UWM Credit Card Acceptance Committee. Committee Charter

Size: px
Start display at page:

Download "UWM Credit Card Acceptance Committee. Committee Charter"

Transcription

1 UWM Credit Card Acceptance Committee Committee Charter Version 9 March 2013

2 Table of Contents Committee Name... 2 Background... 2 Purpose... 3 Sponsors... 3 Role of Sponsors... 3 Committee Membership... 4 Role of Committee Members... 4 Committee Goals... 5 Committee Life Cycle... 5 Revision History... 5 Page i

3 Committee Name UWM Credit Card Acceptance Committee Background UWM accepts credit cards (Visa, MasterCard, Discover and American Express) and debit cards for goods and services such as tuition, books, housing, food and tickets for events. Credit card is the term used throughout this Charter to refer to both credit and debit cards. There are over 35 different business (merchant) units on campus, many of which accept credit cards at multiple locations and over the internet. Approximately 25 different credit card applications (e.g., TouchNet, CyberCash) are used by these business units to store, process and/or transit credit card data. UWM has experienced dramatic growth in credit card sales. In calendar year 2007, the number of credit card transactions totaled 194,000; associated sales were $21 million; and processing fees totaled $184,000. In calendar year 2009, the number of credit card transactions totaled 742,000; associated sales were $42 million; and processing fees totaled $787,000. The increase in activity from 2007 to 2009 is due primarily to Restaurant Operations beginning to accept credit cards for the first time along with an increase in the amount of tuition collected via credit cards. Recently, UWM made a decision to stop accepting Visa for tuition in order to minimize the amount of unrecoverable processing fees. It is yet to be determined what impact, if any, this will have on credit card tuition volume or collectability of accounts receivable. The credit card companies have promulgated contract provisions and security standards that UWM must comply with in order to continue accepting credit cards and avoid fines/penalties. The security standards went into effect during 2004 and have been evolving over the past few years. During this time, UWM has initiated compliance efforts. These efforts have been challenged by the lack of a campus-wide strategy to accept credit cards which in turn has permitted a multitude of different system applications. Recent actions to develop a framework for a campus-wide strategy include the adoption of Administrative Services Manual procedure , Merchant Card Administration. Page 2

4 Purpose The Credit Card Acceptance Committee is charged with proposing and facilitating implementation of cost-effective strategies for accepting cards that: 1. Satisfy customer needs. 2. Take advantage of business opportunities. 3. Minimize exposure to risks related to security. 4. Ensure compliance with standards promulgated by credit card companies. In addition, the Credit Card Acceptance Committee is charged with identifying potential funding sources for the above-referenced strategies Sponsors Johannes J. Britz Interim Provost and Vice Chancellor, Academic Affairs Robin Van Harpen Interim Vice Chancellor, Finance and Administrative Affairs Michael R. Laliberte Vice Chancellor, Student Affairs Role of Sponsors The sponsors have high-level responsibility for the success of the Committee. They help to establish the Committee s authority and maintain its credibility on campus. Sponsors will make decisions relating to strategy, business processes, policy and financial commitments that cannot be made by the Committee. Page 3

5 Committee Membership Credit Card Acceptance Committee Subject Matter Internal Audit Internal Audit Controllership Accounting Auxiliaries - Merchant Student Affairs Security Process IT and IT governance UITS Operations Participant, Committee Chair Paul Rediske Dave Rice Kristin Fekete Cindy Wirtz Autumn Anfang Steve Brukbacher Ed Melchoir Jacques du Plessis Jeff Lange Role of Committee Members In fulfilling the purpose of the Committee, each of its members will be committed to (1) acquiring a thorough understanding of existing business processes across the campus with respect to credit card acceptance and compliance, (2) acquiring a thorough understanding of best practices with respect to credit card acceptance and compliance, (3) working collectively to set goals and communicate those goals to campus stakeholders and (4) facilitating achievement of goals. To accomplish Committee goals and carry out related tasks and duties, subcommittees may be formed. These sub-committees may include other UWM staff. The Committee can also act to add or remove members, as deemed necessary. Page 4

6 Committee Goals 1. Complete a preliminary self-assessment of business units on campus accepting credit cards by December 2010 in order to gauge readiness of campus for official self-assessment to be performed in May Scope and engage an approved scanning vendor to perform network scans beginning in December Draft a strategic plan for UWM with respect to credit card acceptance by January Issues that this plan will address include funding sources and recovery of credit card processing fees. 4. Distribute self-assessments, required by credit card security standards, to the campus by May Ensure related awareness, training and support are provided in a timely manner. 5. All deficiencies identified in the above-referenced self-assessments and network scans will be remedied by June 30, 2011 or an action plan will be drafted to address the exceptions and identify an alternate timeframe for compliance. 6. Work with Purchasing to ensure all new vendor contracts will include appropriate provisions and language for compliance with credit card security standards if applicable. Committee Life Cycle The Committee will have a limited life. Each January, the Committee will evaluate its relevance and need for continuation based upon fulfillment of purpose and achievement of goals. Revision History Date Action By August 18, 2010 Draft creation /Paul Rediske August 23, 2010 Draft revision /Paul Rediske August 26, 2010 Draft revision /Paul Rediske February 21, 2011 Replaced draft version 3 with Version 4 title page Replaced James Hill with Michael Page 5

