Comply by July. Step by Step Guide to PCI-PA-DSS Compliance

Size: px
Start display at page:

Download "Comply by July. Step by Step Guide to PCI-PA-DSS Compliance"

Transcription

1 Comply by July Step by Step Guide to PCI-PA-DSS Compliance June 2010

2 Comply By July Help is on the Way! Payment Card Industry (PCI) Payment Application (PA) Data Security Standard (DSS) June 2010 As the July 1, 2010 deadline approaches for PCI-PA-DSS compliance, campuses across the system have been requesting help in implementing a plan to meet the requirements of tougher credit card standards. These standards carry heavy fines for breaches of credit card security. Comply By July was developed by Augusta State University (ASU) to help them achieve compliance in a timely manner by using a team approach. We are now sharing this easy to read guide to assist other campuses. Please consider this a resource as you put together the compliance plan for your institution. Credit card security standards are nothing new. They have been evolving for years, under the direction of the credit card leaders (Visa, MC and AMEX). More recently the full cooperation of merchants has been expected as identity theft has become more and more prevalent. However, it is not only the credit card industry that has expectations, so do our students, parents and supporters. Our reputations are at stake and so are our pocketbooks. I hope that you will find the enclosed information and guide helpful. Please feel free to contact us, should you have questions, comments, or like to discuss your compliance plan. Stanton Gatewood Chief Information Security Officer Board of Regents University System of Georgia Kathleen Boyd Internal Auditor Office of the President Augusta State University

3 Comply by July PCI-PA-DSS Reference Guide Table of Contents A. Credit Card Security Team Selecting the Right Team Members B. The PCI-PA-DSS Standard Helpful Links C. Comply By July Step by Step Guide D. Endorsement from Senior Management Memo from Senior Management to Inform Campus about PCI-PA-DSS Standard E. Contacting Your Credit Card Processor Have Your Questions Ready F. Questionnaire to Department Cashiers Hello Out There Does Your Department Process Credit Cards? G. Inventory Capturing the Full Scope of the Project Have You Left Off Anyone? H. Compliance Field Visit Checklist Document Your Effort to Establish Compliance

4 Section A Credit Card Security Team Selecting the Right Team Members

5 CREDIT CARD SECURITY TEAM Selecting the Right Team Members The ideal team is composed of professional staff with considerable expertise in either technology, accounting and/or internal audit. The size of your team should reflect the size of your organization and the number of departments that utilize credit cards. Consider the deadline and plan according. IT Security Officer Internal Auditor Information Analyst/Trainer Assistant Director for Systems & Programming Services Controller Assistant Controller

6 Section B The PCI-PA-DSS Standard Helpful Links

7 PCI-PA-DSS Security Standard Helpful Links What it all means If you are having trouble wrapping your head around the alphabet soup of PCI compliance, here are two useful links to get you started: 1.) The PCI Security Standards Council Home Page On this website you will find the security standard definition, the self assessment questionnaire, the list of validated payment applications and lots more. Start here to educate yourself about credit card security standards. The link below will lead you to the home page, and you can navigate your way from there. 2.) TouchNet PCI-PA-DSS Solution Kit Brochure Request Page On this website you can request up to five copies of the TouchNet PCI-PA-DSS brochure. This easy to read brochure simplifies the information on the PCI Security Standards Council website. Even if you are not using TouchNet as a PCI solution, the brochure is worth reading. The brochures will be mailed out immediately upon request at no charge.

8 About the PCI Data Security Standard Excerpted from the PCI Security Council Standards Council Website HISTORY The PCI DSS, a set of comprehensive requirements for enhancing payment account data security, was developed by the founding payment brands of the PCI Security Standards Council, including American Express, Discover Financial Services, JCB International, MasterCard Worldwide and Visa Inc. International, to help facilitate the broad adoption of consistent data security measures on a global basis. The PCI DSS is a multifaceted security standard that includes requirements for security management, policies, procedures, network architecture, software design and other critical protective measures. This comprehensive standard is intended to help organizations proactively protect customer account data. PRINCIPLES The core of the PCI DSS is a group of principles and accompanying requirements, around which the specific elements of the DSS are organized: Build and Maintain a Secure Network Requirement 1: Install and maintain a firewall configuration to protect cardholder data Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters Protect Cardholder Data Requirement 3: Protect stored cardholder data Requirement 4: Encrypt transmission of cardholder data across open, public networks Maintain a Vulnerability Management Program Requirement 5: Use and regularly update anti-virus software Requirement 6: Develop and maintain secure systems and applications Implement Strong Access Control Measures Requirement 7: Restrict access to cardholder data by business need-to-know Requirement 8: Assign a unique ID to each person with computer access Requirement 9: Restrict physical access to cardholder data Regularly Monitor and Test Networks Requirement 10: Track and monitor all access to network resources and cardholder data Requirement 11: Regularly test security systems and processes Maintain an Information Security Policy Requirement 12: Maintain a policy that addresses information security

9 Section C Comply by July Step by Step Guide

10 PCI-PA-DSS "COMPLY BY JULY" STEP BY STEP GUIDE STEP NOTES STATUS 1 Assemble Credit Card Security Team. Team should have representatives from Internal Audit, IT, Business Office. 2 Have backing of Senior Management. Send correspondence from Senior Management. Reference "D" - Letter 3 Talk to your bank to identify your Credit Card Processor. Your Business Office/Controller should already know who the credit card processor is. Ask the bank to keep you informed of all new accounts that are established that have the university's name. 4 Arrange a conference with your Credit Card Processor(s). Reference "E" - Script of Questions 5 Review answers from Credit Card Processor. Determine if it is necessary to hire an assessor and/or a scanning service. 6 Take a preliminary look at the questionnaire that must! Assign responsibility for the questionnaire to IT. be completed for the Credit Card Processor by July 1, This questionnaire is key to compliance! Do not delay! 7 Conduct PCI-PA-DSS Training with Cashiers. Work with your Business Office/Controller to identify which departments need to be there. Conduct a survey. Reference "F" - Questionnaire 8 Get the Word Out. Publish articles in campus newsletters. 1

