Credit Card Numbers / Security Code Best Practices PCI DSS
|
|
|
- Carol McDaniel
- 10 years ago
- Views:
Transcription
1 Credit Card Numbers / Security Code Best Practices PCI DSS
2 1 Overview The aim of this document is to give the 'Credit Card numbers' and 'Security Code' best practices usage within the Amadeus Central system applications. Like all companies processing Credit Card data, Amadeus has to follow the PCI DSS rules (see PCI DSS section). PCI DSS requires strong data security (like concealment, encryption, access restriction ) in PNR and Profile elements containing Credit Card information. One of the major initiatives underway is to secure all PNR/Profile elements where credit card information is appended (e.g. Credit Card Concealment). Today, only the following fields can be populated with Credit Card information because only those fields are secured in Amadeus system: For PNR Elements: - Credit Card Numbers can only be entered in: - Guarantee fields for Hotel and Car segments: '/G' - Deposit fields for hotel and car segments: '/DP' - Special Service Request for Form of Identification: 'SSR FOID' - Special Service Request for Electronic Payment: 'SSR EPAY' - Form of Payment element: 'FP' - Form of Payment sub-elements in miscellaneous documents: 'MCO' and 'SVC'. - Security Code can only be entered in: - Special Service Request for Electronic Payment: 'SSR EPAY' - Form of Payment element/sub-elements: 'FP' For Profile Application: - Credit Card Numbers can be stored only in: - Guarantee fields for Hotel and Car segments: '/G' - Special Service Request for Form of Identification: 'SSR FOID' - Special Service Request for Electronic Payment: 'SSR EPAY' - Form of Payment element: 'FP' - Security Code must not be stored anywhere in the Profile application. All other PNR/Profile fields, and specially free-flow remarks and transferable entries, must not contain any Credit Card Information under any circumstances (neither Credit Card number nor Security Code). If a travel agent and/or airline populates any Credit Card information in other PNR/Profile fields (others than the approved ones listed above), airlines and/or travel agencies are at a high risk of breaching relevant industry security standards including PCI-DSS which could lead to serious consequences such as reputation loss and/or financial loss, fines, third party claims, etc N.V. Page 2 of 8
3 Free-flow text: Remarks, OSI fields and Profile notes: All free-flow text fields (like Remarks - 'RM', 'RC', 'RX', 'OSI' fields and Profile Notes) fall under the category that must not contain any credit card information (those PNR elements are not listed). There is some evidences that agents are making an inappropriate usage of some PNR fields to store Credit Card information - this must not be done anymore (see 'Illustration' section for some examples). Actions and responsibilities: If you are aware of any process that needs to store the Credit Card Information in other fields than the ones stated above, it is your responsibility to notify Amadeus: travel agencies can contact their Local Sales Representative. This will allow us to: - See with you the exact reason why you are using those fields to store card information. - Check if a secure and PCI DSS compliant solution can be proposed (or implemented). As part of the PCI DSS audit, Amadeus has committed to sanitize all the systems where the Credit Card information is not stored correctly (for instance, it can be mechanisms that detect Credit Card numbers in a PNR field and automatically remove it - with/without notification). It can impact at a first step all the logs and in a second step PNR and Profile: it means some strong business impacts for your products/solution/customers if this is not anticipated in advance. About PCI DSS: PCI DSS stands for Payment Card Industry Data Security Standard. PCI DSS is a new worldwide standard for consumer data protection. The purpose of PCI DSS is to help Credit Card processors improving data security measures, ultimately safeguarding cardholder information. Complying with PCI DSS can lead to increase consumer protection and loyalty, limiting the exposure to customer disputes as well as fraud. Information on PCI DSS program is available on 'PCI Security Standards Council' web site: N.V. Page 3 of 8