7 December 1, 2011 Laliberte page 3 Removed Mustafa Yundem, Dawn Thibedeau and Kristen Bornstein page 4 June 21, 2012 Added Melissa Woo page 4 August 17, 2012 October 8, 2012 Replaced John McCarragher with Jacques du Plessis and Melissa Woo with Jeff Lange as committee members page 4 Replaced Christy Brown with Robin Van Harpen as a sponsor. Added Kristin Fekete as the committee member for Accounting page 3 March 7, 2013 Added Autumn Anfang page 4 Page 6

Credit/Debit Card Processing Policy

Credit/Debit Card Processing Policy NUMBER: BUSF 4.11 SECTION: Business and Finance SUBJECT: Credit/Debit Card Processing Policy DATE: November 1, 2006 Policy for: All Campuses Procedures for: All Campuses Authorized by: Rick Kelly Issued

More information

PAYMENT CARD PROCESSING

PAYMENT CARD PROCESSING CSU The California State University Office of Audit and Advisory Services PAYMENT CARD PROCESSING California State University, Bakersfield Audit Report 15-42 October 13, 2015 EXECUTIVE SUMMARY OBJECTIVE

More information

Bradley University Credit Card Security Incident Response Team (Response Team)

Bradley University Credit Card Security Incident Response Team (Response Team) Credit Card Security Incident Response Plan Bradley University has a thorough data security policy 1. To address credit cardholder security, the major card brands (Visa, MasterCard, American Express, Discover

More information

University of Wisconsin Milwaukee. Athletic Board 2010-2011 Annual Report

University of Wisconsin Milwaukee. Athletic Board 2010-2011 Annual Report University of Wisconsin - Milwaukee Faculty Document No. 2821, October 20, 2011 University of Wisconsin Milwaukee Athletic Board 2010-2011 Annual Report Members: Virginia Stoffel FAC Occupational Therapy

More information

The following are responsible for the accuracy of the information contained in this document:

The following are responsible for the accuracy of the information contained in this document: AskUGA 1 of 5 Credit/Debit Cards Responsible administrator: Senior Vice President for Finance and Administration Related Procedure: The Credit/Debit Card Processing Procedures Responsible department: Bursar's

More information

PAYMENT CARD PROCESSING

PAYMENT CARD PROCESSING CSU The California State University Office of Audit and Advisory Services PAYMENT CARD PROCESSING California State University, Long Beach Audit Report 15-43 January 5, 2016 EXECUTIVE SUMMARY OBJECTIVE

More information

CURRICULUM CHANGE PROCEDURES FOR THE CSUF CATALOG

CURRICULUM CHANGE PROCEDURES FOR THE CSUF CATALOG CURRICULUM CHANGE PROCEDURES FOR THE CSUF CATALOG COURSE AND CURRICULUM CHANGE PROCEDURES: Request for New Undergraduate Course: A request for a new undergraduate course is made through the submission

More information

The UMC Web Engine - Model For Success

The UMC Web Engine - Model For Success UNIVERSITY OF MISSISSIPPI MEDICAL CENTER for the UMC Web Environment Page 1 of 12 1.0 PURPOSE The purpose of the is to establish requirements and provide instructions as governed by the Information Policy.

More information

University of Oregon Policy Statement Development Form

University of Oregon Policy Statement Development Form University of Oregon Policy Statement Development Form Policy Title: Electronic Commerce Policy submitted by: Name: Mark McCulloch Phone: 541 346 6249 Email: mmccullo@uoregon.edu Organization: Business

More information

AE Initiative Summary Business Case Data Center Aggregation

AE Initiative Summary Business Case Data Center Aggregation AE Initiative Summary Business Case Data Center Aggregation Business Sponsorship & Ownership Project Name: Team Members Business Unit(s): Business Process Owner(s): Preliminary Cost Estimate: Preliminary

More information

UTAH VALLEY UNIVERSITY Policies and Procedures

UTAH VALLEY UNIVERSITY Policies and Procedures Page 1 of 7 Proposed Policy Number and Title: 457 PCI DSS Compliance Existing Policy Number and Title: Not applicable Approval Process* X Regular Temporary Emergency Expedited X New New New Revision Revision

More information

6-8065 Payment Card Industry Compliance

6-8065 Payment Card Industry Compliance 0 0 0 Yosemite Community College District Policies and Administrative Procedures No. -0 Policy -0 Payment Card Industry Compliance Yosemite Community College District will comply with the Payment Card

More information

VISA EUROPE ACCOUNT INFORMATION SECURITY (AIS) PROGRAMME FREQUENTLY ASKED QUESTIONS (FAQS)

VISA EUROPE ACCOUNT INFORMATION SECURITY (AIS) PROGRAMME FREQUENTLY ASKED QUESTIONS (FAQS) VISA EUROPE ACCOUNT INFORMATION SECURITY (AIS) PROGRAMME FREQUENTLY ASKED QUESTIONS (FAQS) Q1: What is the purpose of the AIS programme? Q2: What exactly is the Payment Card Industry (PCI) Data Security

