Payment Card Industry (PCI) Qualification Requirements

Size: px
Start display at page:

Download "Payment Card Industry (PCI) Qualification Requirements"

Transcription

1 Payment Card Industry (PCI) Qualificatin Requirements Fr Qualified Integratrs and Resellers (QIRs) Versin 3.0 September 2015

2 Dcument Changes Date Versin Descriptin August Initial release f the PCI Qualificatin Requirements fr QIRs Nvember Minr edits t align with PCI DSS and PA-DSS v3.0; Simplificatin f the applicatin prcess September Minr adjustments t prgram requirements, e.g., allw sle prprietrs t jin the prgram by remving the requirement t have tw trained emplyees n staff at all times PCI Qualificatin Requirements fr QIRs, v 3.0 August PCI Security Standards Cuncil, LLC Page i

3 Table f Cntents Dcument Changes... i 1 Intrductin Terminlgy Dcument Structure Related Publicatins QIR Applicatin Prcess Additinal Infrmatin Requests QIR Cmpany Business Requirements Business Legitimacy Cde f Prfessinal Respnsibility QIR Cmpany Fees QIR Cmpany and QIR Emplyee Capability Requirements QIR Cmpany QIR Emplyees Skills and Experience QIR Cmpany Administrative Requirements Cntact Persn Backgrund Checks Adherence t PCI SSC Prcedures Quality Assurance Prtectin f Cnfidential and Sensitive Infrmatin Retentin f Results QIR Cmpany and QIR Emplyee Requalificatin Requirements Prvisins QIR Remediatin and Revcatin Schedule 1 - Terminlgy Appendix A: QIR Agreement Appendix B. Applicatin Checklist PCI Qualificatin Requirements fr QIRs, v 3.0 August PCI Security Standards Cuncil, LLC Page ii

4 1 Intrductin Organizatins qualified by PCI SSC as Qualified Integratr and Reseller Cmpanies (QIR Cmpanies) are authrized t implement, cnfigure and/r supprt PA-DSS validated Payment Applicatins n behalf f merchants r service prviders fr purpses f perfrming Qualified Installatins as part f the QIR Prgram. The quality, reliability and cnsistency f a QIR Cmpany s wrk prvide cnfidence that the Payment Applicatin has been implemented in a manner that supprts the Custmer s PCI DSS cmpliance. All QIR Cmpanies are identified n the QIR List in accrdance with the QIR Agreement. If a cmpany is nt n the QIR List, it is nt recgnized as a QIR Cmpany by PCI SSC. All cmpanies and individuals seeking t qualify as QIR Cmpanies r QIR Emplyees must satisfy initial qualificatin requirements and requalify with PCI SSC every three years, as detailed further in this dcument. Interested applicants shuld cmplete the nline registratin frm lcated n the PCI Security Standards Cuncil Website (Website). 1.1 Terminlgy Fr purpses f this dcument, capitalized terms used but nt defined herein shall have the meanings set frth in Schedule 1 heret. 1.2 Dcument Structure Sectin 1: Intrductin ffers a high-level verview f the QIR applicatin prcess. Sectin 2: QIR Cmpany Business Requirements cvers minimum business requirements that must be demnstrated t PCI SSC by the cmpany. Sectin 3: QIR Cmpany and QIR Emplyee Capability Requirements reviews the infrmatin and dcumentatin necessary t demnstrate the service qualificatins and expertise f the cmpany and its emplyees. Sectin 4: QIR Cmpany Administrative Requirements fcuses n the lgistics f ding business as a QIR Cmpany, including backgrund checks, adherence t QIR Prgram prcedures, prtectin f cnfidential and sensitive infrmatin, and quality assurance. Sectin 5: QIR Requalificatin briefly utlines the QIR requalificatin prcess. Sectin 6: QIR Remediatin and Revcatin Prcess cntains infrmatin regarding remediatin and revcatin prcedures. Schedules and Appendices: The schedules and appendices t the QIR Qualificatin Requirements include the terminlgy schedule, QIR Agreement and Applicatin Checklist. 1.3 Related Publicatins This dcument shuld be used in cnjunctin with the current versins f the fllwing ther PCI SSC publicatins, each available thrugh the Website: PCI DSS, the PCI SSC standard that sets the fundatin fr ther PCI Standards and related requirements PA-DSS, the PCI SSC standard that defines the specific technical requirements and prvides related assessment prcedures and templates used t validate Payment Applicatin cmpliance and dcument the validatin prcess PCI Qualificatin Requirements fr QIRs, v3.0 September PCI Security Standards Cuncil, LLC Page 1

5 QIR Prgram Guide, the guidance dcument that defines requirements that must be satisfied by all QIR Cmpanies in rder t perfrm Qualified Installatins QIR Implementatin Statement, the template prvided by PCI SSC t dcument the Qualified Installatin. QIR Implementatin Instructins, a cmplementary dcument fr the QIR Implementatin Statement that explains hw t dcument the Qualified Installatin. 1.4 QIR Applicatin Prcess T begin the applicatin prcess a cmpany representative must submit a registratin frm thrugh the Website. Upn receipt f the registratin frm, PCI SSC will send an t the cmpany representative with credentials t access the secure web prtal designated by PCI SSC fr the QIR Prgram (the Prtal ) and begin the applicatin prcess. The cmpany s Primary Cntact (see Sectin belw) will manage the applicatin prcess fr bth the cmpany and any cmpany emplyees seeking QIR Emplyee qualificatin. T facilitate preparatin f the applicatin, refer t Appendix B: Applicatin Checklist. Applicatins must cntain all items listed in Appendix B. All applicatin materials must be submitted in English. Dcumentatin prvided in a language ther than English must be accmpanied by a certified English translatin. In the event a cmpany des nt meet the requirements specified in the QIR Qualificatin Requirements, PCI SSC will ntify the cmpany, and the cmpany will have 30 days frm the date f ntificatin t appeal the decisin. Appeals must be addressed t the PCI SSC General Manager. If a cmpany s appeal is denied, its name will nt be placed n the QIR List. Imprtant Nte: PCI SSC reserves the right t reject any applicatin frm any applicant that PCI SSC determines has cmmitted, within tw (2) years prir t the applicatin date, any cnduct that wuld have been cnsidered a Vilatin (defined in the QIR Prgram Guide) if cmmitted by a QIR Cmpany r QIR Emplyee. The perid f ineligibility will be a minimum f ne (1) year as determined by PCI SSC in a reasnable and nn-discriminatry manner, in light f the circumstances. 1.5 Additinal Infrmatin Requests In an effrt t maintain the integrity f the QIR Prgram, PCI SSC may frm time t time request that QIR Cmpanies and QIR Emplyees submit additinal infrmatin r materials in rder t demnstrate adherence t applicable requirements, as part f the QIR apprval prcess, r as part f PCI SSC's QIR quality assurance initiatives, including but nt limited t remediatin, revcatin and appeals as further described in the QIR Prgram Guide. All such additinal infrmatin and materials must be submitted in English r with a certified English translatin. QIR Cmpanies are required t respnd t each such request with the required infrmatin r dcumentatin n later than three (3) weeks frm receipt f the crrespnding written request r as therwise requested by PCI SSC. 2 QIR Cmpany Business Requirements Each QIR Cmpany must satisfy the fllwing business requirements and prvide the fllwing infrmatin t PCI SSC. PCI Qualificatin Requirements fr QIRs, v3.0 September PCI Security Standards Cuncil, LLC Page 2

6 2.1 Business Legitimacy Requirements The QIR Cmpany must be recgnized as a legal entity Prvisins The fllwing infrmatin must be prvided t PCI SSC: Cpy f business license r equivalent (prf f legal existence frm the relevant jurisdictin; see Business License Requirements n Website). Attestatin that the QIR Cmpany (and QIR Cmpany principals) have n past r present allegatins r cnvictins f any fraudulent r criminal activity against them, r a written statement describing any such allegatins r cnvictins and the status and reslutin theref. 2.2 Cde f Prfessinal Respnsibility Requirements PCI SSC has adpted a PCI SSC Cde f Prfessinal Respnsibility (the Cde, available n the Website) t help ensure that PCI SSC-qualified cmpanies and individuals adhere t high standards f ethical and prfessinal cnduct. All PCI SSC-qualified cmpanies and individuals must advcate, adhere t and supprt the Cde Prvisins The QIR Cmpany must cnfirm the PCI SSC Cde f Prfessinal Respnsibility is advcated, adhered t and supprted by the cmpany. Each QIR Emplyee must accept the PCI SSC Cde f Prfessinal Respnsibility at the beginning f each PCI SSC QIR Training curse. 2.3 QIR Cmpany Fees Requirements All fees payable by QIR Cmpanies in cnnectin with the QIR Prgram ( Fees ) must be paid by check r ther means apprved by PCI SSC. All checks shuld be made payable t PCI SSC and mailed t the fllwing address r as therwise instructed by PCI SSC: PCI Security Standards Cuncil 401 Edgewater Place, Suite 600 Wakefield, MA USA Phne number: (781) QIR Cmpanies are respnsible fr payment f the fllwing Fees as then specified n the Website: PCI Qualificatin Requirements fr QIRs, v3.0 September PCI Security Standards Cuncil, LLC Page 3

7 Training and Exam Fees The Fees a QIR Cmpany will pay are the QIR Training and Exam Fee fr each individual QIR Emplyee they want t have qualified (minimum f ne per QIR Cmpany). The Primary Cntact will receive an invice fr training Fees, and will be respnsible fr payment f that invice befre the trainee receives access t QIR training material. Exam Retake (necessary nly if the QIR Emplyee s previus attempt resulted in failure) There is n limit t the number f times an individual QIR Emplyee can retake the QIR Exam and there is n waiting perid required after each failed attempt. The QIR Cmpany will be assessed the Exam Retake Fee prir t each retake attempt. Requalificatin Requalificatin is required every three years n r befre the QIR Emplyee s qualificatin expiratin date. In rder t requalify, individual QIR Emplyees will need t take the QIR Training and Exam. The Fees a QIR Cmpany will pay are the QIR Training and Exam Fee fr each individual QIR Emplyee they want t have requalify. 3 QIR Cmpany and QIR Emplyee Capability Requirements 3.1 QIR Cmpany QIR Cmpanies must be qualified by PCI SSC and maintain a skilled and trained wrkfrce t prvide secure implementatins f PA-DSS validated Payment Applicatins t merchants and Service Prviders. Only cmpanies qualified by PCI SSC as QIR Cmpanies are listed n the PCI SSC website and authrized t perfrm Qualified Installatins Requirements Nte: All Fees assciated with the QIR Prgram are psted n the Website. All such Fees are nn-refundable, updated annually and subject t change upn ntice frm PCI SSC. Psting f a revised QIR Prgram Fee Schedule n the Website shall be deemed t cnstitute ntice f a Fee change. The QIR Cmpany must be either the direct prvider f a PA-DSS validated Payment Applicatin r a cmpletely independent third party licensed r therwise authrized by a PA-DSS validated Payment Applicatin vendr t implement that Payment Applicatin int the merchant r service prvider envirnment. The QIR Cmpany must have prcesses in place t ensure that its QIR Emplyees are trained and have access t applicable dcumentatin t perfrm Qualified Installatins. Prcesses must include, but are nt limited t, participatin in the training prgram(s) prvided by PCI SSC and the Payment Applicatin vendr(s). The PA-DSS standard requires PA-DSS Payment Applicatin vendrs t maintain instructinal dcumentatin and training prgrams fr integratrs and resellers. The QIR Cmpany must have experience installing and cnfiguring applicatins, preferably Payment Applicatins, equal t at least ne year r three separate engagements. The QIR Cmpany must at all times emply at least ne (1) QIR Emplyee. PCI Qualificatin Requirements fr QIRs, v3.0 September PCI Security Standards Cuncil, LLC Page 4