4 Requirement 3 in the PCI DSS Requirement 3 deals with the cardholder data protection. The below section is a copy/paste from the PCI DSS standards that deals with the Credit Card number/security Code policy: QUOTE Requirement 3: Protect stored cardholder data../.. - [Req 3.1] Keep cardholder information storage to a minimum - [Req 3.2] Do not store sensitive authentication data subsequent to authorization (not even if encrypted). - [Req 3.2.2] Do not store the card-validation code: three-digit or four-digit value printed on the front or back of a payment card (e.g., CVV2 and CVC2 data). - [Req 3.3] Mask account numbers when displayed (the first six and last four digits are the maximum number of digits to be displayed).../.. - [Req 3.4] Render Credit Card number, at minimum, unreadable anywhere it is stored... (equals to 'encryption' requirement) END Benefits: Amadeus ensures correct Credit Card processing security by being compliant with Credit Card schemes rules. It will enable our customers to reduce the risk of fraudulent actions within their own organization. It will also allow Amadeus to improve its Credit Card information processing for its customers N.V. Page 4 of 8
5 2 Illustrations This section gives the example of different PNR with Credit Information incorrectly and correctly inserted (Note that real Credit Card number, Passenger name and others confidential information had been removed or renamed in the PNR) Example 1: Inappropriate usage of RC and RM fields RP/HAMLT21BW/HAMLT21BW HO/SU 07FEB06/1144Z ZV EXAMPLE1/EXAMPLE MR 2 IB8428 R 12JUL 3 BCNLEI HK1 C *1A/E* 3 IB8419 H 18JUL 2 LEIBCN HK *1A/E* 4 AP PAX FRAU EXAMPLE 5 AP FIRMA EXAMPLE@COMPANY AG 6 AP GOETHE STRASSE BERLIN 7 AP FAX AP KD NR TK OK11JUL/HAMLT21BW//ETIB 10 RC HAMLT21BW-W/CVV CODE MASTER CARD 123 <== CVC2 information in clear in RC: prohibited 11 RM AX /1106 <== CC number in clear in RM: prohibited 12 FE PAX CHANGE/REFUND RESTRICTED/S FM PAX *C*0.00/S FP PAX CCCAXXXXXXXXXXXX5312/0407/A52134/S2-3 <== CC number concealed properly (FP element): OK Example 2: Inappropriate usage of RC and RM fields RP/BODVI378D/BODVI378D OC/PR 07FEB06/1155Z Y EXAMPLE2/PETER 2 AF6006 N 12AUG 6 ORYMRS HK W *1A/E* 3 AP AP BOD ADELINE 5 APE [email protected] 6 TK OK15JUN/BODVI378D//ETAF 7 RC BODVI378D-W/BODVI378D D0607 <== CC information in clear in RM: prohibited 8 RM CCN:QUINTON 9 RM CCVI 10 RM CVV: PRESENT 114 <== CVV2 information in clear in RM: prohibited 11 RM E-TKT SCRIPT 2009 N.V. Page 5 of 8
6 Example 3: Inappropriate usage of OSI field --- TST RLR --- RP/SELKE18BB/SELKE EXAMPLE3/JOHN MR(ADT) AA/SU 7JUL06/0352Z YIL123 2 KE5704 Y 12OCT 4 NRTICN HK *1A/ 3 KE 001 Y 19OCT 4 ICNNRT HK1 4 AP SEL *1A/E* 5 TK OK07JUL/SELKE18BB 6 OSI 1A KE RSVN NBR IS OSI YY FARE USD 8 OSI KE TKOK/SELKE18BB 9 OSI KE TIDTEST3 10 OSI YY MARTIN//AMADEUS.COM 11 OSI KE AP H 12 OSI KE MODCUSTOMER PICKUP AT AIRPORT 13 OSI KE MOPCHARGE MY CREDIT CARD 14 OSI KE FPCCVI CV123 <== CC number and CVV2 in clear in OSI: prohibited 15 OSI KE AB SUNITA AMADEUS/TEST CVC/WRONG NO AND CVC/BKK///TH 16 RM PRICING ENTRY FXP/R,UP,LAX.LAX 17 RM COSECONOMY Example 4: Correct usage of FP field --- RLR --- RP/MIA1S2CA1/MIA1S2CA1 ZZ/SU 6JAN06/1905Z YEV123 1.EXAMPLE4/NORMAN 2 AA1139 Y 20OCT 1 ORDMIA HK E* 3 AP MIA (305) AMADEUS - A 4 TK OK06JAN/MIA1S2CA1 5 FM *M*0 6 FP CCVIXXXXXXXXXXX2226/1207*CV/A555381/S2 <== CC number is concealed, CVV2 used correctly (FP): OK Example 5: Correct usage of SSR EPAY field RP/MUC1A0701/MUC1A0701 BM/PR 29MAY06/1351Z 2ST123 1.EXAMPLE5/ROSSANA 2 G31715 Y 20SEP 3 BSBCNF HK AP MUC - AMADEUS DEFAULT OFFICE - A 4 TK OK29MAY/MUC1A SSR EPAY G3 HN1 CCVIXXXXXXXXXXX1004/EXP08 09/NAME ANA CXXXX IXX <== CC number is concealed, CVV2 used correctly: OK 2009 N.V. Page 6 of 8
