IMPORTANT BID ADDENDUM FAILURE TO RETURN THIS BID ADDENDUM IN ACCORDANCE WITH INSTRUCTIONS MAY SUBJECT YOUR BID TO REJECTION ON THE AFFECTED ITEM(S).

Size: px
Start display at page:

Download "IMPORTANT BID ADDENDUM FAILURE TO RETURN THIS BID ADDENDUM IN ACCORDANCE WITH INSTRUCTIONS MAY SUBJECT YOUR BID TO REJECTION ON THE AFFECTED ITEM(S)."

Transcription

1 STATE OF NORTH CAROLINA STATE OF NORTH CAROLINA NC Department of Natural and Cultural Resources Purchasing Office IMPORTANT BID ADDENDUM FAILURE TO RETURN THIS BID ADDENDUM IN ACCORDANCE WITH INSTRUCTIONS MAY SUBJECT YOUR BID TO REJECTION ON THE AFFECTED ITEM(S). BID Number: RFP SERVICE: Merchant Services Audit ADDENDUM Number: 1 USING AGENCY: NC DEPT OF NATURAL AND CULTURAL RESOURCES PURCHASER: Cynthia Armes OPENING DATE/TIME: INSTRUCTIONS: June 22, :00 PM A. Questions and Responses: 1. Question: A.i, Are we limited to just 1 day for the security audit for each merchant? This is probably NOT enough time for SAQ-D review and scoping review. Response: Site visits are not required to be limited to one (1) day. Please provide pricing on a per day rate and an estimate of how long each site visit will take. 2. Question: A.i, Can we assume that we will be allowed additional time over the 1 day site visit for preparing the actual report/risk analysis? Response: Yes, however DNCR would like to have the gap analysis one (1) month after the site visit. 3. Question: A.ii, This requirement reference V3.1; however, V3.2 is now released. Is there a reason to not review under V3.2? Response: The merchants can be reviewed under PCI DSS Question: A.iii, Is it possible to combine site visits for the penetration tests with the on-site security audit visits? Response: It is possible, but would depend on scheduling and merchants operations. 5. Question: A.iv, How many public-facing hosts will be in scope for external scanning? Response: Less than Question: A.iv, Do you desire assistance with both external scanning and internal quarterly or only external? Addendum 1, RFP Page 1 of 9

2 Response: DNCR needs assistance with both internal and external scanning. 7. Question: Section A.v, Will the QSA be signing the AOC associated with the SAQ-D for each merchant? Response: The QSA will be assisting with completing the overall SAQ-D for DNCR (merchants will be rolled up), but will not be signing off. 8. Question: Section A.vi, Can the monthly meeting be virtual or is the QSA to be on-site? Response: Monthly meetings can be virtual. 9. Question: A.viii, Will the policy and procedure document(s) be a single document set for all merchants or a separate set for each merchant? Response: Each type of merchant (SAQ, A, B, C, D, etc.) needs a template to fill in their business process. 10. Question: Section A.ix, The training is listed as an annual event with up to 3 live web-based sessions. Will this training be provided on the same day, consecutive days, or will it be 3 distinct occurrences throughout the year? Are there different audiences for each or all the same audience? Response: These trainings will most likely occur on different days, and be presented to different audiences (merchant account owners, IT staff, directors) 11. Question: Section A.ix, Will the mechanism for employee login to training recordings be provided by the Department of Natural and Cultural Resources? Response: The login for merchant training will be provided by DNCR. 12. Question: Section A.xii, Where is the physical location to be visited for each of the sites in a. through j? Response: The physical locations are: a. NC Division of Parks 121 W Jones St., Raleigh, NC Main business office. There are multiple park sites. A representative sample will be selected for site visits, but exact locations have not been decided on at this time. b. DENR Aquarium Pine Knoll Shores 1 Roosevelt Blvd, Pine Knoll Shores, NC c. DENR Aquarium Jen Pier 7223 S Virginia Dare Trail, Nags Head, NC d. DENR Aquarium Roanoke Island 374 Airport Road, Manteo, NC e. DENR Aquarium Fort Fisher 900 Loggerhead Road, Kure Beach, NC f. DENR Zoological Park 4401 Zoo Parkway, Asheboro, NC g. Roanoke Island Festival Park Ticket Sales 1 Festival Park, Manteo, NC h. Roanoke Island Festival Park Museum Store 1 Festival Park, Manteo, NC i. NC Department of Cultural Resources 109 East Jones Street, Raleigh, NC j. DCR AH HPS Book sale 120 W Lane Street, Raleigh, NC Question: Section A.i, Page 11, The PCI-SSC typically equates an on-site assessment to that of a Report on Compliance. What is the NCDNCR interpretation of an on-site assessment? Is this intended to be a Full Report of Compliance for each merchant, a SAQ for each merchant, or a consolidated RoC/SAQ? Response: DNCR equates an on-site assessment to that of a PCI DSS gap analysis. Addendum 1, RFP Page 2 of 9

3 Each merchant will complete their own SAQ, but DNCR will roll up these into one SAQ D. Each merchant that has an on-site visit will need a detailed PCI DSS gap analysis to determine any remediation items. 14. Question: Section A.i, Page 11, In this section you mention that complex merchants will need a full day for the on-site audit. Is it anticipated that on-site time for each merchant will be limited to one day or less to complete the PCI DSS assessment? Response: Site visits are not required to be limited to one day. Please provide pricing on a per day rate and an estimate of how long each site visit will take. 15. Question: Section A.i, Page 11, Have these merchants undergone a PCI assessment before? Were these all passing without the need of remediating activities? Response: These merchants have not received a full PCI gap analysis before. Since these merchants have not received a full PCI gap analysis, there will likely be remediation items. 16. Question: Section A.i, Page 11, Has NCDNCR been advised by their acquiring bank as to the validation requirements? Who is the acquiring bank? Response: NCDCR is a Level 3 merchant, and will be completing an SAQ D. NCDCR validates to First Data Merchant Services. 17. Question: Section A.i, Page 11, What card brands (ie. MasterCard, Visa, American Express, etc.) is accepted by these merchants. Response: DNCR merchants accept MasterCard, Visa, Discover, and American Express. 18. Question: Section A.i, Page 11, Has the Cardholder Data Environment (CDE) been defined and mapped for credit card transactions? Do data flow diagrams exist for each process and merchant? Response: The CDE has not been fully mapped. No, data flow diagrams do not exist for each process or merchant. 19. Question: Section A.i, Page 11, How many different methods/processes are there for credit card data to enter the organization, i.e. mail, phone, , electronic files, etc. and what are they? Response: Merchants accept credit cards via mail, phone, ecommerce, and face to face. Since a full PCI DSS assessment has not been completed, there could be other methods used. 20. Question: Section A.i, Page 11, Are your credit card transactions card present, card not present or both? If both, what is the approximate percentage of each? Response: Credit Card transactions are both card present and card not present. 65% card present and 35% card not present. 21. Question: Section A.i, Page 11, Do you currently have data flow datagrams or similar documentation detailing the different processes which handle cardholder data? Addendum 1, RFP Page 3 of 9