More information

Internal Audit and Advisory Services DRAFT

Internal Audit and Advisory Services DRAFT Internal Audit and Advisory Services DRAFT PAGE(S) Message from the Internal Audit and Advisory Services...1-2 Internal Audit and Advisory Services Plan...3-5 Objectives...6-7 Risk Assessment Process...8

More information

University Policy Accepting Credit Cards to Conduct University Business

University Policy Accepting Credit Cards to Conduct University Business BROWN UNIVERSITY University Policy Accepting Credit Cards to Conduct University Business Purpose Brown University requires all departments that are involved with credit card handling to do so in compliance

More information

Payment Card Industry Data Security Standards Compliance

Payment Card Industry Data Security Standards Compliance Payment Card Industry Data Security Standards Compliance Please turn off, or to vibrate, all cell-phones/electronics Expected course length: 1 Hour Questions are welcomed. Who Created It? & What Is It?

More information

Appendix A - Charter of the Academic and Student Affairs Committee

Appendix A - Charter of the Academic and Student Affairs Committee ATTACHMENT 2 Appendix A - Charter of the Academic and Student Affairs Committee A. Purpose. The Academic and Student Affairs Committee shall be well informed about, provide strategic direction and oversight,

More information

Action Plan to Enhance Institutional Compliance. THE UNIVERSITY OF TEXAS SYSTEM Updated 2003

Action Plan to Enhance Institutional Compliance. THE UNIVERSITY OF TEXAS SYSTEM Updated 2003 Action Plan to Enhance Institutional Compliance THE UNIVERSITY OF TEXAS SYSTEM Updated 2003 Audit Office System-wide Compliance Program June 2003 I N T R O D U C T I O N This 2003 Action Plan to Enhance

More information

The University of Central Arkansas. Strategic Planning

The University of Central Arkansas. Strategic Planning The University of Central Arkansas Strategic Planning Dr. David McFarland Penson Associates Inc. 2009 Penson Associates, Inc Establishing the Support Structure for Planning Penson Associates The strategic

More information

SECTION 509: Payment Card and Electronic Funds Transfer (EFT) Procedures

SECTION 509: Payment Card and Electronic Funds Transfer (EFT) Procedures Page 1 SECTION 509: Payment Card and Electronic Funds Transfer (EFT) Procedures SOURCE: NDSU President NDSU VP for Finance and Administration NDSU VP for Information Technology It is the University s responsibility

More information

Treasurer s Office Updates. Business Manager Meeting Thursday, December 11 th 2014

Treasurer s Office Updates. Business Manager Meeting Thursday, December 11 th 2014 Treasurer s Office Updates Business Manager Meeting Thursday, December 11 th 2014 Overview Cashier s Office Announcement Student Cashiering Treasurer s Office Updates Cashier s Service Announcement What

More information

UTAH VALLEY UNIVERSITY Policies and Procedures

UTAH VALLEY UNIVERSITY Policies and Procedures Page 2 of 7 POLICY TITLE Section Subsection Responsible Office PCI DSS Compliance Facilities, Operations, and Information Technology Information Technology Office of the Vice President of Administration

More information

PCI-PA-DSS. Solution Kit

PCI-PA-DSS. Solution Kit PCI-PA-DSS Solution Kit Table of Contents Introduction Why a PCI-PA-DSS Solution Kit? PCI Standards Defined PCI DSS PA-DSS PTS Move The Button Getting Started Game Board The Winning Strategy TouchNet U.Commerce

More information

INVITAE CORPORATION CORPORATE GOVERNANCE GUIDELINES

INVITAE CORPORATION CORPORATE GOVERNANCE GUIDELINES INVITAE CORPORATION CORPORATE GOVERNANCE GUIDELINES A. The Roles of the Board of Directors and Management 1. The Board of Directors The business of Invitae Corporation (the Company ) is conducted under

More information

June 19, 2013. Bobbi McCracken, Associate Vice Chancellor Financial Services. Subject: Internal Audit of PCI Compliance.

June 19, 2013. Bobbi McCracken, Associate Vice Chancellor Financial Services. Subject: Internal Audit of PCI Compliance. RIVERSIDE: AUDIT & ADVISORY SERVICES June 19, 2013 To: Bobbi McCracken, Associate Vice Chancellor Financial Services Subject: Internal Audit of PCI Compliance Ref: R2013-03 We have completed our audit

More information

Capital Project Planning Process

Capital Project Planning Process Capital Project Planning Process Capital Planning Overview The planning process overview presented in this document combines work being conducted by both Physical and Capital Planning and Physical Facilities

More information

Online Compliance Program for PCI

Online Compliance Program for PCI Appendix F Online Compliance Program for PCI Service Description for PCI Compliance Monitors 1. General Introduction... 3 2. Online Compliance Program... 4 2.1 Introduction... 4 2.2 Portal Access... 4

More information

For discussion only. HR_design_plan_presentation_powerpoint_20120914_AC_meeting.pptx

