White paper. How to take your contact centre out of scope for PCI DSS. Reducing cost and risk in credit card transactions for contact centres

Size: px
Start display at page:

Download "White paper. How to take your contact centre out of scope for PCI DSS. Reducing cost and risk in credit card transactions for contact centres"

Transcription

1 White paper How to take your contact centre out of scope for PCI DSS

2 Executive summary With 77 per cent of UK companies admitting to a security breach (Source: The Ponemon Institute, 2009), and up to 97 per cent of companies falling short of PCI compliance, call centre security looms large on the boardroom agenda. 77% of companies admit to a security breach and up to 97% fall short of PCI compliance. Increasingly however, merchants are finding that eliminating customer card data from their infrastructure means they can reduce the scope of PCI DSS. By doing so, they can reduce the risk of a breach of card data and cut the cost of PCI DSS compliance. The two principal approaches to reduce cost, complexity and the PCI DSS audit scope for cardholder data are: 1. Tokenization 2. Point-to-point encryption These emerging technologies are established for both high street and online retail channels but the contact centre and voice transactions still present additional challenges. Semafone has incorporated these technologies into a unique solution to tackle both fraud risk and PCI compliance by ensuring that no payment information is heard by the agent, or stored by the company. June

3 Reducing the scope of the PCI audit can drive down costs by more than 75%. Contents Executive summary 2 Contents 3 PCI DSS background and audit scope 4 Two ways to eliminate the need for customer card data 5 The challenge for the contact centre 6 How Semafone removes card data from the contact centre 7 Reducing the scope of PCI DSS audits for the contact centre 8 Cutting the cost of PCI audits 10 Conclusion and glossary 11 June

4 Introduction: PCI DSS background The Payment Card Industry Data Security Standard (PCI DSS) is the card schemes compliance programme to combat fraud and protect consumer card data. It applies to all organisations that store, process or transmit cardholder information, from any of its members cards (Visa, MasterCard, American Express, Discover and JCB). Level 1 retailers spend an average of 1.8m to become PCI compliant. Source: Gartner Larger organizations must have their annual compliance assessment carried out by an independent Qualified Security Assessor (QSA), while smaller companies can use a Self- Assessment Questionnaire (SAQ). The current version of the standard (v2.0 since March 2011*) specifies 12 requirements organized into six control objectives. From July 2012 MasterCard says that Level 2 merchants either have to have their SAQ completed by an external QSA or they need an Internal Security Assessor (ISA) with PCI DSS training to sign off their SAQ. Control objectives Build and maintain Protect cardholder data Maintain a vulnerability management program Use strong access controls Regularly monitor and test networks Maintain an information security policy PCI DSS requirements 1. Install and maintain a firewall to protect cardholder data 2. Do not use vendor-supplied defaults for passwords and other security parameters 3. Protect stored cardholder data 4. Encrypt transmission of cardholder data across open, public networks 5. Use up-to-date anti-virus software on all systems commonly affected by malware 6. Develop and maintain secure systems and applications 7. Need-to-know access to cardholder data 8. Give a unique ID to each person with computer access 9. Restrict physical access to cardholder data 10. Track and monitor all access to network resources and cardholder data 11. Regularly test security systems and processes 12. Maintain a business-wide policy that addresses information security * June

5 PCI DSS audit scope PCI DSS has five types of SAQ to be completed. The table shows how different types of SAQ require less controls and can therefore cut the cost of PCI DSS compliance. Each type of SAQ offers a different number of required PCI controls and the costs that go with them. SAQ A Description Card-not-present (e-commerce or mail/telephone order) merchants, all cardholder data functions outsourced. This would never apply to face-to-face merchants. No. of controls 4 B Imprint-only merchants with no electronic cardholder data storage, or standalone, dial-out terminal merchants with no electronic cardholder data storage. 29 C-VT Merchants using only web-based virtual terminals, no electronic cardholder data storage. 60 C Merchants with payment application systems connected to the internet, no electronic cardholder data storage. 80 D All other merchants not included in descriptions for SAQ types A- C above and all service providers defined by a payment brand as eligible to complete an SAQ. 286 June

6 Eliminating customer card data from their infrastructure lets merchants cut the cost of PCI DSS compliance. Two ways to eliminate the need for customer card data PCI DSS requires that merchants must eliminate, render useless, substitute or secure (encrypted to the standards of PCI DSS) all cardholder data. It is rare that cardholder data can be totally eliminated as it is required for refunds, future purchases, loyalty programmes, reconciliation, etc. Therefore, merchants focus on substituting their stored card data or rendering it useless. This is already happening on the high street and online through point-to-point encryption and/or tokenization. Account Data Storage Render Stored Account Data Element permitted Data Unreadale per Req. 3.4 Cardholder Primary Account Yes Yes Data Number (PAN) Cardholder name Yes No x Service Code Yes No x Expiration Date Yes No x Sensitive Full Magnetic Stripe Data No x Cannot store per Req. 3.2 Authentication CAV2/CVC2/ No x Cannot store per Req. 3.2 Data CVV2/CID PIN/PIN block No x Cannot store per Req. 3.2 Figure 1 PCI DSS Applicability Information v Point-to-point encryption Point-to-point encryption can be used to protect and secure cardholder data between two end points. Visa Europe in March 2010 issued a Best Practices for Data Field Encryption with these goals*: 1. Limit cleartext availability of cardholder data and sensitive authentication data to the point of encryption and the point of decryption 2. Use robust key management solutions consistent with international and/or regional standards 3. Use key-lengths and cryptographic algorithms consistent with international and/or regional standards 4. Protect devices used to perform cryptographic operations against physical/logical compromises 5 Use an alternate account or transaction identifier for business processes that require the primary account number to be utilised after authorisation, such as processing of recurring payments, customer loyalty programmes or fraud management 2. Tokenization Tokenization can replace cardholder data, ie the credit or debit card number, with nonsensitive data that can be used as a reference or a token. The card data is then vaulted, usually by a third party, where again it is protected through encryption. Format-preserving encryption and tokenization Encryption and tokenization can both be used, so that the encrypted value or the token retains the format of the original card number. It is also possible to retain the first six digits (the Banking Identification Number BIN which identifies the issuing bank) and the last four digits which do not need to be masked for PCI DSS, so they can be used by production applications and viewed by users. * Visa Europe s Best Practices for Data Field Encryption, Version 1.0 June