4 Response: No, data flow diagrams do not exist for each process. 22. Question: Section A.i, Page 11, Please list the applications (other than POS) that are used to support the credit card processes? Please provide a description of the function of each? Response: CounterPoint, TAMS, and Active Network are the major payment applications used. However, since a full PCI DSS assessment has not been completed, there could be other applications used. These applications are integrated into a POS terminal and merchants also use their ecommerce functionality. 23. Question: Section A.i, Page 11, Please indicate whether each of these applications is developed in house or commercially available software? Response: To my knowledge, DNCR does not have any payment applications developed in house. All known payment applications are commercially available. 24. Question: Section A.i, Page 11, Please confirm that on-site assessments and security audits are limited to fifteen merchants. Page 12 lists 35 merchants with ten being high priority. Response: DNCR will not exceed 15 on-site merchant assessments per year. 25. Question: Section A.xi, Page 12, Section A.xii, Page 12, If ten are SAQ-D reports, what reports will be generated for the remaining five? Response: The other merchants will fall into a SAQ A, SAQ B, or SAQ C. 26. Question: Section A.i, Page 11, How was a full day determined for the complex merchants? Response: A full day is 7-8 hours onsite reviewing the merchant s business process, interviewing staff, and examining the physical security controls. 27. Question: Section A.i, Page 11, Are the PCI processing environments centralized or decentralized? +Centralized: -NCDNCR hosts centralized servers -Single payment application managed by NCDNCR -Policies and procedures have been developed and issued by NCDNCR -The merchants listed share a common infrastructure +De-centralized: -Merchant has and manages their own server environment -Merchant has their own payment application which they manage -Each Merchant maintains their own infrastructure Response: DNCR s PCI processing environment is currently decentralized, but would like to move toward centralizing. 28. Question: Section A.i, Page 11, What WAN transport is used to communicate between your locations and between yourself and vendors, business partners, etc.? Response: DNCR uses NC DIT s State Network. Addendum 1, RFP Page 4 of 9

5 29. Question: Section A.i, Page 11, Does NCDNCR currently outsource any portion of your IT infrastructure, application or operations? Response: Currently merchants manage their own merchant environments. Some merchants have decided to outsource portions of their IT infrastructure, applications, and operations. 30. Question: Section A.i, Page 11, Are you currently using any third-party service providers to store, transmit or process credit card information? Please list each and the nature of the relationship. Consider those who access or process credit card data: Application Developers Managed service providers Network and application hosting Response: Yes, DNCR is currently using third party payment providers to store, transmit, or process credit card information. CounterPoint Integrated Payment Application and ecommerce TAMS Integrated Payment Application ActiveNetwork Integrated Payment Application and ecommerce NC Department of IT hosting Accelerando hosting ActiveNetwork Integrated Payment Application and ecommerce A full PCI DSS assessment has not been completed; there could be other Third Party Service Providers used. 31. Question: Section A.i, Page 11, Is there any centralized logging currently being performed in either environment? If so, what tools are being used to collect and analyze? Response: Logging is currently being performed in NC Department of IT s PCI environment. NC Department of IT is using Alien Vault and manually monitoring logs in the PCI environment. 32. Question: Section A.i, Page 11, Are Intrusion Detection/Prevention systems in place? Response: NC Department of IT is using an IDS/IPS in the PCI environment. 33. Question: Section A.i, Page 11, Is there a POS system in place? Is the POS system or system(s) developed in house commercially available? If commercially available has it been PA-DSS certified? Response: There are multiple POS systems in place. CounterPoint, TAMS, and Active Network are the major payment applications used. However, since a full PCI DSS assessment has not been completed; there could be other applications used. Yes, the POS terminals are PA-DSS certified. 34. Question: Section A.i, Page 11, Please list whether applications are accessible from an internal network, from an external network (i.e. Internet) or both. Response: Applications are accessible from both an internal and external network. 35. Question: Section A.i, Page 11, Is there segmentation in place at the merchant sites between their work network and the credit card processing systems? Addendum 1, RFP Page 5 of 9

6 Are the system and databases that handle credit card data segmented from the remainder network or is it just one flat network? If yes, please explain how the segmentation is accomplished. Response: Not all merchant sites have the appropriate segmentation in place. A full PCI DSS assessment has not been completed so there could be a combination of segmentation and a flat network depending on the site. Full segmentation has not been accomplished at DNCR. 36. Question: Section A.i, Page 11, Within each CDE, approximately how many web and middleware servers are currently deployed within each environment? (e.g. Apache, IIS, WebSphere, TomCat, etc.). -At each complex merchant. -At each non-complex merchant. Response: A full PCI DSS assessment has not been completed. DNCR does not have a count of web and middleware servers for each merchant or for the agency as a whole. 37. Question: Section A.i, Page 11, Within each CDE, approximately how many network devices are in environment? (i.e. routers, switches, firewalls, VPN devices, etc.) -At each complex merchant -At each non-complex merchant Response: A full PCI DSS assessment has not been completed. DNCR does not have a count of network devices for each merchant or for the agency as a whole. 38. Question: Section A.i, Page 11, Is there wireless at the merchant? If yes, is this wireless used in the transmission of point-of-sale transactions? Do you currently have measures in place to detect rogue wireless access points? Response: Some merchant sites have wireless internet. Merchants have been instructed not to use Wireless internet for POS transactions. Yes. 39. Question: Section A.ii, Page 11, During a review there are may not be three compliant options to address a gap. How would this be expected to be addressed? Response: If there are not 3 available compliant solutions then a recommendation on business process change will also be acceptable. 40. Question: Section A.iii, Page 11, Is the penetration test external/internal/both? +If both, please provide number or hosts involved in each. Response: Internal and External Penetration testing is needed. A full PCI DSS assessment has not been completed. DNCR does not have a count of hosts involved. 41. Question: Section A.iii, Page 11, Are you currently performing, internal and external penetration testing, and internal vulnerability assessments? Addendum 1, RFP Page 6 of 9