11 PCI-PA-DSS "COMPLY BY JULY" STEP BY STEP GUIDE STEP NOTES STATUS 9 Prepare comprehensive inventory of Departments Approach this several ways: ask for a list of that use credit cards. Merchant ID numbers from your credit card processor; check with the Business Office; ask your auditor. Reference "G" - Inventory Form 10 Identify Hot Spots on Inventory. Look closely at those areas where you would be hurt the most from a revenue perspective: (i.e. Admissions; Bookstore; Campus Dining; Development and Alumni; Housing). 11 Create a checklist of questions to ask each of the Send the checklist to the department before the departments that are on your inventory. field visit and ask them to fill in what they can. Reference "H" - Checklist 12 Establish teams to visit departments. Have enough teams to cover all the Each team should have a technical & business departments in a short period of time, so that representative. Complete Checklist for each department there is time to act if you discover a problem. and create a corrective action plan. 13 Set appointments to visit departments.! There is some urgency in completing this, so that you can identify problems ASAP. 14 Schedule conference calls with any vendors that have Do not be lulled into a false sense of security by not already provided adequate documentation to vague promises. Go to "plan two" if the vendor assure compliance. is making promises that you do not think can be fulfilled. 2

12 PCI-PA-DSS "COMPLY BY JULY" STEP BY STEP GUIDE STEP NOTES STATUS 15 Work with your credit card processor on establishing a Negotiate with your credit card processor. You "Fix It" timeline, if you cannot meet the July 1, 2010 want to mitigate risk as quickly as possible, deadline. however ask them to work with you if July 1 deadline is not realistic. There may be some flexibility if you can show an implementation plan. 16 Send Completed Questionnaire to Credit Card processor by Begin completing the questionnaire early to July 1, 2010! have ready well ahead of time. Be in Full PCI-PA-DSS Compliance by July 1, 2010! 3

13 Section D Endorsement from Senior Management Memo to Inform Campus about PCI-PA-DSS Standard

14 Important News on Credit Card Security Sample Letter from Your Senior Management News agencies routinely report stories of credit card fraud, identity theft and stories of hackers who have stolen sensitive information by breaking into databases. We CANNOT afford to let that happen here as illustrated by the following story. In 2003, one of our sister institutions had a security breach that cost up to $500,000 to fix. Hackers downloaded personal information stored on a server used as part of the university performing arts center ticketing process. The information included names, addresses, phone numbers, addresses and credit card numbers. It is believed the hackers gained access from a system located outside the US. The Georgia Bureau of Investigation, FBI and Secret Service all worked to find the source. The entire database of theatre goers had to be notified some 57,000 letters later, the university was bombarded with phone calls. A help desk was set up to reassure concerned patrons. Then insurance had to be purchased to protect all those exposed in this incident. And, the university was liable for a fine from the credit card company. In addition to the costs involved, the institution s reputation was tarnished. For the past two years, Business Operations and IT have worked together to implement ways to safeguard sensitive data, including credit card information. Several steps have been taken during this time to evaluate risk, identify problems, educate departments about best practices in cash receipting, and to employ secure technological solutions. As credit card standards continue to evolve, the stakes have grown higher. Beginning July 1, 2010 a new standard comes into effect that is known as the Payment Card Industry Payment Application Data Security Standard (PCI PA-DSS). The role that colleges and universities must take to protect private financial data has gotten bigger. Bottom line: If we are not in compliance with the new standard, we may not be able to process certain credit card transactions. A credit card security team was recently formed at (your institution name here) to ensure that business functions across the campus remain operational after the new credit card security standard goes into effect July 1. The goal of the team is to go beyond meeting minimum standards and to be able to say with confidence that we have taken all reasonable steps to safeguard credit card data. Our students, parents, donors, theatre patrons, employees and other constituents deserve no less. As such, we need your full cooperation. Members of the credit card security team will be calling on departments in the near future. Please instruct your staff to work cooperatively with them. Point out any areas of concern you may have, and discuss frankly such issues as credit card storage, employee access, and other matters that could lead to a breach of security. The team will explore possible solutions with you. Please contact a member of the Credit Card Security Team, if you would like to schedule a risk assessment. Thank you in advance for helping our campus maintain its reputation for safeguarding sensitive data. List Contact Information of your Credit Card Security Team Here Name, Title, and Phone Number

15 Section E Contacting Your Credit Card Processor Have Your Questions Ready

16 PCI-PA-DSS Compliance Have Your Questions Ready: Questions for Credit Card Processor What exactly does our University need to do to satisfy Credit Card Processor that we are in PCI- PA-DSS compliance? Which merchant level is University? Note: You will need to know your merchant level to help you determine which self assessment questionnaire you are to complete for verification purposes. If we self assess, which questionnaire do we complete? What are the requirements that qualify us for that particular questionnaire? Is the questionnaire requirement waived if we hire an assessor? What are the pros and cons for self assessment versus hiring an assessor? Is hiring an assessor a recommendation or a requirement? What is the range of cost we might expect to pay for an assessor? How long does an assessment take to complete? What kind of report should we expect from the assessor? Is this a one-time assessment, or is ongoing assessment required? Frequency? Does the university submit one global questionnaire for all merchants on campus, or must a separate questionnaire be completed for each merchant ID number? Does your Credit Card Swiper (device) store credit card data? Is it PCI compliant? What do we look for in reading the PCI Compliance List to know definitively that our POS systems are in compliance? If at July 1, the Credit Card Processing company realizes that the University has missed something that makes us not in compliance, what will happen? Will credit card data processing stop all across campus, for that one merchant ID, or is there a grace period in which to fix the problem?

17 Section F Questionnaire to Department Cashiers Hello Out There Does Your Department Process Credit Cards?

18 Credit Card Security Questionnaire Department: Contact Name: Contact Contact Phone #: Do you accept credit cards in your department? YES NO If yes, please answer the following questions. If no, you need go no further. For what purpose(s) do you accept credit cards? How are the cards processed? Touchnet POS System Which One? Manually Use credit card machine to imprint card Hand write credit card numbers on credit card slip or other paper Other What identifying information do you record on the credit card slip? Driver s License # Social Security # Campus Card ID # Other Do your credit card receipts have the full credit card number imprinted on them? YES NO Merchant s copy only Customer s copy only Merchant s copy and Customer s copy Entire number Last four digits Other Where do you store credit card records? Cash Register Safe Storage Cabinet Other How long are credit card records kept?

