one hundred eighty (180) days
of receipt of the notice.
Required actions
-
Halt new merchant onboarding for the merchant under investigation.
-
Compile and submit an evidence package containing:
-
Transaction monitoring records covering the prior 180 days.
-
A written corrective action plan.
-
Documentation of any police reports related to alleged coercion claims if applicable.
- Notify the Halyard Pay Compliance lead within 24 hours of receipt.
Failure to submit a complete response by the deadline will be considered a violation of Mastercard Rules section 3.9, resulting in escalating Category C noncompliance assessments until compliance is met. Additional assessments may occur for other Standards violations revealed during the BRAM investigation. Mastercard may grant extensions if the acquirer confirms cessation of violating activities.
Additional Considerations for Coercion Claims
When allegations of coerced Transactions arise, note that Mastercard may extend the usual 120-day
investigation period at its discretion. At least one claim must include a police report from the Cardholder.
Transactions reported as Lost or Stolen Fraud (fraud type codes 00 or 01) are subject to investigation,
though Mastercard may consider other fraud codes. Mastercard will notify issuers with Transactions at the
merchant within the investigation period to prompt claim submissions.
Mastercard's Authority and Determinations on ADC Events
Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Note that the obligations and authorities related to Account Data Compromise (ADC) Events or Potential ADC Events, Events previously described in Mastercard SPME section 10.2 have been removed by Mastercard as of August 2024. Therefore, this policy no longer includes requirements or guidance pertaining to ADC Event investigations or determinations. All other referenced sections, including the consolidation of related incidents into single or multiple events where 3.9 and the BRAM process, remain applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards.
Source authority: Mastercard SPME ������8.6.2, ������10.2, 12.0, and section 3.9.§§3.9, 8.6.2, and 12.0.
Source authority: Mastercard SPME §10.2.
--- a/policies/bram_response/rules.yaml +++ b/policies/bram_response/rules.yaml @@ -1,5 +1,5 @@ program: BRAM -authority: Mastercard SPME 8.6.2, 10.2, 12 +authority: Mastercard SPME 8.6.2, 12 # Removed reference to section 10.2 due to its deletion in the latest SPME update response_window_days: 180 required_evidence: - transaction_monitoring_records @@ -10,6 +10,6 @@ internal_notification_hours: 24 agent_owner: bram_response_agent -# Includes updated police report requirement per SPME 8.6.2 and affirms Mastercard's exclusive authority in determining ADC Event responsibility (SPME 10.2). -# Added policy note on consequences for failure to provide complete responses by deadlines, including escalating Category C noncompliance assessments as specified in SPME 12. -# Allows for potential additional time granted by Mastercard upon Acquirer's confirmation of cessation of violating activity.+# Updated policy to reflect deletion of Mastercard SPME section 10.2 that previously governed ADC Event responsibilities and determinations. +# This policy no longer cites section 10.2 and focuses on continuity of response obligations under sections 8.6.2 and 12. +# Retains police report requirements and escalation provisions per remaining applicable SPME sections. --- a/policies/bram_response/policy.md +++ b/policies/bram_response/policy.md @@ -26,6 +26,6 @@ ## Mastercard's Authority and Determinations on ADC Events -Mastercard retains exclusive authority to determine the occurrence, scope, and responsibility for Account Data Compromise (ADC) Events or Potential ADC Events, including the consolidation of related incidents into single or multiple events where applicable. Mastercard’s decisions in these matters are final and not subject to internal appeal. Customers are advised to seek Mastercard guidance if uncertain about their rights or obligations related to ADC Events. This framework ensures accountability and proper management of ADC risks in line with Mastercard's network security standards. +Note that the obligations and authorities related to Account Data Compromise (ADC) Events or Potential ADC Events previously described in Mastercard SPME section 10.2 have been removed by Mastercard as of August 2024. Therefore, this policy no longer includes requirements or guidance pertaining to ADC Event investigations or determinations. All other referenced sections, including 3.9 and the BRAM process, remain applicable. -Source authority: Mastercard SPME 8.6.2, 10.2, 12.0, and section 3.9.+Source authority: Mastercard SPME §§3.9, 8.6.2, and 12.0.