For discussion only. HR_design_plan_presentation_powerpoint_20120914_AC_meeting.pptx For discussion only HR_design_plan_presentation_powerpoint_20120914_AC_meeting.pptx 1 Vision for the HR Design Project For discussion only The HR Design project is a campus-wide effort to build, through

More information

Audit Committee self-assessment

Audit Committee self-assessment Audit Committee Institute Sponsored by KPMG Audit Committee self-assessment The results of the self assessment and any action plans should be reported to the board after discussion with the chairman of

More information

Roanoke City Public Schools Audit Services FY 2016-2017

Roanoke City Public Schools Audit Services FY 2016-2017 Roanoke City Public Schools Audit Services FY 2016-2017 1/21/16 Background: Per Ordinance 35580-91701, City Council requires that the Municipal Auditing Department conduct continuing financial and performance

More information

NEPTUNE MARINE SERVICES LTD ACN 105 665 843. Charter of the Risk Management Committee

NEPTUNE MARINE SERVICES LTD ACN 105 665 843. Charter of the Risk Management Committee NEPTUNE MARINE SERVICES LTD ACN 105 665 843 Charter of the Risk Management Committee 1. Introduction... 1 2. Objective... 1 3. Constitution of Committee... 1 4. Composition... 2 5. Chairperson... 2 6.

More information

STRATEGIC PLANNING PROCESS TIMELINE AND MILESTONES

STRATEGIC PLANNING PROCESS TIMELINE AND MILESTONES STRATEGIC PLANNING PROCESS TIMELINE AND MILESTONES MAY 10, 2013 In January 2012 the strategic planning Leadership Council was appointed by President David Chicoine and chaired by Provost Laurie Nichols.

More information

Cal Poly Information Security Program

Cal Poly Information Security Program Policy History Date October 5, 2012 October 5, 2010 October 19, 2004 July 8, 2004 May 11, 2004 January May 2004 December 8, 2003 Action Modified Separation or Change of Employment section to address data

More information

University Policy Accepting and Handling Payment Cards to Conduct University Business

University Policy Accepting and Handling Payment Cards to Conduct University Business BROWN UNIVERSITY University Policy Accepting and Handling Payment Cards to Conduct University Business Table of Contents Purpose... 2 Scope... 2 Authorization... 2 Establishing a new account... 2 Policy

More information

University of California Regents Policy 7702 Senior Management Group Performance Management Review Process

University of California Regents Policy 7702 Senior Management Group Performance Management Review Process Senior Management Group Performance Management Review Process Approved July 17, 2008 Amended September 16, 2010 and March 29, 2012 Responsible Officer: Vice President Human Resources Responsible Office:

More information

Information Technology Operational Audit

Information Technology Operational Audit REPORT NO. 2010-005 JULY 2009 DEPARTMENT OF FINANCIAL SERVICES AND SELECTED PARTICIPATING STATE AGENCIES PAYMENT CARD PROGRAMS Information Technology Operational Audit For the Period October 2008 Through

More information

How To Protect Your Credit Card Information From Being Stolen

How To Protect Your Credit Card Information From Being Stolen Visa Account Information Security Tool Kit Welcome to the Visa Account Information Security Program 2 Contents 1. Securing cardholder data is everyone s concern 4 2. Visa Account Information Security (AIS)

More information

How To Be Successful Online

How To Be Successful Online Online Instruction Task Force Final Report and Recommendations: Guidelines and Standards of Practice for Online Programs and Courses at Wayne State University July 2012 Contents I. Introduction... 3 II.

More information

Two Approaches to PCI-DSS Compliance

Two Approaches to PCI-DSS Compliance Disclaimer Copyright Michael Chapple and Jane Drews, 2006. This work is the intellectual property of the authors. Permission is granted for this material to be shared for non-commercial, educational purposes,

More information

Canada Media Fund/Fonds des médias du Canada

Canada Media Fund/Fonds des médias du Canada Canada Media Fund/Fonds des médias du Canada Statement of Corporate Governance Principles I. Introduction The Corporation s mandate is to champion the creation of successful, innovative Canadian content

More information

CONFIGURATION COMMITTEE. Terms of Reference

CONFIGURATION COMMITTEE. Terms of Reference SWBTB (8/13) 166 (g) CONFIGURATION COMMITTEE Terms of Reference 1. CONSTITUTION 1.1 The Board hereby resolves to establish a Committee of the Board to be known as the Configuration Committee (The Committee).

More information

Audit Committee Charter

Audit Committee Charter Audit Committee Charter Role The Audit Committee of the Board of Directors assists the Board of Directors in fulfilling its responsibility for oversight of the quality and integrity of the accounting,

More information

SENSITIVE DATA SECURITY AND PROTECTION CALIFORNIA STATE UNIVERSITY, LOS ANGELES. Audit Report 11-52 January 3, 2012

SENSITIVE DATA SECURITY AND PROTECTION CALIFORNIA STATE UNIVERSITY, LOS ANGELES. Audit Report 11-52 January 3, 2012 SENSITIVE DATA SECURITY AND PROTECTION CALIFORNIA STATE UNIVERSITY, LOS ANGELES Audit Report 11-52 January 3, 2012 Henry Mendoza, Chair Melinda Guzman, Vice Chair Margaret Fortune Steven M. Glazer William