7 Example 6: Inappropriate usage of Profile Notes *F* SMITH/JOHN ZA9Z5X FREQUENT FLYER INFORMATION *ACTIVE* AIRLINE : 6X CUSTOMER TYPE : VIP TIER / PRIORITY : GOLD/1 ALLIANCE TIER : FF NUMBER : EXPIRY DATE : 02SEP PNR TRANSFERABLE DATA 1 A NM 1 SMITH/JOHN 2 A FFN 6X A ST /N/A * INTERNATIONAL 4 A SR SPML - NO FISH * DOMESTIC GENERAL INFORMATION 5 PCZ/ GB 6 PBD/ 19APR PAD/ LHR 8 PIC/ IBM 9 PJT/ PROJECT MANAGER 10 PSX/ M DOCUMENTS 11 PAS/ PT / PB /10JAN2000/10JAN PIV/ PT / /15DEC2000/15JUN PCE/ PT /GTR /15JAN2000/15JAN PID/ PT /Y /01JAN2001/31DEC PROFILE NOTES 1 AX /1106 <== CC number in clear in Profile Notes: prohibited Example 7: Inappropriate usage of Frequent Flyer Profile Number 2009 N.V. *F* SMITH/JOHN ZA9Z5X FREQUENT FLYER INFORMATION *ACTIVE* AIRLINE : 6X CUSTOMER TYPE : VIP TIER / PRIORITY : GOLD/1 ALLIANCE TIER : FF NUMBER : <== CC number should not be used as Frequent Flyer number EXPIRY DATE : 02SEP PNR TRANSFERABLE DATA 1 A NM 1 SMITH/JOHN 2 A FFN 6X A ST /N/A * INTERNATIONAL 4 A SR SPML - NO FISH * DOMESTIC GENERAL INFORMATION 5 PCZ/ GB 6 PBD/ 19APR PAD/ LHR 8 PIC/ IBM 9 PJT/ PROJECT MANAGER 10 PSX/ M DOCUMENTS 11 PAS/ PT / PB /10JAN2000/10JAN PIV/ PT / /15DEC2000/15JUN PCE/ PT /GTR /15JAN2000/15JAN PID/ PT /Y /01JAN2001/31DEC PROFILE NOTES 1 ALWAYS CHECK MEAL PREFERENCE Page 7 of 8
8 3 Glossary CCD: Stands for 'Credit Card Display'. This sign-in attribute is used to determine the agents authorized to view the Credit Card Information (CCD-Y) or those users not permitted to view the information (CCD-N). PNR: A record of each passenger's travel requirements which contains all information necessary to enable reservations to be processed and controlled by the booking and participating travel provider. Security Code: Also known as card validation value (CVV2) or card validation code (CVC2). It is the three-digit value printed to the right of the credit card number in the signature panel area on the back of the card. For American Express cards, the code is a four-digit un-embossed number printed above the card number on the face of all payment cards. The code is uniquely associated with each individual piece of plastic and ties the card account number to the plastic N.V. Page 8 of 8
Amadeus Egypt. Electronic Ticketing. Briefing Module
Amadeus Egypt Electronic Ticketing Briefing Module Table of Contents General Conditions for E-Ticketing... 3 Airline-Specific Conditions... 3 Issuing E-Tickets... 4 Displaying E-Ticket Records... 6 E-Ticket
Electronic Ticketing
Electronic Ticketing Briefing Module Table of contents GENERAL CONDITIONS FOR E-TICKETING 3 AIRLINE-SPECIFIC CONDITIONS 3 ISSUING E-TICKETS..4 DISPLAYING E-TICKET RECORDS 6 E-TICKET HISTORY..10 REVALIDATING
FLYGTAXI Amadeus specification valid from 2011-10-05 2011-07-11
Late Changes FLYGTAXI Amadeus specification valid from 2011-10-05 2011-07-11 This document describes general rules for booking of Ground Transportation using the SUR-segments. The rules are valid for booking
Amadeus Virtual MCO User Guide
Amadeus Virtual MCO User Guide Introduction to Amadeus Virtual MCO The Automated Miscellaneous Charges Order (MCO) solution, enabling agent to Provide to the customer services in addition to the trip,
PCI DSS FAQ. The twelve requirements of the PCI DSS are defined as follows:
What is PCI DSS? PCI DSS is an acronym for Payment Card Industry Data Security Standards. PCI DSS is a global initiative intent on securing credit and banking transactions by merchants & service providers
How To Complete A Pci Ds Self Assessment Questionnaire
Department PCI Self-Assessment Questionnaire Version 1.1 2009 Attestation of Compliance Instructions for Submission This Department PCI Self-Assessment Questionnaire has been developed as an assessment
Appendix 1 Payment Card Industry Data Security Standards Program
Appendix 1 Payment Card Industry Data Security Standards Program PCI security standards are technical and operational requirements set by the Payment Card Industry Security Standards Council to protect
Credit and Debit Card Handling Policy Updated October 1, 2014
Credit and Debit Card Handling Policy Updated October 1, 2014 City of Parkville 8880 Clark Ave. Parkville, MO 64152 Hours: 8:00-5:00 p.m. Monday -Friday Phone Number 816-741-7676 Email: [email protected]
White Paper On. PCI DSS Compliance And Voice Recording Implications
White Paper On PCI DSS Compliance And Voice Recording Implications PCI DSS within the UK is becoming a hot topic of conversation, with many contradictions and confusions being issued by suppliers and professionals
A8.700 TREASURY. This directive applies to all campuses of the University of Hawai i.