8 3.1.2 Prvisins The fllwing infrmatin must be prvided t PCI SSC: Cnfirmatin that the QIR Cmpany is either the direct prvider f a PA-DSS validated Payment Applicatin r a cmpletely independent third-party licensed r therwise authrized by the PA-DSS validated Payment Applicatin vendr t implement the Payment Applicatin int the merchant r service prvider envirnment. Cnfirmatin that the QIR Cmpany has prcesses fr ensuring that all f its QIR Emplyees are trained and have access t dcumentatin frm PCI SSC and the Payment Applicatin vendr, including, but nt limited t the PCI DSS and PA-DSS standard and prgram dcumentatin, and Payment Applicatin vendr training and the PA-DSS Implementatin Guide fr each PA-DSS validated Payment Applicatin fr which they intend t perfrm Qualified Installatins. Cnfirmatin f the QIR Cmpany s experience installing r cnfiguring applicatins equal t ne year r three separate engagements. List f the reginal markets and languages supprted by the QIR Cmpany. Acknwledgement that the QIR Cmpany must cntinually emply at least ne (1) QIR Emplyee in rder t be and remain a QIR Cmpany. 3.2 QIR Emplyees Skills and Experience Each QIR Emplyee perfrming r managing any Qualified Installatin must be qualified by PCI SSC. Only individuals qualified by PCI SSC as QIR Emplyees are authrized t perfrm Qualified Installatins. The Lead QIR must be actively engaged fr the duratin f the Engagement and Qualified Installatin. QIR Emplyees are respnsible fr: Perfrming the Qualified Installatin(s). Ensuring the PA-DSS validated Payment Applicatin is installed in a manner cmpliant with the Payment Applicatin vendr s PA-DSS Implementatin Guide, fllwing the best practices f the QIR Prgram Guide, and in a manner that facilitates Custmers PCI DSS cmpliance. Prducing the QIR Implementatin Statement Requirements All QIR Emplyee(s) perfrming r managing Qualified Installatins fr a given QIR Cmpany must: Have sufficient applicatin installatin and system hardening knwledge and experience t cnduct technically cmplex applicatin installatins. Be knwledgeable regarding the QIR Prgram Guide. Be knwledgeable f apprpriate cntents f the PA-DSS Implementatin Guide(s) fr the Payment Applicatin(s) they implement. Be trained in and have up-t-date knwledge f the PA-DSS validated Payment Applicatin(s) they implement, and perfrm such implementatin(s) in accrdance with applicable QIR Requirements. PCI Qualificatin Requirements fr QIRs, v3.0 September PCI Security Standards Cuncil, LLC Page 5

9 Attend requisite QIR Prgram training, and legitimately pass, f his r her wn accrd withut any unauthrized assistance, all requisite QIR Prgram training examinatins. QIR Emplyees wh fail t pass such exams must nt lead r manage any Qualified Installatin until passing such exams. Be emplyees f the QIR Cmpany (meaning this wrk cannt be subcntracted t nnemplyees) r permitted subcntractrs apprved in writing by PCI SSC. Apprved subcntractrs shall nt be permitted t include a cmpany lg ther than that f the respnsible QIR Cmpany r any reference t anther cmpany in the QIR Implementatin Statement dcuments while perfrming wrk n behalf f the QIR Cmpany Prvisins The fllwing infrmatin must be prvided t PCI SSC fr each individual seeking qualificatin as a QIR Emplyee: Wrk histry, such as a Résumé r Curriculum Vitae, that includes relevant wrk experience and respnsibilities in Payment Applicatin installatins, system hardening, system integratin, netwrk security, etc., and wrk experience related t the payment industry. 4 QIR Cmpany Administrative Requirements 4.1 Cntact Persn Requirements The QIR Cmpany must designate a primary cntact persn fr QIR Prgram purpses. The primary cntact shall serve as the QIR Cmpany s sle pint f cntact fr all QIR cmmunicatins t PCI SSC in cnnectin with the QIR Prgram, and may be changed in accrdance with the QIR Agreement Prvisins The fllwing cntact infrmatin must be prvided t PCI SSC, fr the primary cntact: Name Jb Title Address Phne number address 4.2 Backgrund Checks Requirements The QIR Cmpany must perfrm backgrund checks (as described in Sectin 4.2.2) n all QIR Emplyees, if legally permitted within the applicable jurisdictin. Upn request, the QIR Cmpany must prvide t PCI SSC the backgrund check histry fr each QIR Emplyee, if legally permitted within the applicable jurisdictin. PCI Qualificatin Requirements fr QIRs, v3.0 September PCI Security Standards Cuncil, LLC Page 6

10 4.2.2 Prvisins The QIR must prvide the fllwing t PCI SSC: Cnfirmatin that the QIR Cmpany cnducts backgrund checks fr each emplyee: Backgrund checks must be cmpleted prir t submitting emplyee qualificatin requests t PCI SSC. QIR Emplyees must successfully pass the backgrund check in accrdance with the QIR Cmpany s plicies and prcedures (where legally permitted). Examples f backgrund checks include previus emplyment histry, criminal recrd, credit histry and reference checks. Cnfirmatin that the QIR Cmpany backgrund checks include each f the fllwing (t the extent legally permissible in the applicable jurisdictin): Gathering f current phtgraphs Verificatin f aliases (when applicable) Annual review f recrds f any criminal activity, arrests r cnvictins Autmatic disqualificatin frm QIR Emplyee cnsideratin f individuals wh have cmmitted any felny r crime invlving financial fraud r frgery 4.3 Adherence t PCI SSC Prcedures Implementatin Statements Fr each Qualified Installatin, the resulting QIR Implementatin Statement must fllw the instructins set frth in the QIR Prgram Guide. Each QIR Implementatin Statement must be prepared by a QIR Emplyee and be based n the results f the Qualified Installatin in accrdance with the QIR Prgram Guide. If clarificatin n the intent f any questin in the QIR Implementatin Statement is needed, the QIR Implementatin Instructins shuld be used as a reference guide Marketing S lng as a QIR Cmpany cntinues t appear n the QIR List, in advertising and/r prmting its Services it may refer t its listing n the QIR List and t its qualificatin by PCI SSC as a QIR Cmpany. Withut prir PCI SSC apprval in each instance, hwever, a QIR Cmpany is required nt t: (a) use any trademark, service mark, lg r similar designatin (each a Mark ) f PCI SSC; (b) make any statement cnstituting an implied r express endrsement, recmmendatin r warranty by PCI SSC regarding itself, its Services r any related prducts r services; (c) make any false r misleading statement regarding, r misrepresent the requirements f, PCI SSC, any Participating Payment Brand r any f the PCI Materials; (d) state r imply that any f the PCI Materials (r cmpliance therewith) require usage f any f its prducts r services; r (e) publish r therwise make available any statement, material r prduct (in any frm) that refers t r includes any PCI Materials r prtin theref, r any name r acrnym f PCI SSC r any PCI SSC standard (except fr brief references t PCI SSC and/r its standards (r crrespnding acrnyms) t the extent reasnably necessary fr purpses f describing, marketing r prmting its Services). PCI Qualificatin Requirements fr QIRs, v3.0 September PCI Security Standards Cuncil, LLC Page 7

11 4.4 Quality Assurance Requirements The QIR Cmpany must have implemented a quality assurance prgram as described in Sectin 4.4.2, and upn request, prvide a cpy f its Quality Manual (defined in the QIR Prgram Guide and further described belw) t PCI SSC. The QIR Cmpany must prvide a QIR Feedback Frm t each Custmer at the start f the installatin. The QIR Cmpany must adhere t all quality assurance requirements mandated by PCI SSC. The QIR Cmpany must permit PCI SSC t cnduct audits f any QIR prgram-related requirement at the discretin f PCI SSC Prvisins The QIR Cmpany must prvide the fllwing t PCI SSC: Cntact infrmatin fr the QIR Cmpany s designated quality assurance manager (wh may be the same as the primary cntact), as fllws: Name Jb Title Address Phne number address Cnfirmatin that the QIR Cmpany has a Quality Manual that cmplies with the requirements set frth in the QIR Prgram Guide and include, at a minimum, the fllwing: A reference t the QIR Cmpany s installatin prcedures r details f the installatin prcesses. A reference t prcedures r details f prcesses fr emplyees and cntractrs with access t Custmer sites t strictly fllw secure access, installatin, maintenance and supprt prcesses included in the PA-DSS Implementatin Guide fr each validated Payment Applicatin. Apprpriate requirements, prcesses and/r prcedures t ensure the prper dcumentatin f all installatin results. A requirement fr the Lead QIR t cmplete the QIR Implementatin Statement and sign the cmpleted dcument. A requirement fr a quality review f all QIR Implementatin Statements. A requirement that all QIR Emplyees must adhere t the QIR Prgram Guide. A requirement fr a prcess t manage security vilatins. A prcess t maintain cpies f training recrds cnfirming that QIR Emplyees, befre being assigned t a Qualified Installatin, have received requisite QIR Prgram training. A requirement fr QIR emplyees t dcument within the QIR Implementatin Statement and ntify the Custmer r service prvider f any areas that are nt implemented in accrdance with PCI DSS. PCI Qualificatin Requirements fr QIRs, v3.0 September PCI Security Standards Cuncil, LLC Page 8

