IP Library Granted Patent US 7,930,753
Granted Patent B2
US 7,930,753 · App. 10/611,656 · Granted Apr 19, 2011

Methods and systems for performing security risk assessments of internet merchant entities

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,930,753
App. No.
10/611,656
Granted
Apr 19, 2011
Kind
B2
Abstract

Methods and systems are provided for assessing a security risk for a merchant entity having connectivity to a shared network. Information describing characteristics of the merchant entity are received from the merchant entity. A determination is made which test requirements of a security test scheme are to be used in assessing the security risk for the merchant entity. The security test scheme includes a set of test requirements whose satisfaction by the merchant entity is sufficient to ensure compliance with a multiple sets of security requirements defined by multiple payment-processing organizations. The security test scheme is executed with a security compliance authority server in accordance with the determined test requirements.

Claims (31)

1. A method for implementing a security risk assessment for a merchant entity having connectivity to a shared network, the method comprising:

receiving at a host computer system including a processor, from each of a plurality of payment-processing organizations, a set of security requirements defining protocols for implementing commercial transactions over the shared network using instruments identified with the payment-processing organization;

developing, with the processor at the host computer system, a security test scheme having a set of test requirements whose satisfaction by the merchant entity is sufficient to ensure compliance with the sets of security requirements defined by each of the plurality of payment-processing organizations;

performing a remote scan of a network site maintained by the merchant entity on the shared network in support of shared-network commercial transactions with a security compliance authority server by the host computer system, the remote scan implementing at least a subset of the set of test requirements to evaluate compliance by the merchant entity; and

transmitting a questionnaire from the host computer system to the merchant entity with the security compliance authority server, the questionnaire including queries whose truthful response identifies a level of compliance with at least some of the test requirements.

2. The method recited in claim 1 further comprising scheduling an on-site audit at the merchant entity with the security compliance authority server, the on-site audit being structured to follow a prescribed methodology for identifying a level of compliance with at least some of the test requirements.

3. The method recited in claim 1 wherein a satisfaction level of the test requirements required for compliance with the test requirements is dependent on a characteristic of the merchant entity.

4. The method recited in claim 3 wherein the characteristic comprises a shared-network transaction volume processed by the merchant entity over the shared network.

5. The method recited in claim 1 wherein a frequency of performing the remote scan is dependent on a characteristic of the merchant entity.

6. The method recited in claim 5 wherein the characteristic comprises a shared-network transaction volume processed by the merchant entity over the shared network.

7. The method recited in claim 1 further comprising receiving information describing characteristics of the merchant entity from the merchant entity at the host computer system to limit parameters of the remote scan.

8. The method recited in claim 1 further comprising generating a report at the host computer system summarizing a level of compliance by the merchant entity with the set of test requirements as determined from performing the remote scan.

9. The method recited in claim 1 wherein the merchant entity comprises an Internet merchant.

10. The method recited in claim 1 wherein the merchant entity comprises an Internet merchant gateway.

11. A method for assessing a security risk for a merchant entity having connectivity to a shared network, the method comprising:

receiving information, at a host computer system including a processor, describing characteristics of the merchant entity from the merchant entity;

determining at the host computer system using the processor which test requirements of a security test scheme to use in assessing the security risk for the merchant entity, wherein the security test scheme includes a set of test requirements whose satisfaction by the merchant entity is sufficient to ensure compliance with a plurality of sets of security requirements defined by a plurality of payment-processing organizations; and

executing the security test scheme with a security compliance authority server in accordance with the determined test requirements, wherein executing the security test scheme comprises transmitting a questionnaire from the host computer system to the merchant entity with the security compliance authority server, the questionnaire including queries whose truthful response identifies a level of compliance with at least some of the test requirements.

12. The method recited in claim 11 wherein executing the security test scheme comprises performing a remote scan of a network site maintained by the merchant entity on the shared network in support of shared-network commercial transactions with the security compliance authority server.

13. The method recited in claim 11 wherein executing the security test scheme comprises scheduling an on-site audit at the merchant entity with the security compliance authority server, the on-site audit being structured to follow a prescribed methodology for identifying a level of compliance with at least some of the test requirements.

14. The method recited in claim 11 wherein determining which test requirements of the security test scheme to use in assessing the security risk for the merchant entity is dependent on a characteristic of the merchant entity.

15. The method recited in claim 14 wherein the characteristic comprises a shared-network transaction volume processed by the merchant entity over the shared network.

16. The method recited in claim 11 further comprising generating a report at the host computer system summarizing a level of compliance by the merchant entity with the set of determined test requirements as evaluated from executing the security test scheme.

