Guide to Visa Inc. Agents

Size: px
Start display at page:

Download "Guide to Visa Inc. Agents"

Transcription

1 Guide to Visa Inc. Agents AGENT VisaNet Processor Third Party Agent PF DCC Client Acquiring VNP HRIPF ESO Client VNP acting as Service Provider ISO-Merchant ISO DCV ICPIA Third Party VNP ISO-Cardholder TPS ISO-ATM MS ISO-Prepaid CFS ISO-HR ACS Service Provider

2 Glossary Agent An entity that acts as a VisaNet Processor (VNP), Third Party Agent (TPA), or both. VisaNet Processor (VNP) An entity that is directly connected to VisaNet and provides authorization, clearing, or settlement services to merchants and/or clients. Full Name Client Acquiring VNP Client VNP acting as Service Provider Third Party VNP Definition Visa acquirers or client-owned VNPs that only process acquiring transactions for their merchants only and using BINs specifically licensed to them. (Registration not required.) Visa clients or client-owned entities that are connected directly to VisaNet who provide issuer and/or acquirer card processing services to other Visa clients, merchants that are not acquired by them and/or others. Entities (non-visa clients) that are connected directly to VisaNet and provide issuer and/or acquirer card processing services to Visa clients, merchants and/or other service providers Third Party Agent (TPA) An entity that is not defined as a VisaNet Processor that provides payment-related services, directly or indirectly, to a Visa client and/or stores, transmits, or processes cardholder data. A TPA must be registered by all Visa clients utilizing their services, directly or indirectly. A Third Party Agent is exempt from the registration requirements specified in Third Party Agent Registration Requirements and the associated fees if it only provides services on behalf of its affiliates (including parents and subsidiaries) and those affiliates are Members that own and control at least 25% of the Third Party Agent. (Visa International Operating Regulations October 2014)

3 Acronym Full Name Definition Entity that conducts merchant account or transaction processing solicitation, sales, customer service, and merchant training activities. Also acts on behalf of a client for merchant solicitation, sales, deployment or service of POS terminals or equipment. ISO- Merchant (ISO-M) ISO- Cardholder (ISO-C) ISO-ATM Independent Sales Organization Merchant Independent Sales Organization Cardholder Independent Sales Organization ATM (PIN Security) Entity does not have access to the merchant cardholder data (CHD) or the cardholder data environment (CDE). May also sell or resell gateway services (i.e. white label gateway) in conjunction with selling the merchant account and allow the merchant to implement a payment system solution without installing or configuring their own system. Entity will not sign merchant agreement and/or deposit transaction receipts and/or handle merchant s fund disbursement on behalf of the Visa client. Entity that conducts cardholder solicitation, card application processing services and/or customer service activities. Entity that conducts ATM solicitation to merchant locations and/or deploy and/or service qualified ATMs. A qualified ATM is an ATM owned by or sponsored by a valid Visa or Plus client. ISO-Prepaid (ISO PP) Independent Sales Organization Prepaid. Entity that solicits other entities (i.e. merchants, corporate clients, government entities, other businesses etc.) to sell, activate or load prepaid cards on behalf of an issuer. Prepaid card sales and/or activation is a primary function of their business. Prepaid program managers Contract with Issuer; design and run the program including customer service support.

4 ISO-High Risk (ISO- HR) Independent Sales Organization High Risk. Entity that provides merchant solicitation, sales, customer service, merchant transaction solicitation and/or customer training to "high brand risk merchants". PF Payment Facilitator Payment Facilitator is formerly known as Payment Service Provider. A Payment Facilitator is a third party agent that can 1) sign a merchant agreement on behalf of an acquirer, and 2) receive settlement funds from an acquirer on behalf of a sponsored merchant. - Contracts with an acquirer to provide Visa payment services to sponsored merchants - Solicit sponsored merchant for Visa acceptance - Contracts with sponsored merchants to enable Visa payment acceptance - Monitors compliance of sponsored merchant activity in accordance with Visa Rules - Receives settlement of transaction proceeds from the acquirer; and then provide settlement to the sponsored merchant - Must be located within the acquirer s jurisdiction. - Cannot be listed on the Terminated Merchant File (TMF), or similar files - Cannot act as a sponsor for another Payment Facilitator - Excluded merchant types (but may be signed under direct acquiring agreements): Internet pharmacies, Internet pharmacy referral sites, and outbound telemarketers Includes all commerce type aggregation, including face-to-face in addition to e-commerce merchant aggregation. Payment Facilitators may have access to cardholder data (CHD) or the cardholder data environment (CHE). HRIPF High-Risk Internet Payment Facilitator A High Risk Internet Payment Facilitator (HRIPF) is an entity that contracts with the acquirer to provide payment services to high risk merchants, high brand risk merchant, high risk sponsored merchants or high brand risk sponsored merchants and signs one or more merchants belonging to high brand risk merchant category codes, as defined in the Visa Rules.

5 TPS Third Party Servicer Entity that contracts with a Visa client and stores, processes, or transmits Visa account numbers From a Third Party Agent (entity not defined as a VisaNet Processor) perspective, agent must be registered as a TPS. Example of Visa account numbers: PAN, CVV. Scope of services includes- Payment processing: Transaction processing (authorization and clearing and settlement messages, batch transmissions and data capture), virtual card processing (*Not via VisaNet) Value added services: Chargeback/exception processing, secure password delivery, fraud control, fraud verification services, cardholder accounting, statement processing, remittance processing, data warehousing capture, customer service, risk reporting/service, loyalty programs, rewards programs, interactive voice recognition, skip tracing services. Datacenter hosting: Access to the customer s logical space used to store their payment processing system and may provider of additional services such helping their customer maintain the server, and provide power, fire suppression, cameras, biometric scans, physical security. Secure storage facilities: Secure back-up, storage or destruction of electronic and physical media for financial institutions, companies or service providers that have CHD assets but do not electronically store, process or transmit card data. Managed services: Provides services within a third party s CDE, where the managed service provider has access to any cardholder data. Managed services providers usually manage the compliance obligations on behalf of clients for specific requirements within the PCI DSS: application, system management, operations, network management and may perform day-today application, system management, operations with access to cardholder data. Monitoring services: For critical security alerts - Intrusion Detection Systems (IDS), anti-virus, change-detection, compliance monitoring, audit-log monitoring, etc. Network service provider: Cloud & Infrastructure services: network, server, and endpoint management & monitoring. Managed firewall/router provider: Firewall management, migration, monitoring. Statement printing Call center provider: Call centers accessing CHD Token service providers: Transform cardholder data with tokenization or encryption. Corporate T&E charge reporting: Billing, expense reporting, and loyalty/rewards for corporate card issuers Acquirer token service providers: Tokenization solution provider that has overall responsibility for the design and implementation of a specific tokenization solution, and (directly or indirectly through outsourcing) manages tokenization solutions for its customers and/or manages corresponding responsibilities. May manage tokens for merchants and acquirers. Includes Token as a Service (TaaS) providers and token requestor entities.