12 4.5 Prtectin f Cnfidential and Sensitive Infrmatin Requirements The QIR Cmpany must maintain adequate physical, electrnic and prcedural safeguards cnsistent with industry-accepted practices t prtect sensitive and cnfidential infrmatin against any threats r unauthrized use r access, during strage, prcessing, cmmunicatin r therwise, including withut limitatin, payment card accunt numbers, cardhlder data, payment card transactin infrmatin, infrmatin relating natural persns that culd be used t identify such persns, and any ther infrmatin received by the QIR Cmpany in cnnectin with remediatin r ther Prgram activities that is nt readily publicly available. The QIR Cmpany must adhere t all requirements t such prtect sensitive and cnfidential infrmatin, as required by the applicable Custmer, PCI SSC r Participating Payment Brands. T the extent the QIR Cmpany stres, prcesses r transmits any data t which the PCI DSS applies, the QIR Cmpany shall be required t be certified as cmpliant with the PCI DSS and shall, at its sle cst and expense: (a) cnduct r have cnducted the audits required fr PCI DSS cmpliance; and (b) take all actins required t maintain PCI DSS cmpliance Prvisins The QIR must prvide the fllwing: Cnfirmatin that the QIR Cmpany has implemented and cmplies with apprpriate practices fr prtecting and handling all such cnfidential and sensitive data, including at a minimum the fllwing physical, electrnic, and prcedural safeguards: Systems string Custmer data d nt reside n Internet-accessible systems. Prtectin f systems string Custmer data by adequate netwrk and applicatinlayer cntrls, including a firewall and IDS/IPS. The fllwing physical and lgical access cntrls: Restricted access (e.g., via lcks) t the physical ffice space. Restricted access (e.g., via lcked file cabinets) t paper files. Restricted lgical access t electrnic files via rle-based access cntrl. Encryptin f sensitive Custmer infrmatin when transmitted ver the Internet either by r ther means. Secure transprt and strage f backup media. Encryptin f Custmer data n QIR emplyee laptps. Prcesses t ensure emplyees and cntractrs maintain the cnfidentiality and restrict the use f all such sensitive and cnfidential infrmatin, including written and executed cnfidentiality agreements. PCI Qualificatin Requirements fr QIRs, v3.0 September PCI Security Standards Cuncil, LLC Page 9

13 4.6 Retentin f Results Requirements The QIR Cmpany must maintain recrds f Qualified Installatins. These recrds must: Be retained fr a minimum f three (3) years frm the cmpletin f each Qualified Installatin. The QIR Cmpany must secure (in accrdance with 4.5 abve) and maintain dcumented evidence (whether in digital r hard cpy frmat) f cmpliance with all requirements f the PA-DSS Implementatin Guide, including but nt limited t cpies f cnfiguratin and ther installatin reprts and settings, results, and related wrk papers, ntes, and technical infrmatin created and/r btained during the applicable Qualified Installatin. Fr a list f acceptable frms f evidence, please see the QIR Prgram Guide. Adhere t all evidence-retentin requirements required by PCI SSC. Be available upn request by PCI SSC, PFIs and Participating Payment Brands fr the time perid specified in the QIR Prgram Guide, even if the QIR Cmpany leaves the QIR Prgram Prvisins The QIR Cmpany must prvide t PCI SSC: Cnfirmatin that the QIR Cmpany has a retentin plicy r retentin schedule that cvers the requirements in Sectin A cpy f the QIR Cmpany s recrd retentin plicy r schedule upn request. 5 QIR Cmpany and QIR Emplyee Requalificatin 5.1 Requirements All QIR Cmpanies and QIR Emplyees must requalify with PCI SSC every three (3) years, based n the QIR Cmpany s riginal qualificatin date. Requalificatin is cntingent n: Payment f applicable Fees. The Cmpany maintaining internal prcesses fr managing emplyee training. Successful cmpletin f QIR training prvided by PCI SSC, which includes passing the exam. QIR Emplyees cmpleting the required Cntinued Prfessinal Educatin (CPE) credits. Psitive Feedback frm Custmers, PCI SSC and Participating Payment Brands. 5.2 Prvisins The fllwing must be prvided t PCI SSC and/r will be cnsidered by PCI SSC during the requalificatin prcess fr bth the QIR Cmpany and QIR Emplyees: Payment f all applicable QIR Training and Exam Fees (including requalificatin Fees). Cnfirmatin that the QIR Cmpany has internal prcesses t rutinely educate QIR Emplyees n the apprpriate methds and techniques t install and cnfigure the validated Payment Applicatin(s) that the QIR Cmpany is authrized t implement. PCI Qualificatin Requirements fr QIRs, v3.0 September PCI Security Standards Cuncil, LLC Page 10

14 Prf f cmpleted CPE hurs fr the minimum number f hurs required per year as specified in the CPE Maintenance Guide n the Website. CPE hurs must be reprted t PCI SSC at the end f each year prir t the qualificatin anniversary date. Apprved methds fr btaining and reprting CPE credit are dcumented in the CPE Maintenance Guide. 6 QIR Remediatin and Revcatin Each QIR Cmpany and QIR Emplyee must satisfy applicable QIR Requirements and meet prescribed quality levels fr Qualified Installatins, t remain in Gd Standing. Failure t satisfy applicable requirements r meet applicable quality levels may result in remediatin and/r revcatin. The QIR Prgram Guide prvides mre details n remediatin and revcatin. PCI Qualificatin Requirements fr QIRs, v3.0 September PCI Security Standards Cuncil, LLC Page 11

15 Schedule 1 - Terminlgy Fr purpses f this Agreement, the QIR Qualificatin Requirements, and the QIR Prgram Guide, the fllwing terms shall have the fllwing meanings when capitalized: Term Custmer Engagement Glssary Gd Standing Lead QIR PA-DSS PA-DSS Implementatin Guide Participating Payment Brand Payment Applicatin PCI DSS Meaning A merchant r ther entity by r fr which a given QIR Cmpany has been engaged t perfrm a Qualified Installatin. The entire cmmitment f services, as specified in the cntractual agreement between a QIR Cmpany and its Custmer, t prvide a Qualified Installatin and any nging supprt activities required t maintain the PA-DSS validated Payment Applicatin in a manner which facilitates PCI DSS cmpliance. The current versin f (r successr dcument t) the Payment Card Industry (PCI) Data Security Standard Glssary, Abbreviatins and Acrnyms available n the Website. (a) With respect t a given QIR Cmpany, that the QIR Agreement between the QIR Cmpany and PCI SSC is in full frce and effect, the QIR Cmpany has been apprved by PCI SSC as a QIR Cmpany and such apprval has nt been revked, terminated, suspended, cancelled r withdrawn, the QIR Cmpany is in cmpliance with all QIR Cmpany Requirements, and the QIR Cmpany is nt in breach f any f the terms r cnditins f remediatin, its QIR Agreement (including withut limitatin, all prvisins regarding cmpliance with the QIR Qualificatin Requirements and payment), r any ther agreement with PCI SSC; and (b) With respect t a given QIR Emplyee, that the QIR Emplyee is in cmpliance with all QIR Emplyee Requirements. In regard t a given Qualified Installatin, the key QIR Emplyee leading the Engagement fr the QIR Cmpany The then current versin f the Payment Card Industry (PCI) Payment Applicatin Data Security Standard Requirements and Security Assessment Prcedures (r successr dcument theret), as made publicly available by PCI SSC n the Website. An implementatin guide prepared by the applicable Payment Applicatin vendr fr a given Payment Applicatin (required pursuant t the PA- DSS). A glbal payment card brand r scheme that is als a limited liability cmpany member f PCI SSC (r affiliate theref). A sftware applicatin used in cnnectin with the strage, prcessing r transmissin f cardhlder data. The then current versin f the Payment Card Industry (PCI) Data Security Standard Requirements (r successr dcument theret), as made publicly available by PCI SSC n the Website. PCI Qualificatin Requirements fr QIRs, v3.0 September PCI Security Standards Cuncil, LLC Page 12

16 Term PCI Materials PCI SSC PFI (r PCI Frensic Investigatr) QIR Agreement QIR Cmpany (r Qualified Integratr and Reseller Cmpany) QIR Cmpany Requirements QIR Emplyee QIR Emplyee Requirements QIR Feedback Frm QIR Implementatin Statement QIR Installatin QIR List QIR Prgram QIR Prgram Fee Schedule Meaning The PCI DSS, PA-DSS, QIR Qualificatin Requirements, QIR Prgram Guide, QIR Prgram training materials, Website and all related and ther materials prvided r therwise made accessible by PCI SSC in cnnectin with the QIR Prgram. PCI Security Standards Cuncil, LLC, a Delaware limited liability cmpany. An entity apprved as a PCI Frensic Investigatr by PCI SSC t perfrm frensic investigatins as part f the PCI SSC PCI Frensic Investigatr Prgram. A list f PFIs appears n the Website. The QIR Agreement attached as Appendix A t the QIR Qualificatin Requirements. Refers t a cmpany that has satisfied and cntinues t satisfy all requirements set frth in the QIR Qualificatin Requirements, QIR Prgram Guide and QIR Agreement and is thereby qualified t implement, cnfigure, r supprt PA-DSS validated Payment Applicatins n behalf f Custmers. The requirements applicable t QIR Cmpanies and the prvisins required f QIR Cmpanies as set ut in the QIR Qualificatin Requirements, and such additinal requirements as PCI SSC may establish fr QIR Cmpanies frm time t time in cnnectin with the QIR Prgram. A full-time emplyee f a QIR Cmpany wh has been apprved as a QIR Emplyee and is in cmpliance with all QIR Emplyee Requirements. The requirements applicable t QIR Emplyees as set ut in the QIR Qualificatin Requirements, and such additinal requirements as PCI SSC may establish fr QIR Emplyees frm time t time in cnnectin with the QIR Prgram. The then current versin f (r successr dcument t) the QIR Feedback Frm fr Payment Brands and Others, as made publicly available by PCI SSC n the Website. The reprt prvided t a Custmer upn cmpletin f the rendering f a Qualified Installatin. The installatin f a PA-DSS validated Payment Applicatin within a Custmer s cardhlder data envirnment (defined in the Glssary), cnducted by a QIR Cmpany acting in that capacity. The list f QIR Cmpanies maintained n the Website. The PCI SSC Qualified Integratrs and Resellers Prgram managed by PCI SSC, as further described herein and in the QIR Prgram Guide and related PCI SSC guidance and publicatins. The then current schedule f Fees payable by QIR Cmpanies in cnnectin with participatin in the QIR Prgram, as made publicly available by PCI SSC n the Website. PCI Qualificatin Requirements fr QIRs, v3.0 September PCI Security Standards Cuncil, LLC Page 13

17 Term QIR Prgram Guide QIR Qualificatin Requirements QIR Requirements Qualified Installatin Services Website Meaning The then current versin f the Payment Card Industry (PCI) Qualified Integratrs and Resellers (QIRs) Prgram Guide (r successr dcument theret), as made publicly available by PCI SSC n the Website. With respect t a given QIR Cmpany, the then mst current versin f (r successr dcument t) the Payment Card Industry (PCI) Qualificatin Requirements Fr Qualified Integratrs and Resellers (QIRs), as made publicly available n the Website and amended by PCI SSC frm time t time in its sle discretin, all supplements and addenda theret, and any and all related agreements and/r undertakings applicable t a such QIR Cmpany in cnnectin with the QIR Prgram. With respect t a given QIR Cmpany, the requirements and bligatins theref pursuant t the QIR Qualificatin Requirements, the QIR Agreement and the QIR Prgram Guide, each addendum and supplement t each f the freging, each agreement entered int between such QIR Cmpany and PCI SSC, and any and all ther plicies, prcedures, requirements r bligatins impsed, mandated, prvided fr r therwise established by PCI SSC frm time t time in cnnectin with any PCI SSC prgram in which such QIR Cmpany is then a participant, including but nt limited t, the requirements f all applicable PCI SSC training prgrams, quality assurance and remediatin prgrams, prgram guides and ther related PCI SSC prgram materials. The installatin and/r cnfiguratin f a PA-DSS validated Payment Applicatin fr purpses f cmpliance with the applicable PA-DSS Implementatin Guide and the QIR Prgram Guide as part f the QIR Prgram. The QIR Installatins and all related services perfrmed by a given QIR Cmpany t PCI SSC, the QIR Cmpany s Custmers r thers in cnnectin with the QIR Agreement and the QIR Prgram The PCI SSC website at PCI Qualificatin Requirements fr QIRs, v3.0 September PCI Security Standards Cuncil, LLC Page 14

18 Appendix A: QIR Agreement This dcument (the Agreement ) is a legally binding agreement between PCI Security Standards Cuncil, LLC ("PCI SSC") and QIR (defined belw), effective as f the date PCI SSC ntifies QIR that QIR s applicatin and registratin fr qualificatin as a QIR Cmpany have been apprved (the Effective Date ). Fr purpses heref, QIR is the cmpany, rganizatin r ther legal entity that, thrugh its individual representative(s), was identified t PCI SSC in the QIR Registratin Frm infrmatin submitted t PCI SSC thrugh the nline QIR Cmpany registratin page n the Website, received a link prviding access t this Agreement frm PCI SSC, and clicks ACCEPT belw. By clicking ACCEPT belw, the individual ding s: (i) represents and warrants t PCI SSC that s/he is authrized t legally bind QIR t the terms heref and (ii) fr gd and valuable cnsideratin, the receipt and sufficiency f which is acknwledged, agrees n QIR s behalf that (a) QIR has read, understands, and accepts, agrees t and is legally bund by the terms heref, (b) PCI SSC may reject r terminate this Agreement if QIR fails t satisfy applicable QIR Requirements, and (c) capitalized terms used but nt defined herein shall have the meanings in Schedule 1 t the Payment Card Industry (PCI) Qualificatin Requirements fr Qualified Integratrs and Resellers (QIRs) as available at (the Website ). 1. QIR Qualificatin; Listing; Primary Cntact. During the Term (defined belw): (a) QIR is hereby qualified by PCI SSC t perfrm Qualified Installatins subject t applicable QIR Requirements, and (B) PCI SSC is authrized t display QIR s name and QIR Cmpany qualificatin status infrmatin n the QIR List and incrprate int QIR s listing n the QIR List such QIR trademarks as (and in the manner) QIR has designated fr such purpse. QIR acknwledges and agrees that in the event PCI SSC determines in its sle but reasnable discretin that QIR meets any cnditin fr remediatin r revcatin (defined in the QIR Prgram Guide), PCI SSC may, upn ntice, ffer QIR the pprtunity t participate in remediatin, revke QIR's QIR Cmpany qualificatin, anntate r remve the listing f QIR n the QIR List, and/r terminate this Agreement. QIR hereby designates the individual identified t PCI SSC as QIR s Primary Cntact as part f the QIR registratin prcess t serve as QIR s sle pint f cntact all QIR Prgram cmmunicatins t PCI SSC. 2. QIR Requirements. During the Term, QIR agrees t cmply with all QIR Requirements, including but nt limited t the plicies, prcedures, terms and cnditins set frth in the QIR Qualificatin Requirements r the QIR Prgram Guide, and thse therwise established by PCI SSC in cnnectin with applicable QIR Prgram quality assurance initiatives and remediatin prcedures. 3. QIR Representatins. QIR hereby represents and warrants that it: (a) is in cmpliance with all applicable QIR Requirements; (b) will cmply with all applicable laws, rdinances, rules and regulatins pertaining t this Agreement r its bligatins hereunder during the Term; and (c) will ensure t its best knwledge that all infrmatin it prvides t PCI SSC is and remains accurate and cmplete. 4. Limitatin f Liability; Indemnificatin. A. PCI SSC EXPRESSLY DISCLAIMS ANY AND ALL REPRESENTATIONS OR WARRANTIES, EXPRESS OR IMPLIED, WITH RESPECT TO THE QIR PROGRAM, THE PCI MATERIALS, THIS AGREEMENT OR THE SUBJECT MATTER HEREOF, INCLUDING BUT NOT LIMITED TO, IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE AND WARRANTIES OF TITLE AND NON-INFRINGEMENT. B. EXCEPT FOR DAMAGES CAUSED BY A PARTY S GROSS NEGLIGENCE OR WILLFUL MISCONDUCT OR AS PROVIDED IN SECTION 4.C, IN NO EVENT SHALL: (I) EITHER PARTY BE LIABLE TO THE OTHER FOR ANY CONSEQUENTIAL, INCIDENTAL, INDIRECT, PUNITIVE OR SPECIAL DAMAGES OR FOR ANY DAMAGES AS A RESULT OF LOSS OF BUSINESS, REVENUE, GOODWILL, OR OTHER COMMERCIAL OR ECONOMIC LOSS, TO THE EXTENT ARISING OUT OF OR IN CONNECTION WITH THE QIR PROGRAM, THE PCI MATERIALS, THIS AGREEMENT OR THE SUBJECT MATTER HEREOF, HOWEVER CAUSED, WHETHER UNDER THEORY OF CONTRACT, TORT (INCLUDING NEGLIGENCE) OR OTHERWISE, EVEN IF ADVISED OF THE POSSIBILITY OF PCI Qualificatin Requirements fr QIRs, v 3.0 September PCI Security Standards Cuncil, LLC Page 15

19 SUCH DAMAGES; OR (II) THE AGGREGATE LIABILITY OF EITHER PARTY TO THE OTHER UNDER OR IN CONNECTION WITH THE QIR PROGRAM, THE PCI MATERIALS, THIS AGREEMENT OR THE SUBJECT MATTER HEREOF EXCEED THE AMOUNT OF FEES PAID TO PCI SSC HEREUNDER. C. QIR shall defend, indemnify, and hld harmless PCI SSC and its fficers, directrs, members, emplyees, agents, representatives, cntractrs, attrneys, successrs, and assigns (cllectively, "Indemnified Parties") frm and against any and all claims, lsses, liabilities, damages, suits, actins r prceedings (including withut limitatin, reasnable attrney's fees and related csts) (cllectively, Claims ) arising r resulting frm any claim by any third party regarding QIR s (i) breach f any warranty, representatin r agreement herein; r (ii) perfrmance r nn-perfrmance f the Services; prvided, hwever, that QIR s bligatins pursuant t this Sectin 4.C shall nt apply t any Claim t the extent arising frm the negligence r willful miscnduct f an Indemnified Party r any defect in the PCI SSC Materials t the extent used by QIR withut mdificatin and fr their intended purpse. 5. Term and Terminatin. This Agreement shall cmmence as f the Effective Date, remain in full frce and effect fr a perid until terminated pursuant t this Sectin (the Term ), and may be terminated (a) by QIR upn ntice r (b) by PCI SSC (i) as f the end f any calendar year f the Term upn at least sixty (60) days ntice; (ii) upn ntice in cnnectin with (A) any vluntary r invluntary bankruptcy, receivership, rerganizatin, disslutin r liquidatin f QIR that is nt therwise dismissed within thirty (30) days, (B) QIR's breach f any representatin r warranty under this Agreement, (C) Revcatin f QIR s QIR Cmpany qualificatin, r (D) failure f QIR t satisfy applicable QIR Cmpany re-qualificatin requirements in accrdance with QIR Prgram plicy and prcedure; r (iii) upn fifteen (15) days ntice in the event f QIR's breach f any ther prvisin heref that is nt cured within such 15-day perid. Sectins 4, 6, 7 and 8 f this Agreement and Sectin f the QIR Prgram Guide shall any survive terminatin f this Agreement. 6. Cnfidentiality and Required Disclsures; Use f Marks. QIR hereby acknwledges and agrees t cmply with the cnfidentiality and required disclsure prvisins set frth in the QIR Qualificatin Requirements. T help ensure its ability t prmptly make such required disclsures, QIR shall ensure that its written agreements with each Custmer permit QIR t make such disclsures t PCI SSC, in accrdance with the QIR Qualificatin Requirements. 7. Ntices. Ntices hereunder shall be in writing and deemed effective when delivered persnally, r by vernight curier upn verificatin f receipt, r by facsimile transmissin upn electrnic cnfirmatin f transmissin, r by certified r registered mail, return receipt requested, five (5) days after the mailing date. Ntices t QIR shall be sent t its Primary Cntact at the address specified fr QIR during QIR Cmpany registratin n the Website. Ntices t PCI SSC shall be sent t PCI SSC, attentin: General Manager, at 401 Edgewater Place, Suite 600, Wakefield, Massachusetts A party heret may change its cntact r address fr ntices and/r its Primary Cntact by ntice in accrdance with this Sectin. Ntwithstanding the freging, PCI SSC may prvide any ntice under this Agreement by electrnic mail transmissin t QIR s last designated Primary Cntact r by psting t the QIR Prgram Prtal, which ntice shall be deemed effective immediately thereafter. 8. General. This Agreement is gverned by the laws f the State f Delaware, withut resrt t its cnflict f laws prvisins. If any prvisin heref is r is determined t be vid, invalid r unenfrceable, the validity f the remaining prvisins shall nt be affected thereby. This Agreement (including the QIR Qualificatin Requirements and QIR Prgram Guide, each hereby incrprated int and made a part f this Agreement) sets frth the exclusive agreement between the parties with respect t its subject matter, and supersedes and merges all prir understandings and agreements, ral r written, between the parties with respect t such subject matter. This Agreement may be mdified, altered r amended by PCI SSC upn thirty (30) days ntice, prvided, that if QIR des nt agree with such mdificatin, alteratin r amendment, QIR may terminate this Agreement upn ntice t PCI SSC within such thirty (30) day perid, and therwise, such mdificatin, alteratin r amendment will be effective as f the end f such 30-day perid. The waiver r failure f either party heret t exercise any right prvided fr PCI Qualificatin Requirements fr QIRs, v 3.0 September PCI Security Standards Cuncil, LLC Page 16

20 in this Agreement shall nt be deemed a waiver f any further right. QIR may nt assign this Agreement, r assign, delegate r subcntract any f its rights r bligatins hereunder, withut PCI SSC s prir written cnsent. All remedies herein are cumulative, in additin t any ther remedies available at law r in equity, subject nly t the express limitatins n liabilities and remedies set frth herein. In the event f an express cnflict between this Agreement and the QIR Qualificatin Requirements r the QIR Prgram Guide, this Agreement shall cntrl. PCI Qualificatin Requirements fr QIRs, v 3.0 September PCI Security Standards Cuncil, LLC Page 17