17. The method recited in claim 11 wherein the merchant entity comprises an Internet merchant.

18. The method recited in claim 11 wherein the merchant entity comprises an Internet merchant gateway.

19. A non-transitory computer-readable storage medium having a computer-readable program embodied therein for direction operation of a security compliance authority server including a communications system, a processor, and a storage device, wherein the computer-readable program includes instructions for operating the security compliance authority server to assess a security risk for an merchant entity having connectivity to a shared network in accordance with the following:

receiving, with the communications system, information describing characteristics of the merchant entity;

determining, with the processor, which test requirements of a security test scheme to use in assessing the security risk for the merchant entity, wherein the security test scheme is stored on the storage device and includes a set of test requirements whose satisfaction by the merchant entity is sufficient to ensure compliance with a plurality of sets of security requirements defined by a plurality of payment-processing organizations; and

executing, with the processor, the security test scheme in accordance with the determined test requirements, wherein executing the security test scheme comprises transmitting a questionnaire from the host computer system to the merchant entity with the security compliance authority server, the questionnaire including queries whose truthful response identifies a level of compliance with at least some of the test requirements.

20. The computer-readable storage medium recited in claim 19 wherein the instructions for executing the security test scheme comprise instructions for performing a remote scan of a network site maintained by the merchant entity on the shared network in support of shared-network commercial transactions.

21. The computer-readable storage medium recited in claim 19 wherein the instructions for executing the security test scheme comprise instructions for scheduling an on-site audit at the merchant entity.

Assignments (8)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Aug 19, 2019
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: FIRST DATA CORPORATION; DW HOLDINGS, INC.; FIRST DATA RESOURCES, INC. (K/N/A FIRST DATA RESOURCES, LLC); FUNDSXPRESS FINANCIAL NETWORKS, INC.; INTELLIGENT RESULTS, INC. (K/N/A FIRST DATA SOLUTIONS, INC.); LINKPOINT INTERNATIONAL, INC.; MONEY NETWORK FINANCIAL, LLC; SIZE TECHNOLOGIES, INC.; TASQ TECHNOLOGY, INC.; TELECHECK INTERNATIONAL, INC.
Reel/Frame 050090/0060 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Aug 19, 2019
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: FIRST DATA CORPORATION; DW HOLDINGS, INC.; FIRST DATA RESOURCES, LLC; FUNDSXPRESS FINANCIAL NETWORK, INC.; FIRST DATA SOLUTIONS, INC.; LINKPOINT INTERNATIONAL, INC.; MONEY NETWORK FINANCIAL, LLC; SIZE TECHNOLOGIES, INC.; TASQ TECHNOLOGY, INC.; TELECHECK INTERNATIONAL, INC.
Reel/Frame 050091/0474 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENT RIGHTS Recorded Aug 19, 2019
From: WELLS FARGO BANK, NATIONAL ASSOCIATION
To: FIRST DATA CORPORATION
Reel/Frame 050094/0455 →
RELEASE OF SECURITY INTEREST Recorded Jul 30, 2019
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: CARDSERVICE INTERNATIONAL, INC.; DW HOLDINGS INC.; FIRST DATA CORPORATION; FIRST DATA RESOURCES, LLC; FUNDSXPRESS, INC.; INTELLIGENT RESULTS, INC.; LINKPOINT INTERNATIONAL, INC.; SIZE TECHNOLOGIES, INC.; TASQ TECHNOLOGY, INC.; TELECHECK INTERNATIONAL, INC.; TELECHECK SERVICES, INC.
Reel/Frame 049902/0919 →
SECURITY AGREEMENT Recorded Jan 31, 2011
From: DW HOLDINGS, INC.; FIRST DATA RESOURCES, LLC; FUNDSXPRESS FINANCIAL NETWORKS, INC.; FIRST DATA SOLUTIONS, INC.; LINKPOINT INTERNATIONAL, INC.; MONEY NETWORK FINANCIAL, LLC; SIZE TECHNOLOGIES, INC.; TASQ TECHNOLOGY, INC.; TELECHECK INTERNATIONAL, INC
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 025719/0590 →
SECURITY AGREEMENT Recorded Nov 17, 2010
From: DW HOLDINGS, INC.; FIRST DATA RESOURCES, INC. (K/N/A FIRST DATA RESOURCES, LLC); FUNDSXPRESS FINANCIAL NETWORKS, INC.; INTELLIGENT RESULTS, INC. (K/N/A FIRST DATA SOLUTIONS, INC.); LINKPOINT INTERNATIONAL, INC.; MONEY NETWORK FINANCIAL, LLC; SIZE TECHNOLOGIES, INC.; TASQ TECHNOLOGY, INC.; TELECHECK INTERNATIONAL, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 025368/0183 →
SECURITY AGREEMENT Recorded Oct 31, 2007
From: FIRST DATA CORPORATION; CARDSERVICE INTERNATIONAL, INC.; FUNDSXPRESS, INC.; LINKPOINT INTERNATIONAL, INC.; TASQ TECHNOLOGY, INC.; TELECHECK SERVICES, INC.; DW HOLDINGS, INC.; FIRST DATA RESOURCES, INC.; INTELLIGENT RESULTS, INC.; SIZE TECHNOLOGIES, INC.; TELECHECK INTERNATIONAL, INC.
To: CREDIT SUISSE, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 020045/0165 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 26, 2003
From: MELLINGER, PHILIP T.; DEGEN, ROBERT G.
To: FIRST DATA CORPORATION
Reel/Frame 014726/0376 →