19 Section G Inventory Capturing the Full Scope of the Project Have You Left Off Anyone?

20 Inventory of Departments with Credit Card Processing Activity - Sample TEAM Merchant/Department Outlet # Hierarchy Level YES/NO FD-100 POS Other Touchnet Terminal MPL BillPay Upay NOTES POS SYSTEMS 1 BOOKSTORE 2 PERFORMING ARTS CENTER 3 DEVELOPMENT AND ALUMNI 4 GOLF CLUB 5 CAREER CENTER TOUCHNET 6 BUSINESS OFFICE 7 CONTINUING EDUCATION 8 REGISTRAR'S OFFICE 9 CAMPUS SERVICES 10 STUDY ABROAD 11 SCIENCE OLYMPIAD 12 SPECIAL EVENTS 13 PUBLIC SAFETY/PARKING 14 ATHLETICS 15 STUDENT ACTIVITIES 16 LIBRARY 17 COLLEGE OF BUSINESS 19 PSYCHOLOGY 19 COLLEGE OF EDUCATION OTHER

21 Inventory of Departments with Credit Card Processing Activity - Sample 20 CAMPUS DINIING YES/NO FD-100 POS Other Touchnet Terminal MPL BillPay Upay NOTES 21 UNIVERSITY HOUSING 22 GEORGIA 411

22 Section H Compliance Field Visit Checklist Document Your Effort to Establish Compliance

23 PCI-PA-DDS Compliance Checklist Adaptation fromtouchnet PCI-PA-DSS Solution Kit, page 7 Date of Field Visit: Department: Department Contact(s): Does Department Accept Credit Cards Yes No For what purpose does department accept Credit Cards? PART I: IDENTIFY EACH DEPARTMENT'S PAY PRACTICES What credit card brands does department accept? Visa MasterCard Discover AMEX Other What volume (number of transactions) does the department accept per fiscal year (per card brand/type)? Visa MasterCard Discover AMEX Other What dollar value do these volumes represent on fiscal year basis (per card brand/type)? Visa MasterCard Discover AMEX Other What channels does the department use to accept credit cards? Online In Person Telephone By Mail Other PART II: CHECK EACH SYSTEM FOR PCI-DSS COMPLIANCE Where is the credit card application hosted? On Campus Off Campus Off Campus Data Center Third Party Service Provider Other Is the hosting facility PCI-PA-DSS compliant? Yes No Was compliance specified via Self-Assessment Questionnaire or independent audit? Yes No Has proof of PCI -PA-DSS compliance been filed for each system? Yes No ( Note: Proof should be forward to Internal Audit for filing in PCI Compliance Notebook) 1

24 PART III: CHECK EACH SOFTWARE APPLICATION FOR PA-DSS CERTIFICATION What POS software is used to accept, process or store any sensitive credit card data? Is there an additional credit card processing system used? Yes No If Yes, Please specify which one. Does staff type credit card numbers typed into a desktop computer? Yes No If yes, are the numbers masked after they are entered? Yes No If masked, describe. What system is currently in place to accept/process credit cards? Card Imprinter Handwritten TouchNet Card Swipe Make Model Other POS See below If there is currently a POS System in place, provide name, all components and versions. Confirm by field visit. Obtain vendor contact information, product name and version Vendor Version Hardware Version Software Version Vendor Version Hardware Version Software Version Vendor Version Hardware Version Software Version Is the application a custom application used only by university/department? Yes No Obtain Vendor Contact Information: Product Name Vendor Name Street Address City, State, Zip Name of Contact Phone Is the application (and version) listed by the PCI Council as PA DSS certified? Be sure to check the version of the application. Print copy of list, highlight application. Yes No Retain for file. If not on PCI Website, contact vendor for PA-DSS status clarification, or proof of compliance. Confirm PCI Compliance Plan. Date contacted Name of Contact Contact Info Recommended Solution Contacted by Timeframe Must be in compliance by July 1 If July 1 date cannot be met, apprise First Data of implementation plan in writing. Written approval obtained date Send by certified mail. 2

25 PART IV: CHECK ALL MERCHANT DEVICES FOR PTS VALIDATION Does the merchant use any card swipe devices? Yes No Do the devices store payment data? Yes No What devices are in use? Manufacturer Model Number Version How is device connected to the processor Internet Phone Other For PIN-entry equipment, is the device listed as validated by the PCI Council? FD 100 Yes No N/A For what purpose is the card swipe used? PART V: TOUCHNET Is TouchNet used in the Department? Yes No How is TouchNet Used? Marketplace Upay-Tlink BillPay COMPLETED BY (One of Three Teams): Date Date OR Date Date OR Date Date Note: Adapted from TouchNet PCI-PA-DSS Solution Kit, page 7 3

Project Title slide Project: PCI. Are You At Risk?

Project Title slide Project: PCI. Are You At Risk? Blank slide Project Title slide Project: PCI Are You At Risk? Agenda Are You At Risk? Video What is the PCI SSC? Agenda What are the requirements of the PCI DSS? What Steps Can You Take? Available Services

More information

PC-DSS Compliance Strategies. 2011 NDUS CIO Retreat July 27, 2011 Theresa Semmens, CISA

PC-DSS Compliance Strategies. 2011 NDUS CIO Retreat July 27, 2011 Theresa Semmens, CISA PC-DSS Compliance Strategies 2011 NDUS CIO Retreat July 27, 2011 Theresa Semmens, CISA True or False Now that my institution has outsourced credit card processing, I don t have to worry about compliance?

More information

Payment Card Industry Data Security Standards Compliance

Payment Card Industry Data Security Standards Compliance Payment Card Industry Data Security Standards Compliance Please turn off, or to vibrate, all cell-phones/electronics Expected course length: 1 Hour Questions are welcomed. Who Created It? & What Is It?

