1 / 3100%
Introduction
c c c c c c c c c c c c c A recent external audit of the Padgett-Beale financial
operations has been concluded. An “early look” copy of the audit
was received by the Office of the Chief Financial Officer (CFO). The
findings of this audit concluded that there was reason for concern as
it pertains to the use of Shadow-IT systems in some of the Padgett-
Beale properties. These unauthorized / unapproved cashless
payment technologies could pose significant risk to our guests and
the companies financial holdings if not properly vetted and approved
for use by our IT Governance board. Our primary focus for this
presentation will be the use of micro payment cards and systems at
some of the Padgett-Beale properties and the risks and concerns
involved with the utilization of these card systems. c c c c c c c c c c c c
Analysis
Our first, and most obvious concern, is that these cards
and systems have not been vetted or approved for use by IT
Governance board of Padgett-Beale. These systems are considered
shadow IT and are being purchased, utilized, and operated without
the knowledge of the company (Forcepoint, 2018). The legal and
financial implications of these cards and systems could pose a
significant risk of loss to guest data and financial information (Salido,
2010). We suspect we are non-compliant regarding the
requirements set forth by the Payment Card Industry - Data Security
Standard (PCI-DSS) without our knowledge and will be held liable for
failing to meet these requirements. There are twelve requirements
ranging from network configurations and encryption to cardholder
data security and systems testing that are required. In the event of a
breach Padgett-Beale could pay penalties ranging between $5,000
and $500,000 per month(Willis, 2019).
c c c c c c c c c c c c c Our second concern, is that since these systems are in
place, what security is being provided at the guest point of sale?
Since we are unaware of the specifics of these micro-payment cards
and systems there is reason to be concerned about how our guest’s
credit card data is being secured and what data is being transmitted
across our networks or transferred to the purchased cards. Without
knowing the card types and systems being utilized our guests and
company data systems could be exposed to multiple threats leading
to a breach in our guest’s and company’s data security (Square, n.d.).
c c c c c c c c c c c c c Our third concern is the security of the radio frequency
identification (RFID) of these point-of-sale systems. Are these
systems transmitting over Padgett-Beale network infrastructure or
over a radio or cellular connections? What encryption is being
provided for this communication? Can this transmission data be
intercepted and if so, can the data being transmitted be stolen?
Our fourth concern is in reference to the types of prepaid cards be
given or sold to our guests. Once again, we do not know the
specific card types. We must consider what is being done with used
cards. Are the cards simply thrown away after use or are they
turned in to be re-used later? What fees are being included in the
purchase and use of these cards? If the cards are re-loadable, what
guest personally identifiable data and sensitive information is being
stored on the cards? If the cards are magnetic stripe, they could
store static data of the financial transaction information inside of the
stripe itself. These cards do not require a pin or verification code
for use. Since the data on the stripe is static and held on the card
the possibilities of data theft are greater. If the stored data is copied
from the magnetic stripe that data can be reused multiple times (8
FAQs about EMV credit cards, 2021).
Our fifth and final concern is to what contracts are being accepted
on behalf of Padgett-Beale with third party vendors without
company knowledge or approval. What are the terms of the
contracts? What security guarantees are being provided? What fees
are being charged to our guests or our properties?
Summary
c c c c c c c c c c c c c In conclusion, you can see that we have more questions
than answers about the shadow IT micro payment cards and systems
being utilized by some of our Padgett-Beale properties. We have
numerous concerns to include our lack of knowledge about the
systems use and the implications of failure to comply with PCI-DSS
requirements, the security of the point-of-sale systems, the data
transmission paths and transmission security, the types of prepaid
cards be distributed and utilized by our guests, and what contracts
have been accepted on the behalf of Padgett-Beale with third party
vendors. Based on these points, it is the recommendation of the
CFO’s office that an immediate “cease and desist” order be issued to
all properties utilizing these technologies until fully reviewed and
approved by the IT Governance board of Padgett-Beale.
Furthermore, policy needs to be drafted that specifically states
purchase of shadow-IT applications, tools, services, and systems that
have not been vetted and approved by Padgett-Beale is forbidden.
References
8 FAQs about EMV credit cards. CreditCards.com. (2021, December
17). Retrieved April 30, 2022, from
https://www.creditcards.com/education/emv-faq-chip-cards-answers-
1264/
Forcepoint. (2018, August 10). What is Shadow IT? Forcepoint.
https://www.forcepoint.com/cyber-edu/shadow-it
Square. (n.d.). POS systems: Point of sale for small businesses.
Square. Retrieved April 30, 2022, from
https://squareup.com/us/en/point-of-sale
Salido, J. (2010, November 1). Data Governance for Privacy
Confidentiality and Compliance A Holistic Approach. Www.isaca.org.
https://www.isaca.org/resources/isaca-journal/past-issues/2010/data-
governance-for-privacy-confidentiality-and-compliance-a-holistic-
approach
Willis, L. (2019, January 3). Retrieved April 30, 2022, from
https://www.americanbar.org/groups/litigation/committees/minority-
trial-lawyer/practice/2019/the-payment-card-industry-data-security-
standard/
Students also viewed