6 POS services: Deploys and or services POS terminals/atms. Service may include performing maintenance, installation, software or hardware upgrades, replacing POS terminals/atms and accessing the CDE and CHD (remote or physical) but no access to PIN data. Software as a Service (SaaS): Hosting provider that allows customers to use the provider s apps running on provider s cloud infrastructure (hosting of servers, storage, and network components). Platform as a Service (PaaS): Hosting provider where customer deploys consumer-created or acquired applications onto provider s cloud infrastructure (hosting of purchased applications). Infrastructure as a Service (IaaS): Hosting provider that allows the customer to deploy and control its own software on provider s cloud infrastructure (Infrastructure as a Service - cloud infrastructure hosting of proprietary applications. TPS-PIN Third Party Servicer PIN (PIN Security). Entity that contracts with a Visa client and stores, processes, or transmits Visa PIN transactions From a Third Party Agent (entity not defined as a VisaNet Processor) perspective, agent must be registered as a TPS-PIN. Example of Visa PIN transactions: PIN Data from ATM transactions, PIN@POS terminals. ESO Encryption Support Organization (PIN Security). Entity that performs cryptographic key management services to support clients' ATM programs or to deploy Point of Sale PIN Entry Devices (POS PEDs) or PIN pads. ATM and PIN Pad manufacturers that manage various cryptographic key management responsibilities for clients are also considered ESOs. Entities using vendor supplied Remote Key Distribution techniques must ensure that such vendors are registered with Visa as ESOs. An ESO maintains a business relationship with a client that includes: Loading or injecting encryption keys into ATMS, terminals or PIN Pads Loading software into a terminal or ATM which will accept Visa branded cards Merchant help desk support, including re-programming of terminal software

7 MS Merchant Servicer A merchant servicer is a type of third party agent that stores, processes or transmits Visa account numbers on behalf of a client's merchant with which they have a contract. Entity may be contracted by the merchant directly, not with the merchant s acquirer to provide specific merchant payment services that includes Payment Gateways and online shopping cart Payment processing: Transaction processing (authorization and clearing and settlement messages, batch transmissions and data capture), virtual card processing. Qualified Integrator & Reseller*: Sell, install, and/or service payment applications on behalf of software vendors or others. Integrator services may include: servicing the payment applications (for example, troubleshooting, delivering remote updates, and providing remote support). Technology Solution Integrators Provides SaaS (host the software in the cloud or installs applications directly on the server) for a merchant. The integrator's technology is configured to a gateway's system. POS Integrators - integrates POS devices/systems and may have remote access for ongoing support. Value added services: Chargeback/exception processing, secure password delivery, fraud control, fraud verification services, cardholder accounting, statement processing, remittance processing, data warehousing capture, customer service, risk reporting/service, loyalty programs, rewards programs, interactive voice recognition, skip tracing services. Datacenter hosting: Access to the customer s logical space used to store their payment processing system or provider of additional services such helping their customer maintain the server, and provide power, fire suppression, cameras, biometric scans, physical security. Secure storage facilities: Secure back-up, storage or destruction of electronic and physical media for financial institutions, companies or service providers that have CHD assets but do not electronically store, process or transmit card data. Managed services: Provides services within a third party s CDE, where the managed service provider has access to any cardholder data. Managed services providers usually manage the compliance obligations on behalf of clients for specific requirements within the PCI DSS: application, system management, operations, network management and may perform day-today application, system management, operations with access to cardholder data. Monitoring services: For critical security alerts - Intrusion Detection Systems (IDS), anti-virus, change-detection, compliance monitoring, audit-log monitoring, etc. Network service provider: Cloud & Infrastructure services: network, server, and endpoint management & monitoring. Managed firewall/router provider: Firewall management, migration, monitoring. Statement printing Call center provider: Call centers accessing CHD

8 Token service providers: Transform cardholder data with tokenization or encryption. Corporate T&E charge reporting: Billing, expense reporting, and loyalty/rewards for corporate card issuers Acquirer token service providers: Tokenization solution provider that has overall responsibility for the design and implementation of a specific tokenization solution, and (directly or indirectly through outsourcing) manages tokenization solutions for its customers and/or manages corresponding responsibilities. May manage tokens for merchants and acquirers. Includes Token as a Service (TaaS) providers and token requestor entities. POS services: Deploys and or services POS terminals/atms. Service may include performing maintenance, installation, software or hardware upgrades, and replacement for POS terminals/atms and has access to the CDE and CHD (remote or physical) but no access to PIN data. Software as a Service (SaaS): Hosting provider that allows customers to use the provider s apps running on provider s cloud infrastructure (hosting of servers, storage, and network components). Platform as a Service (PaaS): Hosting provider where customer deploys consumer-created or acquired applications onto provider s cloud infrastructure (hosting of purchased applications). Infrastructure as a Service (IaaS): Hosting provider that allows the customer to deploy and control its own software on provider s cloud infrastructure (Infrastructure as a Service - cloud infrastructure hosting of proprietary applications. *QIR can be recognized as a type of service provider on the Visa Global Registry of Service Providers if they self-identify through the Merchant Servicer Self-Identification Program. DCC Dynamic Currency Conversion Entity that contracts with a Visa client to provide currency conversion services to sponsored merchants at checkout. (i.e. conversion of transaction cost to local currency when making payment in a foreign currency) For more info: DCCcompliance@visa.com CFS Corporate Franchise Servicers Entity that provide, manage or control an environment/connectivity to franchisees that may or may not host or provide payment card payment services (payment applications, inventory management systems, etc.).