Prepared by Treasury Office. This amends A8.710 dated July 2001. A8.710 April 2005 A8.700 TREASURY P 1 of 5 A8.710 Credit Card Program 1. Purpose To provide uniform procedures for the processing of credit
Amadeus Flown Segment & Past Dated PNR Pricing:
Amadeus Flown Segment & Past Dated PNR Pricing: Amadeus Travel Agency can now have facility to price the past dated PNR Flown Segment with new itinerary. This will help travel agency to re-issue & re-price
Credit Card Handling Security Standards
Credit Card Handling Security Standards Overview This document is intended to provide guidance to merchants (colleges, departments, auxiliary organizations or individuals) regarding the processing of charges
Welcome to Amadeus Basic Reservation Guide
Welcome to Amadeus Basic Reservation Guide Sign-In & Sign-Out Sign-in first available area: JI0001AA/SU Sign-in All areas: JI*0001AA/SU Sign-in with password together: JI0001AA/SU-Password Sign-out from
Accepting Payment Cards and ecommerce Payments
Policy V. 4.1.1 Responsible Official: Vice President for Finance and Treasurer Effective Date: September 29, 2010 Accepting Payment Cards and ecommerce Payments Policy Statement The University of Vermont
TERMINAL CONTROL MEASURES
UCR Cashiering & Payment Card Services TERMINAL CONTROL MEASURES Instructions: Upon completion, please sign and return to [email protected] when requesting a stand-alone dial up terminal. The University
Key Steps to Meeting PCI DSS 2.0 Requirements Using Sensitive Data Discovery and Masking
Key Steps to Meeting PCI DSS 2.0 Requirements Using Sensitive Data Discovery and Masking SUMMARY The Payment Card Industry Data Security Standard (PCI DSS) defines 12 high-level security requirements directed
Revenue Accounting Reference Number SAA-RS-01 JUNE 2014 Effective Date 2007 SECTION 2 CREDIT CARD SALES 2.1 CREDIT CARD FRAUD PROTECTION
SECTION 2 CREDIT CARD SALES 2.1 CREDIT CARD FRAUD PROTECTION Credit card fraud is a world-wide trend. All Agents and Travel Consultants should be aware of this possibility and familiarise themselves with
What are the PCI DSS requirements? PCI DSS comprises twelve requirements, often referred to as the digital dozen. These define the need to:
What is the PCI standards council? The Payment Card Industry Standards Council is an institution set-up by American Express, Discover Financial Services, JCB, MasterCard Worldwide and Visa International
Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance
Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance Merchants with Only Imprint Machines or Only Standalone, Dial-out Terminals Electronic Cardholder
New York University University Policies
New York University University Policies Title: Payment Card Industry Data Security Standard Policy Effective Date: April 11, 2012 Supersedes: N/A Issuing Authority: Executive Vice President for Finance
Amadeus Electronic Ticketing Course
Amadeus Electronic Ticketing Course Help Pages When issuing or modifying e-ticket you can consult HE ETT To display information on e-ticketing policy or market for specific airline HE ETT XX Complete Specific
Secure Flight Passenger Data Overview
Customer Solutions Secure Flight Passenger Data Overview October 2010 Page Nº 1 Table of Contents 1 Introduction... 3 2 What is Secure Flight program?... 3 2.1 Mission and objectives of TSA Secure Flight
quick REF GUIDE Booking easyjet through Amadeus Version 2.2
quick REF GUIDE Booking easyjet through Amadeus Version 2.2 032014 CREATE A BOOKING AMADEUS NEUTRAL AVAILABILITY AN10NOVLONBCN The standard availability entry. easyjet availability is integrated with other
UCSD Credit Card Processing Policy & Procedure
UCSD Credit Card Processing Policy & Procedure The Payment Process UCSD accepts Visa, MasterCard, American Express and Discover credit cards. We perform credit transactions only, no debit sales with cash
Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance
Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire B and Attestation of Compliance Imprint Machines or Stand-alone Dial-out Terminals Only, no Electronic Cardholder Data Storage
UW Platteville Credit Card Handling Policy
UW Platteville Credit Card Handling Policy Issued: December 2011 Revision History: November 7, 2013; July 11, 2014; November 1, 2014; August 24, 2015 Overview: In order for UW Platteville to accept credit
2.0 PAYMENT CARD INDUSTRY DATA SECURITY STANDARDS (PCI-DSS)
CSU, Chico Credit Card Handling Security Standard Effective Date: July 28, 2015 1.0 INTRODUCTION This standard provides guidance to ensure that credit card acceptance and ecommerce processes comply with
EAA Policy for Accepting and Handling Credit and Debit Card Payments ( Policy )
EAA Policy for Accepting and Handling Credit and Debit Card Payments ( Policy ) Background Due to increased threat of identity theft, fraudulent credit card activity and other instances where cardholder
Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015
Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015 I. PURPOSE The purpose of this policy is to establish guidelines for processing charges on Payment Cards to protect
6-8065 Payment Card Industry Compliance
0 0 0 Yosemite Community College District Policies and Administrative Procedures No. -0 Policy -0 Payment Card Industry Compliance Yosemite Community College District will comply with the Payment Card
Credit Card Processing and Security Policy
Credit Card Processing and Security Policy Policy Number: Reserved for future use Responsible Official: Vice President of Administration and Finance Responsible Office: Student Account Services Effective
Payment Application Data Security Standard
Payment Card Industry (PCI) Payment Application Data Security Standard ROV Reporting Instructions for PA-DSS v2.0 March 2012 Changes Date March 2012 Version Description Pages 1.0 To introduce PA-DSS ROV
COLUMBUS STATE COMMUNITY COLLEGE POLICY AND PROCEDURES MANUAL
PAYMENT CARD INDUSTRY COMPLIANCE (PCI) Effective June 1, 2011 Page 1 of 6 (1) Definitions a. Payment Card Industry Data Security Standards (PCI-DSS): A set of standards established by the Payment Card
DalPay Internet Billing. Technical Integration Overview
DalPay Internet Billing Technical Integration Overview Version 1.3 Last revision: 01/07/2011 Page 1 of 10 Version 1.3 Last revision: 01/07/2011 Page 2 of 10 REVISION HISTORY... 4 INTRODUCTION... 5 DALPAY
Accelerating PCI Compliance
Accelerating PCI Compliance PCI Compliance for B2B Managed Services March 8, 2016 What s the Issue? Credit Card Data Breaches are Expensive for Everyone The Wall Street Journal OpenText Confidential. 2016
AheevaCCS and the Payment Card Industry Data Security Standard
Account Data PCI DSS White Paper by Aheeva, January 2012 AheevaCCS and the Payment Card Industry Data Security Standard Introduction In 2006, the major payment brands including American Express, MasterCard
Information Technology
Credit Card Handling Security Standards Overview Information Technology This document is intended to provide guidance to merchants (colleges, departments, organizations or individuals) regarding the processing
Payment Cardholder Data Handling Procedures (required to accept any credit card payments)
Payment Cardholder Data Handling Procedures (required to accept any credit card payments) Introduction: The Procedures that follow will allow the University to be in compliance with the Payment Card Industry
This appendix is a supplement to the Local Government Information Security: Getting Started Guide, a non-technical reference essential for elected
This appendix is a supplement to the Local Government Information Security: Getting Started Guide, a non-technical reference essential for elected officials, administrative officials and business managers.
Amadeus Electronic Ticketing. Amadeus Iran
Amadeus Electronic Ticketing Welcome to the 2011 version of the Electronic Ticket Direct Quick Reference Guide. The Amadeus ETD Quick Reference Guide is intended for travel agents who use the Amadeus System.