More information

How To Protect Your Credit Card Information From Being Stolen

How To Protect Your Credit Card Information From Being Stolen Visa Account Information Security Tool Kit Welcome to the Visa Account Information Security Program 2 Contents 1. Securing cardholder data is everyone s concern 4 2. Visa Account Information Security (AIS)

More information

How To Comply With The Pci Ds.S.A.S

How To Comply With The Pci Ds.S.A.S PCI Compliance and the Data Security Standards Introduction The PCI DSS, a set of comprehensive requirements for enhancing payment account data security, was developed by the founding payment brands of

More information

WHITE PAPER. PCI Basics: What it Takes to Be Compliant

WHITE PAPER. PCI Basics: What it Takes to Be Compliant WHITE PAPER PCI Basics: What it Takes to Be Compliant Introduction A long-running worldwide advertising campaign by Visa states that the card is accepted everywhere you want to be. Unfortunately, and through

More information

What are the PCI DSS requirements? PCI DSS comprises twelve requirements, often referred to as the digital dozen. These define the need to:

What are the PCI DSS requirements? PCI DSS comprises twelve requirements, often referred to as the digital dozen. These define the need to: What is the PCI standards council? The Payment Card Industry Standards Council is an institution set-up by American Express, Discover Financial Services, JCB, MasterCard Worldwide and Visa International

More information

PCI Compliance. Top 10 Questions & Answers

PCI Compliance. Top 10 Questions & Answers PCI Compliance Top 10 Questions & Answers 1. What is PCI Compliance and PCI DSS? 2. Who needs to follow the PCI Data Security Standard? 3. What happens if I don t comply? 4. What are the basic requirements

More information

PCI Compliance at The University of South Carolina. Failure is not an option. Rick Lambert PMP University of South Carolina ricklambert@sc.

PCI Compliance at The University of South Carolina. Failure is not an option. Rick Lambert PMP University of South Carolina ricklambert@sc. PCI Compliance at The University of South Carolina Failure is not an option Rick Lambert PMP University of South Carolina ricklambert@sc.edu Payment Card Industry Data Security Standard (PCI DSS) Who Must

More information

Whitepaper. PCI Compliance: Protect Your Business from Data Breach

Whitepaper. PCI Compliance: Protect Your Business from Data Breach Merchants often underestimate the financial impact of a breach. Direct costs include mandatory forensic audits, credit card replacement, fees, fines and breach remediation. PCI Compliance: Protect Your

More information

Credit Card Processing Overview

Credit Card Processing Overview CardControl 3.0 Credit Card Processing Overview Overview Credit card processing is a very complex and important system for anyone that sells goods. This guide will hopefully help educate and inform new

More information

PCI Overview. PCI-DSS: Payment Card Industry Data Security Standard

PCI Overview. PCI-DSS: Payment Card Industry Data Security Standard PCI-DSS: Payment Card Industry Data Security Standard Why is this important? Cardholder data and personally identifying information are easy money That we work with this information makes us a target That

More information

Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015

Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015 Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015 I. PURPOSE The purpose of this policy is to establish guidelines for processing charges on Payment Cards to protect

More information

PCI Compliance Top 10 Questions and Answers

PCI Compliance Top 10 Questions and Answers Where every interaction matters. PCI Compliance Top 10 Questions and Answers White Paper October 2013 By: Peer 1 Hosting Product Team www.peer1.com Contents What is PCI Compliance and PCI DSS? 3 Who needs

More information

Your guide to the Payment Card Industry Data Security Standard (PCI DSS) Merchant Business Solutions. Version 5.0 (April 2011)

Your guide to the Payment Card Industry Data Security Standard (PCI DSS) Merchant Business Solutions. Version 5.0 (April 2011) Your guide to the Payment Card Industry Data Security Standard (PCI DSS) Merchant Business Solutions Version 5.0 (April 2011) Contents Contents...2 Introduction...3 What are the 12 key requirements of

More information

Whitepaper. PCI Compliance: Protect Your Business from Data Breach

Whitepaper. PCI Compliance: Protect Your Business from Data Breach Merchants often underestimate the financial impact of a breach. Direct costs include mandatory forensic audits, credit card replacement, fees, fines and breach remediation. PCI Compliance: Protect Your

More information

La règlementation VisaCard, MasterCard PCI-DSS

La règlementation VisaCard, MasterCard PCI-DSS La règlementation VisaCard, MasterCard PCI-DSS Conférence CLUSIF "LES RSSI FACE À L ÉVOLUTION DE LA RÉGLEMENTATION" 7 novembre 07 Serge Saghroune Overview of PCI DSS Payment Card Industry Data Security

More information

CardControl. Credit Card Processing 101. Overview. Contents

CardControl. Credit Card Processing 101. Overview. Contents CardControl Credit Card Processing 101 Overview Credit card processing is a very complex and important system for anyone that sells goods. This guide will hopefully help educate and inform new and old

More information

Important Info for Youth Sports Associations

Important Info for Youth Sports Associations Important Info for Youth Sports Associations What the Heck is PCI DSS and Why Should I Care? Joe Posey Terrapin Financial Services Your Club is an ecommerce Business You accept online registration over

More information

Why Is Compliance with PCI DSS Important?

Why Is Compliance with PCI DSS Important? Why Is Compliance with PCI DSS Important? The members of PCI Security Standards Council (American Express, Discover, JCB, MasterCard, and Visa) continually monitor cases of account data compromise. These

More information

Credit Card Handling Security Standards

Credit Card Handling Security Standards Credit Card Handling Security Standards Overview This document is intended to provide guidance to merchants (colleges, departments, auxiliary organizations or individuals) regarding the processing of charges

More information

PCI-PA-DSS. Solution Kit

PCI-PA-DSS. Solution Kit PCI-PA-DSS Solution Kit Table of Contents Introduction Why a PCI-PA-DSS Solution Kit? PCI Standards Defined PCI DSS PA-DSS PTS Move The Button Getting Started Game Board The Winning Strategy TouchNet U.Commerce

More information

2.0 PAYMENT CARD INDUSTRY DATA SECURITY STANDARDS (PCI-DSS)

2.0 PAYMENT CARD INDUSTRY DATA SECURITY STANDARDS (PCI-DSS) CSU, Chico Credit Card Handling Security Standard Effective Date: July 28, 2015 1.0 INTRODUCTION This standard provides guidance to ensure that credit card acceptance and ecommerce processes comply with

More information

SecurityMetrics Introduction to PCI Compliance

SecurityMetrics Introduction to PCI Compliance SecurityMetrics Introduction to PCI Compliance Card Data Compromise What is a card data compromise? A card data compromise occurs when payment card information is stolen from a merchant. Some examples

More information

Dartmouth College Merchant Credit Card Policy for Managers and Supervisors

Dartmouth College Merchant Credit Card Policy for Managers and Supervisors Dartmouth College Merchant Credit Card Policy for Managers and Supervisors Mission Statement Dartmouth College requires all departments that process, store or transmit credit card data remain in compliance

More information

Adyen PCI DSS 3.0 Compliance Guide

Adyen PCI DSS 3.0 Compliance Guide Adyen PCI DSS 3.0 Compliance Guide February 2015 Page 1 2015 Adyen BV www.adyen.com Disclaimer: This document is for guidance purposes only. Adyen does not accept responsibility for any inaccuracies. Merchants

More information

PCI DSS Payment Card Industry Data Security Standard. Merchant compliance guidelines for level 4 merchants

PCI DSS Payment Card Industry Data Security Standard. Merchant compliance guidelines for level 4 merchants Appendix 2 PCI DSS Payment Card Industry Data Security Standard Merchant compliance guidelines for level 4 merchants CONTENTS 1. What is PCI DSS? 2. Why become compliant? 3. What are the requirements?

