Web Advisory Committee June 17, 2009.  Implementing E-commerce at UW  Current Status and Future Plans  PCI Data Security Standard  Questions.

Slides:



Advertisements
Similar presentations
Surviving the PCI Self -Assessment James Placer, CISSP West Michigan Cisco Users Group Leadership Board.
Advertisements

Payment Card Industry Data Security Standard AAFA ISC/SCLC Fall 08.
ISACA January 8, IT Auditor at Cintas Corporation Internal Audit Department Internal Security Assessor (ISA) Certification September 2010 Annual.
Evolving Challenges of PCI Compliance Charlie Wood, PCI QSA, CRISC, CISA Principal, The Bonadio Group January 10, 2014.
.. PCI Payment Card Industry Compliance October 2012 Presented By: Jason P. Rusch.
PCI DSS for Retail Industry
UCSB Credit Card Processing and PCI Compliance
PCI Compliance: The Gateway to Paradise PCI Compliance: The Gateway to Paradise.
Continuing Education Registrations Automated!. Presentation Outline History – Where We Were (Michael) Present – Where We Are Now (Dave) Present – What.
Navigating the New SAQs (Helping the 99% validate PCI compliance)
Zenith Visa Web Acquiring A quick over view. Web Acquiring Allows merchants to receive payments for goods and services through the Internet Allows customers.
Merchant Card Processing (PCI Compliance for Supervisors) Sponsored by UW-Platteville’s Financial Services and The Office of Information Security.
Complying With Payment Card Industry Data Security Standards (PCI DSS)
2014 PCI DSS Meeting OSU Business Affairs Process Improvement Team (PIT) Robin Whitlock & Dan Hough 10/28/2014.
This refresher course will:
JEFF WILLIAMS INFORMATION SECURITY OFFICER CALIFORNIA STATE UNIVERSITY, SACRAMENTO Payment Card Industry Data Security Standard (PCI DSS) Compliance.
Property of CampusGuard Compliance With The PCI DSS.
Credit Card Compliance Regulations Mandated by the Payment Card Industry Standards Council Accounting and Financial Services.
Payment Card PCI DSS Compliance SAQ-D Training Accounts Receivable Services, Controller’s Office 7/1/2012.
Presented by : Vivian Eberhardt, Supervisor Cash and Credit Operations
PCI Compliance Forrest Walsh Director, Information Technology California Chamber of Commerce.
Data Security Standard. What Is PCI ? Who Does It Apply To ? Who Is Involved With the Compliance Process ? How We Can Stay Compliant ?
Property of the University of Notre Dame Navigating the Regulatory Maze: Notre Dame’s PCI DSS Solution EDUCAUSE Midwest Regional Conference March 17, 2008.
Credit Card Changes that Impact You! Changes to Accounts Receivable, Cash Receipts and Student Billing 7.77 Wanda Mahon & Bucky Wall Corporate Readiness.
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Commonwealth of Massachusetts Office of the State Comptroller March 2007.
Copyright Security-Assessment.com 2005 Payment Card Industry Digital Security Standards Presented By Carl Grayson.
4/8/99 C. Edward Chow Page 1 Secure Internet Payment Processing.
ECommerce Project. The Team Project Sponsors: –Shelagh Holm, Director of Administrative Information Systems –Ron Ritter, Assoc Director and Treasurer,
Northern KY University Merchant Training
PCI and how it affects College Stores… ROBIN MAYO | PCIP ECOMMERCE MANAGER EAST CAROLINA UNIVERISTY.
PCI's Changing Environment – “What You Need to Know & Why You Need To Know It.” Stephen Scott – PCI QSA, CISA, CISSP
PCI DSS The Payment Card Industry (PCI) Data Security Standard (DSS) was developed by the PCI Security Standards Council to encourage and enhance cardholder.
Payment Card Industry Data Security Standard (PCI DSS) By Roni Argetsinger
MasterCard Site Data Protection Program Program Alignment.
PCI DSS Managed Service Solution October 18, 2011.
- 1 - Gateway to Managed Payment Services Extending your Sales Channels Accept secure on-line internet payments Vision and Strategy YESpay E-Commerce.
The influence of PCI upon retail payment design and architectures Ian White QSA Head of UK&I and ME PCI Team September 4, 2013 Weekend Conference 7 & 8.
An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.
PCI requirements in business language What can happen with the cardholder data?
Date goes here PCI COMPLIANCE: What’s All the Fuss? Mark Banbury Vice President and CIO, Plan Canada.
DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program.
Credit Card Processing Gail “Montreal” Shoffey Keeler August 14, 2007.
PCI DSS Readiness Presented By: Paul Grégoire, CISSP, QSA, PA-QSA
Payment Card PCI DSS Compliance SAQ-A Training Accounts Receivable Services, Controller’s Office 7/1/2012.
Presented by Bob Wesolowski James R. Rennert, CFRE President Dir. of Mission Advancement Caring Habits, Inc. Sisters of St. Joseph Briarcliff Manor, NY.
E-Commerce at uWaterloo Karen Hamilton, Finance Jason Testart, IST.
Smart Payment Processing ™ Recur} Happen again. Persist. Return. Come back. Reappear. Come again.
PCI Compliance: The Gateway to Paradise PCI Compliance: The Gateway to Paradise.
Data Security and Payment Card Acceptance Presented by: Brian Ridder Senior Vice President First National September 10, 2009.
Payment Card PCI DSS Compliance SAQ-B Training Accounts Receivable Services, Controller’s Office 7/1/2012.
ThankQ Solutions Pty Ltd Tech Forum 2013 PCI Compliance.
1 Payment Card Industry (PCI) Security Standard Developed by the PCI Security Council formed by major card issuers: Visa, MasterCard, American Express,
Payment Card Industry (PCI)
Jon Bonham, CISA, QSA Director, ERC
Standards in Use. EMV June 16Caribbean Electronic Payments LLC2.
PCI COMPLIANCE & A/R AUTOMATION 101 Nodus Technologies, Inc.
Credit Card Compliance
MARTA’s Road to PCI Compliance
PCI DSS Improve the Security of Your Ecommerce Environment
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Payment card industry data security standards
Internet Payment.
Session 11 Other Assurance Services
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
PCI Compliance : Whys and wherefores
Rld pci compliance project
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Payment Card Industry (PCI)
MARTA’s Road to PCI Compliance
Presentation transcript:

