Misconceptions of PCI DSS in K12. Illustration by Lance Jackson



Similar documents
La règlementation VisaCard, MasterCard PCI-DSS

How To Comply With The Pci Ds.S.A.S

How To Protect Your Business From A Hacker Attack

Payment Card Industry Data Security Standards.

Payment Card Industry Data Security Standard

How To Protect Your Credit Card Information From Being Stolen

Project Title slide Project: PCI. Are You At Risk?

PCI COMPLIANCE GUIDE For Merchants and Service Members

worldpay.com Understanding the 12 requirements of PCI DSS SaferPayments Be smart. Be compliant. Be protected.

How To Protect Visa Account Information

Credit Card Processing Overview

Merchant guide to PCI DSS

PCI DSS. CollectorSolutions, Incorporated

CardControl. Credit Card Processing 101. Overview. Contents

COLORADO STATE UNIVERSITY Financial Procedure Statements FPI 6-6

Two Approaches to PCI-DSS Compliance

What Every Business Should Know About PCI Compliance

TNHFMA 2011 Fall Institute October 12, 2011 TAKING OUR CUSTOMERS BUSINESS FORWARD. The Cost of Payment Card Data Theft and Your Business

Payment Card Industry Data Security Standard Explained

Credit Card Acceptance Policy. Vice Chancellor of Business Affairs. History: Effective July 1, 2011 Updated February 2013

Payment Card Industry Data Security Standard PCI DSS

PCI Compliance: Protection Against Data Breaches

PCI DSS Presentation University of Cincinnati

PAI Secure Program Guide

CHEAT SHEET: PCI DSS 3.1 COMPLIANCE

PCI Standards: A Banking Perspective

The Cost of Payment Card Data Theft and Your Business. Aaron Lego Director of Business Development

Varonis Systems & The Payment Card Industry Data Security Standard (PCI DSS)

Payment Card Industry Data Security Standards

SecurityMetrics Introduction to PCI Compliance

2015 PCI DSS Meeting. OSU Business Affairs Projects, Improvement, and Technology (PIT) Robin Whitlock

/ BROCHURE / CHECKLIST: PCI/ISO COMPLIANCE. By Melbourne IT Enterprise Services

AUTOMATING AUDITS AND ENSURING CONTINUOUS COMPLIANCE WITH ALGOSEC

Achieving PCI Compliance for Your Site in Acquia Cloud

Becoming PCI Compliant

It Won t Happen To Me! A Network and PCI Security Webinar Presented By FMS and VendorSafe

PCI DSS Compliance Information Pack for Merchants

Credit Card Handling Security Standards

Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015

Office of Finance and Treasury

Comodo HackerGuardian. PCI Security Compliance The Facts. What PCI security means for your business

PCI Security Compliance

FORT HAYS STATE UNIVERSITY CREDIT CARD SECURITY POLICY

Why Is Compliance with PCI DSS Important?

PCI Compliance at The University of South Carolina. Failure is not an option. Rick Lambert PMP University of South Carolina

PCI Compliance Tutorial - Virtual Terminal

Your guide to the Payment Card Industry Data Security Standard (PCI DSS) Merchant Business Solutions. Version 5.0 (April 2011)

PCI-DSS: A Step-by-Step Payment Card Security Approach. Amy Mushahwar & Mason Weisz

CITY OF SAN DIEGO ADMINISTRATIVE REGULATION Number PAYMENT CARD INDUSTRY (PCI) COMPLIANCE POLICY. Page 1 of 9.

Payment Card Industry Data Security Standards Compliance

Best Practices for PCI DSS V3.0 Network Security Compliance

Accelerating PCI Compliance

COLLEGE POLICY ON CREDIT/DEBIT CARD PAYMENT PROCESSING

Tokenization Amplified XiIntercept. The ultimate PCI DSS cost & scope reduction mechanism

Guide to BBPS and BBMS Blackbaud Payment Services and Blackbaud Merchant Services explained.

Data Security, Fraud Prevention, and Cost Control. Mike Dorland, CPP Regional Marketing Representative Michigan Retailers Association

Josiah Wilkinson Internal Security Assessor. Nationwide

SECTION: SUBJECT: PCI-DSS General Guidelines and Procedures

PCI DSS COMPLIANCE DATA

E Pay. A Case Study in PCI Compliance. Illinois State Treasurer. Dan Rutherford

University of Oregon Policy Statement Development Form

PCI Compliance Overview

PCI PA-DSS Requirements. For hardware vendors

How To Protect Your Data From Being Stolen

PCI DSS 3.0 Overview. OSU Business Affairs Business Affairs PIT Crew - Project, Improvement, & Technology Robin Whitlock

PCI (Payment Card Industry) Compliance For Healthcare Offices By Ron Barnett

The Petroleum Marketer s PCI compliance Reference Guide

The PCI DSS Compliance Guide For Small Business

VESTA CORPORATION WHITEPAPER Payment Card Industry Data Security Standards (PCI DSS) and Mobile Operators: Trends and Implications

Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS)

June 19, Bobbi McCracken, Associate Vice Chancellor Financial Services. Subject: Internal Audit of PCI Compliance.