9 The CFS is a corporate entity or franchisor that provides, manages or controls a centralized or hosted network environment irrespective of whether Visa cardholder data is being stored, transmitted or processed through it. Although it may or may not host or provide card payment services, more importantly, the insecurity of the shared network can affect an independent location or franchisee and that of its own cardholder data environment if accessed by unauthorized parties. Typically, managed services are provided to the franchisees such as property management systems, inventory control systems, menu distribution systems, etc. CFSs are not directly connected to VisaNet. DCV Distribution Channel Vendor Entity that is responsible for packaging, storing and shipping of non-personalized Visa products (e.g. warehouses, wholesalers, logistics companies). ICPIA Instant Card Personalization Issuance Agent Instant Card Personalization and Issuance refers to the ability to instantly personalize Visa cards as the customer waits or to respond immediately to the request for an emergency replacement of a cardholder's lost or stolen card. Entity has a direct contractual relationship with the Visa client and performs instant card personalization and issuance for the issuer, generally a retailer or kiosk location. ACS Service Provider Access Control Server Service Provider Visa-approved entity operating the Enrollment Server and/or Access Control Server for providing 3-D Secure services (Verified by Visa) to Visa issuers.

10 General Information (FAQs) Direct Contract with Bank Solicitation CHD/Transaction Processing for Bank Direct Contract with Merchant CHD/Transaction Processing for Merchant Settlement To Merchant PCI DSS requirement (AOC for Level 1-SP) (SAQ-D for Level 2- SP) ISO- Merchant (ISO- M) Y Y Merchant Servicer (MS) - Y/N - Y Y - Y Third Party Servicer (TPS) Y - Y Y Payment Facilitator (PF) Y Y/N Y Y Y Y Y How do I register a Third Party Agent? Visa clients must use the Visa Membership Management (VMM) to register third party agents. VMM is an online tool that allows clients to register and maintain third party agents. To use VMM, clients must first be enrolled on Visa Online (VOL). To enroll for VOL go to Once VOL enrollment has been approved the client must request access to VMM. Search for Visa Membership Management on VOL and accesses the VMM link. If the client has never accessed VMM before they will be prompted to register as a new user of VMM. (Please select Officer ) Ensure due diligence has been completed. Understand the agent type prior to registration. Have all applicable documentation (PCI DSS, DBA filing) ready for upload in VMM as part of initial registration.

11 How do I register a VisaNet Processor/ACS Processor? Registration relating to VisaNet services and 3-D secure Verified by Visa (ACS issuing) is also via Visa Membership Management (VMM). Please reference the VMM guide for additional steps to register VisaNet Processor and ACS Processor. Is registration required for software providers? No. Point-of-Sale (POS) software providers that only sell the payment application and do not store, process or transmit Visa cardholder data are not required to register. The Payment Application Data Security Standard (PA-DSS) is available to ensure the secure development of these applications. Details on payment applications are available at Is registration required if a Visa client owns at least 25% of an agent? Third party agents are exempt from the registration requirements specified in Third Party Registration Requirements and the associated fees if it (1) only provides services on behalf of its affiliates (including parents and subsidiaries); and (2) those affiliates are clients that own and control at least 25% of the Third Party Agent. Is registration required for sub-isos? ISO registration is required for any entity that solicits on behalf of a Visa client. An ISO is any entity that solicits merchant or cardholder accounts, discuss pricing, fees or rates, processes merchant or cardholder accounts, discusses terms and agreements, manages and /or drafts contracts, submits contracts to the acquirer or issuer (their registering client bank). A registered ISO may use referral entities or sales representatives to solicit on their behalf; however, those entities may only solicit and market in the name of the registered ISO. Acquirers must not process applications from any entity that they have not registered as an ISO with Visa. Registration is not required for referral entities or sales representatives that solicit in the name of the registered ISO. Referral entities or sales representatives who market in their own name may only generate leads to registered ISOs and may not provide ISO services such as direct solicitation of merchant or cardholder accounts, discuss pricing, fees or rates, process merchant or cardholder accounts, discuss terms and agreements, manages / draft contracts, submit contracts to an acquirer or issuer. Are there new registration requirements for Payment Facilitators? Yes. The Payment Facilitator name that appears in conjunction with the sponsored merchant name on transaction receipts and billing statements, the BIN used, and the location of the Payment Facilitator must be included in the comments section of the VMM registration case. Note: Reference the Merchant Data Manual (MDM) for Merchant Name Description formatting requirements for Payment Facilitators.

12 What is the difference between a Payment Facilitator and other service providers that process Visa transactions? Payment Facilitators contract with an acquirer to provide any of the following services: Solicitation, onboarding, and sponsoring of merchants (directly sign merchant agreements for sponsored merchant with under $100k annual Visa volume) Aggregate transactions for sponsored merchants Store, process, or transmit Visa cardholder data Provide other payment related services including card acceptance, card processing, and settle funds directly with sponsored merchants. Other third party agents such as MS and TPS entities do not provide solicitation activities, sponsor merchants directly or settle directly; the acquirer settles with their merchant directly through their unique merchant IDs. What types of agents require PCI DSS compliance? Any agent that provides managed services and/or stores, processes or transmits Visa cardholder data must validate PCI DSS compliance at the time of registration or provide proof that the agent is the process of validating compliance with a reasonable target completion date. PCI DSS compliance validation with Visa is required every 12 months thereafter. The fine assessed to clients for using a non compliant starts at $10,000 USD per agent. Agent that performs one or more services reviewed in the PCI DSS assessment fall into one of the following agent types and requires PCI DSS compliance validation: Third Party Servicer (TPS), Merchant Servicer (MS), Corporate Franchise Servicer (CFS), Payment Facilitator (PF), High Brand Risk Internet Payment Facilitator (HBRIPF), Dynamic Currency Conversion (DCC). Are there different PCI DSS validation requirements for each Service Provider Level? Yes. Agents fall into two levels based on the volume of Visa transactions stored, processed or transmitted annually. There are different validation requirements for each level:

