Questions and Answers PCI Compliance (Updated May 23, 2014)



Similar documents
TREASURER S OFFICE ADMINISTRATIVE STANDARDS FOR THE TREASURER S FISCAL PROCEDURE No MERCHANT DEBIT AND CREDIT CARD RECEIPTS

Merchant Services Tool Kit TEXPO 2013

SecurityMetrics Introduction to PCI Compliance

Section 3.9 PCI DSS Information Security Policy Issued: June 2016 Replaces: January 2015

Intro to PCI Compliance

11/24/2014. PCI Compliance: Major Changes in e-quantum/quantum Net

ACCEPTING PAYMENT CARDS FOR CONDUCTING UNIVERSITY BUSINESS:

2.1.2 CARDHOLDER DATA SECURITY

Payment Card Industry Data Security Standard

ACCEPTING PAYMENT CARDS FOR CONDUCTING UNIVERSITY BUSINESS:

PCI DSS FAQ. The twelve requirements of the PCI DSS are defined as follows:

EAA Policy for Accepting and Handling Credit and Debit Card Payments ( Policy )

The PCI DSS Compliance Guide For Small Business

Finance & Ecommerce Systems

Saint Louis University Merchant Card Processing Policy & Procedures

PCI General Policy. Effective Date: August Approval: December 17, Maintenance of Policy: Office of Student Accounts REFERENCE DOCUMENTS:

Appendix 1 Payment Card Industry Data Security Standards Program

FORT HAYS STATE UNIVERSITY CREDIT CARD SECURITY POLICY

Q: What is PCI? Q: To whom does PCI apply? Q: Where can I find the PCI Data Security Standards (PCI DSS)? Q: What are the PCI compliance deadlines?

PCI Compliance: How to ensure customer cardholder data is handled with care

Accounting and Administrative Manual Section 100: Accounting and Finance

How To Become A Pca Compliant Organization

GRINNELL COLLEGE CREDIT CARD PROCESSING AND SECURITY POLICY

TNHFMA 2011 Fall Institute October 12, 2011 TAKING OUR CUSTOMERS BUSINESS FORWARD. The Cost of Payment Card Data Theft and Your Business

E-Market Policy Accepting Online Payment for Conducting University Business

IMPROVING COMPLIANCE, COSTS & MARGINS:

UO Third Party Credit Card Processing Request

What are the PCI DSS requirements? PCI DSS comprises twelve requirements, often referred to as the digital dozen. These define the need to:

PCI Overview. PCI-DSS: Payment Card Industry Data Security Standard

Langara College PCI Awareness Training

Sales Rep Frequently Asked Questions

POLICY NAME : MERCHANT (PCI) POLICY AND PROCEDURES ACCEPTING CREDIT/DEBIT CARD PAYMENTS

U.S. Merchant Class Settlement MasterCard Frequently Asked Questions Merchant

Payment Card Industry Data Security Standard (PCI DSS) Q & A November 6, 2008

Your Compliance Classification Level and What it Means

Clark University's PCI Compliance Policy

University Policy Accepting Credit Cards to Conduct University Business

PCI Compliance. Top 10 Questions & Answers

Payment Card Industry Data Security Standards Compliance

The Cost of Payment Card Data Theft and Your Business. Aaron Lego Director of Business Development

DalPay Internet Billing. Technical Integration Overview

PCI Policies Appalachian State University

How To Program A Credit Card Terminal To Be A Pca Compliant (Cpo) Or Not (Pca) Compliant (Dns) (Cisp) (Dhs) (Pci) (Susu) (Usu/

. Merchant Accounts are special bank accounts issued by a merchant. . Merchant Level: This classification is based on transaction volume.

PROTECTION OF OUR MERCHANTS AND REFERRAL PARTNERS IS OUR FIRST CONCERN

1/18/10. Walt Conway. PCI DSS in Context. Some History The Digital Dozen Key Players Cardholder Data Outsourcing Conclusions. PCI in Higher Education

Policy Title: Payment Cards Policy Effective Date: 5/5/2010. Policy Number: FA-PO-1214 Date of Last Revision: 11/5/2014

The University of Georgia Credit/Debit Card Processing Procedures

PAI Secure Program Guide

Payment Card Industry Data Security Standard (PCI DSS) and Payment Application Data Security Standard (PA-DSS) Frequently Asked Questions

Merchant Card Processing Best Practices

POLICY & PROCEDURE DOCUMENT NUMBER: DIVISION: Finance & Administration. TITLE: Policy & Procedures for Credit Card Merchants

* Any merchant that has suffered a hack that resulted in an account data compromise may be escalated to a higher validation level.