7 retailers/payment_security/downloads resources.aspx The challenge for the contact centre Technology and services for the de-scoping of high street and online retailers are already well established, with chip and PIN machines where the customer is present, and payment pages hosted by the merchant s Payment Service Provider (PSP) for online transactions. The contact centre has its own specific challenges for PCI DSS compliance. However, the contact centre has its own distinctive issues, with three specific challenges to address for PCI DSS compliance: The physical contact centre environment Call recordings Agents and network Securing the physical contact centre environment PCI DSS requires that employees are screened for security purposes. But if paper and pens are available then other controls come into play. So any writing paper needs to be secured and later destroyed so cardholder data can not be reconstructed. Many contact centres have adopted paperless environments with only white boards and markers available. Agents access to cardholder data also means that PCI DSS requires a policy covering access to mobile phones, the web and , as staff could theoretically use these tools to transmit cardholder data out of the merchant s environment. Draconian measures such as banning pens, paper, mobile phones, personal effects, access and web access can have very negative impacts on the contact centre. It can make it harder to retain staff and those who do stay resent being treated as potential thieves, making it very difficult to create a positive work environment. No and web access within a contact centre is also impractical as these are required to fulfil day to day activities. Call recordings Customers share both cardholder data and Sensitive Authentication Data (SAD) ie the PAN (Permanent Account Number), expiry date, issue number and their security code (CVC, CVC2, etc). If merchants don t take the security code then the call recordings can be protected through encryption. PCI DSS does not permit capturing the security code on call recordings even if the recordings are encrypted. Barclaycard s white paper, Safe and Sound Processing Telephone Payment Securely, details the challenges of the contact centre*. Agents and network The fact that contact centre agents generally input customers cardholder data on their behalf brings the contact centre agent desktop into scope for PCI DSS, as the machine is being used to enter this cardholder data. Also, as the contact centre desktop is connected to the merchant s network, this immediately brings the merchant s network into scope. * Barclaycard Safe and Sound white paper June

8 Removing cardholder data from the contact centre Semafone is a contact centre solution that shields all PAN and CVC data from agents, call recordings and screen recordings. Agents do not hear or see cardholder data, call recordings do not capture either the PAN or CVC, and screen recordings only capture asterisks and the last four digits of the PAN. The agent will only see asterisks on the Semafone hosted web page as the cardholder enters their card data. Agents do not ask cardholders to speak their card details, they ask them to use their telephone keypad to enter their PAN and CVC. Semafone masks the DTMF (Dual Tone Multi-Frequency) tones from the cardholder s telephone and replaces them with a flat tone. This is achieved while voice communications remain intact between the agent and the cardholder. The agent can then call up Semafone s enable payment page for the merchant s preferred Payment Service Provider (PSP), passing across the cardholder name, transaction reference, amount and any other payment details required for authorization (such as cardholder address). The agent will only see asterisks on the Semafone hosted web page as the cardholder enters their card data but other than the last four digits, no other digits of the PAN and CVC are transmitted to the page. The agent then verbally collects further payment details such as valid from, valid to and issue number and enters these details into Semafone s payment page. If the cardholder makes a mistake, they can tell the agent who will then reset the PAN or CVC field from a button on the hosted web page, or simply press the star button on their phone. From the first six digits of the PAN (the BIN) Semafone can determine the length of the PAN. Once the last digit of PAN has been entered by the cardholder the agent receives an audio prompt and a visual cue in terms of the last four digits of the PAN being displayed on the Semafone hosted web page. Semafone performs a Luhn digit check (an algorithm that validates the card number) and if this fails Semafone shows the agent a message indicating an invalid card number has been entered. The agent is then able to ask the cardholder to re-enter their card details. Once the transaction details have been collected, the agent can request the transaction authorization. Semafone combines the details from its hosted payment page with the PAN and CVC it has collected from the cardholder s DTMF tones. Semafone then securely transmits these transaction details to the merchant s PSP through the PSP s Application Programming Interface (API) service. The PSP returns to Semafone the results of the authorization including the authorization code and the transaction token. These can be displayed by the Semafone hosted page or can be posted back to the agent application. June

9 Removing card data from call recordings Call recordings are an essential part of the modern contact centre, and mandated by the FSA for mortgage companies when handling collections over the phone. They re also required for dealing with complaints and managers may use them for training and instruction purposes. It is impossible to reverse engineer any card data from the call recording, putting it safely outside PCI DSS scope. However, it is important that customers credit card data is not retained in the recordings. Semafone copes with this requirement by automatically removing the card data from the recordings as they happen. The call recording will capture all voice communications but DTMF tones are masked and only a flat tone is recorded. It is therefore impossible to reverse engineer any card data from the call recording and Semafone has put the call safely outside PCI DSS scope. The Semafone approach has several advantages over the alternative approach of pausing recordings: 1. Pausing call recordings is often in conflict with regulatory bodies that mandate complete recordings 2. Triggering pause and resume by hand is not a robust system, with human error resulting in either the capture of card details on the call recording (and thus the loss of PCI DSS compliance) or the missing of important sections of the call, which is causing major issues for quality monitoring and business improvement June

10 Reducing the scope of PCI DSS audits for the contact centre Semafone in the cloud By capturing card data (PAN and CVC), Semafone is technically in scope for PCI DSS. However, Semafone can be deployed within the telephony cloud of the merchant s network provider rather than the enterprise itself. The merchant will be deemed to have outsourced their payment process for PCI DSS purposes, as it will not have handled any cardholder data. While the telephone network provider will have to be PCI DSS certified, the merchant will be deemed to have outsourced its payment process for PCI DSS purposes, as it will not have handled any cardholder data. In this case, if they have no customer facing card transactions they can complete an SAQ A form and attest to two statements ( Restrict physical access to cardholder data and Maintain a policy that addresses information security ), leaving just four controls to implement for PCI DSS. If the merchant has no customer-facing transactions, they can complete an SAQ C attesting to 80 controls, automatically cutting out 206 controls from SAQ D. Voice DTMF PVG PSTN C82 WWW Provider Edge Network DMZ LAN Firewall SIP or TDM connection DPM Server SBC/CCM Telco Data Centre DMZ Payment Gateway Firewall PBX/ACD Customer Site Out of Scope Voice LAN Agents CRM June