Your Compliance Classification Level and What it Means
General Information What are the Payment Card Industry (PCI) Data Security Standards? The PCI Data Security Standards represents a common set of industry tools and measurements to help ensure the safe
PAYU HUNGARY KFT. PAYMENT INFORMATION. PayU Hungary Kft. T: +36 1 510 0707 1074 Budapest, F: +36 1 336 0345
PAYU HUNGARY KFT. PAYMENT INFORMATION USEFUL INFORMATION ON PAYU PayU has introduced its services in Hungary with a firm background rendered by banks providing bankcard payment option via the internet,
E ticket industry default Effective from June 1 st, 2008
E ticket industry default Effective from June 1 st, 2008 May 22 nd, 2008 Version 1.0 E Ticket Industry default- Brussels Airlines Travel Agents procedures Version 1-23/05/2008 1 Table of contents 1 Introduction...3
INFORMATION SECURITY POLICY. Policy for Credit Card Acceptance to Conduct College Business
DELAWARE COLLEGE OF ART AND DESIGN 600 N MARKET ST WILMINGTON DELAWARE 19801 302.622.8000 INFORMATION SECURITY POLICY including Policy for Credit Card Acceptance to Conduct College Business stuff\policies\security_information_policy_with_credit_card_acceptance.doc
Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire C and Attestation of Compliance
Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire C and Attestation of Compliance Payment Application Connected to Internet, No Electronic Cardholder Data Storage Version
PCI Compliance Just the Facts. Rick Dakin President [email protected] 303.554.6333 ext. 7001
PCI Compliance Just the Facts Rick Dakin President [email protected] 303.554.6333 ext. 7001 Agenda Regulatory Landscape Scary Bedtime Stories What went wrong? PCI Compliance Process o What
Payment Card Industry (PCI) Data Security Standard
Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Self-Assessment Questionnaire D Service Providers For use with PCI DSS Version 3.1 Revision 1.1 July 2015 Section 1: Assessment
Content. Quick Reference Online Assistant ticket order tool. Overview... 2. Retrieve a PNR... 3. Pricing... 4. Payment... 6. TSA Data...
Quick Reference Online Assistant ticket order tool Content Overview... 2 Retrieve a PNR... 3 Pricing... 4 Payment... 6 TSA Data... 9 Additional options... 11 1 Overview The ticket order tool Online Assistant
A multi-layered approach to payment card security.
A multi-layered approach to payment card security. CARD-NOT-PRESENT 1 A recent research study revealed that Visa cards are the most widely used payment method at Canadian websites, on the phone, or through
Visa Asia Pacific Account Information Security (AIS) Program Payment Application Best Practices (PABP)
Visa Asia Pacific Account Information Security (AIS) Program Payment Application Best Practices (PABP) This document is to be used for payment application vendors to validate that the payment application
DalPay Internet Billing. Virtual Terminal User Guide
DalPay Internet Billing Virtual Terminal User Guide Version 1.2 Last revision: 01/01/2010 Page 1 of 11 Version 1.2 Last revision: 01/01/2010 Page 2 of 11 REVISION HISTORY... 4 INTRODUCTION... 5 A. WHAT
Policy Title: Payment Cards Policy Effective Date: 5/5/2010. Policy Number: FA-PO-1214 Date of Last Revision: 11/5/2014
Policy Title: Effective Date: 5/5/2010 Policy Number: FA-PO-1214 Date of Last Revision: 11/5/2014 Oversight Department: Financial Services Next Review Date: 10/1/2016 1. PURPOSE The for Radford University
Steps for staying PCI DSS compliant Visa Account Information Security Guide October 2009
Steps for staying PCI DSS compliant Visa Account Information Security Guide October 2009 The guide describes how you can make sure your business does not store sensitive cardholder data Contents 1 Contents
CAL POLY POMONA FOUNDATION. Policy for Accepting Payment (Credit) Card and Ecommerce Payments
CAL POLY POMONA FOUNDATION Policy for Accepting Payment (Credit) Card and Ecommerce Payments 1 PURPOSE The purpose of this policy is to establish business processes and procedures for accepting payment
Payment Card Security
Payment Card Security January 31, 2008 Kieran Norton, Senior Manager Security & Privacy Services, Deloitte & Touche LLP Focus of the Presentation PCI Overview Background Current Environment Key Considerations
Amadeus Selling Platform Profiles Plus. User Guide
Amadeus Selling Platform Profiles Plus User Guide YOUR USE OF THIS DOCUMENTATION IS SUBJECT TO THESE TERMS Use of this documentation You are authorized to view, copy, or print the documentation for your
Electronic Miscellaneous Document SV EMD Distribution Policy. Guidelines for Travel Agencies
Electronic Miscellaneous Document SV EMD Distribution Policy Guidelines for Travel Agencies March 2013 INDEX WHAT IS AN EMD?... 4 What is the difference between an Associated versus a Standalone EMD?...
