payment card industry compliance project

Slides:



Advertisements
Similar presentations
IT Security Policy Framework
Advertisements

Surviving the PCI Self -Assessment James Placer, CISSP West Michigan Cisco Users Group Leadership Board.
Payment Card Industry Data Security Standard AAFA ISC/SCLC Fall 08.
1 Presented to Department of Information Technology Jan 28, 2009 New Mexico Department of Health ELECTRONIC REPORTING (e-Reporting) e-Reporting.
NEW MEXICO DRIVER REENGINEERING SOLUTION Initiation Certification November 19, 2008 Project Certification Committee.
Data Warehouse External Data Loads Implementation Certification May 27, 2009 Project Certification Committee May 27,
JEFF WILLIAMS INFORMATION SECURITY OFFICER CALIFORNIA STATE UNIVERSITY, SACRAMENTO Payment Card Industry Data Security Standard (PCI DSS) Compliance.
Presented by : Vivian Eberhardt, Supervisor Cash and Credit Operations
PCI Compliance Forrest Walsh Director, Information Technology California Chamber of Commerce.
Data Security Standard. What Is PCI ? Who Does It Apply To ? Who Is Involved With the Compliance Process ? How We Can Stay Compliant ?
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Commonwealth of Massachusetts Office of the State Comptroller March 2007.
Payment Card Industry (PCI) Data Security Standard
PCI's Changing Environment – “What You Need to Know & Why You Need To Know It.” Stephen Scott – PCI QSA, CISA, CISSP
Disclaimer Copyright Michael Chapple and Jane Drews, This work is the intellectual property of the authors. Permission is granted for this material.
Web Advisory Committee June 17,  Implementing E-commerce at UW  Current Status and Future Plans  PCI Data Security Standard  Questions.
Payment Card Industry Data Security Standard (PCI DSS) By Roni Argetsinger
PCI DSS Managed Service Solution October 18, 2011.
An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.
Teresa Macklin Information Security Officer 27 May, 2009 Campus-wide Information Security Activities.
Credit Card Processing Gail “Montreal” Shoffey Keeler August 14, 2007.
DAS: State Controller's Division1January 2010 Department of Administrative Services State Controller’s Division Updated January, 2010.
Organization and Implementation of a National Regulatory Program for the Control of Radiation Sources Staffing and Training.
Introduction to Payment Card Industry Data Security Standard
North Carolina Community College System IIPS Conference – Spring 2009 Jason Godfrey IT Security Manager (919)
Security Professional Services. Security Assessments Vulnerability Assessment IT Security Assessment Firewall Migration Custom Professional Security Services.
Introduction To Plastic Card Industry (PCI) Data Security Standards (DSS) April 28,2012 Cathy Pettis, SVP ICUL Service Corporation.
Cash Handling and Funds Collection Policies and Procedures.
Information Security 2013 Roadshow - PCI. Roadshow Outline  What IS PCI  Why we Care about PCI  What PCI Means to You and Me.
IT Security Policy Framework ● Policies ● Standards ● Procedures ● Guidelines.
ThankQ Solutions Pty Ltd Tech Forum 2013 PCI Compliance.
1 Privacy Plan of Action © HIPAA Pros 2002 All rights reserved.
Legal, Regulations, Investigations, and Compliance Chapter 9 Part 2 Pages 1006 to 1022.
Important acronyms AO = authorizing official ISO = information system owner CA = certification agent.
Building & Safety Department June 10, Mission Statement To protect the health, safety, and general welfare of the citizens of the community through.
MARTA’s Road to PCI Compliance
Payment Card Industry (PCI) Rules and Standards
TCEQ Helps Compliance and Assistance Programs
Payment Card Industry (PCI) Rules and Standards
Performing Risk Analysis and Testing: Outsource or In-house
PCI-DSS Security Awareness
PCI Compliance Service
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Team 4 – Mack, Josh, Felicia, Kevin and Walter
Internet Payment.
Breaches by Merchant Type
2018 – 2020 Budget| Presented by: Devon Thiele
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Medical Cannabis Project Comprehensive Software Solution
STATE OF NEW MEXICO STATE PERSONNEL OFFICE (SPO)
Public Employees Retirement Association Infrastructure Upgrade
Regulation and Licensing Department Accela Replacement Project Planning Request Agency CIO/IT Lead - Michelle Langehennig, Chief Information Officer.
New Mexico Business Portal Closeout Department of Information Technology Estevan Lujan, Acting Cabinet Secretary September 26, 2018.
Regulation and Licensing Department Accela Replacement Project Initiation Request Agency CIO/IT Lead - Michelle Langehennig, Chief Information Officer.
DEPARTMENT OF PUBLIC SAFETY – Forensic Laboratory
VTrcks/Exis – Vaccine Tracking System Integration Implementation Phase
Red Flags Rule An Introduction County College of Morris
Rld pci compliance project
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
MARTA’s Road to PCI Compliance
Presented to the Project Certification Committee on November 16, 2011.
Executive Sponsor: Marcos Trujillo, Acting Division Director
Executive Sponsor: Marcos Trujillo, Acting Division Director
GENERAL SERVICES DEPARTMENT Facilities Management Division PROOF-NM Project (Process Re-engineering & Optimization of Operations & Maintenance Functions.
Office of Superintendent of Insurance OSI Paperless, Web-based Environment – Project Change Request Presented to the DoIT Project Certification Committee.
PLANNING A SECURE BASELINE INSTALLATION
City Council Meeting November 14, 2016
Regulation and Licensing Department RLD Permitting and Inspection Software Modernization Change (Planning) Request Agency CIO/IT Lead - Michelle Langehennig,
Pipeline Safety Electronic Data Reporting Project
Executive Sponsor: Tom Church, Cabinet Secretary
Professional Licensure Bureau Modernization
Presentation transcript:

payment card industry compliance project Michelle Langehennig Chief Information Officer Eric Scott Network Administrator Supervisor

RLD Vision and Mission RLD Vision: To ensure New Mexicans receive quality care and services from qualified professionals. RLD Mission RLD is in the business of ensuring that New Mexicans receive quality care and services from qualified individuals and businesses in 35 different industries, professions and trades. We touch everyday activities of every New Mexican, while ensuring fair and prompt administrative process to help spur economic development. Construction Industries Division: Provide code compliance oversight; issue licenses, permits and citations; perform inspections; administer exams; process complaints; and enforce laws, rules and regulations relating to general construction and manufactured housing standards to industry professionals.

Project Description RLD PCI Compliance is a two part project. Completed in Phase I: RLD separated all traffic through the firewall and segmented the traffic by a demilitarized zone(DMZ) allowing the cardholder traffic to be separate from the network traffic. The Accela application redirect is complete and is no longer storing data on the RLD network. The Accela and MLO data is now separated in the current data storage environment. Installed Cisco Umbrella to provide a view of DNS traffic. To Be Completed in Phase II: Move payment providers from PayPal to Wells Fargo. Saving RLD over $150,000 in fees. Replace core equipment and host to eliminate aging equipment, obtain more data storage and allow RLD to remain PCI compliant.

Accomplishments Achieved full PCI compliance for RLD and associated Permitting and Licensing application to increase the security of the card-holder data environment (CDE). Separated all Card holder data and regular network traffic making RLD a more secure environment. Separated applications taking credit cards from the rest of the network creating a compliant environment to take credit cards. Provide a view of DNS traffic to protect the network from threats. Replaced out dated firewalls to create a hardened and safer environment for the public and the RLD network.

Objectives Move payment providers from PayPal to Wells Fargo to eliminate over $150,000 of fees imposed by financial service provider. Maintain PCI compliance through the life of the Permitting and Licensing programs and for as long as the PCI DSS compliance specification is relevant. Eliminate aging equipment and obtain more data storage allowing RLD to remain PCI compliant.

Deliverables PCI DSS 3.2 compliant payment portal that takes credit card payments from existing RLD applications, customizable and configurable by RLD IT staff. Customized code within existing RLD applications that point to the new payment portal. Policies and Procedures appropriate to the new SAQ-A environment. DNS protection software Core hardware to replace the current infrastructure

Project Budget Item Cost Estimate Phase 1 Hardware $32,100 Phase 1 Software $8,900 Phase 1 Implementation $26,000 Phase 2 Hardware $267,400 *Total $334,400 *IV&V not currently budgeted, as waiver was granted by DoIT on 7/26/2018

Conclusion RLD is requesting certification of $267,400 for the Planning / Implementation Phase to complete phase 2 of the PCI Compliance Project.