7 If so, have the penetration tests been successful, i.e. satisfactory for compliance? Response: DNCR is currently performing internal vulnerability assessment. N/A 42. Question: Section A.iv, Page 11, Is the quarterly scanning interval/external (ASV)/both? +If both, please provide number of hosts involved in each. Response: Quarterly internal vulnerability scans are completed. A full PCI DSS assessment has not been completed. DNCR does not have a count of hosts involved. 43. Question: Section A.iv, Page 11, Are you currently engaged with an ASV to conduct the quarterly external scans? If so, have the scans been successful, i.e. satisfactory for compliance? Response: No. N/A 44. Question: Section A.iv, Page 11, Are you performing the required quarterly internal scans required for compliance? If so, have the scans been successful, i.e. satisfactory for compliance? Response: Yes, DNCR is performing internal vulnerability scans. Yes. 45. Question: Section A.v, Page 11, Will each merchant be completing their own SAQ? Response: Yes. 46. Question: Section A.v, Page 11, Will the vendor be expected to sign the SAQ? Response: No, the vendor is not expected to sign the SAQ since DNCR is able to self-assess. 47. Question: Section A.v, Page 11, Please clarify SAQ D self-assessments shall require assistance? Please clarify the level of review expected. Would the review be limited to validation of the existence of controls or expanded to include the validation of the effectiveness of controls? Response: Vendor will work with DNCR staff to complete overall SAQ D. Review will also include the effectiveness of controls. 48. Question: Section A.vi, Page 11, We suggest weekly status calls. Is NCDNCR open to meetings more frequently than monthly? Response: Yes, we are open to more frequent meetings. Please provide the price for weekly meetings, as well as, monthly. 49. Question: Section A.vi, Page 11, Approximately how many individuals from your organization do you feel will need to be involved in the assessment? (e.g. IT, application development, database management, business process, etc.) Addendum 1, RFP Page 7 of 9

8 Response: Approximately 10 individuals for each assessment. This includes merchant owners, merchant staff, and IT staff, and central business office. 50. Question: Section A.vi, Page 11, Can you provide an organization chart with titles and functions? Response: Yes, each department has an organizational chart. 51. Question: Section A.vii, Page 11/12, Is the Risk Assessment and Management Plan discussed to meet Requirements 12.2 or intended more as a Project Plan? Response: Risk Assessment and Management Plan will need to satisfy Requirement 12.2, but will also be utilized for our project plan along with the PCI gap analysis. 52. Question: Section A.viii, Page 12, Do PCI policies exist? If yes, have they been reviewed as part of a previous PCI effort? If so on a scale of 1 (low) to 5 (high how comprehensive are they?) (e.g. change control, data control, data retention, data classification, acceptable use disposal, etc.) Response: Limited PCI policies exist. DNCR is still in the process of discovering and reviewing existing policies. Existing policies are a 3, however, many areas are missing documentation. 53. Question: Section A.x, Page 12, Is training other than PCI Security Awareness expected? If yes, what type and to what extent? Will training be expected to be conducted per merchant or will all merchants attend the main training when offered? Response: No. N/A All merchants are expected to attend the main PCI Security Awareness Training. 54. Question: Section A.xi, Page 12, Section A.xii, Page 12, If the ten steps listed above address the SAQ-D for the ten listed high priority merchants, what SAQs are expected for the other five that are needed? Response: The other merchants will fall into a SAQ A, SAQ B, or SAQ C. 55. Question: Section A.x, Page 12, Does a formal information security policy exist? Response: Yes. 56. Question: Section B.5, Page 12, Are the 3 web based security awareness training sessions expected to be done by October 2016? Response: No, the 3 trainings are not expected to be completed by October Question: Attachment C: Pricing, Many of the activities are performed per merchant, including travel to each. Some activities are more global in nature, i.e. the web training. Should this total be broken down by merchant and global activities or combined? Response: Pricing should be broken down by per merchant (ex. site visit) and global activities as applicable (ex. training). Addendum 1, RFP Page 8 of 9

9 B. Offeror s Certification of Addendum Check ONLY one of the following categories and return one properly executed copy of this addendum prior to bid opening time and date. Bid has already been mailed. Changes resulting from this addendum are as follows Bid has already been mailed. NO CHANGES resulted from this addendum Bid has NOT been mailed and ANY CHANGES resulting from this addendum are included in our bid. BIDDER: ADDRESS (CITY & STATE): AUTHORIZED SIGNATURE: DATE: NAME and TITLE (Typed): Please note that the US Postal Service does not deliver any mail (US Postal Express, Certified, Priority, Overnight, etc.) on a set delivery schedule to this Office. It is the responsibility of the Vendor to have the bid in this Office by the specified time and date of opening. SEND ALL PROPOSALS DIRECTLY TO THE ISSUING AGENCY ADDRESS AS SHOWN BELOW: DELIVERED BY US POSTAL SERVICE DELIVERED BY ANY OTHER MEANS RFP NO RFP NO North Carolina Department of Natural and Cultural Resources North Carolina Department of Natural and Cultural Resources Purchasing Office Purchasing Office, Archives & History Building, 3 rd Floor 4605 Mail Service Center 109 East Jones Street Raleigh, NC Raleigh, NC Signature of Offeror: Print Name: Company: Address: Telephone Number Title: Address County of Service Street/PO Box City Zip Code Fax: Principal Place of Business if different from above (See General Information on Submitting Proposals, Item 18.): Will any of the work under this Contract be performed outside the United States? Yes No -(If yes, describe in technical proposal.) N.C.G.S and Executive Order 24 prohibit the offer to, or acceptance by, any State Employee of any gift from anyone with a contract with the State, or from any person seeking to do business with the State. By execution of any response in this procurement, you attest, for your entire organization and its employees or agents, that you are not aware that any such gift has been offered, accepted, or promised by any employees of your organization. THIS PAGE MUST BE SIGNED AND INCLUDED IN YOUR PROPOSAL. Addendum 1, RFP Page 9 of 9

Vendor 1 QUESTION CCSF RESPONSE

Vendor 1 QUESTION CCSF RESPONSE Vendor 1 QUESTION 1 If we have already filled out the vendor profile application, business tax declaration and local business forms will we need to fill them out again? 2 Is CCSF open to rolling up all

More information

Spokane Airport Board (Spokane International Airport, Airport Business Park, Felts Field) Addendum #1 - Q&A

Spokane Airport Board (Spokane International Airport, Airport Business Park, Felts Field) Addendum #1 - Q&A Spokane Airport Board (Spokane International Airport, Airport Business Park, Felts Field) Request for Proposals (RFP) for PCI DSS COMPLIANCE SERVICES Project # 15-49-9999-016 Addendum #1 - Q&A May 29,

More information

PCI Compliance at The University of South Carolina. Failure is not an option. Rick Lambert PMP University of South Carolina ricklambert@sc.