CREDIT CARD NUMBER HANDLING PROCEDURES POLICY. 2014 October
CREDIT CARD NUMBER HANDLING PROCEDURES POLICY 2014 October Royal Roads University Page 1 of 6 21 October 2014 Table of Contents Policy Statement... 3 Rationale... 3 Applicability of the Policy... 3 Definitions...
Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance
Cyber Security: Secure Credit Card Payment Process Payment Card Industry Standard Compliance A Non-Technical Guide Essential for Business Managers Office Managers Operations Managers Compliant? Bank Name
Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance
Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance Card-not-present Merchants, All Cardholder Data Functions Fully Outsourced Version 3.0 February
PCI PA - DSS. Point XSA Implementation Guide. Atos Worldline Banksys XENTA SA. Version 1.00
PCI PA - DSS Point XSA Implementation Guide Atos Worldline Banksys XENTA SA Version 1.00 POINT TRANSACTION SYSTEMS AB Box 92031, 120 06 Stockholm, Tel. +46 8 566 287 00 www.point.se Page number 2 (16)
CREDIT CARD MERCHANT POLICY. All campuses served by Louisiana State University (LSU) Office of Accounting Services
Louisiana State University Finance and Administrative Services Operating Procedure FASOP: AS-22 CREDIT CARD MERCHANT POLICY Scope: All campuses served by Louisiana State University (LSU) Office of Accounting
Becoming PCI Compliant
Becoming PCI Compliant Jason Brown - [email protected] Enterprise Security Architect Enterprise Architecture Department of Technology, Management and Budget State of Michigan @jasonbrown17 History
GRINNELL COLLEGE CREDIT CARD PROCESSING AND SECURITY POLICY
GRINNELL COLLEGE CREDIT CARD PROCESSING AND SECURITY POLICY PURPOSE The Payment Card Industry Data Security Standard was established by the credit card industry in response to an increase in identify theft
SECTION 2 - CREDIT CARD SALES
SECTION 2 - CREDIT CARD SALES 2.1 CREDIT CARD FRAUD PROTECTION Credit card fraud is a world-wide trend. All Agents and Travel Consultants should be aware of this possibility. To prevent credit card fraud,
Langara College PCI Awareness Training
Langara College PCI Awareness Training Have you heard of PCI? Due to the increase of credit card fraud and identity theft, major credit card companies like Visa, MasterCard and Amex have formed a security
A Websense Research Brief Prevent Data Loss and Comply with Payment Card Industry Data Security Standards
A Websense Research Brief Prevent Loss and Comply with Payment Card Industry Security Standards Prevent Loss and Comply with Payment Card Industry Security Standards Standards for Credit Card Security
FORT HAYS STATE UNIVERSITY CREDIT CARD SECURITY POLICY
FORT HAYS STATE UNIVERSITY CREDIT CARD SECURITY POLICY Page 1 of 6 Summary The Payment Card Industry Data Security Standard (PCI DSS), a set of comprehensive requirements for enhancing payment account
Payment Card Industry (PCI) Data Security Standard
Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.1 April 2015 Section 1: Assessment Information Instructions for Submission
Introduction to PCI DSS Compliance. May 18, 2009 1:15 p.m. 2:15 p.m.
Introduction to PCI DSS Compliance May 18, 2009 1:15 p.m. 2:15 p.m. Disclaimer The opinions of the contributors expressed herein do not necessarily state or reflect those of the National Association of
University of York Policy on the Management of Debit/ Credit Card Data
University of York Policy on the Management of Debit/ Credit Card Data Version 1.0 25th February 2015 Index 1 Introduction and Policy Statement 1.1 The Payment Card Industry Data Security Standard (PCI
POLICY & PROCEDURE DOCUMENT NUMBER: 3.3101. DIVISION: Finance & Administration. TITLE: Policy & Procedures for Credit Card Merchants
POLICY & PROCEDURE DOCUMENT NUMBER: 3.3101 DIVISION: Finance & Administration TITLE: Policy & Procedures for Credit Card Merchants DATE: October 24, 2011 Authorized by: K. Ann Mead, VP for Finance & Administration
SECTION: SUBJECT: PCI-DSS General Guidelines and Procedures
1. Introduction 1.1. Purpose and Background 1.2. Central Coordinator Contact 1.3. Payment Card Industry Data Security Standards (PCI-DSS) High Level Overview 2. PCI-DSS Guidelines - Division of Responsibilities
An instruction from FB to Agents to issue e-ticket from 1 June 2008.