21 Appendix B. Applicatin Checklist This Appendix prvides a checklist f items that the applicant QIR Cmpany ( Cmpany ) and its applicant QIR Emplyees ( Emplyees ) will need t prvide, cmplete r d during the QIR Prgram applicatin prcess. The applicatin can be fund nline in the Prtal. Secure access t the Prtal will be prvided during the applicatin prcess. Cmpany Applies t QIR Prgram PA-DSS Vendr Authrizatin The Cmpany must cnfirm that it is either a direct prvider f a PA-DSS validated Payment Applicatin r a cmpletely independent third party licensed r therwise authrized by a PA-DSS validated Payment Applicatin vendr t implement that Payment Applicatin int the merchant r service prvider envirnment. Direct prvider f a PA-DSS validated Payment Applicatin Independent third party license r therwise authrized by the PA-DSS validated Payment Applicatin vendr t implement the validated Payment Applicatin int the Custmer r service prvider envirnment QIR Agreement The Cmpany must accept the QIR Agreement. Fees Primary Cntact Infrmatin Markets Languages Attestatin Cmpleted The Cmpany must pay all applicable Fees (see QIR Prgram Fee Schedule n Website) prir t qualificatin, payable t PCI SSC. The Cmpany must identify a Primary Cntact and include all cntact details. The Primary Cntact is the individual that will receive all Cuncil cmmunicatins and will be the liaisn between the QIR Cmpany/Emplyee and PCI SSC. The Cmpany must identify all reginal markets served. The Cmpany must identify all supprted languages. The Cmpany must cnfirm that it (and its principles) have n past r present allegatins r cnvictins f any fraudulent r criminal activity against them, r prvide a written statement describing any such allegatins r cnvictins and the status and reslutin theref. The Cmpany must cnfirm experience in infrmatin technlgy and experience in installing and cnfiguring applicatins, preferably Payment Applicatins, equal t at least ne year r three separate engagements The Cmpany must cnfirm that it has prcesses in place fr ensuring all QIR Emplyees are trained in and maintain up-t-date knwledge abut the PA-DSS validated Payment Applicatin(s) fr which they will be perfrming Qualified installatins. (This training may have ccurred prir t the QIR Applicatin prcess.) The Cmpany must cnfirm that it perfrms persnnel backgrund checks (t the extent legally permissible in the applicable jurisdictin) and that each QIR emplyee has successfully cmpleted the backgrund check. PCI Qualificatin Requirements fr QIRs, v 3.0 September PCI Security Standards Cuncil, LLC Page 18

22 The Cmpany must agree that it emplys a minimum f ne (1) QIR Emplyee at all time, in rder t becme and remain listed as a QIR Cmpany n the PCI SSC Website. The Cmpany must cnfirm that it has incrprated the fllwing int a Quality Manual as defined in sectin f the QIR Qualificatin Requirements: A reference t the QIR Cmpany s installatin prcedures r details f the installatin prcesses. A reference t prcedures r details f prcesses fr emplyees and cntractrs with access t Custmer sites t strictly fllw secure access, installatin, maintenance and supprt prcesses included in the PA-DSS Implementatin Guide fr each validated Payment Applicatin. Business License Webpage Link Apprpriate requirements, prcesses and/r prcedures t ensure the prper dcumentatin f all installatin results. A requirement fr the Lead QIR t cmplete the QIR Implementatin Statement and sign the cmpleted dcument. A requirement fr quality review f all QIR Implementatin Statements. A requirement that all QIR Emplyees must adhere t the QIR Prgram Guide A requirement fr a prcess t manage security vilatins. A requirement t maintain cpies f training recrds cnfirming that each QIR Emplyee, befre being assigned t a Qualified Installatin, has received requisite QIR Prgram training. A requirement fr QIR Emplyees t dcument within the QIR Implementatin Statement and ntify the Custmer r service prvider f any areas that are nt implemented in accrdance with PCI DSS. The Cmpany must uplad a cpy f its business license (See Business License Requirements n Website) The Cmpany must prvide the URL fr its webpage. Emplyees Apply t QIR Prgram Wrk Histry, Résumé, Curriculum Vitae Training Registratin The Primary Cntact must uplad a cpy f each applicant QIR Emplyee s Wrk Histry, Résumé r Curriculum Vitae that includes relevant wrk experience and respnsibilities in installatins, system hardening, netwrk security, etc., and wrk experience related t the payment industry. Once the Primary Cntact has cmpleted the Emplyee Applicatin, the PCI SSC QIR Prgram Manager will register the Emplyee fr training. The Primary Cntact will receive an invice fr training fees, and will be respnsible fr payment f that invice befre the trainee receives access t QIR training material. PCI Qualificatin Requirements fr QIRs, v 3.0 September PCI Security Standards Cuncil, LLC Page 19

23 Cde f Prfessinal Respnsibility QIR Training and Exam The Emplyee must agree t supprt the Cde f Prfessinal Respnsibility. This agreement is intrduced at the beginning f the nline training curse. The Emplyee will electrnically agree t the Cde. The Emplyee must cmplete QIR Training and successfully pass the training exam. PCI Qualificatin Requirements fr QIRs, v 3.0 September PCI Security Standards Cuncil, LLC Page 20

Payment Card Industry (PCI) Qualified Integrators and Resellers

Payment Card Industry (PCI) Qualified Integrators and Resellers Payment Card Industry (PCI) Qualified Integratrs and Resellers Prgram Guide Versin 3.0 September 2015 Dcument Changes Date Versin Descriptin August 2012 1.0 Initial release f the PCI Qualified Integratrs

More information

University of Texas at Dallas Policy for Accepting Credit Card and Electronic Payments

University of Texas at Dallas Policy for Accepting Credit Card and Electronic Payments University f Texas at Dallas Plicy fr Accepting Credit Card and Electrnic Payments Cntents: Purpse Applicability Plicy Statement Respnsibilities f a Merchant Department Prcess t Becme a Merchant Department

More information

VCU Payment Card Policy

VCU Payment Card Policy VCU Payment Card Plicy Plicy Type: Administrative Respnsible Office: Treasury Services Initial Plicy Apprved: 12/05/2013 Current Revisin Apprved: 12/05/2013 Plicy Statement and Purpse The purpse f this

More information

expertise hp services valupack consulting description security review service for Linux

expertise hp services valupack consulting description security review service for Linux expertise hp services valupack cnsulting descriptin security review service fr Linux Cpyright services prvided, infrmatin is prtected under cpyright by Hewlett-Packard Cmpany Unpublished Wrk -- ALL RIGHTS

More information

DisplayNote Technologies Limited Data Protection Policy July 2014

DisplayNote Technologies Limited Data Protection Policy July 2014 DisplayNte Technlgies Limited Data Prtectin Plicy July 2014 1. Intrductin This dcument sets ut the bligatins f DisplayNte Technlgies Limited ( the Cmpany ) with regard t data prtectin and the rights f

More information

Multi-Year Accessibility Policy and Plan for NSF Canada and NSF International Strategic Registrations Canada Company, 2014-2021

Multi-Year Accessibility Policy and Plan for NSF Canada and NSF International Strategic Registrations Canada Company, 2014-2021 Multi-Year Accessibility Plicy and Plan fr NSF Canada and NSF Internatinal Strategic Registratins Canada Cmpany, 2014-2021 This 2014-21 accessibility plan utlines the plicies and actins that NSF Canada

More information

Cyber Security: Simulation Platform

Cyber Security: Simulation Platform Service Overview The Symantec Cyber Security: Simulatin Platfrm is a Web hsted Service with immersive and hands-n access t cyber exercises fr ffensive (red team) events, inspired by real-life security

More information

Privacy and Security Training Policy (PS.Pol.051)

Privacy and Security Training Policy (PS.Pol.051) Privacy and Security Training Plicy (PS.Pl.051) Purpse T define the plicies and prcedures fr prviding privacy and security training in respect f the CnnectingGTA Slutin. Definitins Electrnic Service Prvider

More information

Bill Payment Agreement & Disclosures

Bill Payment Agreement & Disclosures Bill Payment Agreement & Disclsures Welcme t Online Banking Bill Payment Service. Use f the Bill Payment Service indicates acceptance f terms and cnditins set frth in the Online Banking Agreement & Disclsures

More information

THIRD PARTY PROCUREMENT PROCEDURES

THIRD PARTY PROCUREMENT PROCEDURES ADDENDUM #1 THIRD PARTY PROCUREMENT PROCEDURES NORTH CENTRAL TEXAS COUNCIL OF GOVERNMENTS TRANSPORTATION DEPARTMENT JUNE 2011 OVERVIEW These prcedures establish standards and guidelines fr the Nrth Central

More information

WHAT YOU NEED TO KNOW ABOUT. Protecting your Privacy

WHAT YOU NEED TO KNOW ABOUT. Protecting your Privacy WHAT YOU NEED TO KNOW ABOUT Prtecting yur Privacy YOUR PRIVACY IS OUR PRIORITY Credit unins have a histry f respecting the privacy f ur members and custmers. Yur Bard f Directrs has adpted the Credit Unin

More information

CENTURIC.COM ONLINE DATA BACKUP AND DISASTER RECOVERY SOLUTION ADDENDUM TO TERMS OF SERVICE

CENTURIC.COM ONLINE DATA BACKUP AND DISASTER RECOVERY SOLUTION ADDENDUM TO TERMS OF SERVICE CENTURIC.COM ONLINE DATA BACKUP AND DISASTER RECOVERY SOLUTION ADDENDUM TO TERMS OF SERVICE This Agreement, named the Online Data Backup and Disaster Recvery Slutin Addendum t Centuric s Terms f Service

More information

FAFSA / DREAM ACT COMPLETION PROGRAM AGREEMENT

FAFSA / DREAM ACT COMPLETION PROGRAM AGREEMENT FAFSA / DREAM ACT COMPLETION PROGRAM AGREEMENT If using US Pstal Service, please return t: Califrnia Student Aid Cmmissin Prgram Administratin & Services Divisin ATTN: Institutinal Supprt P.O. Bx 419028

More information

BLUE RIDGE COMMUNITY AND TECHNICAL COLLEGE BOARD OF GOVERNORS

BLUE RIDGE COMMUNITY AND TECHNICAL COLLEGE BOARD OF GOVERNORS BLUE RIDGE COMMUNITY AND TECHNICAL COLLEGE BOARD OF GOVERNORS SERIES: 1 General Rules RULE: 17.1 Recrd Retentin Scpe: The purpse f this rule is t establish the systematic review, retentin and destructin

More information

GUIDANCE FOR BUSINESS ASSOCIATES

GUIDANCE FOR BUSINESS ASSOCIATES GUIDANCE FOR BUSINESS ASSOCIATES This Guidance fr Business Assciates dcument is intended t verview UPMCs expectatins, as well as t prvide additinal resurces and infrmatin, t UPMC s HIPAA business assciates.