More information

PCI Compliance: How to ensure customer cardholder data is handled with care

PCI Compliance: How to ensure customer cardholder data is handled with care PCI Compliance: How to ensure customer cardholder data is handled with care Choosing a safe payment process for your business Contents Contents 2 Executive Summary 3 PCI compliance and accreditation 4

More information

ACCEPTING PAYMENT CARDS FOR CONDUCTING UNIVERSITY BUSINESS:

ACCEPTING PAYMENT CARDS FOR CONDUCTING UNIVERSITY BUSINESS: Boston College Policy ACCEPTING PAYMENT CARDS FOR CONDUCTING UNIVERSITY BUSINESS: PURPOSE OF POLICY: The purpose of this policy is to establish procedures for accepting payment cards at Boston College

More information

How To Protect Your Business From A Hacker Attack

How To Protect Your Business From A Hacker Attack Payment Card Industry Data Security Standards The payment card industry data security standard PCI DSS Visa and MasterCard have developed the Payment Card Industry Data Security Standard or PCI DSS as

More information

Project Charter Updated

Project Charter Updated Enterprise IT Service Management Pilot Proof of Concept Project Charter Updated Prepared By: M. Riley & J. Foster Date of Publication: March 13, 2006 Date Last Revised: April 25, 2007 PMO CH1, 8/01 Document

More information

IT04 UO ACH Security Policy

IT04 UO ACH Security Policy IT04 UO ACH Security Policy Effective 1 July 2009 Last Revised Who Should Read This Policy Employees who have access to and, therefore, responsibility for safeguarding customer bank account and Automated

More information

Frequently Asked Questions

Frequently Asked Questions Contents CISP Program Overview... 2 1. To whom does CISP apply?...2 2. What does VISA define as "cardholder data"?...2 3. What if a merchant or service provider does not store Visa cardholder data?...2

More information

GUIDELINES FOR ACADEMIC PROGRAM REVIEW For self-studies due to the Office of the Provost on October 1, 2016 RESEARCH AND SERVICE CENTERS

GUIDELINES FOR ACADEMIC PROGRAM REVIEW For self-studies due to the Office of the Provost on October 1, 2016 RESEARCH AND SERVICE CENTERS GUIDELINES FOR ACADEMIC PROGRAM REVIEW For self-studies due to the Office of the Provost on October 1, 2016 RESEARCH AND SERVICE CENTERS OVERVIEW OF PROGRAM REVIEW Primary responsibility for maintaining

More information

Harvard University Payment Card Industry (PCI) Compliance Business Process Documentation

Harvard University Payment Card Industry (PCI) Compliance Business Process Documentation Harvard University Payment Card Industry (PCI) Compliance Business Process Documentation Business Process: Documented By: PCI Data Security Breach Stephanie Breen Creation Date: 1/19/06 Updated 11/5/13

More information

PCI DSS 3.0 Overview. OSU Business Affairs Business Affairs PIT Crew - Project, Improvement, & Technology Robin Whitlock

PCI DSS 3.0 Overview. OSU Business Affairs Business Affairs PIT Crew - Project, Improvement, & Technology Robin Whitlock PCI DSS 3.0 Overview OSU Business Affairs Business Affairs PIT Crew - Project, Improvement, & Technology Robin Whitlock 01/16/2015 Purpose of Today s Presentation To provide an overview of PCI 3.0 based

More information

Office of the President University Policy

Office of the President University Policy Office of the President University Policy SUBJECT: UNIVERSITY ENVIRONMENTAL HEALTH AND SAFETY Effective Date: 7-3-12 Policy Number: 4.1.2 Supersedes: Page Of Presidential 1 6 Memorandum #85 Responsible

More information

Cal Poly PCI DSS Compliance Training and Information. Information Security http://security.calpoly.edu 1

Cal Poly PCI DSS Compliance Training and Information. Information Security http://security.calpoly.edu 1 Cal Poly PCI DSS Compliance Training and Information Information Security http://security.calpoly.edu 1 Training Objectives Understanding PCI DSS What is it? How to comply with requirements Appropriate

More information

Title: Data Security Policy Code: 1-100-200 Date: 11-6-08rev Approved: WPL INTRODUCTION

Title: Data Security Policy Code: 1-100-200 Date: 11-6-08rev Approved: WPL INTRODUCTION Title: Data Security Policy Code: 1-100-200 Date: 11-6-08rev Approved: WPL INTRODUCTION The purpose of this policy is to outline essential roles and responsibilities within the University community for

More information

CREDIT CARD SECURITY POLICY PCI DSS 2.0

CREDIT CARD SECURITY POLICY PCI DSS 2.0 Responsible University Official: University Compliance Officer Responsible Office: Business Office Reviewed Date: 10/29/2012 CREDIT CARD SECURITY POLICY PCI DSS 2.0 Introduction and Scope Introduction

More information

IT DISASTER RECOVERY SAN FRANCISCO STATE UNIVERSITY. Audit Report 11-32 August 25, 2011