11 Figure 2 Semafone deployed within a telephony cloud Level 1 merchants gain Level 1 merchants need to have a QSA complete their Report on Compliance (ROC) with the full 286 controls within SAQ D. But if the merchant qualifies for SAQ C with the permission of their acquirer the amount of controls is reduced to just 80. Semafone in the enterprise Where a merchant does not deploy Semafone within their telephony network provider, but within their enterprise itself, it is still possible to limit the scope of PCI DSS. The Semafone telephony cards and servers can be segregated by firewalls, so the network outside the firewall will be de-scoped. Importantly, this will include the contact centre environment, including the agents desktops. The merchant will still need to complete an SAQ C for the Semafone environment but will not need these controls outside of the segregated area. As agents do not hear or see card data there is no requirement to secure the physical contact centre environment. So agents can have web access, access, mobile phones and the use of paper and pens at their desks. This helps to create a more productive environment and ensure higher The story can be even better for Level 1 merchants that qualify for SAQ A (a growing list, including utilities such as gas, electric, water, phone, cable, satellite TV, and ecommerce businesses such as Amazon, ebay, LastMinute.com and Expedia). Qualifying for SAQ A means that with their acquirer s consent they can report Not Applicable to 282 of the 286 controls, leaving just 4 within scope. Voice DTMF PSTN Payment Gateway Firewall WWW As agents do not hear or see card data there is no requirement under PCI DSS to secure the physical contact centre environment. PBX/ACD PCI Chassis On-Site DMZ Voice TPM/DPM Server Firewall Agents LAN CRM Customer Site Out of Scope rates of staff retention. June

12 Figure 3 Semafone deployed within the merchant s enterprise By removing the need to handle customer card data, merchants can significantly reduce the costs of implementing and maintaining PCI DSS compliance. Cutting the cost of PCI audits IT research firm Gartner reported in 2008 that merchant spending to protect cardholder data and become PCI compliant increased by almost five times during the previous 18 months. Among the Level 1 retailers (more than 6 million transactions per year) Gartner surveyed, an average of 1.8 million was spent to become PCI compliant, excluding the costs of PCI assessment services. Level 2 merchants (1-6 million transactions per year) spent 730,000 on PCI compliance and Level 3 merchants (20,000-1 million transactions per year) spent an average of 103,000, excluding security assessment. Gartner did not discuss Level 4 merchants in the report. The Ponemon Institute reported in March 2010 that Tier 1 merchants are spending 150,000 for their annual PCI DSS audits. Ten per cent of these merchants were spending more than 330,000. The rising cost of compliance Auditing costs for Level 2 merchants are set to rise significantly from this year with the announcement that from June 2011 MasterCard will require that all Level 2 merchants must either have an external audit through a qualified QSA or that their internal auditors have attended and passed the PCI Internal Security Assessor (ISA) training. By removing the need to handle customer card data, merchants can significantly reduce the costs of implementing and maintaining PCI DSS compliance. Large enterprises can pay over 150,000 for logging tools, for example, a sum that can be cut if the need for such tools is outsourced. Maintaining all of the latest security patches can also be a significant drain on compliance budgets, especially if they need to be applied to each agent s desktop, with the individual testing that requires. Reducing PCI audit scope cuts costs Reducing PCI scope from SAQ D to SAQ C can drive down PCI compliance and audit costs by more than 75 per cent. For merchants with no customer-facing transactions that can de-scope to SAQ A, the reduction is closer to 90 per cent. Reducing the size of a merchant s card data environment also significantly reduces the cost of achieving and maintaining PCI DSS compliance. In a recent series of estimates carried out by Semafone, the annual cost per agent seat can range from 11,324 for a small ten-agent contact centre with only anti-virus tools in place, dropping to a Semafone-enabled SAQ A rating at a cost of 2,282, saving more than 75 per cent per year. In larger contact centres with greater economies of scale, costs can drop from 1,213 to just 140, a saving of almost 90 per cent. June

13 Conclusion PCI DSS compliance is continual and not just an annual audit. Merchants need to set longterm objectives to reduce their risks from cardholder data and to measure the ongoing cost of doing so. Glossary API Application Programming Interface CVC Card Verification Code DTMF Dual Tone Multi-Frequency PAN Permanent Account Number PCI DSS Payment Card Industry Data Security Standard PIN Personal Identification Number PSP Payment Service Provider For most organisations this will be to avoid managing cardholder data. The ability to achieve this on the high street and online has been well understood for some time but this has left the Achilles heel within the contact centre. Semafone is the only company that allows merchants to close the gap in their de-scoping strategy by allowing them to remove their contact centres from PCI DSS compliance. Semafone can reduce costs, ease the admin burden and contribute to a more productive working environment for staff, helping merchants to finally realise the cost savings that they want to achieve. Advantages of Semafone for contact centres Significantly reduced costs for PCI DSS compliance Zero negative impact on staff working conditions Enhanced security for customers ROC Report on Compliance SAD Sensitive Authentication Data SAQ Self-Assessment Questionnaire QSA Qualified Security Assessor June

PCI Compliance. Reducing cost & risk in Credit Card Transactions for Contact Centres V1.0

PCI Compliance. Reducing cost & risk in Credit Card Transactions for Contact Centres V1.0 PCI Compliance Reducing cost & risk in Credit Card Transactions for Contact Centres V1.0 Contents Executive Summary 3 PCI DSS and the battle against card fraud Introduction 4 PCI DSS Requirements PCI DSS

More information

How to Take your Contact Centre Out of Scope for PCI DSS. Reducing Cost and Risk in Credit Card Transactions for Contact Centres

How to Take your Contact Centre Out of Scope for PCI DSS. Reducing Cost and Risk in Credit Card Transactions for Contact Centres How to Take your Contact Centre Out of Scope for PCI DSS Reducing Cost and Risk in Credit Card Transactions for Contact Centres 1 2 Contents 4 Executive Summary 6 PCI DSS Background 8 PCI DSS What s Involved

