What should companies that outsource do to prevent credit card fraud?

These stories appear several years apart; during thisregulated environment. WNS is the first BPO service
period, according to industry body NASSCOM, theprovider to achieve the prestigious PCI DSS
Indian BPO industry alone grew more than 100% [fromcertification at an enterprise level in the category of
$5.2 billion in 2005 to $12.5 billion in March 2008]. In the“Level 1 Service provider”.
last financial year alone, it grew 32%. This exponentialOther IT service and business process organizations
growth was not coincidental. It is a reflection ofhave learned from the past breaches and have
customer confidence and faith in the offshore deliveryimplemented information security management
model, indicating that customers believe that deliverysystems based on industry accepted standards such
offshore offers significant value adds such as processas ISO 27001. Certification is a 'must have' in the
optimization, cost reduction, and operational efficiency,industry.
with risk managed appropriately.BPO organizations are also focused on staff
As an example, to combat fraud, the Indian BPOeducation. For example, WNS has significantly invested
industry is adopting some of the most stringent globalin educating staff about information protection through
standards in the handling of sensitive information anddelivery methods ranging from online classroom based
data. One such standard is the payment card industrytraining programs, do’s and don’ts checklists, an
data security standards (PCI DSS), as prescribed byinformation security handbook, screensavers, and
PCI data Security Council. The PCI DSS version 1.1 is aother communication tactics including floor level
comprehensive set of requirements for enhancingfocused discussions.
payment account data security developed by some ofThe problem however is largely global. A recent
the world’s leading founding payment brandssurvey of U.S. online retailers who accept overseas
including Amex, Discover, JCB, MasterCard and Visa inorders conducted for payment processors report the
order to facilitate the broad adoption of consistenttop 10 countries in the world of fraud range from
data security measures on a global basis. It is aNigeria to Russia to Canada [source: but not India.
multifaceted security standard that prescribesHowever, smart companies should at leasta) review
requirements for security management, policies,the compliance norms and ensure that the organization
procedures, network architecture, software design andthey are outsourcing to has the necessary relevant
other critical protective measures and is intended tocertification;b) have a watertight contract in place
help organizations aggressively protect customerencompassing service levels and penalties;c) conduct
account data.periodic audits of the outsourcers thereby ensuring that
WNS Global Services, as an example, hasstringent standards are adhered to; andd) put in place
implemented the PCI DSS provisions in order to assurewell-defined service level agreements.
customers of its information protection maturity andIt ultimately should be acknowledged that fraud is a
ensure that sensitive information such as paymentglobal phenomenon and the companies that are
card information is viewed, assessed, transacted,certified and have trained staff are the ones with
transmitted and stored in a highly secure and PCI DSSwhom to do business with.