IT DISASTER RECOVERY SAN FRANCISCO STATE UNIVERSITY. Audit Report 11-32 August 25, 2011 IT DISASTER RECOVERY SAN FRANCISCO STATE UNIVERSITY Audit Report 11-32 August 25, 2011 Members, Committee on Audit Henry Mendoza, Chair Melinda Guzman, Vice Chair Margaret Fortune Steven M. Glazer William

More information

Research Administration at The University of Chicago

Research Administration at The University of Chicago Research Administration at The University of Chicago Mary Ellen Sheridan, Ph.D. Associate Vice President for Research University Research Administration University of Chicago Outline of JST Seminar Facts

More information

BROCK UNIVERSITY FINANCIAL PLANNING AND INVESTMENT COMMITTEE CHARTER

BROCK UNIVERSITY FINANCIAL PLANNING AND INVESTMENT COMMITTEE CHARTER Board of Trustees BROCK UNIVERSITY FINANCIAL PLANNING AND INVESTMENT COMMITTEE CHARTER The Board of Trustees (the Board ) has established a committee of the Board known as the Financial Planning and Investment

More information

Tackling Campus-Wide e-commerce

Tackling Campus-Wide e-commerce SUNGARD SUMMIT 2007 sungardsummit.com 1 Tackling Campus-Wide e-commerce Presented by: Troy Boroughs University of Richmond March 22, 2007 A Community of Learning Introduction For years, the University

More information

Validation of PCI Compliance Requirements NC Office of the State Controller June 23, 2015

Validation of PCI Compliance Requirements NC Office of the State Controller June 23, 2015 Validation of PCI Compliance Requirements NC Office of the State Controller June 23, 2015 Purpose The purpose of this document is to provide instructions to entities that subscribe to merchant cards processing

More information

Approved by President Mohammed Qayoumi. Reviews: IT Management Advisory Committee

Approved by President Mohammed Qayoumi. Reviews: IT Management Advisory Committee Policy History Date Action Approved by President Mohammed Qayoumi May 27, 2013 April 9, 2013 Reviews: IT Management Advisory Committee Draft Policy Released Table of Contents Introduction and Purpose...

More information

South East Water Corporation Finance Audit and Risk Management Committee Charter. October 2012

South East Water Corporation Finance Audit and Risk Management Committee Charter. October 2012 South East Water Corporation Finance Audit and Risk Management Committee Charter October 2012 Version: 1.0 Page 1 of 6 DOCUMENT NUMBER BS 2359 1. Purpose The South East Water Corporation Board's Finance

More information

IT DISASTER RECOVERY CALIFORNIA STATE UNIVERSITY, CHANNEL ISLANDS. Audit Report 11-30 August 12, 2011

IT DISASTER RECOVERY CALIFORNIA STATE UNIVERSITY, CHANNEL ISLANDS. Audit Report 11-30 August 12, 2011 IT DISASTER RECOVERY CALIFORNIA STATE UNIVERSITY, CHANNEL ISLANDS Audit Report 11-30 August 12, 2011 Members, Committee on Audit Henry Mendoza, Chair Melinda Guzman, Vice Chair Margaret Fortune Steven

More information

CITY OF SAN ANTONIO OFFICE OF THE CITY AUDITOR. Audit of Payment Card Industry Data Security Standards (PCI DSS) Security Governance

CITY OF SAN ANTONIO OFFICE OF THE CITY AUDITOR. Audit of Payment Card Industry Data Security Standards (PCI DSS) Security Governance CITY OF SAN ANTONIO OFFICE OF THE CITY AUDITOR Audit of Payment Card Industry Data Security Standards (PCI DSS) Security Governance Project No. AU13-012 September 16, 2013 Kevin W. Barthold, CPA, CIA,

More information

CSUSB Web Application Security Standard CSUSB, Information Security & Emerging Technologies Office

CSUSB Web Application Security Standard CSUSB, Information Security & Emerging Technologies Office CSUSB, Information Security & Emerging Technologies Office Last Revised: 03/17/2015 Draft REVISION CONTROL Document Title: Author: File Reference: CSUSB Web Application Security Standard Javier Torner

More information

CHARTER OF SUCCESSION PLANNING COMMITTEE

CHARTER OF SUCCESSION PLANNING COMMITTEE TABLE OF CONTENTS 1.0 MANDATE... 1 2.0 OBJECTIVE... 1 3.0 CO-ORDINATION WITH OTHER COMMITTEES... 1 4.0 OPERATING PRINCIPLES... 2 5.0 PRINCIPAL DUTIES AND RESPONSIBILITIES... 5 Approved by the Board of

More information

FINANCIAL SERVICES INFORMATION

FINANCIAL SERVICES INFORMATION FINANCIAL SERVICES INFORMATION FINANCIAL POLICY The generosity of individual donors and churches helps students receive quality, professional training at a cost less than that charged by many institutions.