13 How often does Visa require PCI DSS compliance validation? Any agent that stores, processes or transmits Visa cardholder data must perform the PCI DSS compliance review every 12 months. If Visa does not receive the appropriate revalidation documents, the agent s listing on the Registry changes as follows: 1-60 days overdue, the service provider is highlighted in Yellow on the Registry days overdue, the service provider is highlighted in Red on the Registry After 91 days overdue, the service provider is removed from the Registry How do I update information? agents@visa.com to update agent information. Please attach the legal registration certificate of company name for change of legal name/address. Registered agents are required to notify their Visa client of any changes to information such as: Legal Name / Business Aliases (DBAs, Alternate Names) Legal Address Company Primary Contact Types of services offered Number of Visa transactions processed annually Compliance status (where applicable) Mergers and Acquisitions Financial solvency

Third Party Agent (TPA) Registration Program - TPA Types and Functional Descriptions

Third Party Agent (TPA) Registration Program - TPA Types and Functional Descriptions Third Party Agent (TPA) Registration Program - TPA Types and Functional Descriptions Independent Sales Organizations (ISO) ISO Merchant (ISO M) Conducts merchant account or transaction processing solicitation,

More information

Guide to Visa Inc. Agents

Guide to Visa Inc. Agents Guide to Visa Inc. Agents AGENT VisaNet Processor Third Party Agent Client Acquiring VNP PF HRIPSP DCC ESO Client VNP acting as Service Provider ISO DCV Third Party VNP ISO-Merchant ICPIA ISO-Cardholder

More information

Third Party Agent Registration Program Frequently Asked Questions

Third Party Agent Registration Program Frequently Asked Questions Third Party Agent Registration Program Frequently Asked Questions U.S., Canada and Latin America & Caribbean Regions General Information What is the Third Party Agent Registration Program? The Third Party

More information

THIRD PARTY AGENT REGISTRATION PROGRAM

THIRD PARTY AGENT REGISTRATION PROGRAM THIRD PARTY AGENT REGISTRATION PROGRAM Frequently Asked Questions For the U.S., Canada and Latin America & Caribbean Regions General Information Q. What is the Third Party Agent Registration Program? A.

More information

Agent Registration. Program Guide. (For use in Asia Pacific, Central Europe, Middle East, Africa)

Agent Registration. Program Guide. (For use in Asia Pacific, Central Europe, Middle East, Africa) Agent Registration Program Guide (For use in Asia Pacific, Central Europe, Middle East, Africa) Version 1 April 2014 Contents 1 INTRODUCTION... 3 1.1 ABOUT THIS GUIDE... 3 1.2 WHO NEEDS TO BE REGISTERED?...

More information

Agent Registration. Program Guidelines. (For use in Asia Pacific, Central Europe, Middle East and Africa)

Agent Registration. Program Guidelines. (For use in Asia Pacific, Central Europe, Middle East and Africa) (For use in Asia Pacific, Central Europe, Middle East and Africa) January 2012 Contents 1 INTRODUCTION... 3 1.1 BACKGROUND... 3 1.2 PURPOSE OF DOCUMENT... 4 1.3 WHO NEEDS TO BE REGISTERED?... 5 1.4 WHY

More information

Third Party Agent Registration and PCI DSS Compliance Validation Guide

Third Party Agent Registration and PCI DSS Compliance Validation Guide Visa Europe Third Party Agent Registration and PCI DSS Compliance Validation Guide May 2016 Version 1.3 Visa Europe 2015 Contents 1 Introduction... 4 1.1 Definitions of Agents... 4 2 Registration Process...

More information

Registry of Service Providers

Registry of Service Providers Registry of Service Providers Program Guide Contents 1 2 1.1 What is the Registry of Service Providers? 2 1.2 Who can register? 3 1.3 Why register with Visa? 3 1.4 Implications for Visa Clients 4 2 5 2.1

More information

Third Party Risk Management Basics. Webinar. 26 February 2015

Third Party Risk Management Basics. Webinar. 26 February 2015 Third Party Risk Management Basics Webinar 26 February 2015 Stan Hui Payment System Security Oscar Munoz Third Party Risk Roxanne Baumann Third Party Risk Disclaimer The information or recommendations

More information

PCI DSS FAQ. The twelve requirements of the PCI DSS are defined as follows:

PCI DSS FAQ. The twelve requirements of the PCI DSS are defined as follows: What is PCI DSS? PCI DSS is an acronym for Payment Card Industry Data Security Standards. PCI DSS is a global initiative intent on securing credit and banking transactions by merchants & service providers

More information

Merchant Service Group, LLC Compliance Q & A

Merchant Service Group, LLC Compliance Q & A GENERAL ISO INFORMATION 1. What name(s) can an ISO use when selling? * ISO can only solicit using their corporate or DBA name that has been registered and approved with the Associations. * All additional

More information

Registration and PCI DSS compliance validation

Registration and PCI DSS compliance validation Visa Europe A Guide for Third Party Agents Registration and PCI DSS compliance validation October 2015 Version 1.1 Visa Europe 2015 Contents 1 Introduction... 4 1.1 Definitions of Agents... 4 2 Registration

More information

PCI Compliance Overview

PCI Compliance Overview PCI Compliance Overview 1 PCI DSS Payment Card Industry Data Security Standard Standard that is applied to: Merchants Service Providers (Banks, Third party vendors, gateways) Systems (Hardware, software)

More information

GLOSSARY OF MOST COMMONLY USED TERMS IN THE MERCHANT SERVICES INDUSTRY

GLOSSARY OF MOST COMMONLY USED TERMS IN THE MERCHANT SERVICES INDUSTRY GLOSSARY OF MOST COMMONLY USED TERMS IN THE MERCHANT SERVICES INDUSTRY Acquiring Bank The bank or financial institution that accepts credit and/or debit card payments for products or services on behalf