PCI Compliance at The University of South Carolina. Failure is not an option. Rick Lambert PMP University of South Carolina ricklambert@sc. PCI Compliance at The University of South Carolina Failure is not an option Rick Lambert PMP University of South Carolina ricklambert@sc.edu Payment Card Industry Data Security Standard (PCI DSS) Who Must

More information

San Jose Airport PCI@SJC. Diane Mack-Williams SJC Airport Technology Services ACI NA San Diego, 15th October 2011

San Jose Airport PCI@SJC. Diane Mack-Williams SJC Airport Technology Services ACI NA San Diego, 15th October 2011 San Jose Airport PCI@SJC Diane Mack-Williams SJC Airport Technology Services ACI NA San Diego, 15th October 2011 Why PCI-DSS at SJC? SJC as a Service Provider Definition: Business entity that is not a

More information

Case 2:13-cv-01887-ES-JAD Document 282-2 Filed 12/09/15 Page 1 of 116 PageID: 4879. Appendix A

Case 2:13-cv-01887-ES-JAD Document 282-2 Filed 12/09/15 Page 1 of 116 PageID: 4879. Appendix A Case 2:13-cv-01887-ES-JAD Document 282-2 Filed 12/09/15 Page 1 of 116 PageID: 4879 Appendix A Case 2:13-cv-01887-ES-JAD Document 282-2 Filed 12/09/15 Page 2 of 116 PageID: 4880 Payment Card Industry (PCI)

More information

How To Ensure Account Information Security

How To Ensure Account Information Security Global PCI DSS Framework Emöke Bitter Business Leader, Risk Management 26 February 2009 Agenda Introduction Merchants Service Providers Registry of Service Providers Payment Applications Resources Information

More information

PCI Compliance. How to Meet Payment Card Industry Compliance Standards. May 2015. cliftonlarsonallen.com. 2015 CliftonLarsonAllen LLP

PCI Compliance. How to Meet Payment Card Industry Compliance Standards. May 2015. cliftonlarsonallen.com. 2015 CliftonLarsonAllen LLP 2015 CliftonLarsonAllen LLP PCI Compliance How to Meet Payment Card Industry Compliance Standards May 2015 cliftonlarsonallen.com Overview PCI DSS In the beginning Each major card brand had its own separate

More information

Becoming PCI Compliant

Becoming PCI Compliant Becoming PCI Compliant Jason Brown - brownj52@michigan.gov Enterprise Security Architect Enterprise Architecture Department of Technology, Management and Budget State of Michigan @jasonbrown17 History

More information

CITY OF CORONA RFP 15-005SB. ADDENDUM No. 2

CITY OF CORONA RFP 15-005SB. ADDENDUM No. 2 CITY OF CORONA ADDENDUM No. 2 Purchasing Division (951) 736-2272 400 S. Vicentia Ave., Ste. 320 purchasing@discovercorona.com Corona, CA 92882 09/22/2014 Scott Briggs Addendum No. 2 for the Evaluation

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance Card-not-present Merchants, All Cardholder Data Functions Fully Outsourced Version 3.0 February

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire Instructions and Guidelines Version 1.1 February 2008 Table of Contents About this Document... 1 PCI Data Security Standard

More information

Achieving PCI Compliance for Your Site in Acquia Cloud

Achieving PCI Compliance for Your Site in Acquia Cloud Achieving PCI Compliance for Your Site in Acquia Cloud Introduction PCI Compliance applies to any organization that stores, transmits, or transacts credit card data. PCI Compliance is important; failure

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance All other SAQ-Eligible Merchants and Service Providers Version 2.0 October 2010 Document

More information

PCI Compliance. What is New in Payment Card Industry Compliance Standards. October 2015. cliftonlarsonallen.com. 2015 CliftonLarsonAllen LLP

PCI Compliance. What is New in Payment Card Industry Compliance Standards. October 2015. cliftonlarsonallen.com. 2015 CliftonLarsonAllen LLP cliftonlarsonallen.com PCI Compliance What is New in Payment Card Industry Compliance Standards October 2015 Overview PCI DSS In the beginning Each major card brand had its own separate criteria for implementing

More information

05.118 Credit Card Acceptance Policy. Vice Chancellor of Business Affairs. History: Effective July 1, 2011 Updated February 2013

05.118 Credit Card Acceptance Policy. Vice Chancellor of Business Affairs. History: Effective July 1, 2011 Updated February 2013 05.118 Credit Card Acceptance Policy Authority: Vice Chancellor of Business Affairs History: Effective July 1, 2011 Updated February 2013 Source of Authority: Office of State Controller (OSC); Office of

More information

North Carolina Office of the State Controller Technology Meeting

North Carolina Office of the State Controller Technology Meeting PCI DSS Security Awareness Training North Carolina Office of the State Controller Technology Meeting April 30, 2014 agio.com A Note on Our New Name Secure Enterprise Computing was acquired as the Security

More information

Technical breakout session

Technical breakout session Technical breakout session Small leaks sink great ships Managing data security, fraud and privacy risks Tarlok Birdi, Deloitte Ron Borsholm, WTS May 27, 2009 Agenda 1. PCI overview: the technical intent

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire Instructions and Guidelines Version 3.2 May 2016 Document Changes Date Version Description October 1, 2008 1.2 October 28,

More information

Why Is Compliance with PCI DSS Important?

