1 / 5100%
E-Commerce and Micropayments
An external audit of the company's financial operations was
conducted over a week ago. Some of the problem areas were
known and being worked on via the Chief Financial Officer’s (CFO’s)
staff. The staff no longer can focus on the technical accounting.
What has significantly changed, however, is that the CFO of today
and of the future must be able to take financial data and use it to
influence operational decision-making and strategy, (Ainsworth,
2019). One set of findings stood out the most which was
unauthorized or unapproved use of cashless payment technology by
certain locations and offices within the company. These
technologies are considered Shadow IT. What Is Shadow IT? (2018)
article defines Shadow IT as the use of information technology
systems, devices, software, applications, and services without explicit
IT department approval.
There were two types of technologies included in the audit report
which mentioned micro payments using a payment card and mobile
payments using a third party. I have decided to focus on the
payment cards with Team #1. It was reported that these cards were
issued by guest services to hotel guest and via unattended vending
machines to visitors. The report continues with how they were
loaded with cash value deposited to the account per credit card
charges. Guest services was giving hotel’s affinity program guests
“reward dollars”. The cards are used at service locations not
attended by a cashier. These locations included game arcade, self-
service laundry, sales kiosk, etc. A third-party service provider was
used to process payments which used an electronic funds transfer to
pay the hotel its share of income.
This payment system would be an asset to the company’s income,
and I would like to discuss continued use. I would like to start with
known or suspected compliance issues for the Payment Card
Industry Data Security Standard (PCI-DSS). The PCI DSS deals with
payment card data and cardholder information, including primary
account numbers (PAN), credit/debit card numbers, and sensitive
authentication data (SAD) such as CVVs, (Wills, 2019). It is known
that organizations have difficulties with this regulation. The
following are five known challenges that must be addressed per
Pradhan (2020) article. Failing to accurately strategize compliance
efforts; Organizations are failing to see compliance as an ongoing
activity; Disparate systems result in performance management issues;
lack of right cybersecurity talent, resulting in a lack of
comprehension of security issues; Compliance is not made a part of
the larger cybersecurity paradigm to build a strong security
infrastructure. First challenge is basically understanding all
requirements are mandatory; second is how very technical it is; third
is pressure involved in certification; forth is a gap for understanding
and fulfillment of requirements; fifth is the definition of the
infrastructure.
IT Governance board requested information about potential privacy
and security issues. I am going address both now. Sahoo (2020)
article mentioned common PCI compliance mistakes or negligence.
There is negligence towards annual assessments or audit is essential
in PCI compliance for every merchant, regardless of the level. It is
expected that organizations conduct a regular internal audit at least
once a year. Cardholder data scan should be a part of your regular
assessment process to rapidly assess the IT server or workstation
environment. This is essential for tracing sensitive and unprotected
cardholder data in the environment. Integration of file-integrity
monitoring or change-detection software on logs is a PCI DSS
Compliance mandate. Organizations are advised to integrate these
tools or software with the SIEM to ensure that existing log data
does not just change without generating alerts. The mistakes or
negligence just mention can be looked at as security issues. Privacy
is of concerned but safely covered. The PCI DSS places great
emphasis on the security and data protection of payment cardholders
and covers everything in this area: identity theft, loss of data, and
breaches. Thus, the primary purpose of this standard is to protect
users’ payment information. All other personal information about
users is outside the scope of the PCI DSS, (Diachenko & Tsymbal,
2021).
I want to introduce the method I recommend earlier for continuing
to use which is RFID. Without getting too technical, RFID stands for
Radio Frequency Identification, which means the use of radio waves
to track tags containing electronic information, (Team, 2018). The
guest would be able to pay for items with just a swipe or tap of
their token which could be a card, wristband, or even on a lanyard.
This would allow guest to travel without cashless amongst the
establishment. Financial aspects on how payments are made would
be via one of the two categories of either open-loop or closed-loop
systems. I would highly recommend an open-loop RFID system
which link a payment device (e.g., a card embedded with RFID chip)
directly to consumers’ credit or debit card (alternatively, consumers
can set up a prepaid account which they refill by mail, online or at
select merchant locations), (Ozturk, 2016). Information is exchanged
within two ways. The first way is each tag contains unique
identification number and electronically sorted information about the
product (e.g., product attributes, physical dimensions, and price) to
which it is embedded and transmits that data to the reader through
radio waves, (Ozturk, 2016). The main concern is about what the
people on the other side of the spectrum use the information for,
(Bowler, 2016). Bowler (2016) stated the only concern is the
information gathered is what you purchase, how much you spent
within a day, and your before as well as your current balance. This
information is shared with a third party whom you would have to go
through to create an account and establish a balance on your device.
The information is protected via the device by a frequency which
cannot be replicated. We will have to rely on the third-party IT
team to protect the information gathered to create the account.
My final thoughts about PCI DSS are that its requirements are
precise, and organizations cannot make it difficult to use unless they
do not follow the dos and don’ts. A periodic check as well as an
audit will help with maintaining the requirements. Security is not
really an issue with RFID until someone losses their device which
can be solved by just deactivating it within their account. On
another note, a positive reason to consider continue use is what
other data can be collected for future use. For an event, some
things you can track with the technology include: (Bowler, 2016)
When attendees are coming in and leaving
When and how people move around the venue
Where you may need to put more resources
What products are being consumed
What types of interactions are taking place
This data can help verify what items are selling the most, what needs
to be restocked, promotions, sponsors, and many other things.
References
Bowler, J. (2016, December 30).
RFID Wristbands - What you need
to know (according to our London office)
. Printsome Insights.
https://blog.printsome.com/rfid-wristbands-good-bad/
Diachenko, D., & Tsymbal, J. (2021, November 22).
How To Ensure
Website Compliance with the PCI DSS and GDPR
. Dinarys.
https://dinarys.com/blog/pci-dss-and-gdpr#contents-2
Ozturk, A. B. (2016, April 11).
Customer acceptance of cashless
payment systems in the hospitality industry, Vol. 28 No. 4, pp. 801-
817
. International Journal of Contemporary Hospitality Management.
https://doi-org.ezproxy.umgc.edu/10.1108/IJCHM-02-2015-0073
Pradhan, I. (2020, March 23).
5 PCI-DSS compliance challenges
impacting organizations’ data security readiness
. Sophos News.
https://news.sophos.com/en-us/2020/03/23/5-pci-dss-compliance-
challenges-impacting-organizations-data-security-
readiness/#:~:text=%205%20PCI-
DSS%20compliance%20challenges%20impacting%20organizations%E2
%80%99%20data
Sahoo, N. (2020, December 10).
PCI DSS: Most Common Compliance
Mistakes and How to Avoid Them
. PaymentsJournal.
https://www.paymentsjournal.com/pci-dss-most-common-compliance-
mistakes-and-how-to-avoid-them/
Team, T. (2018, January 4).
The Beginner’s Guide to RFID
Technology for Events | Token Blog
. Token RFID.
https://www.gettoken.com/beginners-guide-rfid-technology-events/
Wills, L. (2019, January 3).
The Payment Card Industry Data Security
Standard
. The American Bar Association.
https://www.americanbar.org/groups/litigation/committees/minority-
trial-lawyer/practice/2019/the-payment-card-industry-data-security-
standard/
Students also viewed