More information

DATA REQUEST GUIDELINES

DATA REQUEST GUIDELINES DATA REQUEST GUIDELINES This dcument describes prcedures law enfrcement authrities and individuals invlved in civil litigatin shuld fllw t request data frm LinkedIn and its affiliated service prviders.

More information

We will record and prepare documents based off the information presented

We will record and prepare documents based off the information presented Dear Client: We appreciate the pprtunity f wrking with yu regarding yur Payrll needs. T ensure a cmplete understanding between us, we are setting frth the pertinent infrmatin abut the services that we

More information

THE CITY UNIVERSITY OF NEW YORK IDENTITY THEFT PREVENTION PROGRAM

THE CITY UNIVERSITY OF NEW YORK IDENTITY THEFT PREVENTION PROGRAM THE CITY UNIVERSITY OF NEW YORK IDENTITY THEFT PREVENTION PROGRAM 1. Prgram Adptin The City University f New Yrk (the "University") develped this Identity Theft Preventin Prgram (the "Prgram") pursuant

More information

SEO/SEM AGREEMENT. 4. CUSTOMER RESPONSIBILITIES. For the purposes of providing these services, Customer agrees:

SEO/SEM AGREEMENT. 4. CUSTOMER RESPONSIBILITIES. For the purposes of providing these services, Customer agrees: SEO/SEM AGREEMENT THIS AGREEMENT ("Agreement") is made and entered int this day f, (the "Effective Date") by and between Ishbel M. Lane ("Cnsultant") and ("Custmer"). WHEREAS, the Custmer wishes t engage

More information

NAIC Replacement Requirements For Certain Life Insurance Policies And Annuity Contracts

NAIC Replacement Requirements For Certain Life Insurance Policies And Annuity Contracts NAIC Replacement Requirements Fr Certain Life Insurance Plicies And Annuity Cntracts Duties f Prducers If a transactin invlves a replacement, the prducer must leave with the applicant, at the time an applicatin

More information

First Global Data Corp.

First Global Data Corp. First Glbal Data Crp. Privacy Plicy As f February 23, 2015 Ding business with First Glbal Data Crp. ("First Glbal", First Glbal Mney, "we" r "us", which includes First Glbal Data Crp. s subsidiary, First

More information

Symantec User Authentication Service Level Agreement

Symantec User Authentication Service Level Agreement Symantec User Authenticatin Service Level Agreement Overview and Scpe This Symantec User Authenticatin service level agreement ( SLA ) applies t Symantec User Authenticatin prducts/services, such as Managed

More information

Carbonite Recovery Services Cover Sheet

Carbonite Recovery Services Cover Sheet Carbnite Recvery Services Cver Sheet Frm: Name f Requestr Cmpany Name (if applicable) Ticket Number (frm cnfirmatin email): Fax T: Carbnite Recvery Services Team 617-536- 0686 This FAX shuld include the

More information

Financial Planning Agreement

Financial Planning Agreement Financial Planning Agreement This Financial Planning Agreement, the ( Agreement ), dated as f, 20, is by and between Vulcan Investments LLC, 2100 SuthBridge Pkwy, Suite 650 Birmingham, AL. 35209, an investment

More information

International Association of Trampoline Parks Certified Service Technician Level 1 (CST-1) Certification Program

International Association of Trampoline Parks Certified Service Technician Level 1 (CST-1) Certification Program Internatinal Assciatin f Trampline Parks Certified Service Technician Level 1 (CST-1) Certificatin Prgram 1. Issuance f a Level 1 Certified Service Technician (CST-1) certificatin signifies that the hlder

More information

Audit Committee Charter

Audit Committee Charter Audit Cmmittee Charter Membership The Audit Cmmittee (the "Cmmittee") f the Bard f Directrs (the "Bard") f Philip Mrris Internatinal Inc. (the "Cmpany") shall cnsist f at least three directrs all f whm

More information

COPIES-F.Y.I., INC. Policies and Procedures Data Security Policy

COPIES-F.Y.I., INC. Policies and Procedures Data Security Policy COPIES-F.Y.I., INC. Plicies and Prcedures Data Security Plicy Page 2 f 7 Preamble Mst f Cpies FYI, Incrprated financial, administrative, research, and clinical systems are accessible thrugh the campus

More information

Process of Setting up a New Merchant Account

Process of Setting up a New Merchant Account Prcess f Setting up a New Merchant Accunt Table f Cntents PCI DSS... 3 Wh t cntact?... 3 Bakcgrund n PCI... 3 Why cmply?... 3 Hw t cmply?... 3 PCI DSS Scpe... 4 Des PCI DSS Apply t Me?... 4 What if I am

More information

How To Ensure Your Health Care Is Safe

How To Ensure Your Health Care Is Safe Guidelines fr Custdians t assess cmpliance with the Persnal Health Infrmatin Privacy and Access Act (PHIPAA) This dcument is designed t help custdians evaluate readiness fr cmpliance with PHIPAA and t

More information

Accessible Service Policy

Accessible Service Policy Accessible Service Plicy Date Created Revisin Oct. 16, 2012 1 Gal This plicy is intended t meet the requirements f the Accessibility Standards fr Custmer Service, Ontari Regulatin 429/07 under the Accessibility

More information

Immaculate Conception School, Prince George Bring Your Own Device Policy for Students

Immaculate Conception School, Prince George Bring Your Own Device Policy for Students Bring Yur Own Device Plicy fr Students Purpse This plicy utlines the acceptable use f electrnic devices t maintain a safe and secure educatin envirnment with the gal f preparing students fr the future,

More information

DATE APPROVED March 2011. Version Date Comments / Changes 1.0 March 2011 Initial policy released

DATE APPROVED March 2011. Version Date Comments / Changes 1.0 March 2011 Initial policy released Page 1 f 11 APPROVED (S) REVISED / REVIEWED SUMMARY Versin Date Cmments / Changes 1.0 Initial plicy released 1. PURPOSE OF THIS POLICY T define the purpses fr which Crprate Purchase Cards are t be used

More information

Investment Adviser Switch Workshop

Investment Adviser Switch Workshop Investment Adviser Switch Wrkshp Investment Adviser Registratin, Renewal, Amendment And Pst-Registratin Requirements Presented by Office f the Attrney General Maryland Divisin f Securities 1 Registratin

More information

Peratr Accreditatin and Services in Queensland

Peratr Accreditatin and Services in Queensland Infrmatin Bulletin PT 204/09.15 Operatr Accreditatin fr Limusine Services What is peratr accreditatin? The Transprt Operatins (Passenger Transprt) Act 1994 requires peratrs f public passenger services

More information

Notice of Protection Provided by Utah Life and Health Insurance Guaranty Association

Notice of Protection Provided by Utah Life and Health Insurance Guaranty Association Ntice f Prtectin Prvided by Utah Life and Health Insurance Guaranty Assciatin This ntice prvides a brief summary f the Utah Life and Health Insurance Guaranty Assciatin ("the Assciatin") and the prtectin

More information

Plus500CY Ltd. Statement on Privacy and Cookie Policy

Plus500CY Ltd. Statement on Privacy and Cookie Policy Plus500CY Ltd. Statement n Privacy and Ckie Plicy Statement n Privacy and Ckie Plicy This website is perated by Plus500CY Ltd. ("we, us r ur"). It is ur plicy t respect the cnfidentiality f infrmatin and

More information

Privacy Policy. The Central Equity Group understands how highly people value the protection of their privacy.

Privacy Policy. The Central Equity Group understands how highly people value the protection of their privacy. Privacy Plicy The Central Equity Grup understands hw highly peple value the prtectin f their privacy. Fr that reasn, the Central Equity Grup takes particular care in dealing with any persnal and sensitive

More information

Consumer ebanking Account and Services Agreement

Consumer ebanking Account and Services Agreement Cnsumer ebanking Accunt and Services Agreement Intrductin: As used in this agreement, the wrds yu and yur refer t the accunt hlder(s) and the wrds Bank, us, and we refer t CnnectOne Bank. Cnsumer ebanking:

More information

Loss Share Data Specifications Change Management Plan

Loss Share Data Specifications Change Management Plan Lss Share Data Specificatins Change Management Plan Last Updated: 2/27/2013 Table f Cntents I. Purpse... 3 II. Change Management Apprach... 3 III. Categries f Revisins... 4 IV. Help and Supprt... 6 Lss

More information

CMS Eligibility Requirements Checklist for MSSP ACO Participation

CMS Eligibility Requirements Checklist for MSSP ACO Participation ATTACHMENT 1 CMS Eligibility Requirements Checklist fr MSSP ACO Participatin 1. General Eligibility Requirements ACO participants wrk tgether t manage and crdinate care fr Medicare fee-fr-service beneficiaries.

More information

Purpose Statement. Objectives

Purpose Statement. Objectives Apprved by Academic Affairs Cuncil, June 24, 2014 Faculty Handbk Part VI: Other Plicies and Prcedures Sectin R. Intellectual Prperty Classified Emplyee Handbk Part VI: Other Plicies and Prcedures Sectin

More information

Request for Resume (RFR) CATS II Master Contract. All Master Contract Provisions Apply

Request for Resume (RFR) CATS II Master Contract. All Master Contract Provisions Apply Sectin 1 General Infrmatin RFR Number: (Reference BPO Number) Functinal Area (Enter One Only) F50B3400026 7 Infrmatin System Security Labr Categry A single supprt resurce may be engaged fr a perid nt t

More information

FORM ADV (Paper Version) UNIFORM APPLICATION FOR INVESTMENT ADVISER REGISTRATION AND REPORT FORM BY EXEMPT REPORTING ADVISERS

FORM ADV (Paper Version) UNIFORM APPLICATION FOR INVESTMENT ADVISER REGISTRATION AND REPORT FORM BY EXEMPT REPORTING ADVISERS APPENDIX A FORM ADV (Paper Versin) UNIFORM APPLICATION FOR INVESTMENT ADVISER REGISTRATION AND REPORT FORM BY EXEMPT REPORTING ADVISERS Frm ADV: General Instructins Read these instructins carefully befre

More information

Electronic Data Interchange (EDI) Requirements

Electronic Data Interchange (EDI) Requirements Electrnic Data Interchange (EDI) Requirements 1.0 Overview 1.1 EDI Definitin 1.2 General Infrmatin 1.3 Third Party Prviders 1.4 EDI Purchase Order (850) 1.5 EDI PO Change Request (860) 1.6 Advance Shipment

More information

TrustED Briefing Series:

TrustED Briefing Series: TrustED Briefing Series: Since 2001, TrustCC has prvided IT audits and security assessments t hundreds f financial institutins thrugh ut the United States. Our TrustED Briefing Series are white papers

More information

HIPAA Compliance 101. Important Terms. Pittsburgh Computer Solutions 724-942-1337

