Browse Definitions :
Definition

point-of-sale security (POS security)

Point-of-sale security (POS security) is the study of vulnerabilities in retail checkout points and prevention of access by unauthorized parties looking to steal customer and payment card details from them. The purpose of POS security is creating a safe environment for customer transactions.

Memory scraping POS malware is a major concern, as even large retailers have fallen prey to this credit card-stealing method. Memory scrapers access data at the time of the transaction, when payment data is not yet unencrypted. In late 2013, for example, criminals used a variant of the Backoff memory scraper to access information from over 70,000 accounts in the Target database. 

Out of date, unsupported operating systems are a great risk as they provide malware writers with more unpatched vulnerabilities. Windows XP-based systems still in use in many retail environments are vulnerable because they lack some of the more advanced security features of newer versions. For the sake of security, POS systems should use only up-to-date and well-supported operating systems.

Point-of-sale systems physical access and user privileges should also be strictly managed. If, for example, an employee uses a POS terminal for web surfing, they can expose the system to security risks. Ideally, the administrative account should be rigorously protected and the activities of other users strictly limited.

Isolation of POS systems on a network reduces the potential attack surface and makes suspicious activities easier to detect. Whitelisting can also help secure POS systems by limiting communication to only authorized external sites.

This was last updated in January 2015

Continue Reading About point-of-sale security (POS security)

SearchCompliance
  • ISO 31000 Risk Management

    The ISO 31000 Risk Management framework is an international standard that provides businesses with guidelines and principles for ...

  • pure risk

    Pure risk refers to risks that are beyond human control and result in a loss or no loss with no possibility of financial gain.

  • risk reporting

    Risk reporting is a method of identifying risks tied to or potentially impacting an organization's business processes.

SearchSecurity
  • Pretty Good Privacy (PGP)

    Pretty Good Privacy or PGP was a popular program used to encrypt and decrypt email over the internet, as well as authenticate ...

  • email security

    Email security is the process of ensuring the availability, integrity and authenticity of email communications by protecting ...

  • Blowfish

    Blowfish is a variable-length, symmetric, 64-bit block cipher.

SearchHealthIT
SearchDisasterRecovery
  • What is risk mitigation?

    Risk mitigation is a strategy to prepare for and lessen the effects of threats faced by a business.

  • fault-tolerant

    Fault-tolerant technology is a capability of a computer system, electronic system or network to deliver uninterrupted service, ...

  • synchronous replication

    Synchronous replication is the process of copying data over a storage area network, local area network or wide area network so ...

SearchStorage
  • direct access

    In computer storage, direct access is the process of reading and writing data on a storage device by going directly to where the ...

  • kibi, mebi, gibi, tebi, pebi and exbi

    Kibi, mebi, gibi, tebi, pebi and exbi are binary prefix multipliers that, in 1998, were approved as a standard by the ...

  • holographic storage (holostorage)

    Holographic storage is computer storage that uses laser beams to store computer-generated data in three dimensions.

Close