Skip to content
Cyber Security
VNPT Money has received the highest-level international security certificate PCI DSS

VNPT Money has received the highest-level international security certificate PCI DSS

30/06/2022
On June 29, 2022, just one year after receiving the PCI DSS 3.2.1 Level 2 certificate, VNPT Money has officially been awarded the Level 1 PCI DSS certificate by CMC Corporation - the highest level of security certification for card payments.
Challenge

VNPT Money acts as a payment intermediary providing services to merchants. The customer's VNPT Money service is gradually growing and expanding to reach a wider customer base. Currently, VNPT Money complies with PCI DSS level 2 and aims to elevate the system's compliance level to PCI DSS level 1 in this assessment.

Achieving the PCI DSS level 1 certification represents the highest level of security for organizations involved in international card payments, which will enhance their competitive position in the market and easily gain the trust of new customers.

VNPT Money presents three main requirements:

  1. Solution requirements: The consulting solutions need to align closely with the customer's actual system operations. The solutions should optimize the investment cost and operational resources while ensuring the required level of security as per PCI DSS level 1 standards.
  2. Capability requirements: The individuals participating in the project as QSA (Qualified Security Assessor - an individual authorized to confirm an organization's compliance with PCI DSS requirements) must possess experience in projects within the banking sector or similar payment intermediary projects.
  3. Time requirements: The timeframe must be ensured within one month as the customer's PCI DSS level 2 certification will expire in May 2022.
Solution

The upgrade of the PCI DSS certification from level 2 to level 1 requires significant efforts from both VNPT Media and CMC. With their extensive experience in consulting and implementing PCI DSS for major banks and payment intermediaries, the experts from CMC TS and CMC Cyber Security have provided consulting services to help the customers bridge the gap between PCI DSS level 2 and level 1 quickly and securely. They have proposed solutions that enable the customers to meet all the security requirements of PCI DSS, leading to the evaluation and issuance of the PCI DSS level 1 certification in just one month.

Result

VNPT Money has successfully met the strict assessment criteria of 12 PCI DSS standards, including building and maintaining a firewall system to protect payment card data, regular usage and updates of anti-virus software, establishment and maintenance of secure network systems and applications, and more. Additionally, VNPT Money has fulfilled the requirements for multi-factor authentication and secure data encryption according to PCI DSS 3.2.1 Level 1.

Achieving the highest-level PCI DSS certification confirms that VNPT Money meets stringent requirements for data security in terms of storage, processing, and transmission, following international standards to provide safer and higher-quality services for its customers. Furthermore, this accomplishment serves as a foundation for VNPT Money to expand its offerings, providing additional products and services to the market and fostering collaboration opportunities with global financial organizations such as JCB and Visa.


Photo: Mr. Vu Lam Bang - Deputy General Director of CMC Cyber Security (left) and Mrs. Nguyen Thi Luyen - Director of ENT Division, CMC TS (right) presenting the PCI DSS 3.2.1 Level certification to Mr. Nguyen Dang Thang - Director of VNPT FinTech (second from the left).

At the ceremony, Mr. Nguyen Dang Thang - Director of VNPT FinTech, expressed:

"By upgrading to the Level 1 PCI DSS security certification, VNPT Money expects to meet the highest and most stringent security standards to provide safer and higher-quality services for our customers. Additionally, this is also a foundation for VNPT Money to expand its offerings, providing additional products and services to the market."

Mr. Vu Lam Bang - Deputy General Director of CMC Cyber Security shared:

"CMC is proud to be selected by VNPT Media and VNPT Money as the organization to assess and grant the international security certificate PCI DSS 3.2.1 Level 1. Achieving the highest-level PCI DSS certification confirms that VNPT Money not only meets the stringent requirements for data security in terms of storage, processing, and transmission according to international standards but also ensures the safety and security of the national payment infrastructure, thereby opening up cooperation opportunities with global financial organizations."

51 votes / Averange: 0