Varonis Systems & The Payment Card Industry Data Security Standard (PCI DSS)

Frequently Asked Questions

GLOSSARY OF MOST COMMONLY USED TERMS IN THE MERCHANT SERVICES INDUSTRY

PCI-PA-DSS. Solution Kit

Policies and Procedures. Merchant Card Services Office of Treasury Operations

FAQ s for Payment Card Processing at the University

PCI DSS COMPLIANCE DATA

DalPay Internet Billing. Virtual Terminal User Guide

PCI Security Compliance

La règlementation VisaCard, MasterCard PCI-DSS

Your guide to the Payment Card Industry Data Security Standard (PCI DSS) Merchant Business Solutions. Version 5.0 (April 2011)

John B. Dickson, CISSP October 11, 2007

VISA EUROPE ACCOUNT INFORMATION SECURITY (AIS) PROGRAMME FREQUENTLY ASKED QUESTIONS (FAQS)

SecurityMetrics. PCI Starter Kit

CREDIT CARD PROCESSING POLICY AND PROCEDURES

CITY OF SAN ANTONIO OFFICE OF THE CITY AUDITOR. Audit of Payment Card Industry Data Security Standards (PCI DSS) Security Governance

McGill Merchant Manual

ROYAL BOROUGH OF WINDSOR AND MAIDENHEAD SECURITY POLICY. Processing Electronic Card Payments

Card Network Update Chip (EMV) Acceptance in the United States At-A-Glance

Payment Card Industry Data Security Standard Explained

b. USNH requires that all campus organizations and departments collecting credit card receipts:

Accepting Payment Cards and ecommerce Payments

PCI Compliance Top 10 Questions and Answers

PayLeap Guide. One Stop

STOP Important Information Please Read

PCI Data Security Standard

How To Comply With The Pci Ds.S.A.S

The Cyber Attack and Hacking Epidemic A Legal and Business Survival Guide

Merchant guide to PCI DSS

PAYMENT CARD INDUSTRY (PCI) COMPLIANCE HISTORY & OVERVIEW

Cards at School. Why Banks View Campuses as High Risk Customers. Payments

Clark Brands Payment Methods Manual. First Data Locations

688 Sherbrooke Street West, Room 730 James Administration Building, Room 524

Getting Started. Quick Reference Guide for Payment Processing

Payment Card Industry Data Security Standard (PCI DSS)

Contract Duration This contract runs through June 30, 2013 with annual options to renew through June 30, 2015 (two option years).

Credit and Debit Card Handling Policy Updated October 1, 2014

PCI-DSS Compliance. Ron Dinwiddie Chief Technology Officer J. Spargo & Associates

This policy applies to all GPC units that process, transmit, or handle cardholder information in a physical or electronic format.

PCI Standards: A Banking Perspective

Tokenization Amplified XiIntercept. The ultimate PCI DSS cost & scope reduction mechanism

Worldpay s guide to the Payment Card Industry Data Security Standard (PCI DSS)

Online Payment Processing Definitions From Credit Research Foundation (

University Policy Accepting and Handling Payment Cards to Conduct University Business

Transcription:

Questions and Answers PCI Compliance (Updated ) The Alberta government is working toward PCI compliance, an industry standard created by the credit card industry to improve cardholder data security. The following are prepared responses to frequently asked questions. 1. What is PCI compliance? The payment card industry (PCI) has developed a set of security standards that applies to all merchants who accept American Express, Discover Financial Services, JCB International, MasterCard Worldwide or Visa Inc. The Payment Card Industry Data Security Standard (PCI-DSS) is the set of requirements all major merchants like the government must adhere to if they want to continue accepting credit card payments for goods and services. For more information about the PCI Data Security Standard, visit https://www.pcisecuritystandards.org. 2. Why is it important to Albertans that government achieve PCI compliance? Albertans expect their government to accept credit card payments for things like permits, fines, and campsite reservations, but they also want to know their information is safe. The Alberta government is working toward PCI compliance to further reduce the chance of credit card fraud and identity theft. 3. Is PCI compliance necessary? The province wants to continue offering Albertans a range of payment options that work for them, including credit cards. Compliance is required by the payment card industry. Failure to comply could result in the government paying fines or no longer being allowed to accept credit cards.

