E-Commerce

Recent resources tagged with E-Commerce.

The Data Center Within a Data Center: Building a Secure Environment for Compliance

Added by the EDUCAUSE Librarian
Title:The Data Center Within a Data Center: Building a Secure Environment for Compliance (ID: SEC08074)
Author(s):David Seidl (University of Notre Dame)
Origin:Presented at Security Professionals Conference (05/04/2008)
Type:Presentations/Speeches
Abstract:

PCI compliance can be daunting, particularly in a university network environment. Notre Dame chose a data center within a data center approach to simplify compliance and minimize integration issues. This project includes implementing the data center, a virtual network to support point-of-sale devices, and related operational procedures.

View this resource:

Straight Talk About Data Security

Added by the EDUCAUSE Librarian
Title:Straight Talk About Data Security (ID: CSD5298)
Author(s):Walter Conway (Walter Conway Associates, LLC) and Dennis Reedy (Indiana University System)
Source:Business Officer Magazine
Origin:Contributed by Organizations or Campuses (12/26/2007)
Type:Articles, Papers, and Reports
Abstract:

"If you accept payment cards on campus, you need to comply with a standard designed for safe handling of sensitive consumer information. Indiana University’s compliance plans offer some guidance."

View this resource:

PCI Confusion Is The Norm

Added by the EDUCAUSE Librarian
Title:PCI Confusion Is The Norm (ID: CSD5261)
Author(s):Evan Schuman (eWeek.com)
Source:Storefront Backtalk
Origin:Contributed by Organizations or Campuses (12/07/2007)
Type:Articles, Papers, and Reports
Abstract:

With all of the concern today about retailers inadequately protecting their credit card data, it's logical to assume that retail IT managers would have made themselves quite familiar with the ins-and-outs of the Payment Card Industry Data Security Standard (PCI DSS).

View this resource:

A Central Solution for Enabling Online Payments Across the University

Added by the EDUCAUSE Librarian
Title:A Central Solution for Enabling Online Payments Across the University (ID: EDU07146)
Author(s):Brian Foley (Washington State University)
Origin:Presented at EDUCAUSE Annual Conferences (10/23/2007)
Type:Presentations/Speeches
Abstract:

WSU has developed a central solution to allow departments to accept online payments from their Web sites without having to accept credit card information. A central payment site allows departmental sites to use the centrally maintained site for payments, while still keeping the look and feel of their own sites.

View this resource:

Tackling Campus-Wide E-Commerce

Added by the EDUCAUSE Librarian
Title:Tackling Campus-Wide E-Commerce (ID: EDU07218)
Author(s):Troy Boroughs (University of Richmond)
Origin:Presented at EDUCAUSE Annual Conferences (10/23/2007)
Type:Presentations/Speeches
Abstract:

Payment card industry (PCI) standards dictate effective management of credit card systems across the organization. The University of Richmond will discuss its development of a centralized e-commerce policy and oversight group, choosing appropriate vendor solutions, and achieving PCI compliance campus-wide.

View this resource:

Lessons Learned on the Road to PCI Compliance

Added by the EDUCAUSE Librarian
Title:Lessons Learned on the Road to PCI Compliance (ID: LIVE0717)
Author(s):Mark S. Welch (University of Notre Dame) and Walter Conway (Walter Conway Associates, LLC)
Origin:EDUCAUSE Live!, Web Seminars Contributed by EDUCAUSE (09/05/2007)
Type:Presentations/Speeches
Abstract:

Many of us are working within our institutions to achieve Payment Card Industry (PCI) compliance. We see a number of merchants on campuses with different business needs, systems, and vendor relationships in place. In many cases, achieving compliance with PCI DSS, the Data Security Standard, is proving difficult.

The presenters will share experiences and valuable lessons learned in implementing PCI DSS, including merchant levels (does it matter?), limiting the scope of the PCI effort (yes, it can be done), the Payment Applications Best Practices list (is it required?), and recent findings on information security breaches.

Welch and Conway will represent NACUBO and all of higher education at the first PCI Security Standards Council meeting of participating organizations to be held in Toronto next month. Bring your questions, suggestions, and observations to share with them in advance of that meeting.

View this resource:

“Give Us Credit”: Evolving Security Standards for Credit Card Information

Added by the EDUCAUSE Librarian
Title:“Give Us Credit”: Evolving Security Standards for Credit Card Information (ID: ERM0759)
Author(s):Jane Drews (The University of Iowa) and Kathleen R. Kimball (The Pennsylvania State University)
Origin:EDUCAUSE Review Articles (08/29/2007)
Type:Articles, Papers, and Reports
Abstract:

The author gives an overview of the six PCI DSS main compliance categories and twelve major requirements for merchant to be deemed compliant.

View this resource:

Bankcard Information Security Requirements

Added by the EDUCAUSE Librarian
Title:Bankcard Information Security Requirements (ID: CSD5049)
Source:Oakland University
Origin:Contributed by Organizations or Campuses (09/13/2006)
Type:Policies and Procedures
Abstract:

Oakland University is subject to rules, regulations, and contractual provisions regarding the handling of Bankcards and Cardholder Information, as those terms are defined in this document.  This Policy provides mandatory security measures and procedures for University departments accepting Bankcards for payment.

View this resource:

Cambridge University researchers hack chip-and-PIN payment terminals

Added by the EDUCAUSE Librarian
Title:Cambridge University researchers hack chip-and-PIN payment terminals (ID: CSD4930)
Author(s):Jaikumar Vijayan (PC World)
Source:Computer World
Origin:Contributed by Organizations or Campuses (2007)
Type:Articles, Papers, and Reports
Abstract:"Researchers at the University of Cambridge in the U.K. have demonstrated how a chip-and-PIN terminal used to authenticate credit and debit card transactions in that country can be compromised to steal sensitive data."
View this resource:

E-Commerce and the Cardholder Information Security Program (CISP)

Added by the EDUCAUSE Librarian
Title:E-Commerce and the Cardholder Information Security Program (CISP) (ID: EPS280)
Author(s):Connie J. Sadler (Brown University)
Origin:Contributed by Organizations or Campuses (2005)
Type:Effective Practices
Abstract:

This submission provides basic information important for universities that sell products or services online and collect fees via credit card. The approach is meant to help institutions of higher education get started in assessing their responsibilities with regard to cardholder data that they may process or otherwise come in contact with, and help institutions determine whether there are regulatory obligations, what those obligations are, and some steps to take to help meet those obligations.

View this resource: