Brief: Visa has developed a set of best practices aiming to to support the growth of the emerging mobile Payment acceptance channel. These practices are targeted at two distinct audiences: vendors that develop & sell mobile payment acceptance applications and merchants that use them.
Visa best practices call for important security considerations such as encryption of all public transmission & handling of account data (card reader level), event logging, tokenization of cardholder data etc.
The most interesting thing in these guidelines is that they:
Allocate more clearly merchant and service provider responsibilities in relation to securing cardholder data when a mobile phone/tablet is used as an acceptance device instead of a traditional terminal.
Provide a foundation of appropriate procedural controls and add-on technical security measures in order to maintain stakeholder trust in m-payments, since these devices have limited native security controls.