More information

How To Protect Your Business From A Hacker Attack

How To Protect Your Business From A Hacker Attack Payment Card Industry Data Security Standards The payment card industry data security standard PCI DSS Visa and MasterCard have developed the Payment Card Industry Data Security Standard or PCI DSS as

More information

Property of CampusGuard. Compliance With The PCI DSS

Property of CampusGuard. Compliance With The PCI DSS Compliance With The PCI DSS Today s Agenda PCI DSS Introduction How are Colleges and Universities Affected? How Do You Validate Compliance? Best Practices Q&A CampusGuard Full-Service QSA/ASV Firm We Know

More information

Information Technology

Information Technology Credit Card Handling Security Standards Overview Information Technology This document is intended to provide guidance to merchants (colleges, departments, organizations or individuals) regarding the processing

More information

POLICY & PROCEDURE DOCUMENT NUMBER: 3.3101. DIVISION: Finance & Administration. TITLE: Policy & Procedures for Credit Card Merchants

POLICY & PROCEDURE DOCUMENT NUMBER: 3.3101. DIVISION: Finance & Administration. TITLE: Policy & Procedures for Credit Card Merchants POLICY & PROCEDURE DOCUMENT NUMBER: 3.3101 DIVISION: Finance & Administration TITLE: Policy & Procedures for Credit Card Merchants DATE: October 24, 2011 Authorized by: K. Ann Mead, VP for Finance & Administration

More information

PCI DSS COMPLIANCE DATA

PCI DSS COMPLIANCE DATA PCI DSS COMPLIANCE DATA AND PROTECTION EagleHeaps FROM CONTENTS Overview... 2 The Basics of PCI DSS... 2 PCI DSS Compliance... 4 The Solution Provider Role (and Accountability).... 4 Concerns and Opportunities

More information

TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No. 08-01 MERCHANT DEBIT AND CREDIT CARD RECEIPTS

TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No. 08-01 MERCHANT DEBIT AND CREDIT CARD RECEIPTS TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No. 08-01 MERCHANT DEBIT AND CREDIT CARD RECEIPTS 1. Introduction Debit and Credit Card Receipt Standards apply to the administration

More information

CREDIT CARD MERCHANT POLICY. All campuses served by Louisiana State University (LSU) Office of Accounting Services

CREDIT CARD MERCHANT POLICY. All campuses served by Louisiana State University (LSU) Office of Accounting Services Louisiana State University Finance and Administrative Services Operating Procedure FASOP: AS-22 CREDIT CARD MERCHANT POLICY Scope: All campuses served by Louisiana State University (LSU) Office of Accounting

More information

PCI DSS 3.0 Overview. OSU Business Affairs Business Affairs PIT Crew - Project, Improvement, & Technology Robin Whitlock

PCI DSS 3.0 Overview. OSU Business Affairs Business Affairs PIT Crew - Project, Improvement, & Technology Robin Whitlock PCI DSS 3.0 Overview OSU Business Affairs Business Affairs PIT Crew - Project, Improvement, & Technology Robin Whitlock 01/16/2015 Purpose of Today s Presentation To provide an overview of PCI 3.0 based

More information

Accepting Payment Cards and ecommerce Payments

Accepting Payment Cards and ecommerce Payments Policy V. 4.1.1 Responsible Official: Vice President for Finance and Treasurer Effective Date: September 29, 2010 Accepting Payment Cards and ecommerce Payments Policy Statement The University of Vermont

More information

Payment Card Industry Data Security Standards.

Payment Card Industry Data Security Standards. Payment Card Industry Data Security Standards. Your guide to protecting cardholder data Helping you manage the risk. Credit Card fraud and data compromises are an increasingly serious problem, costing

More information

Information for merchants. Program implementation details for merchants. Payment Card Industry Data Security Standard (PCI DSS)

Information for merchants. Program implementation details for merchants. Payment Card Industry Data Security Standard (PCI DSS) Postbank P.O.S. Transact GmbH (now EVO Kartenakzeptanz GmbH) has recently been purchased by EVO Payments International Group Program implementation details for merchants Payment Card Industry Data Security

More information

PAI Secure Program Guide

PAI Secure Program Guide PAI Secure Program Guide A complete guide to understanding the Payment Card Industry Data Security Requirements and utilizing the PAI Secure Program. Letter From the CEO Welcome to PAI Secure. As you

More information

SECTION: SUBJECT: PCI-DSS General Guidelines and Procedures

SECTION: SUBJECT: PCI-DSS General Guidelines and Procedures 1. Introduction 1.1. Purpose and Background 1.2. Central Coordinator Contact 1.3. Payment Card Industry Data Security Standards (PCI-DSS) High Level Overview 2. PCI-DSS Guidelines - Division of Responsibilities

More information

University of Dayton Credit / Debit Card Acceptance Policy September 1, 2009

University of Dayton Credit / Debit Card Acceptance Policy September 1, 2009 University of Dayton Credit / Debit Card Acceptance Policy September 1, 2009 Effective Date of this Policy: August 1, 2008 Last Revision: September 1, 2009 Contact for More Information: UDit Internal Auditor