Web Advisory Committee June 17, 2009

 Implementing E-commerce at UW  Current Status and Future Plans  PCI Data Security Standard  Questions

 Prepare an e-commerce business plan.  Obtain approval from Financial Systems Mgmt. Committee.  Organize project.  Obtain bank merchant account & Beanstream account.  Design/build application or install packaged application or configure hosted application according to standards (PCI, Bank, UW).  Integrate with Beanstream if not hosted.  Test.  Review/signoff by Finance and Security.  Go – live.

 Describe the products or services to be offered and the rationale for offering them via e-commerce.  Provide estimated annual transaction and dollar volume.  Describe the business process to handle the additional workload from the e-commerce function, including the accounting, maintenance, and reconciliation of general ledger accounts and the credit card operation.  Indicate whether the operation currently accepts credit cards.  Identify the hardware requirements and hardware location.  Identify the source of technical support.  Identify areas or departments that need to be involved in the development and implementation of your e-commerce initiative; examples may include Finance, Information Systems and Technology, or Procurement and Contract Services.  Identify the working group to develop the initiative.

 Must use Beanstream for credit card processing.  Beanstream provides multiple integration methods.  UW uses Beanstream’s hosted payment page to ensure security, privacy, and for easier PCI compliance. No credit card information is stored on a UW server.  IST provides an e-commerce server to host Linux applications.  Use of other, secure servers is acceptable.

 May use a hosted shopping cart / event management site. Little experience with this at UW.  Must use Beanstream for credit card payment processing in all cases.

 Retail Services  Housing ◦ Residence deposits ◦ Off campus housing landlord fees  Watcard  Parking  CEMC  Events and conferences come and go

 Continuing Education  Conference Centre  Food Services

 UW approved, hosted shopping cart system.  UW approved, hosted event/conference system.  Hosting will significantly reduce implementation effort for all UW participants.  Will make small volume e-commerce sites more feasible.

 PCI = Payment Card Industry (Amex, Discover, JCB, MC, Visa)  PCI Data Security Standard (DSS)  PCI DSS v1.2 released October 2008  72 page document  Consistent security measures around the processing, storage, and transmission of credit card data  A nice baseline of security measures for any application

 Depends on how credit card data is handled  SAQ = Self Assessment Questionnaire  Assessment from an external QSA  Regular network scans of e- commerce sites SAQ Validation Type Description SAQ: V1.2 1 Card-not-present (e-commerce or mail/telephone-order) merchants, all cardholder data functions outsourced. This would never apply to face-to-face merchants. A 2 Imprint-only merchants with no electronic cardholder data storage B 3 Stand-alone terminal merchants, no electronic cardholder data storage B 4 Merchants with POS systems connected to the Internet, no electronic cardholder data storage C 5 All other merchants (not included in Types 1-4 above) and all service providers defined by a payment brand as eligible to complete an SAQ. D

 Our acquirer requires us to be compliant with PCI DSS  All validation types apply to UW  Security measures for validation type 5 are expensive  Strategy: Eliminate cases where validation type 5 apply

 E-commerce websites must not collect, transmit or store credit card information  Reduce scope: Isolate IP-based PoS terminals from the rest of the campus network  Include in more general security policies and procedures

 Heavy fines from the acquiring bank  Bank could suspend the University’s ability to process any credit card

 ml ml  rds/pci_dss.shtml rds/pci_dss.shtml  EcommerceSystemSecurityStandards EcommerceSystemSecurityStandards