Why Is Compliance with PCI DSS Important? Why Is Compliance with PCI DSS Important? The members of PCI Security Standards Council (American Express, Discover, JCB, MasterCard, and Visa) continually monitor cases of account data compromise. These

More information

Taylor Brumbeloe, ecommerce Financial Specialist Office of State Controller. John Frye, Financial Services Director Village of Pinehurst

Taylor Brumbeloe, ecommerce Financial Specialist Office of State Controller. John Frye, Financial Services Director Village of Pinehurst Taylor Brumbeloe, ecommerce Financial Specialist Office of State Controller John Frye, Financial Services Director Village of Pinehurst Rick Owens, Vice President Administrative Services Pitt Community

More information

Puzzled about PCI compliance? Proactive ways to navigate through the standard for compliance

Puzzled about PCI compliance? Proactive ways to navigate through the standard for compliance Puzzled about PCI compliance? Proactive ways to navigate through the standard for compliance March 29, 2012 1:00 p.m. ET If you experience any technical difficulties, please contact 888.228.0988 or support@learnlive.com

More information

PCI DSS. Payment Card Industry Data Security Standard. www.tuv.com/id

PCI DSS. Payment Card Industry Data Security Standard. www.tuv.com/id PCI DSS Payment Card Industry Data Security Standard www.tuv.com/id What Is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is the common security standard of all major credit cards brands.the

More information

How To Protect Your Credit Card Information From Being Stolen

How To Protect Your Credit Card Information From Being Stolen Visa Account Information Security Tool Kit Welcome to the Visa Account Information Security Program 2 Contents 1. Securing cardholder data is everyone s concern 4 2. Visa Account Information Security (AIS)

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire C and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire C and Attestation of Compliance Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire C and Attestation of Compliance Payment Application Connected to Internet, No Electronic Cardholder Data Storage Version

More information

PCI DSS 3.0 and You Are You Ready?

PCI DSS 3.0 and You Are You Ready? PCI DSS 3.0 and You Are You Ready? 2014 STUDENT FINANCIAL SERVICES CONFERENCE Linda Combs combslc@jmu.edu Ron King rking@campusguard.com AGENDA PCI and Bursar Office Role Key Themes in v3.0 Timelines Changes

More information

PCI Data Security Standards

PCI Data Security Standards PCI Data Security Standards An Introduction to Bankcard Data Security Why should we worry? Since 2005, over 500 million customer records have been reported as lost or stolen 1 In 2010 alone, over 134 million

More information

AISA Sydney 15 th April 2009

AISA Sydney 15 th April 2009 AISA Sydney 15 th April 2009 Where PCI stands today: Who needs to do What, by When Presented by: David Light Sense of Security Pty Ltd Agenda Overview of PCI DSS Compliance requirements What & When Risks

More information

Two Approaches to PCI-DSS Compliance

Two Approaches to PCI-DSS Compliance Disclaimer Copyright Michael Chapple and Jane Drews, 2006. This work is the intellectual property of the authors. Permission is granted for this material to be shared for non-commercial, educational purposes,

More information

5 TIPS TO PAY LESS FOR PCI COMPLIANCE

5 TIPS TO PAY LESS FOR PCI COMPLIANCE Ebook 5 TIPS TO PAY LESS FOR PCI COMPLIANCE SIMPLE STEPS TO REDUCE YOUR PCI SCOPE 2015 SecurityMetrics 5 TIPS TO PAY LESS FOR PCI COMPLIANCE 1 5 TIPS TO PAY LESS FOR PCI COMPLIANCE SIMPLE STEPS TO REDUCE

More information

Josiah Wilkinson Internal Security Assessor. Nationwide

Josiah Wilkinson Internal Security Assessor. Nationwide Josiah Wilkinson Internal Security Assessor Nationwide Payment Card Industry Overview PCI Governance/Enforcement Agenda PCI Data Security Standard Penalties for Non-Compliance Keys to Compliance Challenges

More information

1/18/10. Walt Conway. PCI DSS in Context. Some History The Digital Dozen Key Players Cardholder Data Outsourcing Conclusions. PCI in Higher Education

1/18/10. Walt Conway. PCI DSS in Context. Some History The Digital Dozen Key Players Cardholder Data Outsourcing Conclusions. PCI in Higher Education PCI in Higher Education Walter Conway, QSA 403 Labs, LLC Walt Conway PCI consultant, blogger, trainer, speaker, author Former Visa VP Help schools become PCI compliant Represent Higher Education at PCI

More information

Payment Card Industry Standard - Symantec Services

Payment Card Industry Standard - Symantec Services Payment Card Industry Standard - Symantec Services The Payment Card Industry Data Security Standard (PCI, or PCI DSS) was developed by the PCI Security Standards Council to assure cardholders that their

More information

PCI DSS Compliance. 2015 Information Pack for Merchants

PCI DSS Compliance. 2015 Information Pack for Merchants PCI DSS Compliance 2015 Information Pack for Merchants This pack contains general information regarding PCI DSS compliance and does not take into account your business' particular requirements. ANZ recommends

More information

How To Protect Your Business From A Hacker Attack

How To Protect Your Business From A Hacker Attack Payment Card Industry Data Security Standards The payment card industry data security standard PCI DSS Visa and MasterCard have developed the Payment Card Industry Data Security Standard or PCI DSS as

More information

PCI Requirements Coverage Summary Table

PCI Requirements Coverage Summary Table StillSecure PCI Complete Managed PCI Compliance Solution PCI Requirements Coverage Summary Table December 2011 Table of Contents Introduction... 2 Coverage assumptions for PCI Complete deployments... 2

More information

Office of Finance and Treasury

Office of Finance and Treasury Office of Finance and Treasury How to Accept & Process Credit and Debit Card Transactions Procedure Related Policy Title Credit Card Processing Policy For University Merchant Locations Responsible Executive

More information

Credit Cards and Oracle: How to Comply with PCI DSS. Stephen Kost Integrigy Corporation Session #600

Credit Cards and Oracle: How to Comply with PCI DSS. Stephen Kost Integrigy Corporation Session #600 Credit Cards and Oracle: How to Comply with PCI DSS Stephen Kost Integrigy Corporation Session #600 Background Speaker Stephen Kost CTO and Founder 16 years working with Oracle 12 years focused on Oracle

More information

PCI Compliance. Top 10 Questions & Answers

PCI Compliance. Top 10 Questions & Answers PCI Compliance Top 10 Questions & Answers 1. What is PCI Compliance and PCI DSS? 2. Who needs to follow the PCI Data Security Standard? 3. What happens if I don t comply? 4. What are the basic requirements

More information

PCI DSS Overview. By Kishor Vaswani CEO, ControlCase

PCI DSS Overview. By Kishor Vaswani CEO, ControlCase PCI DSS Overview By Kishor Vaswani CEO, ControlCase Agenda About PCI DSS PCI DSS Applicability to Banks, Merchants and Service Providers PCI DSS Technical Requirements Overview of PCI DSS 3.0 Changes Key

More information

PCI Requirements Coverage Summary Table

PCI Requirements Coverage Summary Table StillSecure PCI Complete Managed PCI Compliance Solution PCI Requirements Coverage Summary Table January 2013 Table of Contents Introduction... 2 Coverage assumptions for PCI Complete deployments... 2