More information

POLICY NAME : MERCHANT (PCI) POLICY AND PROCEDURES ACCEPTING CREDIT/DEBIT CARD PAYMENTS

POLICY NAME : MERCHANT (PCI) POLICY AND PROCEDURES ACCEPTING CREDIT/DEBIT CARD PAYMENTS Publication Date 2009-08-11 Issued by: Financial Services Chief Information Officer Revision V 1.0 POLICY NAME : MERCHANT (PCI) POLICY AND PROCEDURES ACCEPTING CREDIT/DEBIT CARD PAYMENTS Overview: There

More information

P R O G R E S S I V E S O L U T I O N S

P R O G R E S S I V E S O L U T I O N S PCI DSS: PCI DSS is a set of technical and operational mandates designed to ensure that all organizations that process, store or transmit credit card information maintain a secure environment and safeguard

More information

Payment Card Industry Data Security Standard

Payment Card Industry Data Security Standard Payment Card Industry Data Security Standard Abhinav Goyal, B.E.(Computer Science) MBA Finance Final Trimester Welingkar Institute of Management ISACA Bangalore chapter 13 th February 2010 Credit Card

More information

FORT HAYS STATE UNIVERSITY CREDIT CARD SECURITY POLICY

FORT HAYS STATE UNIVERSITY CREDIT CARD SECURITY POLICY FORT HAYS STATE UNIVERSITY CREDIT CARD SECURITY POLICY Page 1 of 6 Summary The Payment Card Industry Data Security Standard (PCI DSS), a set of comprehensive requirements for enhancing payment account

More information

CREDIT CARD PROCESSING POLICY AND PROCEDURES

CREDIT CARD PROCESSING POLICY AND PROCEDURES CREDIT CARD PROCESSING POLICY AND PROCEDURES Note: For purposes of this document, debit cards are treated the same as credit cards. Any reference to credit cards includes credit and debit card transactions.

More information

UCSB Credit Card Processing and PCI Compliance

UCSB Credit Card Processing and PCI Compliance UCSB Credit Card Processing and PCI Compliance Sandra Featherson Associate Director of Controls Campus Credit Card Coordinator May 2011 Agenda Campus Credit Card Process Overview Terminology Approval/Acceptance

More information

PCI Compliance: Protection Against Data Breaches

PCI Compliance: Protection Against Data Breaches Protection Against Data Breaches Get Started Now: 877.611.6342 to learn more. www.megapath.com The Growing Impact of Data Breaches Since 2005, there have been 4,579 data breaches (disclosed through 2013)

More information

How To Protect Visa Account Information

How To Protect Visa Account Information Account Information Security Merchant Guide At Visa, protecting our cardholders is at the core of everything we do. One of the many reasons people trust our brand is that we make buying and selling safer

More information

A PCI Journey with Wichita State University

A PCI Journey with Wichita State University A PCI Journey with Wichita State University Blaine Linehan System Software Analyst III Financial Operations & Business Technology Division of Administration & Finance 1 Question #1 How many of you know

More information

Comodo HackerGuardian. PCI Security Compliance The Facts. What PCI security means for your business

Comodo HackerGuardian. PCI Security Compliance The Facts. What PCI security means for your business Comodo HackerGuardian PCI Security Compliance The Facts What PCI security means for your business Overview The Payment Card Industry Data Security Standard (PCI DSS) is a set of 12 requirements intended

More information

Merchant guide to PCI DSS

Merchant guide to PCI DSS Merchant guide to PCI DSS Contents What is PCI DSS and why was it introduced?... 3 Who needs to become PCI DSS compliant?... 3 BOIPA Simple PCI DSS - 3 step approach to helping businesses... 3 What does

More information

PCI COMPLIANCE GUIDE For Merchants and Service Members

PCI COMPLIANCE GUIDE For Merchants and Service Members PCI SAQ C-VT PCI COMPLIANCE GUIDE For Merchants and Service Members PCI DSS v2.0 SAQ CVT Merchant Guide 1 Contents Contents... 2 Introduction... 3 Defining an SAQ C Merchant... 3 REQUIREMENTS FOR SAQ-VT...

More information

PCI Standards: A Banking Perspective

PCI Standards: A Banking Perspective Slide 1 PCI Standards: A Banking Perspective Bob Brown, CISSP Wachovia Corporate Information Security Slide 2 Agenda 1. Payment Card Initiative History 2. Description of the Industry 3. PCI-DSS Control

More information

Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS)

Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS) Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS) What is PCI DSS? The 12 Requirements Becoming compliant with SaferPayments Understanding the jargon SaferPayments Be smart.

More information

Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions

Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions PCI/PA-DSS FAQs Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions What is PCI DSS? The Payment Card Industry Data

More information

Varonis Systems & The Payment Card Industry Data Security Standard (PCI DSS)

Varonis Systems & The Payment Card Industry Data Security Standard (PCI DSS) CONTENTS OF THIS WHITE PAPER Overview... 1 Background... 1 Who Needs To Comply... 1 What Is Considered Sensitive Data... 2 What Are the Costs/Risks of Non-Compliance... 2 How Varonis Helps With PCI Compliance...

More information

TNHFMA 2011 Fall Institute October 12, 2011 TAKING OUR CUSTOMERS BUSINESS FORWARD. The Cost of Payment Card Data Theft and Your Business

TNHFMA 2011 Fall Institute October 12, 2011 TAKING OUR CUSTOMERS BUSINESS FORWARD. The Cost of Payment Card Data Theft and Your Business TAKING OUR CUSTOMERS BUSINESS FORWARD The Cost of Payment Card Data Theft and Your Business Aaron Lego Director of Business Development Presentation Agenda Items we will cover: 1. Background on Payment

More information

PCI COMPLIANCE FOR HIGHER EDUCATION BEST PRACTICES CHECKLIST. Presented By: The Treasury Institute for Higher Education.