More information

Becoming PCI Compliant

Becoming PCI Compliant Becoming PCI Compliant Jason Brown - brownj52@michigan.gov Enterprise Security Architect Enterprise Architecture Department of Technology, Management and Budget State of Michigan @jasonbrown17 History

More information

PCI Compliance. How to Meet Payment Card Industry Compliance Standards. May 2015. cliftonlarsonallen.com. 2015 CliftonLarsonAllen LLP

PCI Compliance. How to Meet Payment Card Industry Compliance Standards. May 2015. cliftonlarsonallen.com. 2015 CliftonLarsonAllen LLP 2015 CliftonLarsonAllen LLP PCI Compliance How to Meet Payment Card Industry Compliance Standards May 2015 cliftonlarsonallen.com Overview PCI DSS In the beginning Each major card brand had its own separate

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire D and Attestation of Compliance All other SAQ-Eligible Merchants and Service Providers Version 2.0 October 2010 Document

More information

Tokenization Amplified XiIntercept. The ultimate PCI DSS cost & scope reduction mechanism

Tokenization Amplified XiIntercept. The ultimate PCI DSS cost & scope reduction mechanism Tokenization Amplified XiIntercept The ultimate PCI DSS cost & scope reduction mechanism Paymetric White Paper Tokenization Amplified XiIntercept 2 Table of Contents Executive Summary 3 PCI DSS 3 The PCI

More information

PCI DSS Compliance. 2015 Information Pack for Merchants

PCI DSS Compliance. 2015 Information Pack for Merchants PCI DSS Compliance 2015 Information Pack for Merchants This pack contains general information regarding PCI DSS compliance and does not take into account your business' particular requirements. ANZ recommends

More information

PCI Compliance. Top 10 Questions & Answers

PCI Compliance. Top 10 Questions & Answers PCI Compliance Top 10 Questions & Answers 1. What is PCI Compliance and PCI DSS? 2. Who needs to follow the PCI Data Security Standard? 3. What happens if I don t comply? 4. What are the basic requirements

More information

PCI Data Security Standards

PCI Data Security Standards PCI Data Security Standards An Introduction to Bankcard Data Security Why should we worry? Since 2005, over 500 million customer records have been reported as lost or stolen 1 In 2010 alone, over 134 million

More information

Why Is Compliance with PCI DSS Important?

Why Is Compliance with PCI DSS Important? Why Is Compliance with PCI DSS Important? The members of PCI Security Standards Council (American Express, Discover, JCB, MasterCard, and Visa) continually monitor cases of account data compromise. These

More information

PCI Compliance Top 10 Questions and Answers

PCI Compliance Top 10 Questions and Answers Where every interaction matters. PCI Compliance Top 10 Questions and Answers White Paper October 2013 By: Peer 1 Hosting Product Team www.peer1.com Contents What is PCI Compliance and PCI DSS? 3 Who needs

More information

Frequently Asked Questions

Frequently Asked Questions PCI Compliance Frequently Asked Questions Table of Content GENERAL INFORMATION... 2 PAYMENT CARD INDUSTRY DATA SECURITY STANDARD (PCI DSS)...2 Are all merchants and service providers required to comply

More information

Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015

Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015 Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015 I. PURPOSE The purpose of this policy is to establish guidelines for processing charges on Payment Cards to protect

More information

Payment Card Industry (PCI) Data Security Standard. Attestation of Compliance for Self-Assessment Questionnaire C-VT. Version 2.0

Payment Card Industry (PCI) Data Security Standard. Attestation of Compliance for Self-Assessment Questionnaire C-VT. Version 2.0 Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Self-Assessment Questionnaire C-VT Version 2.0 October 2010 Attestation of Compliance, SAQ C-VT Instructions for Submission

More information

White Paper On. PCI DSS Compliance And Voice Recording Implications

White Paper On. PCI DSS Compliance And Voice Recording Implications White Paper On PCI DSS Compliance And Voice Recording Implications PCI DSS within the UK is becoming a hot topic of conversation, with many contradictions and confusions being issued by suppliers and professionals

More information

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008 Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008 What is the PCI DSS? And what do the acronyms CISP, SDP, DSOP and DISC stand for? The PCI DSS is a set of comprehensive requirements

More information

AheevaCCS and the Payment Card Industry Data Security Standard

AheevaCCS and the Payment Card Industry Data Security Standard Account Data PCI DSS White Paper by Aheeva, January 2012 AheevaCCS and the Payment Card Industry Data Security Standard Introduction In 2006, the major payment brands including American Express, MasterCard

More information

PCI DSS FAQ. The twelve requirements of the PCI DSS are defined as follows:

PCI DSS FAQ. The twelve requirements of the PCI DSS are defined as follows: What is PCI DSS? PCI DSS is an acronym for Payment Card Industry Data Security Standards. PCI DSS is a global initiative intent on securing credit and banking transactions by merchants & service providers

More information

Keeping your Telephone Payments Watertight: Making your Contact Centre PCI Compliant

Keeping your Telephone Payments Watertight: Making your Contact Centre PCI Compliant Keeping your Telephone Payments Watertight: Making your Contact Centre PCI Compliant 1 PCI DSS: Y ur Payment Security Lifeguard If the mention of PCI DSS compliance leaves you all at sea, you are not alone.