To Agents in IATA BSP s Use and Issuance of Bulgaria Air e-tickets The purpose of this instruction is to provide guidance on the use and issuance of Bulgaria Air e-tickets on and after 1. June 2008, when
PCI-DSS: A Step-by-Step Payment Card Security Approach. Amy Mushahwar & Mason Weisz
PCI-DSS: A Step-by-Step Payment Card Security Approach Amy Mushahwar & Mason Weisz The PCI-DSS in a Nutshell It mandates security processes for handling, processing, storing and transmitting payment card
Visa U.S.A Cardholder Information Security Program (CISP) Payment Application Best Practices
This document is to be used to verify that a payment application has been validated against Visa U.S.A. Payment Application Best Practices and to create the Report on Validation. Please note that payment
Electronic Miscellaneous Document (and / or) Amadeus Airline Ancillary Services
Electronic Miscellaneous Document (and / or) Amadeus Airline Ancillary Services Guidelines for Travel Agencies 11 October 11, 2013 INDEX 1 WHAT IS AN EMD?...5 What is the difference between an Associated
PCI PA - DSS. Point BKX Implementation Guide. Version 2.01. Atos Xenta, Atos Xenteo and Atos Yomani using the Point BKX Payment Core
PCI PA - DSS Point BKX Implementation Guide Atos Xenta, Atos Xenteo and Atos Yomani using the Point BKX Payment Core Version 2.01 POINT TRANSACTION SYSTEMS AB Box 92031, 120 06 Stockholm, Tel. +46 8 566
Payment Card Industry (PCI) Data Security Standard
Payment Card Industry (PCI) Data Standard Attestation of Compliance for Self-Assessment Questionnaire D Service Providers Version 3.1 April 2015 Section 1: Assessment Information Instructions for Submission
Payment Card Industry (PCI) Data Security Standard
Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 3.0 February 2014 Section 1: Assessment Information Instructions for Submission
A MERCHANTS GUIDE TO THE PAYMENT APPLICATION DATA SECURITY STANDARD (PA-DSS)
A MERCHANTS GUIDE TO THE PAYMENT APPLICATION DATA SECURITY STANDARD (PA-DSS) The mandatory guide for storing, processing or transmitting cardholder information Overview and applicability Any application
UNL PAYMENT CARD POLICY AND PROCEDURES. Table of Contents
UNL PAYMENT CARD POLICY AND PROCEDURES Table of Contents Payment Card Merchant Security Standards Policy and Procedures... 2 Introduction... 4 Payment Card Industry Data Security Standard... 4 Definitions...
Passing PCI Compliance How to Address the Application Security Mandates
Passing PCI Compliance How to Address the Application Security Mandates The Payment Card Industry Data Security Standards includes several requirements that mandate security at the application layer. These
Attestation of Compliance for Onsite Assessments Service Providers
Attestation of Compliance Service Providers Payment Card Industry (PCI) Data Security Standard Attestation of Compliance for Onsite Assessments Service Providers Version 2.0 October 2010 Instructions for
Viterbo University Credit Card Processing & Data Security Procedures and Policy
The requirements for PCI-DSS compliance are quite numerous and at times extremely complicated due to their interdependent nature and scope. The University has deemed it necessary for those areas currently
Merchant Account Glossary of Terms
Merchant Account Glossary of Terms From offshore merchant accounts to the truth behind free merchant accounts, get answers to some of the most common and frequently asked questions. If you cannot find
PCI PA - DSS. Point ipos Implementation Guide. Version 1.01. VeriFone Vx820 using the Point ipos Payment Core
PCI PA - DSS Point ipos Implementation Guide VeriFone Vx820 using the Point ipos Payment Core Version 1.01 POINT TRANSACTION SYSTEMS AB Box 92031, 120 06 Stockholm, Tel. +46 8 566 287 00 www.point.se Page
Why Is Compliance with PCI DSS Important?
Why Is Compliance with PCI DSS Important? The members of PCI Security Standards Council (American Express, Discover, JCB, MasterCard, and Visa) continually monitor cases of account data compromise. These
Version 15.3 (October 2009)
Copyright 2008-2010 Software Technology, Inc. 1621 Cushman Drive Lincoln, NE 68512 (402) 423-1440 www.tabs3.com Portions copyright Microsoft Corporation Tabs3, PracticeMaster, and the pinwheel symbol (
Global Visa Card-Not-Present Merchant Guide to Greater Fraud Control. Protect Your Business and Your Customers with Visa s Layers of Security
Global Visa Card-Not-Present Merchant Guide to Greater Fraud Control Protect Your Business and Your Customers with Visa s Layers of Security Millions of Visa cardholders worldwide make one or more purchases