More information

Credit Card Processing Overview

Credit Card Processing Overview CardControl 3.0 Credit Card Processing Overview Overview Credit card processing is a very complex and important system for anyone that sells goods. This guide will hopefully help educate and inform new

More information

Visa MasterCard Registration Procedures

Visa MasterCard Registration Procedures Effective May Visa Term Definition Registration Requirements Forms Initial Registration Annual Renewal An organization or individual, which is not a Member, whose *Enhanced /Service Provider bankcard-related

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.0 February 2014 Section 1: Assessment Information Instructions for Submission

More information

CardControl. Credit Card Processing 101. Overview. Contents

CardControl. Credit Card Processing 101. Overview. Contents CardControl Credit Card Processing 101 Overview Credit card processing is a very complex and important system for anyone that sells goods. This guide will hopefully help educate and inform new and old

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.0 February 2014 Section 1: Assessment Information Instructions for Submission

More information

TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No. 08-01 MERCHANT DEBIT AND CREDIT CARD RECEIPTS

TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No. 08-01 MERCHANT DEBIT AND CREDIT CARD RECEIPTS TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No. 08-01 MERCHANT DEBIT AND CREDIT CARD RECEIPTS 1. Introduction Debit and Credit Card Receipt Standards apply to the administration

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Self-Assessment Questionnaire D Service Providers For use with PCI DSS Version 3.1 Revision 1.1 July 2015 Section 1: Assessment

More information

Miami University. Payment Card Data Security Policy

Miami University. Payment Card Data Security Policy Miami University Payment Card Data Security Policy IT Policy IT Standard IT Guideline IT Procedure IT Informative Issued by: IT Services SCOPE: This policy covers all units within Miami University that

More information

Payment Cardholder Data Handling Procedures (required to accept any credit card payments)

Payment Cardholder Data Handling Procedures (required to accept any credit card payments) Payment Cardholder Data Handling Procedures (required to accept any credit card payments) Introduction: The Procedures that follow will allow the University to be in compliance with the Payment Card Industry

More information

PCI General Policy. Effective Date: August 2008. Approval: December 17, 2015. Maintenance of Policy: Office of Student Accounts REFERENCE DOCUMENTS:

PCI General Policy. Effective Date: August 2008. Approval: December 17, 2015. Maintenance of Policy: Office of Student Accounts REFERENCE DOCUMENTS: Effective Date: August 2008 Approval: December 17, 2015 PCI General Policy Maintenance of Policy: Office of Student Accounts PURPOSE: To protect against the exposure and possible theft of account and personal

More information

Are You Ready For PCI v 3.0. Speaker: Corbin DelCarlo Institution: McGladrey LLP Date: October 6, 2014

Are You Ready For PCI v 3.0. Speaker: Corbin DelCarlo Institution: McGladrey LLP Date: October 6, 2014 Are You Ready For PCI v 3.0 Speaker: Corbin DelCarlo Institution: McGladrey LLP Date: October 6, 2014 Today s Presenter Corbin Del Carlo QSA, PA QSA Director, National Leader PCI Services Practice 847.413.6319

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Standard Attestation of Compliance for Self-Assessment Questionnaire D Service Providers Version 3.1 April 2015 Section 1: Assessment Information Instructions for Submission

More information

mobile payment acceptance Solutions Visa security best practices version 3.0

mobile payment acceptance Solutions Visa security best practices version 3.0 mobile payment acceptance Visa security best practices version 3.0 Visa Security Best Practices for, Version 3.0 Since Visa s first release of this best practices document in 2011, we have seen a rapid

More information

What To Do if Compromised. Visa USA Fraud Investigations and Incident Management Procedures

What To Do if Compromised. Visa USA Fraud Investigations and Incident Management Procedures What To Do if Compromised Visa USA Fraud Investigations and Incident Management Procedures Table of Contents Introduction......................................................... 1 Security Breach Reporting............................................

More information

Visa Prepaid Issuer Risk Program Standards Guide

Visa Prepaid Issuer Risk Program Standards Guide Visa Prepaid Issuer Risk Program Standards Guide Visa Supplemental Requirements 24 April 2015 Visa Public Important Information on Confidentiality and Copyright 2007-2015 Visa. All Rights Reserved. Notice:

More information

Franchise Data Compromise Trends and Cardholder. December, 2010

Franchise Data Compromise Trends and Cardholder. December, 2010 Franchise Data Compromise Trends and Cardholder Security Best Practices December, 2010 Franchise Data Security Agenda Cardholder Data Compromise Overview Breach Commonalities Hacking Techniques Franchisee

More information

UW Platteville Credit Card Handling Policy

UW Platteville Credit Card Handling Policy UW Platteville Credit Card Handling Policy Issued: December 2011 Revision History: November 7, 2013; July 11, 2014; November 1, 2014; August 24, 2015 Overview: In order for UW Platteville to accept credit

More information

We believe First Data is well positioned to take advantage of all of these trends given the breadth of our solutions and our global operating

We believe First Data is well positioned to take advantage of all of these trends given the breadth of our solutions and our global operating Given recent payment data breaches, clients are increasingly demanding robust security and fraud solutions; and Financial institutions continue to outsource and leverage technology providers given their

More information

AIS Webinar. Payment Application Security. Hap Huynh Business Leader Visa Inc. 1 April 2009

AIS Webinar. Payment Application Security. Hap Huynh Business Leader Visa Inc. 1 April 2009 AIS Webinar Payment Application Security Hap Huynh Business Leader Visa Inc. 1 April 2009 1 Agenda Security Environment Payment Application Security Overview Questions and Comments Payment Application

More information

How Secure is Your Payment Card Data?