PCI COMPLIANCE FOR HIGHER EDUCATION BEST PRACTICES CHECKLIST. Presented By: The Treasury Institute for Higher Education. PCI COMPLIANCE FOR HIGHER EDUCATION BEST PRACTICES CHECKLIST Presented By: The Treasury Institute for Higher Education & AmbironTrustWave Pg. 1 of 10 Executive Summary This checklist is intended to help

More information

PCI Compliance Overview

PCI Compliance Overview PCI Compliance Overview 1 PCI DSS Payment Card Industry Data Security Standard Standard that is applied to: Merchants Service Providers (Banks, Third party vendors, gateways) Systems (Hardware, software)

More information

Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance

Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance A Non-Technical Guide Essential for Business Managers Office Managers Operations Managers Compliant? Bank Name

More information

Appendix 1 Payment Card Industry Data Security Standards Program

Appendix 1 Payment Card Industry Data Security Standards Program Appendix 1 Payment Card Industry Data Security Standards Program PCI security standards are technical and operational requirements set by the Payment Card Industry Security Standards Council to protect

More information

The Petroleum Marketer s PCI compliance Reference Guide

The Petroleum Marketer s PCI compliance Reference Guide The Petroleum Marketer s PCI compliance Reference Guide 1. Become familiar with the 12 standards of card data security: Build and maintain a secure network Requirement 1 Install and maintain a firewall

More information

CHEAT SHEET: PCI DSS 3.1 COMPLIANCE

CHEAT SHEET: PCI DSS 3.1 COMPLIANCE CHEAT SHEET: PCI DSS 3.1 COMPLIANCE WHAT IS PCI DSS? Payment Card Industry Data Security Standard Information security standard for organizations that handle data for debit, credit, prepaid, e-purse, ATM,

More information

PCI DSS Compliance. 2015 Information Pack for Merchants

PCI DSS Compliance. 2015 Information Pack for Merchants PCI DSS Compliance 2015 Information Pack for Merchants This pack contains general information regarding PCI DSS compliance and does not take into account your business' particular requirements. ANZ recommends

More information

PCI Compliance: How to ensure customer cardholder data is handled with care

PCI Compliance: How to ensure customer cardholder data is handled with care PCI Compliance: How to ensure customer cardholder data is handled with care Choosing a safe payment process for your business Contents Contents 2 Executive Summary 3 PCI compliance and accreditation 4

More information

Clark University's PCI Compliance Policy

Clark University's PCI Compliance Policy ï» Clark University's PCI Compliance Policy Who Should Read this Policy: All persons who have access to credit card information, including: Every employee that accesses handles or maintains credit card

More information

PCI Security Compliance

PCI Security Compliance E N T E R P R I S E Enterprise Security Solutions PCI Security Compliance : What PCI security means for your business The Facts Comodo HackerGuardian TM PCI and the Online Merchant Overview The Payment

More information

Before You Swipe: Best Practices in Accepting Credit, Debit and Pre-Paid. Paid Card Payments

Before You Swipe: Best Practices in Accepting Credit, Debit and Pre-Paid. Paid Card Payments Before You Swipe: Best Practices in Accepting Credit, Debit and Pre-Paid Paid Card Payments Sean Christy, Sutherland Robyn Miller, Pro Bono Partnership of Atlanta March 22, 2012 Mission of Pro Bono Partnership

More information

PCI DSS FAQ. The twelve requirements of the PCI DSS are defined as follows:

PCI DSS FAQ. The twelve requirements of the PCI DSS are defined as follows: What is PCI DSS? PCI DSS is an acronym for Payment Card Industry Data Security Standards. PCI DSS is a global initiative intent on securing credit and banking transactions by merchants & service providers

More information

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008 Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008 What is the PCI DSS? And what do the acronyms CISP, SDP, DSOP and DISC stand for? The PCI DSS is a set of comprehensive requirements

More information

2015 PCI DSS Meeting. OSU Business Affairs Projects, Improvement, and Technology (PIT) Robin Whitlock

2015 PCI DSS Meeting. OSU Business Affairs Projects, Improvement, and Technology (PIT) Robin Whitlock 2015 PCI DSS Meeting OSU Business Affairs Projects, Improvement, and Technology (PIT) Robin Whitlock 11/3/2015 Today s Presentation What do you need to do? What is PCI DSS? Why PCI DSS? Who Needs to Comply

More information

The PCI DSS Compliance Guide For Small Business

The PCI DSS Compliance Guide For Small Business PCI DSS Compliance in a hosted infrastructure A Rackspace White Paper Spring 2010 Summary The Payment Card Industry Data Security Standard (PCI DSS) is a global information security standard defined by

More information

05.118 Credit Card Acceptance Policy. Vice Chancellor of Business Affairs. History: Effective July 1, 2011 Updated February 2013

05.118 Credit Card Acceptance Policy. Vice Chancellor of Business Affairs. History: Effective July 1, 2011 Updated February 2013 05.118 Credit Card Acceptance Policy Authority: Vice Chancellor of Business Affairs History: Effective July 1, 2011 Updated February 2013 Source of Authority: Office of State Controller (OSC); Office of

More information

Tokenization Amplified XiIntercept. The ultimate PCI DSS cost & scope reduction mechanism

Tokenization Amplified XiIntercept. The ultimate PCI DSS cost & scope reduction mechanism Tokenization Amplified XiIntercept The ultimate PCI DSS cost & scope reduction mechanism Paymetric White Paper Tokenization Amplified XiIntercept 2 Table of Contents Executive Summary 3 PCI DSS 3 The PCI

More information

Payment Card Industry Data Security Standard PCI DSS

Payment Card Industry Data Security Standard PCI DSS Payment Card Industry Data Security Standard PCI DSS What is PCI DSS? Requirements developed by the five card brands: VISA, Mastercard, AMEX, JCB and Discover. Their aim was to put together a common set

More information

Dartmouth College Merchant Credit Card Policy for Processors

Dartmouth College Merchant Credit Card Policy for Processors Mission Statement Dartmouth College Merchant Credit Card Policy for Processors Dartmouth College requires all departments that process, store or transmit credit card data remain in compliance with the

More information

CSU, Chico Credit Card PCI-DSS Risk Assessment

CSU, Chico Credit Card PCI-DSS Risk Assessment CSU, Chico Credit Card PCI-DSS Risk Assessment Division/ Department Name: Merchant ID Financial Account Location (University, Auxiliary Organization) Business unit functional contact: : Title: Telephone:

More information

The 12 Essentials of PCI Compliance How it Differs from HIPPA Compliance Understand & Implement Effective PCI Data Security Standard Compliance

The 12 Essentials of PCI Compliance How it Differs from HIPPA Compliance Understand & Implement Effective PCI Data Security Standard Compliance Date: 07/19/2011 The 12 Essentials of PCI Compliance How it Differs from HIPPA Compliance Understand & Implement Effective PCI Data Security Standard Compliance PCI and HIPAA Compliance Defined Understand