More information

IT Security Compliance PCI DSS FOR MERCHANTS THE PAYMENT CARD INDUSTRY DATE SECURITY STANDARD WHITE PAPER

IT Security Compliance PCI DSS FOR MERCHANTS THE PAYMENT CARD INDUSTRY DATE SECURITY STANDARD WHITE PAPER July 9 th, 2012 Prepared By: Mark Akins PCI QSA, CISSP, CISA WHITE PAPER IT Security Compliance PCI DSS FOR MERCHANTS THE PAYMENT CARD INDUSTRY DATE SECURITY STANDARD PCI DSS for Merchants The Payment

More information

Information Technology

Information Technology Credit Card Handling Security Standards Overview Information Technology This document is intended to provide guidance to merchants (colleges, departments, organizations or individuals) regarding the processing

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire Instructions and Guidelines Version 1.1 February 2008 Table of Contents About this Document... 1 PCI Data Security Standard

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire Instructions and Guidelines Version 3.2 May 2016 Document Changes Date Version Description October 1, 2008 1.2 October 28,

More information

PCI DSS Compliance Services January 2016

PCI DSS Compliance Services January 2016 PCI DSS Compliance Services January 2016 20160104-Galitt-PCI DSS Compliance Services.pptx Agenda 1. Introduction 2. Overview of the PCI DSS standard 3. PCI DSS compliance approach Copyright Galitt 2 Introduction

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance Merchants with Only Imprint Machines or Only Standalone, Dial-out Terminals Electronic Cardholder

More information

Information Sheet. PCI DSS Overview

Information Sheet. PCI DSS Overview The payment card industry (PCI) protects cardholder data through technical and operations standard set by its Council. Compliance with PCI standards is mandatory. It is enforced by the major payment card

More information

How To Protect Your Business From A Hacker Attack

How To Protect Your Business From A Hacker Attack Payment Card Industry Data Security Standards The payment card industry data security standard PCI DSS Visa and MasterCard have developed the Payment Card Industry Data Security Standard or PCI DSS as

More information

Payment Card Industry Data Security Standard Training. Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc.

Payment Card Industry Data Security Standard Training. Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc. Payment Card Industry Data Security Standard Training Chris Harper Vice President of Technical Services Secure Enterprise Computing, Inc. March 27, 2012 Agenda Check-In 9:00-9:30 PCI Intro and History

More information

2015 PCI DSS Meeting. OSU Business Affairs Projects, Improvement, and Technology (PIT) Robin Whitlock

2015 PCI DSS Meeting. OSU Business Affairs Projects, Improvement, and Technology (PIT) Robin Whitlock 2015 PCI DSS Meeting OSU Business Affairs Projects, Improvement, and Technology (PIT) Robin Whitlock 11/3/2015 Today s Presentation What do you need to do? What is PCI DSS? Why PCI DSS? Who Needs to Comply

More information

PCI Standards: A Banking Perspective

PCI Standards: A Banking Perspective Slide 1 PCI Standards: A Banking Perspective Bob Brown, CISSP Wachovia Corporate Information Security Slide 2 Agenda 1. Payment Card Initiative History 2. Description of the Industry 3. PCI-DSS Control

More information

PCI Compliance. What is New in Payment Card Industry Compliance Standards. October 2015. cliftonlarsonallen.com. 2015 CliftonLarsonAllen LLP

PCI Compliance. What is New in Payment Card Industry Compliance Standards. October 2015. cliftonlarsonallen.com. 2015 CliftonLarsonAllen LLP cliftonlarsonallen.com PCI Compliance What is New in Payment Card Industry Compliance Standards October 2015 Overview PCI DSS In the beginning Each major card brand had its own separate criteria for implementing

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Self-Assessment Questionnaire D Service Providers For use with PCI DSS Version 3.1 Revision 1.1 July 2015 Section 1: Assessment

More information

COLORADO STATE UNIVERSITY Financial Procedure Statements FPI 6-6

COLORADO STATE UNIVERSITY Financial Procedure Statements FPI 6-6 1. Procedure Title: PCI Compliance Program COLORADO STATE UNIVERSITY Financial Procedure Statements FPI 6-6 2. Procedure Purpose and Effect: All Colorado State University departments that accept credit/debit

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Standard Attestation of Compliance for Self-Assessment Questionnaire D Service Providers Version 3.1 April 2015 Section 1: Assessment Information Instructions for Submission

More information

Josiah Wilkinson Internal Security Assessor. Nationwide

Josiah Wilkinson Internal Security Assessor. Nationwide Josiah Wilkinson Internal Security Assessor Nationwide Payment Card Industry Overview PCI Governance/Enforcement Agenda PCI Data Security Standard Penalties for Non-Compliance Keys to Compliance Challenges

More information

Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS)

Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS) Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS) What is PCI DSS? The 12 Requirements Becoming compliant with SaferPayments Understanding the jargon SaferPayments Be smart.

More information

Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance

Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance A Non-Technical Guide Essential for Business Managers Office Managers Operations Managers Compliant? Bank Name

More information

PC-DSS Compliance Strategies. 2011 NDUS CIO Retreat July 27, 2011 Theresa Semmens, CISA

PC-DSS Compliance Strategies. 2011 NDUS CIO Retreat July 27, 2011 Theresa Semmens, CISA PC-DSS Compliance Strategies 2011 NDUS CIO Retreat July 27, 2011 Theresa Semmens, CISA True or False Now that my institution has outsourced credit card processing, I don t have to worry about compliance?

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.0 February 2014 Section 1: Assessment Information Instructions for Submission

More information

An article on PCI Compliance for the Not-For-Profit Sector

An article on PCI Compliance for the Not-For-Profit Sector Level 8, 66 King Street Sydney NSW 2000 Australia Telephone +61 2 9290 4444 or 1300 922 923 An article on PCI Compliance for the Not-For-Profit Sector Page No.1 PCI Compliance for the Not-For-Profit Sector

More information

PCI Compliance Overview

PCI Compliance Overview PCI Compliance Overview 1 PCI DSS Payment Card Industry Data Security Standard Standard that is applied to: Merchants Service Providers (Banks, Third party vendors, gateways) Systems (Hardware, software)

More information

Adyen PCI DSS 3.0 Compliance Guide

Adyen PCI DSS 3.0 Compliance Guide Adyen PCI DSS 3.0 Compliance Guide February 2015 Page 1 2015 Adyen BV www.adyen.com Disclaimer: This document is for guidance purposes only. Adyen does not accept responsibility for any inaccuracies. Merchants

More information

Key Steps to Meeting PCI DSS 2.0 Requirements Using Sensitive Data Discovery and Masking

Key Steps to Meeting PCI DSS 2.0 Requirements Using Sensitive Data Discovery and Masking Key Steps to Meeting PCI DSS 2.0 Requirements Using Sensitive Data Discovery and Masking SUMMARY The Payment Card Industry Data Security Standard (PCI DSS) defines 12 high-level security requirements directed

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance Imprint Machines or Stand-alone Dial-out Terminals Only, no Electronic Cardholder Data Storage

