Presentation is loading. Please wait.

Presentation is loading. Please wait.

Data Compliance.

Similar presentations


Presentation on theme: "Data Compliance."— Presentation transcript:

1 Data Compliance

2 Agenda Introduction Define PCI/PII Why should I care?
Regulations Penalties Customer How does this impact me? Office personnel Remote personnel What should I do? Understanding your responsibility Reporting an incident Questions

3 Introduction Joe Myers
Business Applications Manager, Radio Systems Corporation Blue, GPS CRM, Warranty Tracker Oracle InvisibleFence.COM Husband, father, musician, nerd Brief work history (~15 years of software-related exp) SCADA Engineer at Knoxville Utilities Board Software Development at Pilot Travel Centers and Skillsoft Compliance Learning Database Development and Maintenance at Radio Systems Corporation

4 PCI Defined Payment Card Institute Data Security Standard (PCI DSS) is a set of requirements when you accept credit card payments. This is regulated and enforced by the banking institutions. Failure to comply can result in your business not being able to accept credit cards. 769 participating council members All major credit cards and the supported banking institutions

5 PCI Defined PCI Compliance Level 1 Over 6 million Visa and/or MasterCard transactions processed per year (Annual Report of Compliance – Auditor) PCI Compliance Level 2 1 million to 6 million Visa and/or MasterCard transactions processed per year (Self Assessment + Attestation of Compliance) PCI Compliance Level 3 20,000 to 1 million Visa and/or MasterCard e-commerce transactions processed per year (Self Assessment) PCI Compliance Level 4 (most distributors and dealers) Less than 20,000 Visa and/or MasterCard e-commerce transactions processed per year all other companies that process up to 1 million Visa transactions per year (Self Assessment)

6 PCI Defined PCI Security Standards PCI Quick Reference
PCI Quick Reference

7 Why Should I Care? Love Thy Customer
One mistake could impact ALL distributors & dealers Reduction in sales Failure to comply can result in: Fines ($100 - $1000 per effected customer) Raises you to highest PCI Level, immediately Quarterly bank audit Inability to take cards

8 How Does This Impact Me? Office Personnel Field Personnel
Card Data Environment Systems Phones/ Field Personnel Contracts

9 Protect from this..

10 And even this…

11 What Should I Do? Understanding your responsibilities
Card Data Environment (CDE) Policy Reporting Reporting an incident Who What When

12 What Should I Do? Card Data Environment
Be aware of others around you when taking payments Over the phone? Don’t repeat back the whole credit card info with others around. DO NOT write the info down, if you HAVE to, shred it when done DO NOT send credit card information in !

13 What Should I Do? Policy Document the DONTs and
make sure your team knows the rules and abides by them.

14 What Should I Do? CRM – you are covered. Radio Systems Corporation handles the system compliance E-Fence – Attestation of Compliance (AOC) Cloud Version Use something else? It’s your responsibility to ensure compliance Secure hardware, software Get AOCs if applicable Documentation User education Yearly reporting to your bank

15 What Should I Do? Reporting
Depending on your level of PCI, most will self-assess Most will use the SAQ C-VT, SAQ C or SAQ D for Merchant forms SAQ = Self Assessment Quesetionaire

16 Reporting an Incident Call your merchant provider / bank
Depending on the situation, call local law enforcement

17 Wrap Up Questions?

18 Thanks


Download ppt "Data Compliance."

Similar presentations


Ads by Google