More information

Governance For Compliance The Convergence of Central and Distributed IT Compliance Presented to VASCAN Conference 2009

Governance For Compliance The Convergence of Central and Distributed IT Compliance Presented to VASCAN Conference 2009 Governance For Compliance The Convergence of Central and Distributed IT Compliance Presented to VASCAN Conference 2009 JASON C. RICHARDS CHIEF INFORMATION SECURITY OFFICER VIRGINIA COMMUNITY COLLEGE SYSTEM

More information

FIRST COAST HEALTH ALLIANCE, LLC CHARTER AUDIT, FINANCE, AND NETWORK CONTRACTS COMMITTEE

FIRST COAST HEALTH ALLIANCE, LLC CHARTER AUDIT, FINANCE, AND NETWORK CONTRACTS COMMITTEE AUDIT, FINANCE, AND NETWORK CONTRACTS COMMITTEE 1. Establishment and Purpose. The Audit, Finance, and Networks Contracts Committee is established by the Board for the purpose of overseeing the integrity

More information

Compliance. TODAY June 2012. Meet Lanny A. Breuer. Assistant Attorney General, Criminal Division, U.S. Department of Justice.

Compliance. TODAY June 2012. Meet Lanny A. Breuer. Assistant Attorney General, Criminal Division, U.S. Department of Justice. Compliance TODAY June 2012 a publication of the health care compliance association www.hcca-info.org Meet Lanny A. Breuer Assistant Attorney General, Criminal Division, U.S. Department of Justice See page

More information

PCI Compliance. Top 10 Questions & Answers

PCI Compliance. Top 10 Questions & Answers PCI Compliance Top 10 Questions & Answers 1. What is PCI Compliance and PCI DSS? 2. Who needs to follow the PCI Data Security Standard? 3. What happens if I don t comply? 4. What are the basic requirements

More information

Merchant guide to PCI DSS

Merchant guide to PCI DSS Merchant guide to PCI DSS Contents What is PCI DSS and why was it introduced?... 3 Who needs to become PCI DSS compliant?... 3 BOIPA Simple PCI DSS - 3 step approach to helping businesses... 3 What does

More information

AUDIT COMMITTEE CHARTER

AUDIT COMMITTEE CHARTER AUDIT COMMITTEE CHARTER Purpose The Audit Committee ( Committee ) shall assist the Board of Directors (the Board ) in the oversight of (1) the integrity of the financial statements of the Company, (2)

More information

Graduate Faculty Committee Doc. No. 1184 Approved December 20, 2010

Graduate Faculty Committee Doc. No. 1184 Approved December 20, 2010 Graduate Faculty Committee Doc. No. 1184 Approved December 20, 2010 RECOMMENDATION OF THE SUBCOMMITTEE ON GRADUATE COURSE AND CURRICULUM AND THE FACULTY OF THE SCHOOL OF INFORMATION STUDIES TO ADD A CONCENTRATION

More information

UTech Services Compliance, Auditing, Risk, and Security (CARS) Team Charter

UTech Services Compliance, Auditing, Risk, and Security (CARS) Team Charter Pennsylvania State System of Higher Education California University of Pennsylvania UTech Services Compliance, Auditing, Risk, and Security (CARS) Team Charter Version [1.0] 1/29/2013 Revision History

More information

2014 Guide to IT Governance

2014 Guide to IT Governance 2014 Guide to IT Governance What is IT Governance? IT governance provides the conceptual framework, structures, processes, resources and information aligned to university strategies and objectives, enabling

More information

Research Administration at the University of Maryland

Research Administration at the University of Maryland Research Administration at the University of Maryland Anne S. Geronimo, M.S. Director, Research Development Division of Research University of Maryland June 2007 Tokyo, Japan University of Maryland Profile

More information

Project Delays Prevent EPA from Implementing an Agency-wide Information Security Vulnerability Management Program

Project Delays Prevent EPA from Implementing an Agency-wide Information Security Vulnerability Management Program U.S. ENVIRONMENTAL PROTECTION AGENCY OFFICE OF INSPECTOR GENERAL Audit Report Catalyst for Improving the Environment Project Delays Prevent EPA from Implementing an Agency-wide Information Security Vulnerability

More information

Brown Smith Wallace, LLC

Brown Smith Wallace, LLC Brown Smith Wallace, LLC Successful Software Selection Whitepaper Series How to Adhere to Payment Card Industry Data Security Standards By Ron Schmittling, CPA/CITP, QSA, CISA, CIA To learn more about

More information

Why should the CSU have a records/information retention and disposition policy?

Why should the CSU have a records/information retention and disposition policy? RECORDS MANAGEMENT SERVICES Frequently Asked Questions (FAQs) Retention Policy Why should the CSU have a records/information retention and disposition policy? A records/information retention and disposition

More information

DTCC RISK COMMITTEE CHARTER

DTCC RISK COMMITTEE CHARTER DTCC RISK COMMITTEE CHARTER Purpose The ability to identify, manage and mitigate risk is fundamental to the services that The Depository Trust & Clearing Corporation ( DTCC ) provides to its members and

More information

Significant accomplishments of Audit Operations and RACP are described below.