More information

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program MERCHANTS Can Level 1 merchants currently use internal auditors to perform an onsite assessment? Yes. However, after June 30,

More information

Your Compliance Classification Level and What it Means

Your Compliance Classification Level and What it Means General Information What are the Payment Card Industry (PCI) Data Security Standards? The PCI Data Security Standards represents a common set of industry tools and measurements to help ensure the safe

More information

PDQ Guide for the PCI Data Security Standard Self-Assessment Questionnaire C (Version 1.1)

PDQ Guide for the PCI Data Security Standard Self-Assessment Questionnaire C (Version 1.1) PDQ has created an Answer Guide for the Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire C to help wash operators complete questionnaires. Part of the Access Customer Management

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Self-Assessment Questionnaire D Service Providers For use with PCI DSS Version 3.1 Revision 1.1 July 2015 Section 1: Assessment

More information

115 th Annual Convention

115 th Annual Convention 115 th Annual Convention Date: Saturday, October 12, 2013 Time: 11:00 am 12:00 pm Location: The Walt Disney World Swan and Dolphin Resort, Southern Hemisphere Salon 4-5 Title: Activity Type: Speaker: Data

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.0 February 2014 Section 1: Assessment Information Instructions for Submission

More information

PCI on Amazon Web Services (AWS) What You Need To Know Understanding the regulatory roadmap for PCI on AWS

PCI on Amazon Web Services (AWS) What You Need To Know Understanding the regulatory roadmap for PCI on AWS PCI on Amazon Web Services (AWS) What You Need To Know Understanding the regulatory roadmap for PCI on AWS David Clevenger November 2015 Summary Payment Card Industry (PCI) is an accreditation body that

More information

ARE YOU REALLY PCI DSS COMPLIANT? Case Studies of PCI DSS Failure! Jeff Foresman, PCI-QSA, CISSP Partner PONDURANCE

ARE YOU REALLY PCI DSS COMPLIANT? Case Studies of PCI DSS Failure! Jeff Foresman, PCI-QSA, CISSP Partner PONDURANCE ARE YOU REALLY PCI DSS COMPLIANT? Case Studies of PCI DSS Failure! Jeff Foresman, PCI-QSA, CISSP Partner PONDURANCE AGENDA PCI DSS Basics Case Studies of PCI DSS Failure! Common Problems with PCI DSS Compliance

More information

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program

FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program FREQUENTLY ASKED QUESTIONS The MasterCard Site Data Protection (SDP) Program MERCHANTS Can Level 1 merchants currently use internal auditors to perform an onsite assessment? Yes. However, after June 30,

More information

PCI Compliance Top 10 Questions and Answers

PCI Compliance Top 10 Questions and Answers Where every interaction matters. PCI Compliance Top 10 Questions and Answers White Paper October 2013 By: Peer 1 Hosting Product Team www.peer1.com Contents What is PCI Compliance and PCI DSS? 3 Who needs

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Self-Assessment Questionnaire A Version 2.0 Attestation Of Compliance, SAQ A Instructions for Submission The merchant must

More information

Data Security Standard (DSS) Compliance. SIFMA June 13, 2012

Data Security Standard (DSS) Compliance. SIFMA June 13, 2012 Payment Card Industry (PCI) Data Security Standard (DSS) Compliance SIFMA June 13, 2012 EisnerAmper Consulting Services Group Overview of EisnerAmper Fifth fhlargest accounting firm in the Metro New York

More information

PCI Overview. PCI-DSS: Payment Card Industry Data Security Standard

PCI Overview. PCI-DSS: Payment Card Industry Data Security Standard PCI-DSS: Payment Card Industry Data Security Standard Why is this important? Cardholder data and personally identifying information are easy money That we work with this information makes us a target That

More information

PCI DSS Presentation University of Cincinnati

PCI DSS Presentation University of Cincinnati PCI DSS Presentation University of Cincinnati Quick PCI Level Set Higher Ed Challenges Getting Compliant Application w/ customers Q& A PCI DSS Payment Card Industry Data Security Standard What is the PCI

More information

PCI DSS 3.0 Changes Bill Franklin Executive IT Auditor bfranklin@compassitc.com January 23, 2014

PCI DSS 3.0 Changes Bill Franklin Executive IT Auditor bfranklin@compassitc.com January 23, 2014 PCI DSS 3.0 Changes Bill Franklin Executive IT Auditor bfranklin@compassitc.com January 23, 2014 Agenda Introduction PCI DSS 3.0 Changes What Can I Do to Prepare? When Do I Need to be Compliant? Questions

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.0 February 2014 Section 1: Assessment Information Instructions for Submission

More information

PCI DSS Compliance What Texas BUC$ Need to Know! Ron King CampusGuard rking@campusguard.com

PCI DSS Compliance What Texas BUC$ Need to Know! Ron King CampusGuard rking@campusguard.com PCI DSS Compliance What Texas BUC$ Need to Know! Ron King CampusGuard rking@campusguard.com Whoops!...3.1 Changes 3.1 PCI DSS Responsibility Information Technology Business Office PCI DSS Work Information

More information

HOW SECURE IS YOUR PAYMENT CARD DATA? COMPLYING WITH PCI DSS

HOW SECURE IS YOUR PAYMENT CARD DATA? COMPLYING WITH PCI DSS HOW SECURE IS YOUR PAYMENT CARD DATA? COMPLYING WITH PCI DSS August 23, 2011 MOSS ADAMS LLP 1 TODAY S PRESENTERS Presenters Francis Tam, CPA, CISA, CISM, CITP, CRISC, PCI QSA Managing Director, IT Security

More information

PCI DSS Gap Analysis Briefing

PCI DSS Gap Analysis Briefing PCI DSS Gap Analysis Briefing The University of Chicago October 1, 2012 Walter Conway, QSA 403 Labs, LLC Agenda The PCI DSS ecosystem - Key players, roles - Cardholder data - Merchant levels and SAQs UofC

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance Merchants with Only Imprint Machines or Only Standalone, Dial-out Terminals Electronic Cardholder

More information

SecureGRC TM - Cloud based SaaS

SecureGRC TM - Cloud based SaaS - Cloud based SaaS Single repository for regulations and standards Centralized repository for compliance related organizational data Electronic workflow to speed up communications between various entries

More information

Project Title slide Project: PCI. Are You At Risk?