HIPAA Compliance 101. Important Terms. Pittsburgh Computer Solutions 724-942-1337 HIPAA Cmpliance 101 Imprtant Terms Cvered Entities (CAs) The HIPAA Privacy Rule refers t three specific grups as cvered entities, including health plans, healthcare clearinghuses, and health care prviders

More information

TUITION DISCOUNT PROGRAM FOR THE SCHOOL OF HEALTH SCIENCES AND PRACTICE

TUITION DISCOUNT PROGRAM FOR THE SCHOOL OF HEALTH SCIENCES AND PRACTICE TUITION DISCOUNT PROGRAM FOR THE SCHOOL OF HEALTH SCIENCES AND PRACTICE Date: Nvember 5, 2014 Supersedes: Graduate Schl Educatin Benefits, HR.314, dated 5/8/2001 References: Nne. I. PURPOSE T establish

More information

FAYETTEVILLE STATE UNIVERSITY

FAYETTEVILLE STATE UNIVERSITY FAYETTEVILLE STATE UNIVERSITY IDENTITY THEFT PREVENTION (RED FLAGS RULE) Authrity: Categry: Issued by the Fayetteville State University Bard f Trustees. University-Wide Applies t: Administratrs Faculty

More information

Systems Support - Extended

Systems Support - Extended 1 General Overview This is a Service Level Agreement ( SLA ) between and the Enterprise Windws Services t dcument: The technlgy services the Enterprise Windws Services prvides t the custmer. The targets

More information

Personal Data Security Breach Management Policy

Personal Data Security Breach Management Policy Persnal Data Security Breach Management Plicy 1.0 Purpse The Data Prtectin Acts 1988 and 2003 impse bligatins n data cntrllers in Western Care Assciatin t prcess persnal data entrusted t them in a manner

More information

Process for Responding to Privacy Breaches

Process for Responding to Privacy Breaches Prcess fr Respnding t Privacy Breaches 1. Purpse 1.1 This dcument sets ut the steps that ministries must fllw when respnding t a privacy breach. It must be read in cnjunctin with the Infrmatin Incident

More information

HIPAA Notice of Privacy Practices. Central Ohio Surgical Associates, Inc.

HIPAA Notice of Privacy Practices. Central Ohio Surgical Associates, Inc. HIPAA Ntice f Privacy Practices Central Ohi Surgical Assciates, Inc. THIS NOTICE OF PRIVACY PRACTICES (THE NOTICE ) DESCRIBES HOW HEALTH INFORMATION ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN

More information

SETTING UP A SYNDICATE SERVICE COMPANY IN HONG KONG

SETTING UP A SYNDICATE SERVICE COMPANY IN HONG KONG SETTING UP A SYNDICATE SERVICE COMPANY IN HONG KONG 2012 2 Disclaimer This is fr reference nly and is nt cnsidered t be legal advice. Whilst all care has been taken t ensure the accuracy f the infrmatin

More information

Using PayPal Website Payments Pro UK with ProductCart

Using PayPal Website Payments Pro UK with ProductCart Using PayPal Website Payments Pr UK with PrductCart Overview... 2 Abut PayPal Website Payments Pr & Express Checkut... 2 What is Website Payments Pr?... 2 Website Payments Pr and Website Payments Standard...

More information

Hillsborough Board of Education Acceptable Use Policy for Using the Hillsborough Township Public Schools Network

Hillsborough Board of Education Acceptable Use Policy for Using the Hillsborough Township Public Schools Network 2361/Page 1 f 6 Hillsbrugh Bard f Educatin Acceptable Use Plicy fr Using the Hillsbrugh Twnship Public Schls Netwrk It is the gal f the HTPS (Hillsbrugh Twnship Public Schls) Netwrk t prmte educatinal

More information

Texas Woman's University University Policy Manual

Texas Woman's University University Policy Manual Texas Wman's University University Plicy Manual Plicy Name: Plicy Number: 6.06 Date Passed: July 2004 Health Insurance Prtability& Accuntability Act (HIPAA) Date Reviewed: September 2008 Next Review: September

More information

Key Steps for Organizations in Responding to Privacy Breaches

Key Steps for Organizations in Responding to Privacy Breaches Key Steps fr Organizatins in Respnding t Privacy Breaches Purpse The purpse f this dcument is t prvide guidance t private sectr rganizatins, bth small and large, when a privacy breach ccurs. Organizatins

More information

FREQUENTLY ASKED QUESTIONS ON THE EUCOMED ETHICAL BUSINESS LOGO

FREQUENTLY ASKED QUESTIONS ON THE EUCOMED ETHICAL BUSINESS LOGO Rue Jseph II, 40 www.eucmed.rg FREQUENTLY ASKED QUESTIONS ON THE EUCOMED ETHICAL BUSINESS LOGO Q1: What is the Eucmed Ethical Business Lg? A1: The Ethical Business Lg is a Lg licensed by Eucmed, the Eurpean

More information

SSL Certificates Reseller Agreement

SSL Certificates Reseller Agreement Added 8-27-2008 SSL Certificates Reseller Agreement 1. DEFINITIONS 1.1. "Certificate End Users" mean persns wh purchase Certificate Services frm Custmer r Certificate Resellers per this Agreement. 1.2.

More information

Application Fee Schedule Please check the appropriate box below. See also Additional Information starting on page 6.

Application Fee Schedule Please check the appropriate box below. See also Additional Information starting on page 6. DRIVING SCHOOL LICENSE APPLICATION N. APPLICATION DMV USE ONLY N. LICENSE Received Fee Amunt Expiratin Fee Amunt PART 1 Schl Infrmatin: l READ VEHICLE AND TRAFFIC LAW SECTION 394 AND DMV COMMISSIONER S

More information

Public consultation paper

Public consultation paper Public cnsultatin paper Nvember 2012 Public cnsultatin n guidelines fr prfessinal indemnity insurance arrangements fr nurses and nurse practitiners. Please prvide feedback by email t: nmbafeedback@ahpra.gv.au

More information

FIREFIGHTER HEART AND CIRCULATORY MALFUNCTION BENEFITS PROGRAM STANDARD OPERATING GUIDELINES Approved by the DOLA Executive Director July 1, 2014

FIREFIGHTER HEART AND CIRCULATORY MALFUNCTION BENEFITS PROGRAM STANDARD OPERATING GUIDELINES Approved by the DOLA Executive Director July 1, 2014 FIREFIGHTER HEART AND CIRCULATORY MALFUNCTION BENEFITS PROGRAM STANDARD OPERATING GUIDELINES Apprved by the DOLA Executive Directr July 1, 2014 Prgram Overview: As f July 1, 2014, the Department f Lcal

More information

Online Banking Agreement

Online Banking Agreement Online Banking Agreement 1. General This Online Banking Agreement, which may be amended frm time t time by us (this "Agreement"), fr accessing yur Clrad Federal Savings Bank accunt(s) via the Internet

More information

The information contained in this site is for INFORMATIONAL purposes only and is protected by copyright. We are not providing legal advice.

The information contained in this site is for INFORMATIONAL purposes only and is protected by copyright. We are not providing legal advice. Privacy Plicy Terms f Service: The fllwing terms and cnditins gvern all use f the Rightwaywebhsting.cm website and all cntent, services and prducts available at r thrugh the website (taken tgether, the

More information

Merchant Processes and Procedures

Merchant Processes and Procedures Merchant Prcesses and Prcedures Table f Cntents EXHIBIT C 1. MERCHANT INTRODUCTION TO T-CHEK 3 1.1 Wh is T-Chek Systems? 3 1.2 Hw t Cntact T-Chek Systems 3 1.3 Hw t Recgnize T-Chek Frms f Payment 3 1.3.1

More information

CHARTER OF THE COMPENSATION COMMITTEE OF THE BOARD OF DIRECTORS OF UPLAND SOFTWARE, INC.

CHARTER OF THE COMPENSATION COMMITTEE OF THE BOARD OF DIRECTORS OF UPLAND SOFTWARE, INC. CHARTER OF THE COMPENSATION COMMITTEE OF THE BOARD OF DIRECTORS OF UPLAND SOFTWARE, INC. PURPOSE The purpse f the Cmpensatin Cmmittee f the Bard f Directrs (the Bard ) f Upland Sftware, Inc. (the Cmpany

More information

All Harvard University schools, tubs, local units, Affiliate Institutions, Allied Institutions and University-wide Initiatives.

All Harvard University schools, tubs, local units, Affiliate Institutions, Allied Institutions and University-wide Initiatives. HARVARD UNIVERSITY FINANCIAL POLICY INDEPENDENT CONTRACTOR CLASSIFICATION Plicy Title: Independent Cntractr Respnsible Office: ERP and UFS Effective Date: Octber 4, 2000 Revisin Date: May 12, 2009 Plicy

More information

Frequently Asked Questions about the Faith A. Fields Nursing Scholarship Loan

Frequently Asked Questions about the Faith A. Fields Nursing Scholarship Loan ARKANSAS STATE BOARD OF NURSING 1123 S. University Avenue, Suite 800, University Twer Building, Little Rck, AR 72204 Phne: (501) 686-2700 Fax: (501) 686-2714 www.arsbn.rg Frequently Asked Questins abut

More information

Audit Committee Charter. St Andrew s Insurance (Australia) Pty Ltd St Andrew s Life Insurance Pty Ltd St Andrew s Australia Services Pty Ltd

Audit Committee Charter. St Andrew s Insurance (Australia) Pty Ltd St Andrew s Life Insurance Pty Ltd St Andrew s Australia Services Pty Ltd Audit Cmmittee Charter St Andrew s Insurance (Australia) Pty Ltd St Andrew s Life Insurance Pty Ltd St Andrew s Australia Services Pty Ltd Versin 2.0, 22 February 2016 Apprver Bard f Directrs St Andrew

More information

Data Protection Policy & Procedure

Data Protection Policy & Procedure Data Prtectin Plicy & Prcedure Page 1 Prcnnect Marketing Data Prtectin Plicy V1.2 Data prtectin plicy Cntext and verview Key details Plicy prepared by: Adam Haycck Apprved by bard / management n: 01/01/2015

More information

HP ValuPack Consulting Description OpenVMS Engineering Change Order (ECO) Patch List

HP ValuPack Consulting Description OpenVMS Engineering Change Order (ECO) Patch List HP ValuPack Cnsulting Descriptin OpenVMS Engineering Change Order (ECO) Patch List HP ValuPacks are standardized cnsulting services, prvided by HP Slutin Center Service Prfessinals, with pre-defined custm

More information

MSB FINANCIAL CORP. MILLINGTON BANK AUDIT COMMITTEE CHARTER

MSB FINANCIAL CORP. MILLINGTON BANK AUDIT COMMITTEE CHARTER MSB FINANCIAL CORP. MILLINGTON BANK AUDIT COMMITTEE CHARTER This Audit Cmmittee Charter has been amended as f July 17, 2015. The Audit Cmmittee shall review and reassess this Charter annually and recmmend