More information

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance Card-not-present Merchants, All Cardholder Data Functions Fully Outsourced Version 3.0 February

More information

PCI Compliance 3.1. About Us

PCI Compliance 3.1. About Us PCI Compliance 3.1 University of Hawaii About Us Helping organizations comply with mandates, recover from security breaches, and prevent data theft since 2000. Certified to conduct all major PCI compliance

More information

Safe and Sound Processing Telephone Payments Securely. A white paper from Barclaycard and Visa Europe leading the way in secure payments April 2015

Safe and Sound Processing Telephone Payments Securely. A white paper from Barclaycard and Visa Europe leading the way in secure payments April 2015 Safe and Sound Processing Telephone Payments Securely A white paper from Barclaycard and Visa Europe leading the way in secure payments April 2015 Executive summary The following information and guidance

More information

University of Dayton Credit / Debit Card Acceptance Policy September 1, 2009

University of Dayton Credit / Debit Card Acceptance Policy September 1, 2009 University of Dayton Credit / Debit Card Acceptance Policy September 1, 2009 Effective Date of this Policy: August 1, 2008 Last Revision: September 1, 2009 Contact for More Information: UDit Internal Auditor

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.1 April 2015 Section 1: Assessment Information Instructions for Submission

More information

Credit Card Handling Security Standards

Credit Card Handling Security Standards Credit Card Handling Security Standards Overview This document is intended to provide guidance to merchants (colleges, departments, auxiliary organizations or individuals) regarding the processing of charges

More information

PCI Compliance: How to ensure customer cardholder data is handled with care

PCI Compliance: How to ensure customer cardholder data is handled with care PCI Compliance: How to ensure customer cardholder data is handled with care Choosing a safe payment process for your business Contents Contents 2 Executive Summary 3 PCI compliance and accreditation 4

More information

University of Sunderland Business Assurance PCI Security Policy

University of Sunderland Business Assurance PCI Security Policy University of Sunderland Business Assurance PCI Security Policy Document Classification: Public Policy Reference Central Register IG008 Policy Reference Faculty / Service IG 008 Policy Owner Chief Financial

More information

Payment Card Industry - Achieving PCI Compliance Steps Steps

Payment Card Industry - Achieving PCI Compliance Steps Steps CUR RITY SE Data Security Requirements for K-12 January 28, 2010 Payment Card Industry (PCI) SE CUR RITY 1 Welcome To Join The Voice Conference Dial 866-939-3921 Technical issues press 0 Q & A We ll leave

More information

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer Complying with the PCI DSS All the Moving Parts Don Roeber Vice President, PCI Compliance Manager Lisa Tedeschi Assistant Vice President, Compliance Officer Types of Risk Operational Risk Normal fraud

More information

What are the PCI DSS requirements? PCI DSS comprises twelve requirements, often referred to as the digital dozen. These define the need to:

What are the PCI DSS requirements? PCI DSS comprises twelve requirements, often referred to as the digital dozen. These define the need to: What is the PCI standards council? The Payment Card Industry Standards Council is an institution set-up by American Express, Discover Financial Services, JCB, MasterCard Worldwide and Visa International

More information

DATA SECURITY. Payment Card Industry (PCI) Compliance Steps for Organizations May 26, 2010. 2010 Merit Member Conference

DATA SECURITY. Payment Card Industry (PCI) Compliance Steps for Organizations May 26, 2010. 2010 Merit Member Conference 2010 Merit Member Conference Compliance Steps for Organizations May 26, 2010 Payment Card Industry (PCI) 1 Welcome 2 Welcome Q & A We ll leave time to address questions during the last 15 minutes of the

More information

How Secure is Your Payment Card Data?

How Secure is Your Payment Card Data? How Secure is Your Payment Card Data? Complying with PCI DSS SLIDE 1 PRESENTERS Francis Tam, CPA, CISA, CISM, CITP, CRISC, PCI QSA Managing Director, IT Security Practice PCI Practice Leader Francis has

More information

HOW SECURE IS YOUR PAYMENT CARD DATA? COMPLYING WITH PCI DSS

HOW SECURE IS YOUR PAYMENT CARD DATA? COMPLYING WITH PCI DSS HOW SECURE IS YOUR PAYMENT CARD DATA? COMPLYING WITH PCI DSS August 23, 2011 MOSS ADAMS LLP 1 TODAY S PRESENTERS Presenters Francis Tam, CPA, CISA, CISM, CITP, CRISC, PCI QSA Managing Director, IT Security

More information

Need to be PCI DSS compliant and reduce the risk of fraud?

Need to be PCI DSS compliant and reduce the risk of fraud? Need to be PCI DSS compliant and reduce the risk of fraud? NCR Security lessens your PCI compliance burden and protects the integrity of your network An NCR White Paper Experience a new world of interaction

More information

This appendix is a supplement to the Local Government Information Security: Getting Started Guide, a non-technical reference essential for elected

This appendix is a supplement to the Local Government Information Security: Getting Started Guide, a non-technical reference essential for elected This appendix is a supplement to the Local Government Information Security: Getting Started Guide, a non-technical reference essential for elected officials, administrative officials and business managers.

More information

PCI Security Standards Council

PCI Security Standards Council PCI Security Standards Council Jeremy King, European Director 2013 Why PCI Matters Applying PCI How You Can Participate Agenda 2 Why PCI Matters Applying PCI How You Can Participate Agenda About the PCI

More information

PAI Secure Program Guide

PAI Secure Program Guide PAI Secure Program Guide A complete guide to understanding the Payment Card Industry Data Security Requirements and utilizing the PAI Secure Program. Letter From the CEO Welcome to PAI Secure. As you

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.0 February 2014 Section 1: Assessment Information Instructions for Submission

More information

PCI DSS Overview. By Kishor Vaswani CEO, ControlCase

PCI DSS Overview. By Kishor Vaswani CEO, ControlCase PCI DSS Overview By Kishor Vaswani CEO, ControlCase Agenda About PCI DSS PCI DSS Applicability to Banks, Merchants and Service Providers PCI DSS Technical Requirements Overview of PCI DSS 3.0 Changes Key