4. Can some government offices opt out? All ministries that accept card payment must comply in order for the government to be certified PCI compliant. If one ministry does not achieve compliance, then the whole government will be found non-compliant. Even if a ministry does not accept payment cards, if it has in the past, it is still subject to PCI compliance. Ministries must come up with a plan for locating and disposing of cardholder data as required by PCI. 5. I have heard the province will soon stop collecting credit card numbers. Does that mean I can t pay for something using my credit card? The province will continue to accept credit cards as a form of payment, but the actual processing of card payments will be performed on a TD Merchant Services point of sale (POS) terminal or pay page. 6. What is the benefit of turning over the collection of credit card numbers to a third party? Keeping your personal information separate from your credit card information helps protect you against credit card fraud and identity theft. The province collects your personal information (what you are paying for, shipping address, name etc.) but it never possesses your credit card number. 7. I sometimes make payments to the province using my credit card. How will PCI compliance affect me? In many cases, the order process will similar, except when it comes time to provide your credit card number. Ministries will continue to process orders received by mail, phone, fax or email, although some ministries may no longer offer all of these options. During the checkout process, clients using any of these methods and paying by credit card will be: referred to a secure automated telephone payment system referred to a secure pay page powered by TD Merchant Services, or sent an email containing a link to a pay page.

Where available, clients can also pay in person. Card payment options may vary from Ministry to Ministry. 8. How does the Government Payment Application Service (GPAS) work? Example: you are ordering a book by email. The business unit processes the order on its GPAS system and emails you a payment request that includes a transaction number and a link to TD Merchant Services. You click on the link to open up the TD Merchant Services pay page and fill in the fields like you would in any other e-commerce pay page. After you complete your payment, GPAS emails the business unit payment notification for the service/product you ordered. GPAS then emails you a payment receipt, and you are done. The same process can be applied to fax and phone orders. 9. How does the Telephone Interactive Payment Service (TIPS) work? Example: You are requesting a permit. The employee on the other end of the line handles your request like before, until it is time for you to provide your credit card number. The employee will ask to either put you through to TIPS, or email you a payment request just like the book order example mentioned above. If you choose to pay by phone, the system puts you through to TIPS. You simply follow the prompts and key your credit card information right into your phone. In both cases, the system generates a transaction number that ties the payment to the transaction. The credit card information goes directly to TD Merchant Services. 10. I m used to doing things my way and don t really understand the internet or automated telephone payment systems. Can t you just make an exception and take my payment like you did before? As the Alberta government implements PCI compliance, employees will no longer be able to accept payments in the following ways: Accepting credit card numbers provided verbally over the phone, Accepting card numbers provided in an email, Accepting card numbers provided in a fax or mailed letter, Accepting card numbers provided in a voicemail, Accepting credit card payments manually without a proper point of sale (POS) terminal, or Keying a credit card number into a POS terminal for a Card Not Present (CNP) transaction.

It s all about protecting you from identity theft and credit card fraud. In many cases, the order process will similar, except when it comes time to provide your credit card number. Ministries will continue to process orders received by mail, phone, fax or email. During the checkout process, clients using any of these methods and paying by credit card will be: referred to a secure automated telephone payment system referred to a secure pay page powered by TD Merchant Services, or sent an email containing a link to a pay page. Where available, clients can also pay in person. 11. When does government expect to achieve PCI compliance? Government started phasing out the direct collection of credit card information in June 2013. Ministries are at various stages of implementation. Some business areas within a ministry may stop collecting numbers before other business units within that same ministry. Government is aiming to achieve initial compliance the end of 2014, although the actual certification may take place in early 2015. At that point, government as a whole will no longer be collecting credit card numbers. All ministries will have approved plans in place to locate and dispose any credit card information that may have been collected in the past. 12. Which ministries are involved? Any ministry that accepts credit cards as payment or has collected them in the past is subject to PCI compliance. 13. Does PCI compliance affect only government ministries? PCI Compliance applies to any organization that uses credit cards to collect revenue. With respect to the Government of Alberta s specific PCI Compliance Policy, any agency, board, crown corporation or commission that processes credit card payments under the government s credit card contract must adhere to the government s PCI Compliance policies.

14. Who is responsible for the PCI compliance standards? The Payment Card Industry (PCI) Security Standards Council develops, maintains and manages the PCI Security Standards. The Council has five founding global payment brands American Express, Discover Financial Services, JCB International, MasterCard Worldwide, and Visa Inc. The five global payment brands also recognize the PCI Council as being qualified to validate the credentials of companies and individuals trained to validate compliance with the PCI DSS. But it is the payment card companies that enforce PCI compliance and impose penalties, not the council. The council also provides tools and guidance to help merchants as they work toward achieving compliance. For more information about the Payment Card Industry (PCI) Security Standards Council, visit https://www.pcisecuritystandards.org. 15. Does the government do a lot of credit card transactions? Albertans make credit card payments to the province for a variety of things, such as permits, fines, museum tickets and books. The Alberta government processes about 4.3 million credit and debit card transactions each year, with transaction volume roughly tripling in the past three years. The government has nearly 600 merchant numbers and hundreds of point-of-sale terminals. For more information please visit http://pcicompliance.alberta.ca.