Project Title slide Project: PCI. Are You At Risk? Blank slide Project Title slide Project: PCI Are You At Risk? Agenda Are You At Risk? Video What is the PCI SSC? Agenda What are the requirements of the PCI DSS? What Steps Can You Take? Available Services

More information

Payment Card Industry Data Security Standards Compliance

Payment Card Industry Data Security Standards Compliance Payment Card Industry Data Security Standards Compliance Please turn off, or to vibrate, all cell-phones/electronics Expected course length: 1 Hour Questions are welcomed. Who Created It? & What Is It?

More information

Are You Ready For PCI v 3.0. Speaker: Corbin DelCarlo Institution: McGladrey LLP Date: October 6, 2014

Are You Ready For PCI v 3.0. Speaker: Corbin DelCarlo Institution: McGladrey LLP Date: October 6, 2014 Are You Ready For PCI v 3.0 Speaker: Corbin DelCarlo Institution: McGladrey LLP Date: October 6, 2014 Today s Presenter Corbin Del Carlo QSA, PA QSA Director, National Leader PCI Services Practice 847.413.6319

More information

Credit Cards and Oracle E-Business Suite Security and PCI Compliance Issues

Credit Cards and Oracle E-Business Suite Security and PCI Compliance Issues Credit Cards and Oracle E-Business Suite Security and PCI Compliance Issues August 16, 2012 Stephen Kost Chief Technology Officer Integrigy Corporation Phil Reimann Director of Business Development Integrigy

More information

PAYMENT CARD INDUSTRY (PCI) ANNUAL TRAINING DECEMBER 10, 2009 WESTERN ILLINOIS UNIVERSITY OFFICE OF THE CTSO & BUSINESS SERVICES

PAYMENT CARD INDUSTRY (PCI) ANNUAL TRAINING DECEMBER 10, 2009 WESTERN ILLINOIS UNIVERSITY OFFICE OF THE CTSO & BUSINESS SERVICES PAYMENT CARD INDUSTRY (PCI) ANNUAL TRAINING DECEMBER 10, 2009 WESTERN ILLINOIS UNIVERSITY OFFICE OF THE CTSO & BUSINESS SERVICES AGENDA PCI Players and Roles Merchant Requirements Keys To Successful PCI

More information

Continuous compliance through good governance

Continuous compliance through good governance PCI DSS Compliance: A step into the payment ecosystem and Nets compliance program Continuous compliance through good governance Who are the PCI SSC? The Payment Card Industry Security Standard Council

More information

Your guide to the Payment Card Industry Data Security Standard (PCI DSS) Merchant Business Solutions. Version 5.0 (April 2011)

Your guide to the Payment Card Industry Data Security Standard (PCI DSS) Merchant Business Solutions. Version 5.0 (April 2011) Your guide to the Payment Card Industry Data Security Standard (PCI DSS) Merchant Business Solutions Version 5.0 (April 2011) Contents Contents...2 Introduction...3 What are the 12 key requirements of

More information

PCI v 3.0 What you should know! Emily Coble UNC Chapel Hill Robin Mayo East Carolina University

PCI v 3.0 What you should know! Emily Coble UNC Chapel Hill Robin Mayo East Carolina University PCI v 3.0 What you should know! Emily Coble UNC Chapel Hill Robin Mayo East Carolina University Session Etiquette Please turn off all cell phones. Please keep side conversations to a minimum. If you must

More information

Protecting Your Customers' Card Data. Presented By: Oliver Pinson-Roxburgh

Protecting Your Customers' Card Data. Presented By: Oliver Pinson-Roxburgh Protecting Your Customers' Card Data Presented By: Oliver Pinson-Roxburgh Agenda Trustwave Overview PCI Scope Compromise Statistics PCI Makes Business Sense Registration Process TrustKeeper Features Support

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.1 April 2015 Section 1: Assessment Information Instructions for Submission

More information

This appendix is a supplement to the Local Government Information Security: Getting Started Guide, a non-technical reference essential for elected

This appendix is a supplement to the Local Government Information Security: Getting Started Guide, a non-technical reference essential for elected This appendix is a supplement to the Local Government Information Security: Getting Started Guide, a non-technical reference essential for elected officials, administrative officials and business managers.

More information

HOW SECURE IS YOUR PAYMENT CARD DATA?

HOW SECURE IS YOUR PAYMENT CARD DATA? HOW SECURE IS YOUR PAYMENT CARD DATA? October 27, 2011 MOSS ADAMS LLP 1 TODAY S PRESENTERS Francis Tam, CPA, CISA, CISM, CITP, CRISC, PCI QSA Managing Director PCI Practice Leader Kevin Villanueva,, CISSP,

More information

Payment Card Industry Compliance Overview

Payment Card Industry Compliance Overview January 31, 2014 11:30am 12:30pm Central Hosted by: Texas.gov Presented by: Jayne Holland Barbara Brinson Payment Card Industry Compliance Overview Securing Government Payments Audio Dial In: 866-740-1260

More information

PCI Compliance Training

PCI Compliance Training PCI Compliance Training 1 PCI Training Topics Applicable PCI Standards Compliance Requirements Compliance of Unitec products Requirements for compliant installation and use of products 2 PCI Standards

More information

Credit Card Processing, Point of Sale, ecommerce

Credit Card Processing, Point of Sale, ecommerce Credit Card Processing, Point of Sale, ecommerce Compliance, Self Auditing, and More John Benson Kurt Willey HACKS REGULATIONS Greater Risk for Merchants Topics Compliance Changes Scans Self Audits

More information

Requirements & Potential Costs for SAQ D

Requirements & Potential Costs for SAQ D Requirements & Potential Costs for SAQ D The University of Utah prefers to use vendors who provide web host based (Cloud) payment card processing or who will redirect the payment portion of the software

More information

COLUMBUS STATE COMMUNITY COLLEGE POLICY AND PROCEDURES MANUAL

COLUMBUS STATE COMMUNITY COLLEGE POLICY AND PROCEDURES MANUAL PAYMENT CARD INDUSTRY COMPLIANCE (PCI) Effective June 1, 2011 Page 1 of 6 (1) Definitions a. Payment Card Industry Data Security Standards (PCI-DSS): A set of standards established by the Payment Card

More information

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer Complying with the PCI DSS All the Moving Parts Don Roeber Vice President, PCI Compliance Manager Lisa Tedeschi Assistant Vice President, Compliance Officer Types of Risk Operational Risk Normal fraud

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Standard Attestation of Compliance for Self-Assessment Questionnaire D Service Providers Version 3.1 April 2015 Section 1: Assessment Information Instructions for Submission

More information

BRAND-NAME is What COUNTS!!!