How Secure is Your Payment Card Data? How Secure is Your Payment Card Data? Complying with PCI DSS SLIDE 1 PRESENTERS Francis Tam, CPA, CISA, CISM, CITP, CRISC, PCI QSA Managing Director, IT Security Practice PCI Practice Leader Francis has

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire Instructions and Guidelines Version 3.2 May 2016 Document Changes Date Version Description October 1, 2008 1.2 October 28,

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.0 February 2014 Section 1: Assessment Information Instructions for Submission

More information

Merchant Account Glossary of Terms

Merchant Account Glossary of Terms Merchant Account Glossary of Terms From offshore merchant accounts to the truth behind free merchant accounts, get answers to some of the most common and frequently asked questions. If you cannot find

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.1 April 2015 Section 1: Assessment Information Instructions for Submission

More information

CREDIT CARD PROCESSING GLOSSARY OF TERMS

CREDIT CARD PROCESSING GLOSSARY OF TERMS CREDIT CARD PROCESSING GLOSSARY OF TERMS 3DES A highly secure encryption system that encrypts data 3 times, using 3 64-bit keys, for an overall encryption key length of 192 bits. Also called triple DES.

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.1 April 2015 Section 1: Assessment Information Instructions for Submission

More information

PayLeap Guide. One Stop

PayLeap Guide. One Stop PayLeap Guide One Stop PayLeap does it all. Take payments in person? Check. Payments over the phone or by mail? Check. Payments from mobile devices? Of course. Online payments? No problem. In addition

More information

Section 1: Assessment Information

Section 1: Assessment Information Section 1: Assessment Information Instructions for Submission This document must be completed as a declaration of the results of the service provider s self-assessment with the Payment Card Industry Data

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.0 February 2014 Section 1: Assessment Information Instructions for Submission

More information

115 th Annual Convention

115 th Annual Convention 115 th Annual Convention Date: Saturday, October 12, 2013 Time: 11:00 am 12:00 pm Location: The Walt Disney World Swan and Dolphin Resort, Southern Hemisphere Salon 4-5 Title: Activity Type: Speaker: Data

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.0 February 2014 Section 1: Assessment Information Instructions for Submission

More information

Qualified Integrators and Resellers (QIR) Implementation Statement

Qualified Integrators and Resellers (QIR) Implementation Statement Qualified Integrators and Resellers (QIR) Implementation Statement For each Qualified Installation performed, the QIR Employee must complete this document and confirm whether the validated payment application

More information

Credit Card Processing, Point of Sale, ecommerce

Credit Card Processing, Point of Sale, ecommerce Credit Card Processing, Point of Sale, ecommerce Compliance, Self Auditing, and More John Benson Kurt Willey HACKS REGULATIONS Greater Risk for Merchants Topics Compliance Changes Scans Self Audits

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire C and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire C and Attestation of Compliance Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire C and Attestation of Compliance Payment Application Connected to Internet, No Electronic Cardholder Data Storage Version

More information

University Policy Accepting and Handling Payment Cards to Conduct University Business

University Policy Accepting and Handling Payment Cards to Conduct University Business BROWN UNIVERSITY University Policy Accepting and Handling Payment Cards to Conduct University Business Table of Contents Purpose... 2 Scope... 2 Authorization... 2 Establishing a new account... 2 Policy

More information

PCI PA - DSS. Point BKX Implementation Guide. Version 2.01. Atos Xenta, Atos Xenteo and Atos Yomani using the Point BKX Payment Core

PCI PA - DSS. Point BKX Implementation Guide. Version 2.01. Atos Xenta, Atos Xenteo and Atos Yomani using the Point BKX Payment Core PCI PA - DSS Point BKX Implementation Guide Atos Xenta, Atos Xenteo and Atos Yomani using the Point BKX Payment Core Version 2.01 POINT TRANSACTION SYSTEMS AB Box 92031, 120 06 Stockholm, Tel. +46 8 566

More information

Payment Card Industry Data Security Standard C-VT Guide

Payment Card Industry Data Security Standard C-VT Guide Payment Card Industry Data Security Standard Self-Assessment Questionnaire C-VT Guide Prepared for: University of Tennessee Merchants 12 April 2013 Prepared by: University of Tennessee System Administration

More information

ACQUIRER OR ACQUIRING BANK A financial institution (often a bank) where a merchant has an account to process transactions and card payments

ACQUIRER OR ACQUIRING BANK A financial institution (often a bank) where a merchant has an account to process transactions and card payments A TO Z JARGON BUSTER A ACQUIRER OR ACQUIRING BANK A financial institution (often a bank) where a merchant has an account to process transactions and card payments ATM Automated Teller Machine. Unattended,

More information

Technical breakout session

Technical breakout session Technical breakout session Small leaks sink great ships Managing data security, fraud and privacy risks Tarlok Birdi, Deloitte Ron Borsholm, WTS May 27, 2009 Agenda 1. PCI overview: the technical intent

More information

University Policy Accepting Credit Cards to Conduct University Business

University Policy Accepting Credit Cards to Conduct University Business BROWN UNIVERSITY University Policy Accepting Credit Cards to Conduct University Business Purpose Brown University requires all departments that are involved with credit card handling to do so in compliance

More information

PCI Compliance Updates

PCI Compliance Updates PCI Compliance Updates E-Commerce / Cloud Security Adam Goslin, Chief Operations Officer AGoslin@HighBitSecurity.com Direct: 248.388.4328 PCI Guidance Google: PCI e-commerce guidance https://www.pcisecuritystandards.org/pdfs/pci_dss_v2_ecommerce_guidelines.pdf

More information

PCI PA - DSS. Point ipos Implementation Guide. Version 1.01. VeriFone Vx820 using the Point ipos Payment Core

PCI PA - DSS. Point ipos Implementation Guide. Version 1.01. VeriFone Vx820 using the Point ipos Payment Core PCI PA - DSS Point ipos Implementation Guide VeriFone Vx820 using the Point ipos Payment Core Version 1.01 POINT TRANSACTION SYSTEMS AB Box 92031, 120 06 Stockholm, Tel. +46 8 566 287 00 www.point.se Page

More information

Information Technology

Information Technology Credit Card Handling Security Standards Overview Information Technology This document is intended to provide guidance to merchants (colleges, departments, organizations or individuals) regarding the processing

More information

Certification Program Pre-Engagement Questionnaire

Certification Program Pre-Engagement Questionnaire Certification Program Pre-Engagement Questionnaire Page 1 of 8 2005 Visa Asia Pacific, VPSS Certification Program Pre-Engagement Questionnaire 1 Introduction A first step towards Visa Payment Security

More information

Frequently Asked Questions

Frequently Asked Questions I ccount Information System (IS) Program Frequently sked Questions Q What is IS? ccount Information Security, or IS, is a Risk Management program by Visa aimed to protect account and/or transaction information

More information

What To Do if Compromised. Visa USA Fraud Investigations and Incident Management Procedures

What To Do if Compromised. Visa USA Fraud Investigations and Incident Management Procedures What To Do if Compromised Visa USA Fraud Investigations and Incident Management Procedures Table of Contents Introduction......................................................... 1 Identifying and Detecting

More information

Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance

Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance A Non-Technical Guide Essential for Business Managers Office Managers Operations Managers Compliant? Bank Name

More information

Dartmouth College Merchant Credit Card Policy for Managers and Supervisors

Dartmouth College Merchant Credit Card Policy for Managers and Supervisors Dartmouth College Merchant Credit Card Policy for Managers and Supervisors Mission Statement Dartmouth College requires all departments that process, store or transmit credit card data remain in compliance

More information

Josiah Wilkinson Internal Security Assessor. Nationwide

Josiah Wilkinson Internal Security Assessor. Nationwide Josiah Wilkinson Internal Security Assessor Nationwide Payment Card Industry Overview PCI Governance/Enforcement Agenda PCI Data Security Standard Penalties for Non-Compliance Keys to Compliance Challenges

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.0 February 2014 Section 1: Assessment Information Instructions for Submission

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire C-VT and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire C-VT and Attestation of Compliance Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire C-VT and Attestation of Compliance Merchants with Web-Based Virtual Payment Terminals No Electronic Cardholder Data Storage

More information

Cyber - Security and Investigations. Ingrid Beierly August 18, 2008

Cyber - Security and Investigations. Ingrid Beierly August 18, 2008 Cyber - Security and Investigations Ingrid Beierly August 18, 2008 Agenda Visa Cyber - Security and Investigations Today s Targets Recent Attack Patterns Hacking Statistics (removed) Top Merchant Vulnerabilities

More information

CREDIT CARD MERCHANT POLICY. All campuses served by Louisiana State University (LSU) Office of Accounting Services

CREDIT CARD MERCHANT POLICY. All campuses served by Louisiana State University (LSU) Office of Accounting Services Louisiana State University Finance and Administrative Services Operating Procedure FASOP: AS-22 CREDIT CARD MERCHANT POLICY Scope: All campuses served by Louisiana State University (LSU) Office of Accounting

More information

This policy applies to all GPC units that process, transmit, or handle cardholder information in a physical or electronic format.

This policy applies to all GPC units that process, transmit, or handle cardholder information in a physical or electronic format. Policy Number: 339 Policy Title: Credit Card Processing Policy, Procedure, & Standards Review Date: 07-23-15 Approval Date: 07-27-15 POLICY: All individuals involved in handling credit and debit card transactions

More information

An access number, dialed by a modem, that lets a computer communicate with an Internet Service Provider (ISP) or some other service provider.

An access number, dialed by a modem, that lets a computer communicate with an Internet Service Provider (ISP) or some other service provider. TERM DEFINITION Access Number Account Number Acquirer Acquiring Bank Acquiring Processor Address Verification Service (AVS) Association Authorization Authorization Center Authorization Fee Automated Clearing

More information

Top Five Data Security Trends Impacting Franchise Operators. Payment System Risk September 29, 2009

Top Five Data Security Trends Impacting Franchise Operators. Payment System Risk September 29, 2009 Top Five Data Security Trends Impacting Franchise Operators Payment System Risk September 29, 2009 Top Five Data Security Trends Agenda Data Security Environment Compromise Overview and Attack Methods

More information

Merchant Card Processing Best Practices

Merchant Card Processing Best Practices Merchant Card Processing Best Practices Background: The major credit card companies (VISA, MasterCard, Discover, and American Express) have published a uniform set of data security standards that ALL merchants

More information

To ensure independence, PSC does not represent, resell or receive commissions from any third party hardware, software or solutions vendors.

To ensure independence, PSC does not represent, resell or receive commissions from any third party hardware, software or solutions vendors. About PSC With offices in the USA, Canada, UK and Australia, PSC is a leading PCI, PA DSS, and P2PE assessor, PCI Forensics Company and Approved Scanning Vendor. PSC is one of an elite few companies qualified

More information

How To Ensure Account Information Security

How To Ensure Account Information Security Global PCI DSS Framework Emöke Bitter Business Leader, Risk Management 26 February 2009 Agenda Introduction Merchants Service Providers Registry of Service Providers Payment Applications Resources Information

More information

CREDIT CARD MERCHANT PROCEDURES MANUAL. Effective Date: 5/25/2011

CREDIT CARD MERCHANT PROCEDURES MANUAL. Effective Date: 5/25/2011 CREDIT CARD MERCHANT PROCEDURES MANUAL Effective Date: 5/25/2011 Updated: May 25, 2011 TABLE OF CONTENTS Introduction... 1 Third-Party Vendors... 1 Merchant Account Set-up... 2 Personnel Requirements...

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire Instructions and Guidelines Version 1.1 February 2008 Table of Contents About this Document... 1 PCI Data Security Standard

More information

Need to be PCI DSS compliant and reduce the risk of fraud?