More information

How To Comply With The Pci Ds.S.A.S

How To Comply With The Pci Ds.S.A.S PCI Compliance and the Data Security Standards Introduction The PCI DSS, a set of comprehensive requirements for enhancing payment account data security, was developed by the founding payment brands of

More information

Merchant guide to PCI DSS

Merchant guide to PCI DSS Merchant guide to PCI DSS Contents What is PCI DSS and why was it introduced?... 3 Who needs to become PCI DSS compliant?... 3 BOIPA Simple PCI DSS - 3 step approach to helping businesses... 3 What does

More information

North Carolina Office of the State Controller Technology Meeting

North Carolina Office of the State Controller Technology Meeting PCI DSS Security Awareness Training North Carolina Office of the State Controller Technology Meeting April 30, 2014 agio.com A Note on Our New Name Secure Enterprise Computing was acquired as the Security

More information

PCI DSS 101 FOR CTOs AND BUSINESS EXECUTIVES

PCI DSS 101 FOR CTOs AND BUSINESS EXECUTIVES PCI DSS 101 FOR CTOs AND BUSINESS EXECUTIVES CUTTING THROUGH THE COMPLEXITY AND CONFUSION Over the years, South African retailers have come under increased pressure to gain PCI DSS (Payment Card Industry

More information

Payment Card Industry Data Security Standard PCI DSS

Payment Card Industry Data Security Standard PCI DSS Payment Card Industry Data Security Standard PCI DSS What is PCI DSS? Requirements developed by the five card brands: VISA, Mastercard, AMEX, JCB and Discover. Their aim was to put together a common set

More information

Minnesota State Colleges and Universities System Procedures Chapter 5 Administration. Guideline 5.23.1.10 Payment Card Industry Technical Requirements

Minnesota State Colleges and Universities System Procedures Chapter 5 Administration. Guideline 5.23.1.10 Payment Card Industry Technical Requirements Minnesota State Colleges and Universities System Procedures Chapter 5 Administration Payment Card Industry Technical s Part 1. Purpose. This guideline emphasizes many of the minimum technical requirements

More information

Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions

Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions PCI/PA-DSS FAQs Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions What is PCI DSS? The Payment Card Industry Data

More information

Payment Cardholder Data Handling Procedures (required to accept any credit card payments)

Payment Cardholder Data Handling Procedures (required to accept any credit card payments) Payment Cardholder Data Handling Procedures (required to accept any credit card payments) Introduction: The Procedures that follow will allow the University to be in compliance with the Payment Card Industry

More information

Third Party Agent Registration and PCI DSS Compliance Validation Guide

Third Party Agent Registration and PCI DSS Compliance Validation Guide Visa Europe Third Party Agent Registration and PCI DSS Compliance Validation Guide May 2016 Version 1.3 Visa Europe 2015 Contents 1 Introduction... 4 1.1 Definitions of Agents... 4 2 Registration Process...

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.0 February 2014 Section 1: Assessment Information Instructions for Submission

More information

Guidance Notes PCI DSS Compliance as it relates to Call Recording

Guidance Notes PCI DSS Compliance as it relates to Call Recording Guidance Notes PCI DSS Compliance as it relates to Call Recording Published by DMA Contact Centres & Telemarketing Council First edition Contents Disclaimer...2 1. Background...3 2. The fundamental storage

More information

A MERCHANTS GUIDE TO THE PAYMENT APPLICATION DATA SECURITY STANDARD (PA-DSS)

A MERCHANTS GUIDE TO THE PAYMENT APPLICATION DATA SECURITY STANDARD (PA-DSS) A MERCHANTS GUIDE TO THE PAYMENT APPLICATION DATA SECURITY STANDARD (PA-DSS) The mandatory guide for storing, processing or transmitting cardholder information Overview and applicability Any application

More information

TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No. 08-01 MERCHANT DEBIT AND CREDIT CARD RECEIPTS

TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No. 08-01 MERCHANT DEBIT AND CREDIT CARD RECEIPTS TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No. 08-01 MERCHANT DEBIT AND CREDIT CARD RECEIPTS 1. Introduction Debit and Credit Card Receipt Standards apply to the administration

More information

Project Title slide Project: PCI. Are You At Risk?

Project Title slide Project: PCI. Are You At Risk? Blank slide Project Title slide Project: PCI Are You At Risk? Agenda Are You At Risk? Video What is the PCI SSC? Agenda What are the requirements of the PCI DSS? What Steps Can You Take? Available Services

More information

How To Protect Your Credit Card Information From Being Stolen

How To Protect Your Credit Card Information From Being Stolen Visa Account Information Security Tool Kit Welcome to the Visa Account Information Security Program 2 Contents 1. Securing cardholder data is everyone s concern 4 2. Visa Account Information Security (AIS)

More information

PDQ Guide for the PCI Data Security Standard Self-Assessment Questionnaire C (Version 1.1)

PDQ Guide for the PCI Data Security Standard Self-Assessment Questionnaire C (Version 1.1) PDQ has created an Answer Guide for the Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire C to help wash operators complete questionnaires. Part of the Access Customer Management

More information

PCI Security Compliance

PCI Security Compliance E N T E R P R I S E Enterprise Security Solutions PCI Security Compliance : What PCI security means for your business The Facts Comodo HackerGuardian TM PCI and the Online Merchant Overview The Payment

More information

Office of Finance and Treasury

Office of Finance and Treasury Office of Finance and Treasury How to Accept & Process Credit and Debit Card Transactions Procedure Related Policy Title Credit Card Processing Policy For University Merchant Locations Responsible Executive

More information

Puzzled about PCI compliance? Proactive ways to navigate through the standard for compliance

Puzzled about PCI compliance? Proactive ways to navigate through the standard for compliance Puzzled about PCI compliance? Proactive ways to navigate through the standard for compliance March 29, 2012 1:00 p.m. ET If you experience any technical difficulties, please contact 888.228.0988 or support@learnlive.com

More information

Standard: PCI Data Security Standard (PCI DSS) Version: 2.0 Date: March 2011. Information Supplement: Protecting Telephone-based Payment Card Data

