ECKERD COLLEGE

Payment Card Industry Data Security Standard (PCI DSS) Policy

Payment Card Industry Data Security Standard Policy

Page 1

1.0

BACKGROUND INFORMATION -------------------------------------------------------------------------------------------------------- 3

2.0

PURPOSE ------------------------------------------------------------------------------------------------------------------------------------ 3

3.0

DEFINITIONS -------------------------------------------------------------------------------------------------------------------------------- 3 1. 2. 3. 4. 5. 6. 7. 8.

Cardholder Data ------------------------------------------------------------------------------------------------------------------ 3 Cardholder Information Security Program (CISP) ---------------------------------------------------------------------- 3 Data Security Standards --------------------------------------------------------------------------------------------------------- 3 Merchant Account ----------------------------------------------------------------------------------------------------------------- 3 Merchant----------------------------------------------------------------------------------------------------------------------------- 4 Payment Card Industry Council (PCI) -------------------------------------------------------------------------------------- 4 Self-Assessment -------------------------------------------------------------------------------------------------------------------- 4 Sensitive Data ---------------------------------------------------------------------------------------------------------------------- 4

4.0

AUTHORITY AND RESPONSIBILITY --------------------------------------------------------------------------------------------------- 4

5.0

PROCEDURES ------------------------------------------------------------------------------------------------------------------------------- 4

6.0

COMPLIANCE CERTIFICATION PROCESS -------------------------------------------------------------------------------------------- 5

APPENDIX A - CONFIDENTIALITY / NON-DISCLOSURE STATEMENT - PROCESSORS ------------------------------------------- 6

Payment Card Industry Data Security Standard Policy

Page 2

1.0 Background Information The Payment Card Industry Data Security Standard (PCI DSS) is a set of comprehensive requirements for credit card account data security, developed by the credit card industry in response to an increase in identity theft and credit card fraud. As a merchant who handles credit card data, Eckerd College is obliged to safeguard that information and adhere to the standards established by the Payment Card Industry Council including setting up controls for handling credit card data, computer and internet security and completing an annual self assessment questionnaire.

2.0 Purpose The purpose of this policy is to define the guidelines for accepting and processing credit cards and storing personal cardholder information to comply with the Payment Industry’s Data Security Standards.

3.0 Definitions

1. Cardholder Data Cardholder Data represents any personal information of the cardholder. This could be an account number, expiration date, name, address, telephone number, social security number, card validation code (CVC), or any other cardholder’s identifying information. 2. Cardholder Information Security Program (CISP) The Visa’s Cardholder Information Security Program (CISP) is designed to ensure that all merchants that store, process, or transmit Visa cardholder data, protect it properly. 3. Data Security Standards Standards developed by the PCI Council to assure consumers that their brands and credit cards are reliable and secure. These standards include controls for safe handling of sensitive consumer information. 4. Merchant Account An account established for a unit by a bank to credit sale amounts and debit processing fees.

Payment Card Industry Data Security Standard Policy

Page 3

5. Merchant An organization, department, institution or unit that accepts credit cards as a method of payment for goods, services, information, or gifts. 6. Payment Card Industry Council (PCI) The PCI is a group formed by the credit card industry (VISA, MasterCard, Discover and American Express to establish Data Security Standards (DSS) for the industry. https://www.pcisecuritystandards.org/

7. Self-Assessment The PCI Self-Assessment Questionnaire (SAQ) is a validation tool that is primarily used by merchants to demonstrate compliance to the PCI DSS. The current version of the SAQ, (posted at https://www.pcisecuritystandards.org/tech/supporting_documents.htm), is based on the current version of the Payment Card Industry (PCI) Data Security Standard (DSS).

8. Sensitive Data Sensitive Data include, the account number, magnetic stripe data, CVV2/CVC2 and expiration date.

4.0 Authority and Responsibility The Bursar’s office is responsible for issuing credit card merchant accounts and for overseeing policies and procedures regarding payment processing. Information Technology Service (ITS) is responsible for the operation of the College’s data networks including all merchant services systems.

5.0 Procedures All credit card and debit card transaction acceptance, including web-based transactions, must be managed through the College’s Bursar. Additionally, to ensure that all transactions are handled according to this Policy, sale of goods and services to entities outside the college should be reviewed and approved by the Controller’s Office. Departments, who need to accept credit/debit cards and obtain a physical terminal to either swipe or key transactions, need to contact the Bursar’s Office to execute the required paper work, obtain a Merchant Number, and be given direction as how to process those transactions for accounting purposes.