Registration and PCI DSS compliance validation

A Whitepaper by Vesta Corporation. Payment Card Industry Data Security Standards (PCI DSS) and Mobile Operators: Trends and Implications

Strategies To Effective PCI Scoping ISACA Columbus Chapter Presentation October 2008

Information Security Services. Achieving PCI compliance with Dell SecureWorks security services

PCI DATA SECURITY STANDARD OVERVIEW

An article on PCI Compliance for the Not-For-Profit Sector

Don Roeber Vice President, PCI Compliance Manager. Lisa Tedeschi Assistant Vice President, Compliance Officer

White Paper September 2013 By Peer1 and CompliancePoint PCI DSS Compliance Clarity Out of Complexity

UCSB Credit Card Processing and PCI Compliance

8/17/2010. Over 90% of all compromised merchants are PCI level 4 (small) merchants or merchants with less than 1 million transactions per year

PAYMENT CARD INDUSTRY (PCI) SECURITY STANDARDS COUNCIL

Transcription:

Misconceptions of PCI DSS in K12 Illustration by Lance Jackson Presented by: Barry Campbell Business Development Mgr. bcampbellfars@gmail.com Kaitlyn Hetzel Account Services Manager khetzel@schoolpay.com

What is PCI DSS? Who here knows what PCI-DSS stands for? Payment Card Industry Data Security Standard It is the security requirement that any entity that has access to credit card numbers is required, by VISA, MasterCard, etc., to adhere to.

Link Between Candy Jar and PCI Winner of the Candy Jar announced Winner of the best answer announced Dawn Fortes (Volusia County) Candy represents cardholder data & the jar represents a system that s PCI Compliant Easier to demonstrate our message and won t break any health code violations - Exercise in fun-counting candies in a jar - How it feels when you re establishing your policy is more like this..

PCI-DSS is One Thing- Right? Like a bunny?

Sort of. It s 6 Object Controls Object controls logically group related things. PCI DSS comes down to six areas of focus: 1. Build and maintain a secure network 2. Protect cardholder data 3. Maintain a vulnerability management program 4. Implement strong access control measures 5. Regularly monitor and test networks 6. Maintain an information security policy

Ah! So it s Six Things. Right? Like SIX bunnies

Each Object Control has one or more Requirements For example, Build and Maintain a Secure Network has these two requirements: Install and maintain a firewall configuration to protect cardholder data Do not use vendor-supplied defaults for system passwords and other security parameter.

So How Come I Now Have 220 Bunnies? Meet the SUB requirements!

Making Sense of It All PCI is ultimately a logical set of business operation standards It s not a one and done you always do it PCI DSS isn t a guarantee it s a starting point, not the finish line

The Misconceptions..

M1-It s About ecommerce It s about cardholder data Best practice: Every human and system location in the district that *could* come in contact with or leave a record of a 16 digit card number is a threat to your PCI compliance. Document these and establish a policy for that data interaction.

M2 PCI DSS is Someone s or Some Department s Job PCI is no one person s job, it is everyone s job. Everyone s job who touches cardholder data, that is. Best practice is to have set of policies and procedures that define the behavior of everyone (staff) and everything (hardware/software) in the district that touches cardholder data.

M3 Our Online Payment Service Handles IT If you have an online payment system, they can offload a lot of PCI headaches If you take any credit card payments in person you will be responsible for handling the PCI compliance on those payments Best Practice: Know what your minimum exposure and workload is. If you only take online payments make sure your policy states that But you still are REQUIRED to have a policy

M4- You Have to Pay a Fee to To be PCI Compliant PCI Compliance Fees Are Becoming Commonplace but it is NOT a requirement for PCI Compliance Best practices to cut your costs: Inquire with your processor if there is a PCI Compliance fee/merchant account Inquire if there is any ability to handle PCI at the District level Make sure you are aware of any PCI related procedures that they require

We re Back! Each bunny represents a single PCI question there are 220 of them per Merchant account!

The Rule Breakers. A fun look at the people that make you say, What were they thinking?

The List Keepers

The 80 s Marketers Donor forms.filled out with way too much data

The Get it Rights

So What Should You Do Step One Determine the scope of the PCI policy you will need Where are you taking payments, online, in person both? How many departments are taking payments? How many merchant accounts do we have? Step Two write your policy and have staff sign off on it Step Three make sure your online providers are Level One PCI Providers Each software system that takes payment or touches card data needs to be PCI compliant too All except the smallest companies are required to being audited and appear on a VISA list

Validate Software Providers to the District It is easy to get the status of your various system providers. Just do the following: 1. Ask if they* have a ROC (Report of Compliance provided by audit firm) 2. Are they listed HERE: http://www.visa.com/splisting/searchgrsp.do *Please note whoever owns the interface where the card number is collected should have their name on the ROC

Conclusion Slide Controlling your risk is manageable Make your payments policies and procedures cross departmental Always reduce scope where and when you can - Reduce the number of payment vendors you support - Reduce access to and interaction with 16 digit account numbers