Significant accomplishments of Audit Operations and RACP are described below. The MIT Audit Division delivers audit services through a risk-based program of audit coverage, including process audits, targeted reviews, and advisory services. These efforts, in coordination with the

More information

fghjklzxcvbnmqwertyuiopasdfghj

fghjklzxcvbnmqwertyuiopasdfghj qwertyuiopasdfghjklzxcvbnmqwe fghjklzxcvbnmqwertyuiopasdfghj qwertyuiopasdfghjklzxcvbnmqwe fghjklzxcvbnmqwertyuiopasdfghj qwertyuiopasdfghjklzxcvbnmqwe Development of an Accreditation Program fghjklzxcvbnmqwertyuiopasdfghj

More information

Eclipx Group Limited Risk Management Policy

Eclipx Group Limited Risk Management Policy Eclipx Group Limited Risk Management Policy Date approved: 26 March 2015 Table of Contents 1. Background... 3 1.1 Overview... 3 1.2 Purpose... 3 1.3 Board responsibility... 3 2. Key principles and concepts...

More information

ENROLLMENT MANAGEMENT PLAN

ENROLLMENT MANAGEMENT PLAN ENROLLMENT MANAGEMENT PLAN September, 2009 Vision A premier learning community recognized for supporting student success and enriching society. Mission Cypress College enriches students lives by providing

More information

Chair Wurtz calls the meeting to order at 3:18 P.M.

Chair Wurtz calls the meeting to order at 3:18 P.M. SUMMARY OF FACULTY SENATE MEETING 8/25/08 CALL TO ORDER Chair Wurtz calls the meeting to order at 3:18 P.M. APPROVAL OF THE MINUTES Motion to approve the minutes of the 4/28/08 meeting by Senator Bruess;

More information

Corporate Governance Guidelines of Trinseo S.A.

Corporate Governance Guidelines of Trinseo S.A. Corporate Governance Guidelines of Trinseo S.A. SELECTION AND COMPOSITION OF BOARD OF DIRECTORS Selection of New Directors The board of directors should be responsible for selecting its own members for

More information

RISK AND COMPLIANCE COMMITTEE CHARTER

RISK AND COMPLIANCE COMMITTEE CHARTER 1. GENERAL SCOPE AND AUTHORITY 1.1 Introduction This charter governs the operations of the Risk & Compliance Committee of Redflex Holdings Limited (RHL or Company). 1.2 Purpose The Risk & Compliance Committee

More information

Accepting Payment Cards and ecommerce Payments

Accepting Payment Cards and ecommerce Payments Policy V. 4.1.1 Responsible Official: Vice President for Finance and Treasurer Effective Date: September 29, 2010 Accepting Payment Cards and ecommerce Payments Policy Statement The University of Vermont

More information

HEALTH, SAFETY & ENVIRONMENT AND BUSINESS RISK COMMITTEE CHARTER

HEALTH, SAFETY & ENVIRONMENT AND BUSINESS RISK COMMITTEE CHARTER HEALTH, SAFETY & ENVIRONMENT AND BUSINESS RISK COMMITTEE CHARTER DATE OF ISSUE: VERSION NO.: 1 PROCEDURES: N/A North American Energy Partners Inc. Health, Safety & Environment and Business Risk Committee

More information

J. W. Mays, Inc. Audit Committee Charter PURPOSE

J. W. Mays, Inc. Audit Committee Charter PURPOSE J. W. Mays, Inc. Audit Committee Charter PURPOSE The Audit Committee is appointed by the Board to assist the Board in monitoring (1) the integrity of the financial statements of the Company, (2) the independent

More information

http://www4.uwm.edu/bfs/depts/acct/creditcardacceptance/credit-card-acceptance.cfm

http://www4.uwm.edu/bfs/depts/acct/creditcardacceptance/credit-card-acceptance.cfm Section: Accounting Revised Date: 05/31/2011 Procedure: 2.2.23 Credit Card Acceptance Home Page http://www4.uwm.edu/bfs/depts/acct/creditcardacceptance/credit-card-acceptance.cfm Operating Principles:

More information

How do I accept my offer of admission to Purdue University?

How do I accept my offer of admission to Purdue University? How do I accept my offer of admission to Purdue University? 1. Use your Purdue Career Account username and password to login to the MyPurdue portal, www.mypurdue.purdue.edu. (If you have not activated

More information

PCI Compliance Top 10 Questions and Answers

PCI Compliance Top 10 Questions and Answers Where every interaction matters. PCI Compliance Top 10 Questions and Answers White Paper October 2013 By: Peer 1 Hosting Product Team www.peer1.com Contents What is PCI Compliance and PCI DSS? 3 Who needs

More information

Spotlight on U.S. Bank s IBOS Alliance. E-Payment Service Meets Standard for Protecting Payment Card Data

Spotlight on U.S. Bank s IBOS Alliance. E-Payment Service Meets Standard for Protecting Payment Card Data Spotlight on U.S. Bank s IBOS Alliance E-Payment Service Meets Standard for Protecting Payment Card Data International ACH Addresses Growing Need for Global Payment Initiation Spotlight on U.S. Bank s

More information

Payment Card Industry (PCI) Vulnerability Management Standard

Payment Card Industry (PCI) Vulnerability Management Standard Issued Date: 26-March-2015 Payment Card Industry (PCI) Vulnerability Management Standard Purpose This standard provides guidance on vulnerability management and remediation of the Payment Card Industry

More information