Payment Card Industry Data Security Standard Policy

Page 4

All transactions that the College processes must meet the standards outlined in the Policy. 1. Whenever possible, direct all in-person and telephone payments to the Bursar’s Office for processing. 2. Electronic credit card numbers should not be transmitted or stored on a personal computer or e-mail account. Electronic lists of customer’s credit card numbers should not be retained. Credit card information should only be accepted online, by telephone, mail, or in person. This information should not be accepted via e-mail and departments should not e-mail credit card information. Lock computer terminals and paper storage areas when unattended. 3. Physical cardholder data must be locked in a secure area. Access should be limited to individuals that require the use of the data. Access should also be restricted on a ‘need to know’ basis. 4. Only essential information should be stored. Do not store the Card Validation Code (also known as the Security Digits, V Code, or CID). Do not store users PIN’s or the full data from a cards magnetic stripe. 5. Credit card information should be destroyed by shredding (cross-cut) immediately after processing. 6. Copies of credit card information should only be retained for the time needed to process, or if retained for reconciliation, for as long as one-year maximum if necessary. 7. Credit card receipts may only show the up to the last five digits of the credit card number. If receipts show more than the last five digits, the receipts must be shredded or retained in a secure area. 8. Limit access to computing resources and cardholder information only to those individuals whose job requires such access. 9. All departments must comply with the Payment Card Industry Data Security Standard

6.0 Compliance Certification Process Staff responsible for processing, storing or transmitting credit card data must sign a PCI confidentiality statement - Appendix A.

Payment Card Industry Data Security Standard Policy

Page 5

Appendix A - Confidentiality / Non-Disclosure Statement Processors As a member of the staff of Eckerd College, I acknowledge that in the course of my employment I may have access to personal, proprietary, transaction-specific, and /or otherwise confidential data concerning faculty, staff, students, alumni and/or other persons through the processing of credit card transactions. As an individual with responsibilities for processing, storing and/or transmitting credit card data, I may have direct access to sensitive and confidential information in paper or electronic format. To protect the integrity and the security of the systems and processes as well as the personal and proprietary data of those to whom the College provides service, and to preserve and maximize the effectiveness of College’s resources, I agree to the following: •

I will maintain the confidentiality of my password and will not disclose it to anyone.



I will utilize credit card data for College business purposes only.



I will uphold Eckerd College’s Code of Conduct, available at www.eckerd.edu/hr, and I agree to abide by it.



I will verify the identity of any third-party persons claiming to be repair or maintenance personnel, prior to granting them access to modify or troubleshoot devices.



I will be vigilant and be aware of suspicious behavior around devices.



I will report suspicious behavior and indications of device tampering or substitution to the Bursar who will report to Campus Safety.



I have been provided a copy of the College’s Payment Data Card Security Standard Policy regarding the proper storing, protection, and disposal of such confidential data and I will ensure that any such data is shredded or otherwise disposed of as per approved office policy when no longer needed.



I have read, understand, and agree to abide by the PCI DSS Policy. Any violations to this Policy will be grounds for disciplinary action up to and including termination of employment from Eckerd College.

Name (Print) _______________________Signature__________________________ Date: _____

Department_________________________ Supervisor________________________ Date:_____

Payment Card Industry Data Security Standard Policy

Page 6

PCI DSS Policy.pdf

There was a problem previewing this document. Retrying... Download. Connect more apps... Try one of the apps below to open or edit this item. PCI DSS Policy.

149KB Sizes 2 Downloads 232 Views

Recommend Documents

pci dss pdf
Loading… Page 1. Whoops! There was a problem loading more pages. pci dss pdf. pci dss pdf. Open. Extract. Open with. Sign In. Main menu. Displaying pci dss ...

PCI DSS Policy.pdf
and credit cards are reliable and secure. These standards include controls for. safe handling of sensitive consumer information. 4. Merchant Account. An account established for a unit by a bank to credit sale amounts and debit. processing fees. Page

PCI DSS Shared Responsibility of Google Cloud Platform
comply the requirements of Section 1 of PCI. DSS. 1.1.1.b For a sample of network connections, interview ... products and services implemented by Google.