More information

Offer Specifications Dell Email Management Services (EMS): Policy Based Encryption-E

Offer Specifications Dell Email Management Services (EMS): Policy Based Encryption-E Dell Email Management Services (EMS): Plicy Based Encryptin-E Offer Specificatins Dell Email Management Services (EMS): Plicy Based Encryptin-E Service Overview The Plicy Based Encryptin-E service ( PBE-E

More information

Post-Baccalaureate Certificate Programs

Post-Baccalaureate Certificate Programs Pst-Baccalaureate Certificate Prgrams Certificate prgrams benefit students and/r interest by prviding greater flexibility and brader training in areas related t the students' majr fields and making thse

More information

YOU MUST INCLUDE ALL THE FOLLOWING ITEMS IN ORDER TO PROCESS PAYMENT FOR YOUR SERVICES

YOU MUST INCLUDE ALL THE FOLLOWING ITEMS IN ORDER TO PROCESS PAYMENT FOR YOUR SERVICES Please fill ut cmpletely and send back t 216.475.1579 r vendrpackets@garick.cm YOU MUST INCLUDE ALL THE FOLLOWING ITEMS IN ORDER TO PROCESS PAYMENT FOR YOUR SERVICES We must receive: 4 pages f Vendr packet

More information

HP ValuPack Consulting Description OpenVMS Replacement Software Distribution Kit

HP ValuPack Consulting Description OpenVMS Replacement Software Distribution Kit HP ValuPack Cnsulting Descriptin OpenVMS Replacement Sftware Distributin Kit HP ValuPacks are standardized cnsulting services, prvided by HP Cntact Center Service prfessinals, with pre-defined custm deliverables

More information

NYU Langone Medical Center NYU Hospitals Center NYU School of Medicine

NYU Langone Medical Center NYU Hospitals Center NYU School of Medicine Title: Identity Theft Prgram Effective Date: July 2009 NYU Langne Medical Center NYU Hspitals Center NYU Schl f Medicine POLICY It is the plicy f the NYU Langne Medical Center t educate and train staff

More information

Issuing of qualifications and statement of attainment Policy and Procedures Version: 5.0 Last Modified: 12 February 2015

Issuing of qualifications and statement of attainment Policy and Procedures Version: 5.0 Last Modified: 12 February 2015 Issuing f qualificatins and statement f attainment Plicy and Prcedures Versin: 5.0 Last Mdified: 12 February 2015 Purpse Duke Cllege issues AQF certificatin dcumentatin nly t a learner whm it has assessed

More information

Procedures for Payments Made to or on Behalf of International Students, Visitors and Vendors

Procedures for Payments Made to or on Behalf of International Students, Visitors and Vendors Prcedures fr Payments Made t r n Behalf f Internatinal Students, Visitrs and Vendrs General Infrmatin All payments made t r n behalf f an internatinal visitr, student r vendr have ptential tax cnsideratins

More information

Internet Banking Agreement and Disclosure Statement

Internet Banking Agreement and Disclosure Statement Internet Banking Agreement and Disclsure Statement This agreement cntains the terms and cnditins that gvern accessing r using Internet Banking (NetTeller), Bill Payment Services, Mbile Banking and On Demand

More information

Malpractice and Maladministration Policy

Malpractice and Maladministration Policy TR340 Malpractice and Maladministratin Plicy This plicy aims t: Define malpractice and maladministratin in the cntext f CIM/CAM studying members, Accredited study centres (ASCs), examinatin centres, invigilatrs

More information

ITIL Release Control & Validation (RCV) Certification Program - 5 Days

ITIL Release Control & Validation (RCV) Certification Program - 5 Days ITIL Release Cntrl & Validatin (RCV) Certificatin Prgram - 5 Days Prgram Overview ITIL is a set f best practices guidance that has becme a wrldwide-adpted framewrk fr Infrmatin Technlgy Services Management

More information

Heythrop College Disciplinary Procedure for Support Staff

Heythrop College Disciplinary Procedure for Support Staff Heythrp Cllege Disciplinary Prcedure fr Supprt Staff Intrductin 1. This prcedural dcument des nt apply t thse academic-related staff wh are mentined in the Cllege s Ordinance, namely the Librarian and

More information

c) Be a permanent resident of the United States and the State of Florida. (A resident is

c) Be a permanent resident of the United States and the State of Florida. (A resident is THIRTEENTH JUDICIAL CIRCUIT IN AND FOR HILLSBOROUGH COUNTY (Revised 1/9/06) PROCEDURES FOR PROCESS SERVER CERTIFICATION Cmpleted Applicatins are Sub.iect t Apprpriate Public Recrds Disclsure Law Applicatins

More information

Checklist for Columbia State Community College s Course Creation Process

Checklist for Columbia State Community College s Course Creation Process Checklist fr Clumbia State Cmmunity Cllege s Curse Creatin Prcess Curses cannt be added t the schedule until this prcess is cmpleted, all curse dcuments are submitted, and the curse is apprved by the Directr

More information

Bond Authorization Requested

Bond Authorization Requested District r Charter Schl Cntact Persn: Address 1: Address 2: City: Zip Cde: Telephne: Email Address: Bnd Authrizatin Requested The maximum bnd authrizatin that may be requested per district r charter schl

More information

Morningstar Document Research

Morningstar Document Research Mrningstar Dcument Research FORM SC 13G/A CAPITAL VENTURES INTERNATIONAL - JRCC Filed: February 13, 2014 (perid: ) Amendment t the SC 13G filing The infrmatin cntained herein may nt be cpied, adapted r

More information

BAMS Third Party Service Providers (TPSPs) FAQs

BAMS Third Party Service Providers (TPSPs) FAQs BAMS Third Party Service Prviders (TPSPs) FAQs 1) What is the Third Party Service Prvider (TPSP) Agent Registratin Prgram? The TPSP Agent Registratin Prgram is a Card Brand (Visa USA Inc and MasterCard

More information

HP ValuPack Consulting Description Storage Library System Disaster Recovery Audit ValuPack

HP ValuPack Consulting Description Storage Library System Disaster Recovery Audit ValuPack HP ValuPack Cnsulting Descriptin Strage Library System Disaster Recvery Audit ValuPack HP ValuPacks are standardized cnsulting services, prvided by HP Slutin Center Service Prfessinals, with pre-defined

More information

HP ValuPack Consulting Description Red Hat Linux System Performance Monitoring & Tuning

HP ValuPack Consulting Description Red Hat Linux System Performance Monitoring & Tuning HP ValuPack Cnsulting Descriptin Red Hat Linux System Perfrmance Mnitring & Tuning HP ValuPacks are standardized cnsulting services, prvided by HP Slutin Center Service Prfessinals, with pre-defined custm

More information

ACQUIRED RARE DISEASE DRUG THERAPY EXCEPTION PROCESS

ACQUIRED RARE DISEASE DRUG THERAPY EXCEPTION PROCESS ADMINISTRATIVE POLICY ACQUIRED RARE DISEASE DRUG THERAPY EXCEPTION PROCESS Plicy Number: ADMINISTRATIVE 19.8 T Effective Date: Octber 1, 014 Table f Cntents CONDITIONS OF COVERAGE... BENEFIT CONSIDERATIONS...

More information

TITLE: Supplier Contracting Guidelines Process: FIN_PS_PSG_050 Replaces: Manual Sections 6.4, 7.1, 7.5, 7.6, 7.11 Effective Date: 10/1/2014 Contents

TITLE: Supplier Contracting Guidelines Process: FIN_PS_PSG_050 Replaces: Manual Sections 6.4, 7.1, 7.5, 7.6, 7.11 Effective Date: 10/1/2014 Contents TITLE: Supplier Cntracting Guidelines Prcess: FIN_PS_PSG_050 Replaces: Manual Sectins 6.4, 7.1, 7.5, 7.6, 7.11 Cntents 1 Abut university supplier cntracting... 2 2 When is a cntract required?... 2 3 Wh

More information

Electronic and Information Resources Accessibility Compliance Plan

Electronic and Information Resources Accessibility Compliance Plan Electrnic and Infrmatin Resurces Accessibility Cmpliance Plan Intrductin The University f Nrth Texas at Dallas (UNTD) is cmmitted t prviding a wrk envirnment that affrds equal access and pprtunity t therwise

More information

Project Open Hand Atlanta. Health Insurance Portability and Accountability Act (HIPAA) NOTICE OF PRIVACY PRACTICES

Project Open Hand Atlanta. Health Insurance Portability and Accountability Act (HIPAA) NOTICE OF PRIVACY PRACTICES Prject Open Hand Atlanta Effective Date: April 14, 2003 Health Insurance Prtability and Accuntability Act (HIPAA) The Health Insurance Prtability and Accuntability Act f 1996 (HIPAA) directs health care

More information

Nursing Requirements and Reviews

Nursing Requirements and Reviews LWC BSN Academic Standard fr Admissin, Prgressin and Readmissin Please nte: This infrmatin has been updated and may differ frm what is printed in the LWC nline catalg r print versins. Applicatin Deadlines

More information

Information Security Policy

Information Security Policy Purpse The risk t Charlestn Suthern University, its emplyees and students frm data lss and identity theft is f significant cncern t the University and can be reduced nly thrugh the cmbined effrts f every

More information

COMPLIANCE WITH THE FEDERAL TRADE COMMISSION S SAFEGUARDS RULE

COMPLIANCE WITH THE FEDERAL TRADE COMMISSION S SAFEGUARDS RULE COMPLIANCE WITH THE FEDERAL TRADE COMMISSION S SAFEGUARDS RULE COMPLIANCE WITH THE FEDERAL TRADE COMMISSION S SAFEGUARDS RULE Mst dealers are familiar with the requirements f the Gramm-Leach-Bliley Act

More information

Issue Brief. SBC Distribution Rules for Employer Sponsored Health Plans October 2012. Summary. Which Plans Are Required to Provide the SBC?

Issue Brief. SBC Distribution Rules for Employer Sponsored Health Plans October 2012. Summary. Which Plans Are Required to Provide the SBC? Issue Brief SBC Distributin Rules fr Emplyer Spnsred Health Plans Octber 2012 Summary The Affrdable Care Act (ACA) expands ERISA's disclsure requirements by requiring that a summary f benefits and cverage

More information

Version: Modified By: Date: Approved By: Date: 1.0 Michael Hawkins October 29, 2013 Dan Bowden November 2013

Version: Modified By: Date: Approved By: Date: 1.0 Michael Hawkins October 29, 2013 Dan Bowden November 2013 Versin: Mdified By: Date: Apprved By: Date: 1.0 Michael Hawkins Octber 29, 2013 Dan Bwden Nvember 2013 Rule 4-004J Payment Card Industry (PCI) Patch Management (prpsed) 01.1 Purpse The purpse f the Patch

More information