Need to be PCI DSS compliant and reduce the risk of fraud? Need to be PCI DSS compliant and reduce the risk of fraud? NCR Security lessens your PCI compliance burden and protects the integrity of your network An NCR White Paper Experience a new world of interaction

More information

CREDIT CARD MERCHANT PROCEDURES. Revised 01/21/2014 Prepared by: NIU Merchant Services

CREDIT CARD MERCHANT PROCEDURES. Revised 01/21/2014 Prepared by: NIU Merchant Services CREDIT CARD MERCHANT PROCEDURES Revised 01/21/2014 Prepared by: NIU Merchant Services CREDIT CARD MERCHANT PROCEDURES Contents Role of NIU Merchant Services 2 Security. 3 Method of Payment 3 Departmental

More information

Important Info for Youth Sports Associations

Important Info for Youth Sports Associations Important Info for Youth Sports Associations What the Heck is PCI DSS and Why Should I Care? Joe Posey Terrapin Financial Services Your Club is an ecommerce Business You accept online registration over

More information

University of Dayton Credit / Debit Card Acceptance Policy September 1, 2009

University of Dayton Credit / Debit Card Acceptance Policy September 1, 2009 University of Dayton Credit / Debit Card Acceptance Policy September 1, 2009 Effective Date of this Policy: August 1, 2008 Last Revision: September 1, 2009 Contact for More Information: UDit Internal Auditor

More information

A Compliance Overview for the Payment Card Industry (PCI)

A Compliance Overview for the Payment Card Industry (PCI) A Compliance Overview for the Payment Card Industry (PCI) Many organizations are aware of the Payment Card Industry (PCI) and PCI compliance but are unsure if they are doing everything necessary. This

More information

CREDIT CARD PROCESSING POLICY AND PROCEDURES

CREDIT CARD PROCESSING POLICY AND PROCEDURES CREDIT CARD PROCESSING POLICY AND PROCEDURES Note: For purposes of this document, debit cards are treated the same as credit cards. Any reference to credit cards includes credit and debit card transactions.

More information

Project Title slide Project: PCI. Are You At Risk?

Project Title slide Project: PCI. Are You At Risk? Blank slide Project Title slide Project: PCI Are You At Risk? Agenda Are You At Risk? Video What is the PCI SSC? Agenda What are the requirements of the PCI DSS? What Steps Can You Take? Available Services

More information

V ISA SECURITY ALERT 13 November 2015

V ISA SECURITY ALERT 13 November 2015 V ISA SECURITY ALERT 13 November 2015 U P DATE - CYBERCRIMINALS TARGE TING POINT OF SALE INTEGRATORS Distribution: Value-Added POS Resellers, Merchant Service Providers, Point of Sale Providers, Acquirers,

More information

HOW SECURE IS YOUR PAYMENT CARD DATA? COMPLYING WITH PCI DSS

HOW SECURE IS YOUR PAYMENT CARD DATA? COMPLYING WITH PCI DSS HOW SECURE IS YOUR PAYMENT CARD DATA? COMPLYING WITH PCI DSS August 23, 2011 MOSS ADAMS LLP 1 TODAY S PRESENTERS Presenters Francis Tam, CPA, CISA, CISM, CITP, CRISC, PCI QSA Managing Director, IT Security

More information

Visa global Compromised Account

Visa global Compromised Account Visa global Compromised Account RECOVERY PROGRAM WHAT EVERY MERCHANT SHOULD KNOW ABOUT GCAR WHAT EVERY MERCHANT SHOULD KNOW ABOUT GCAR WHAT The Visa Global Compromised Account Recovery (GCAR) program offers

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.0 February 2014 Section 1: Assessment Information Instructions for Submission

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance Merchants with Only Imprint Machines or Only Standalone, Dial-out Terminals Electronic Cardholder

More information

Steps for staying PCI DSS compliant Visa Account Information Security Guide October 2009

Steps for staying PCI DSS compliant Visa Account Information Security Guide October 2009 Steps for staying PCI DSS compliant Visa Account Information Security Guide October 2009 The guide describes how you can make sure your business does not store sensitive cardholder data Contents 1 Contents

More information

Payments Industry Glossary

Payments Industry Glossary Payments Industry Glossary 2012 First Data Corporation. All trademarks, service marks and trade names referenced in this material are the property of their respective owners. A ACH: Automated Clearing

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance Card-not-present Merchants, All Cardholder Data Functions Fully Outsourced Version 3.0 February

More information

PCI DSS Compliance Services January 2016

PCI DSS Compliance Services January 2016 PCI DSS Compliance Services January 2016 20160104-Galitt-PCI DSS Compliance Services.pptx Agenda 1. Introduction 2. Overview of the PCI DSS standard 3. PCI DSS compliance approach Copyright Galitt 2 Introduction

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.1 April 2015 Section 1: Assessment Information Instructions for Submission

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.0 February 2014 Section 1: Assessment Information Instructions for Submission

More information

This appendix is a supplement to the Local Government Information Security: Getting Started Guide, a non-technical reference essential for elected

This appendix is a supplement to the Local Government Information Security: Getting Started Guide, a non-technical reference essential for elected This appendix is a supplement to the Local Government Information Security: Getting Started Guide, a non-technical reference essential for elected officials, administrative officials and business managers.

More information

Payment Card Industry Data Security Standard Training. Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc.

Payment Card Industry Data Security Standard Training. Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc. Payment Card Industry Data Security Standard Training Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc. March 27, 2012 Agenda Check-In 9:00-9:30 PCI Intro and History

More information

How to complete the Secure Internet Site Declaration (SISD) form

How to complete the Secure Internet Site Declaration (SISD) form 1 How to complete the Secure Internet Site Declaration (SISD) form The following instructions are designed to assist you in completing the SISD form that forms part of your Merchant application. Once completed,

More information

Saint Louis University Merchant Card Processing Policy & Procedures

Saint Louis University Merchant Card Processing Policy & Procedures Saint Louis University Merchant Card Processing Policy & Procedures Overview: Policies and procedures for processing credit card transactions and properly storing credit card data physically and electronically.

More information

ACCEPTING PAYMENT CARDS FOR CONDUCTING UNIVERSITY BUSINESS:

ACCEPTING PAYMENT CARDS FOR CONDUCTING UNIVERSITY BUSINESS: Boston College Policy ACCEPTING PAYMENT CARDS FOR CONDUCTING UNIVERSITY BUSINESS: PURPOSE OF POLICY: The purpose of this policy is to establish procedures for accepting payment cards at Boston College

More information

ACCEPTING PAYMENT CARDS FOR CONDUCTING UNIVERSITY BUSINESS:

ACCEPTING PAYMENT CARDS FOR CONDUCTING UNIVERSITY BUSINESS: Boston College Policy ACCEPTING PAYMENT CARDS FOR CONDUCTING UNIVERSITY BUSINESS: PURPOSE OF POLICY: The purpose of this policy is to establish procedures for accepting payment cards at Boston College

More information