BRAND-NAME is What COUNTS!!! BRAND-NAME is What COUNTS!!! USE PCI-DSS and make a name for your business Amit Jain Lead Solution Architect Aug 2015 Who We Are WHO WE ARE Company facts and figures ESTABLISHED TRUSTED 1995 BY MORE THAN

More information

Understanding Payment Card Industry (PCI) Data Security

Understanding Payment Card Industry (PCI) Data Security Understanding Payment Card Industry (PCI) Data Security Office of the State Controller November 2010 State of North Carolina The Enemy Major Security Breaches TJ-Max Heartland Hannaford Foods BJ s Wholesale

More information

The PCI DSS Compliance Guide For Small Business

The PCI DSS Compliance Guide For Small Business PCI DSS Compliance in a hosted infrastructure A Rackspace White Paper Spring 2010 Summary The Payment Card Industry Data Security Standard (PCI DSS) is a global information security standard defined by

More information

Validation of PCI Compliance Requirements NC Office of the State Controller June 23, 2015

Validation of PCI Compliance Requirements NC Office of the State Controller June 23, 2015 Validation of PCI Compliance Requirements NC Office of the State Controller June 23, 2015 Purpose The purpose of this document is to provide instructions to entities that subscribe to merchant cards processing

More information

PCI Compliance. Crissy Sampier, Longwood University Edward Ko, CampusGuard

PCI Compliance. Crissy Sampier, Longwood University Edward Ko, CampusGuard PCI Compliance Crissy Sampier, Longwood University Edward Ko, CampusGuard Agenda Introductions PCI DSS 101 Chip Cards (EMV) Longwood s PCI DSS Journey Breach Statistics Shortcuts to PCI DSS Compliance

More information

Third-Party Access and Management Policy

Third-Party Access and Management Policy Third-Party Access and Management Policy Version Date Change/s Author/s Approver/s Dean of Information Services 1.0 01/01/2013 Initial written policy. Kyle Johnson Executive Director for Compliance and

More information

Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance

Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance A Non-Technical Guide Essential for Business Managers Office Managers Operations Managers Compliant? Bank Name

More information

SAQ D Compliance. Scott St. Aubin Senior Security Consultant QSA, CISM, CISSP

SAQ D Compliance. Scott St. Aubin Senior Security Consultant QSA, CISM, CISSP SAQ D Compliance Scott St. Aubin Senior Security Consultant QSA, CISM, CISSP Ground Rules WARNING: Potential Death by PowerPoint Interaction Get clarification Share your institution s questions, challenges,

More information

GRINNELL COLLEGE CREDIT CARD PROCESSING AND SECURITY POLICY

GRINNELL COLLEGE CREDIT CARD PROCESSING AND SECURITY POLICY GRINNELL COLLEGE CREDIT CARD PROCESSING AND SECURITY POLICY PURPOSE The Payment Card Industry Data Security Standard was established by the credit card industry in response to an increase in identify theft

More information

PCI Compliance: How to ensure customer cardholder data is handled with care

PCI Compliance: How to ensure customer cardholder data is handled with care PCI Compliance: How to ensure customer cardholder data is handled with care Choosing a safe payment process for your business Contents Contents 2 Executive Summary 3 PCI compliance and accreditation 4

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.0 February 2014 Section 1: Assessment Information Instructions for Submission

More information

Payment Card Industry (PCI) Data Security Standard. Requirements and Security Assessment Procedures. Version 3.1 April 2015

Payment Card Industry (PCI) Data Security Standard. Requirements and Security Assessment Procedures. Version 3.1 April 2015 Payment Card Industry (PCI) Data Security Standard Requirements and Security Assessment Procedures Version 3.1 April 2015 Document Changes Date Version Description Pages October 2008 1.2 July 2009 1.2.1

More information

RFQ Section 1. What is your highest known merchant level (1, 2, 3, or 4) as assigned by your acquirer?

RFQ Section 1. What is your highest known merchant level (1, 2, 3, or 4) as assigned by your acquirer? # SAIC CoM 2014 RG R79343 1. What is your highest known merchant level (1, 2, 3, or 4) as assigned by your acquirer? 2. Approximately how many credit card transactions do you process per year? 300,000;

More information

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008 Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008 What is the PCI DSS? And what do the acronyms CISP, SDP, DSOP and DISC stand for? The PCI DSS is a set of comprehensive requirements

More information

Minnesota State Colleges and Universities System Procedures Chapter 5 Administration. Guideline 5.23.1.10 Payment Card Industry Technical Requirements

Minnesota State Colleges and Universities System Procedures Chapter 5 Administration. Guideline 5.23.1.10 Payment Card Industry Technical Requirements Minnesota State Colleges and Universities System Procedures Chapter 5 Administration Payment Card Industry Technical s Part 1. Purpose. This guideline emphasizes many of the minimum technical requirements

More information

Payment Card Industry Data Security Standard C-VT Guide

Payment Card Industry Data Security Standard C-VT Guide Payment Card Industry Data Security Standard Self-Assessment Questionnaire C-VT Guide Prepared for: University of Tennessee Merchants 12 April 2013 Prepared by: University of Tennessee System Administration

More information

Vanderbilt University

Vanderbilt University Vanderbilt University Payment Card Processing and PCI Compliance Policy and Procedures Manual PCI Compliance Office Information Technology Treasury VUMC Finance Table of Contents Policy... 2 I. Purpose...

More information

PCI Assessments 3.0 What Will the Future Bring? Matt Halbleib, SecurityMetrics

PCI Assessments 3.0 What Will the Future Bring? Matt Halbleib, SecurityMetrics PCI Assessments 3.0 What Will the Future Bring? Matt Halbleib, SecurityMetrics About Us Matt Halbleib CISSP, QSA, PA-QSA Manager PCI-DSS assessments With SecurityMetrics for 6+ years SecurityMetrics Security

More information

PCI DSS v2.0. Compliance Guide

PCI DSS v2.0. Compliance Guide PCI DSS v2.0 Compliance Guide May 2012 PCI DSS v2.0 Compliance Guide What is PCI DSS? Negative media coverage, a loss of customer confidence, and the resulting loss in sales can cripple a business. As

More information

Frequently Asked Questions

Frequently Asked Questions PCI Compliance Frequently Asked Questions Table of Content GENERAL INFORMATION... 2 PAYMENT CARD INDUSTRY DATA SECURITY STANDARD (PCI DSS)...2 Are all merchants and service providers required to comply

More information