eSS offers a number of Information Security (IS) consulting services focused on security, integrity, availability and confidentiality of sensitive data. Our clients include large and small financial institutions, Merchants, POS Key Loading Facilities, Credit Card issuers, Processors and so on.
We offer the following services:
• Perform diagnostic reviews of financial services operations focused on PIN based debit/ATM transactions in preparation of TG-3 (aka TR-39) PIN Security and PCI PIN Compliance audits.
• Provide remediation plans and corrective actions following TG-3/TR-39 PIN Security and/or PCI PIN Compliance audits. This may include writing “Key Management & PIN Security Policies and Procedures”, train the relevant teams in following proper procedures and implement required controls, based on ANSI standards and industry best practices.
• Develop general enterprise policies and procedures; i.e. “Security Policies and Practices” based
on ISO 27001 (formerly known as ISO 17799 or BS 7799) standard
• Assist with developing security controls within financial transaction processing environments that
would offer data confidentiality, authenticity, integrity and non-repudiation in all the processes and exchanges involved.
• Provide assistance in implementing various cryptographic algorithms such as Des/3Des, Public key algorithms such as RSA or Elliptic curve Cryptography (ECC), or a combination of, as needed for different applications.
• Evaluate proper implementations of Public Key Infrastructure (PKI) based operations, e.g. Digital Certificate Authority operations and ecommerce services. Provide gap analysis and guidance on issues and improvements. |