Standard: PCI Data Security Standard (PCI DSS) Version: 2.0 Date: March 2011. Information Supplement: Protecting Telephone-based Payment Card Data Standard: PCI Data Security Standard (PCI DSS) Version: 2.0 Date: March 2011 Information Supplement: Protecting Telephone-based Payment Card Data Table of Contents Executive Summary 3 Clarification of

More information

Comodo HackerGuardian. PCI Security Compliance The Facts. What PCI security means for your business

Comodo HackerGuardian. PCI Security Compliance The Facts. What PCI security means for your business Comodo HackerGuardian PCI Security Compliance The Facts What PCI security means for your business Overview The Payment Card Industry Data Security Standard (PCI DSS) is a set of 12 requirements intended

More information

Dartmouth College Merchant Credit Card Policy for Processors

Dartmouth College Merchant Credit Card Policy for Processors Mission Statement Dartmouth College Merchant Credit Card Policy for Processors Dartmouth College requires all departments that process, store or transmit credit card data remain in compliance with the

More information

WHITE PAPER. PCI Basics: What it Takes to Be Compliant

WHITE PAPER. PCI Basics: What it Takes to Be Compliant WHITE PAPER PCI Basics: What it Takes to Be Compliant Introduction A long-running worldwide advertising campaign by Visa states that the card is accepted everywhere you want to be. Unfortunately, and through

More information

Payment Card Industry - Data Security Standard (PCI-DSS) Security Policy

Payment Card Industry - Data Security Standard (PCI-DSS) Security Policy Payment Card Industry - Data Security Standard () Security Policy Version 1-0-0 3 rd February 2014 University of Leeds 2014 The intellectual property contained within this publication is the property of

More information

PCI DSS 3.0 Overview. OSU Business Affairs Business Affairs PIT Crew - Project, Improvement, & Technology Robin Whitlock

PCI DSS 3.0 Overview. OSU Business Affairs Business Affairs PIT Crew - Project, Improvement, & Technology Robin Whitlock PCI DSS 3.0 Overview OSU Business Affairs Business Affairs PIT Crew - Project, Improvement, & Technology Robin Whitlock 01/16/2015 Purpose of Today s Presentation To provide an overview of PCI 3.0 based

More information

Credit Cards and Oracle: How to Comply with PCI DSS. Stephen Kost Integrigy Corporation Session #600

Credit Cards and Oracle: How to Comply with PCI DSS. Stephen Kost Integrigy Corporation Session #600 Credit Cards and Oracle: How to Comply with PCI DSS Stephen Kost Integrigy Corporation Session #600 Background Speaker Stephen Kost CTO and Founder 16 years working with Oracle 12 years focused on Oracle

More information

MasterCard PCI & Site Data Protection (SDP) Program Update. Academy of Risk Management Innovate. Collaborate. Educate.

MasterCard PCI & Site Data Protection (SDP) Program Update. Academy of Risk Management Innovate. Collaborate. Educate. MasterCard PCI & Site Data Protection (SDP) Program Update Academy of Risk Management Innovate. Collaborate. Educate. The Payment Card Industry Security Standards Council (PCI SSC) Open, Global Forum Founded

More information

PCI General Policy. Effective Date: August 2008. Approval: December 17, 2015. Maintenance of Policy: Office of Student Accounts REFERENCE DOCUMENTS:

PCI General Policy. Effective Date: August 2008. Approval: December 17, 2015. Maintenance of Policy: Office of Student Accounts REFERENCE DOCUMENTS: Effective Date: August 2008 Approval: December 17, 2015 PCI General Policy Maintenance of Policy: Office of Student Accounts PURPOSE: To protect against the exposure and possible theft of account and personal

More information

SECTION: SUBJECT: PCI-DSS General Guidelines and Procedures

SECTION: SUBJECT: PCI-DSS General Guidelines and Procedures 1. Introduction 1.1. Purpose and Background 1.2. Central Coordinator Contact 1.3. Payment Card Industry Data Security Standards (PCI-DSS) High Level Overview 2. PCI-DSS Guidelines - Division of Responsibilities

More information

BT Inbound Contact UK Service Schedule Annex 1 Secure Contact - Payment Card Industry Compliance

BT Inbound Contact UK Service Schedule Annex 1 Secure Contact - Payment Card Industry Compliance SERVICE SCHEDULE ANNEX 1 CONTENTS 1. SERVICE DESCRIPTION 2. ORDERING AND DELIVERY OF THE SERVICE 3. FAULT MANAGEMENT 4. SERVICE LEVEL AGREEMENT 5. DDI NUMBERS 6. AGENT INTERFACE AND NETWORK ACCESS 7. PAYMENT

More information

So you want to take Credit Cards!

So you want to take Credit Cards! So you want to take Credit Cards! Payment Card Industry - Data Security Standard: (PCI-DSS) Doug Cox GSEC, CPTE, PCI/ISA, MBA dcox@umich.edu Data Security Analyst University of Michigan PCI in Higher Ed

More information

Finance Office. Card Handling Policy

Finance Office. Card Handling Policy Finance Office Card Handling Policy Prepared by: Lyndsay Brown Issued: November 2012 1 Contents Page 1 Introduction 3 2 Responsibility 3 3 The PCI Data Security Standard 3 4 PCI DSS Requirements 4 5 Receiving/

More information

Dartmouth College Merchant Credit Card Policy for Managers and Supervisors

Dartmouth College Merchant Credit Card Policy for Managers and Supervisors Dartmouth College Merchant Credit Card Policy for Managers and Supervisors Mission Statement Dartmouth College requires all departments that process, store or transmit credit card data remain in compliance

More information

Credit Card Processing Overview

Credit Card Processing Overview CardControl 3.0 Credit Card Processing Overview Overview Credit card processing is a very complex and important system for anyone that sells goods. This guide will hopefully help educate and inform new

More information

Payment Card Industry (PCI) Data Security Standard

Payment Card Industry (PCI) Data Security Standard Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.0 February 2014 Section 1: Assessment Information Instructions for Submission

More information

PCI DSS and SSC what are these?

PCI DSS and SSC what are these? PCI DSS and SSC what are these? What does PCI DSS mean? PCI DSS is the English acronym for Payment Card Industry Data Security Standard. What is the PCI DSS programme? The bank card data, which are the

More information