FortiScan v5.0.MR1 PCI DSS Jump Start.pdf
Stackable vCPU expansion licenses are. available to grow with you. Be sure to enable 64-bit addressing and hardware-assisted virtualization technology (VT) in ...

how-to-prepare-for-PCI-DSS-audit-ebook.pdf
8 TOP COMPLIANCE TIPS FROM QSAS. INTRODUCTION. Payment Card Industry Data Security Standard. (PCI DSS) audits are often seen as a necessary.

TRB DSS Workshop - Weather DSS (Shawn Truelson).pdf ...
There was a problem previewing this document. Retrying... Download. Connect more apps... Try one of the apps below to open or edit this item. TRB DSS ...

DSS: Data Stream Scan
While data access bugs can be fixed as they are .... able for version 1 queries, but with a default value of 0. .... methods control data access. .... We have access to lengthy SMTP logs of a very large ISP. The .... [8] “The webalizer. what is you

DSS unit (4)_NoRestriction.pdf
DSS unit (4)_NoRestriction.pdf. DSS unit (4)_NoRestriction.pdf. Open. Extract. Open with. Sign In. Main menu. Displaying DSS unit (4)_NoRestriction.pdf.

dss-qb1 4- BY Civildatas.blogspot.in.pdf
Define staggered pitch? BT-1. 7. Differentiate ... A bridge truss carries an axial pull of 400 KN. It is to be a .... dss-qb1 4- BY Civildatas.blogspot.in.pdf. dss-qb1 4- ...

PCI IP Core
Jan 24, 2004 - Configuration Space Access for Host Bus Bridges . ...... The PCI IP core (PCI bridge) provides an interface between the WISHBONE SoC bus ...

Bay Area PCI 2015.pdf
There was a problem previewing this document. Retrying... Download. Connect more apps... Try one of the apps below to open or edit this item. Bay Area PCI ...

Driver pci ven_8086&dev_1c3a&subsys_844d1043&rev_04 ...
Hp laserjet 1000 driver for windows xp.Free download hp. deskjet d1300 printer driver for windows xp.If yua wothhuld yuar fiilongs thiriletounshop woll biwiek.

Cheap Ver 007S Red Pci-E Pci E Express Riser Card 1X To 16X ...
Cheap Ver 007S Red Pci-E Pci E Express Riser Card 1 ... r Machine 50Set Free Shipping & Wholesale Price.pdf. Cheap Ver 007S Red Pci-E Pci E Express ...

pci compliance standards pdf
There was a problem previewing this document. Retrying... Download. Connect more apps... Try one of the apps below to open or edit this item. pci compliance ...

DSS-cont-impl-2016-08-17.pdf
Loading… Page 1. Whoops! There was a problem loading more pages. Retrying... DSS-cont-impl-2016-08-17.pdf. DSS-cont-impl-2016-08-17.pdf. Open. Extract.

pci compliance standards pdf
Page 1. pci compliance standards pdf. pci compliance standards pdf. Open. Extract. Open with. Sign In. Main menu. Displaying pci compliance standards pdf.

DSS 12.F02.Teamcontract_2016-2017.pdf
There was a problem previewing this document. Retrying... Download. Connect more apps... Try one of the apps below to open or edit this item. DSS 12.F02.

dss price list 2016-17.pdf
There was a problem previewing this document. Retrying... Download. Connect more apps... Try one of the apps below to open or edit this item. dss price list ...

Conceptual Design of Fuzzy TOPSIS DSS for Building Information ...
Conceptual Design of Fuzzy TOPSIS DSS for Building Information Modeling (BIM).pdf. Conceptual Design of Fuzzy TOPSIS DSS for Building Information Modeling (BIM).pdf. Open. Extract. Open with. Sign In. Main menu. Displaying Conceptual Design of Fuzzy

SecurityMetrics PCI Data Breach Visualization.pdf
MEMORY-SCRAPING MALWARE. INSTALLED ON THEIR SYSTEM. 89% OF ORGANIZATIONS HAD. FIREWALLS IN PLACE AT TIME OF. COMPROMISE ...

pci compliance guide pdf
Page 1 of 1. File: Pci compliance guide pdf. Download now. Click here if your download doesn't start automatically. Page 1 of 1. pci compliance guide pdf. pci compliance guide pdf. Open. Extract. Open with. Sign In. Main menu. Page 1 of 1.

pdf-1462\defense-security-service-dss-glossary-of-security-terms ...
... the apps below to open or edit this item. pdf-1462\defense-security-service-dss-glossary-of-sec ... nyms-by-us-military-department-of-defense-defense.pdf.