More information

PCI Data Security Standards

PCI Data Security Standards PCI Data Security Standards An Introduction to Bankcard Data Security Why should we worry? Since 2005, over 500 million customer records have been reported as lost or stolen 1 In 2010 alone, over 134 million

More information

Becoming PCI Compliant

Becoming PCI Compliant Becoming PCI Compliant Jason Brown - brownj52@michigan.gov Enterprise Security Architect Enterprise Architecture Department of Technology, Management and Budget State of Michigan @jasonbrown17 History

More information

6-8065 Payment Card Industry Compliance

6-8065 Payment Card Industry Compliance 0 0 0 Yosemite Community College District Policies and Administrative Procedures No. -0 Policy -0 Payment Card Industry Compliance Yosemite Community College District will comply with the Payment Card

More information

Josiah Wilkinson Internal Security Assessor. Nationwide

Josiah Wilkinson Internal Security Assessor. Nationwide Josiah Wilkinson Internal Security Assessor Nationwide Payment Card Industry Overview PCI Governance/Enforcement Agenda PCI Data Security Standard Penalties for Non-Compliance Keys to Compliance Challenges

More information

A Whitepaper by Vesta Corporation. Payment Card Industry Data Security Standards (PCI DSS) and Mobile Operators: Trends and Implications

A Whitepaper by Vesta Corporation. Payment Card Industry Data Security Standards (PCI DSS) and Mobile Operators: Trends and Implications A Whitepaper by Vesta Corporation Payment Card Industry Data Security Standards (PCI DSS) and Mobile Operators: Trends and Implications About This Paper There have been numerous data breaches both announced

More information

How To Become A Pca Compliant Organization

How To Become A Pca Compliant Organization Compliance Management Merchant Guide 2012 Stay Clear Of Fraud Are You Concerned About Data Security Risks? Security is a duty. Companies should remember that they are being trusted by consumers with their

More information

PCI DSS 101 FOR CTOs AND BUSINESS EXECUTIVES

PCI DSS 101 FOR CTOs AND BUSINESS EXECUTIVES PCI DSS 101 FOR CTOs AND BUSINESS EXECUTIVES CUTTING THROUGH THE COMPLEXITY AND CONFUSION Over the years, South African retailers have come under increased pressure to gain PCI DSS (Payment Card Industry

More information

PCI DSS Presentation University of Cincinnati

PCI DSS Presentation University of Cincinnati PCI DSS Presentation University of Cincinnati Quick PCI Level Set Higher Ed Challenges Getting Compliant Application w/ customers Q& A PCI DSS Payment Card Industry Data Security Standard What is the PCI

More information

Payment Card Industry Data Security Standard

Payment Card Industry Data Security Standard Payment Card Industry Data Security Standard Office of the State Treasurer Ryan Pitroff Banking Services Manager Ryan.Pitroff@tre.wa.gov PCI-DSS A common set of industry tools and measurements to help

More information

And Take a Step on the IG Career Path

And Take a Step on the IG Career Path How to Develop a PCI Compliance Program And Take a Step on the IG Career Path Andrew Altepeter Any organization that processes customer payment cards must comply with the Payment Card Industry s Data Security

More information

Payment Card Acceptance Administrative Policy

Payment Card Acceptance Administrative Policy Administrative Procedure Approved By: Brandon Gilliland, Associate Vice President for Finance & Controller Effective Date: October 1, 2014 History: Approval Date: September 25, 2014 Revisions: Type: Administrative

More information

Frequently Asked Questions

Frequently Asked Questions PCI Compliance Frequently Asked Questions Table of Content GENERAL INFORMATION... 2 PAYMENT CARD INDUSTRY DATA SECURITY STANDARD (PCI DSS)...2 Are all merchants and service providers required to comply

More information

Understanding Payment Card Industry (PCI) Data Security

Understanding Payment Card Industry (PCI) Data Security Understanding Payment Card Industry (PCI) Data Security Office of the State Controller November 2010 State of North Carolina The Enemy Major Security Breaches TJ-Max Heartland Hannaford Foods BJ s Wholesale

More information

MasterCard PCI & Site Data Protection (SDP) Program Update. Academy of Risk Management Innovate. Collaborate. Educate.

MasterCard PCI & Site Data Protection (SDP) Program Update. Academy of Risk Management Innovate. Collaborate. Educate. MasterCard PCI & Site Data Protection (SDP) Program Update Academy of Risk Management Innovate. Collaborate. Educate. The Payment Card Industry Security Standards Council (PCI SSC) Open, Global Forum Founded

More information

688 Sherbrooke Street West, Room 730 James Administration Building, Room 524

688 Sherbrooke Street West, Room 730 James Administration Building, Room 524 'McGill Sylvia Franke, LL.B., B.Sc. Albert Caponi, C.A. Chief Information Officer Assistant Vice-Principal (Financial Services) 688 Sherbrooke Street West, Room 730 James Administration Building, Room

More information

Complying with PCI is a necessary step in safely accepting Payment Cards.

Complying with PCI is a necessary step in safely accepting Payment Cards. What Every Director Needs to Know About Credit Cards & Patron Privacy Complying with PCI is a necessary step in safely accepting Payment Cards. Know the Risks! Some Interesting Facts: 94% of data breaches

More information

Policies and Procedures. Merchant Card Services Office of Treasury Operations

Policies and Procedures. Merchant Card Services Office of Treasury Operations Policies and Procedures Merchant Card Services Office of Treasury Operations 1 Welcome! Table of Contents: Introduction Establishing Payment Card Services Payment Card Acceptance Procedures Payment Card

More information

An article on PCI Compliance for the Not-For-Profit Sector

An article on PCI Compliance for the Not-For-Profit Sector Level 8, 66 King Street Sydney NSW 2000 Australia Telephone +61 2 9290 4444 or 1300 922 923 An article on PCI Compliance for the Not-For-Profit Sector Page No.1 PCI Compliance for the Not-For-Profit Sector

More information

The Cost of Payment Card Data Theft and Your Business. Aaron Lego Director of Business Development

The Cost of Payment Card Data Theft and Your Business. Aaron Lego Director of Business Development The Cost of Payment Card Data Theft and Your Business Aaron Lego Director of Business Development Presentation Agenda Items we will cover: 1. Background on Payment Card Industry Data Security Standards

More information