PCI DSS and Data Security

Recent resources tagged with PCI DSS and Data Security.

Navigating the Regulatory Maze: Notre Dame’s PCI Solution

Added by the EDUCAUSE Librarian
Title:Navigating the Regulatory Maze: Notre Dame’s PCI Solution (ID: MWR08070)
Author(s):Robert M. Winding (University of Notre Dame), Michael Chapple (University of Notre Dame), David Seidl (University of Notre Dame), and Robert Richman (University of Notre Dame)
Origin:Presented at Midwest Regional Conferences (03/17/2008)
Type:Presentations/Speeches
Abstract:

Payment Card Industry (PCI) compliance can be daunting, particularly in institutions of higher education with a variety of complex commerce activities. In this presentation, you’ll learn how Notre Dame tackled PCI DSS. We chose a network within a network approach to simplify compliance through isolation and minimize integration issues.

View this resource:

Straight Talk About Data Security

Added by the EDUCAUSE Librarian
Title:Straight Talk About Data Security (ID: CSD5298)
Author(s):Walter Conway (Walter Conway Associates, LLC) and Dennis Reedy (Indiana University System)
Source:Business Officer Magazine
Origin:Contributed by Organizations or Campuses (12/26/2007)
Type:Articles, Papers, and Reports
Abstract:

"If you accept payment cards on campus, you need to comply with a standard designed for safe handling of sensitive consumer information. Indiana University’s compliance plans offer some guidance."

View this resource:

PCI Confusion Is The Norm

Added by the EDUCAUSE Librarian
Title:PCI Confusion Is The Norm (ID: CSD5261)
Author(s):Evan Schuman (eWeek.com)
Source:Storefront Backtalk
Origin:Contributed by Organizations or Campuses (12/07/2007)
Type:Articles, Papers, and Reports
Abstract:

With all of the concern today about retailers inadequately protecting their credit card data, it's logical to assume that retail IT managers would have made themselves quite familiar with the ins-and-outs of the Payment Card Industry Data Security Standard (PCI DSS).

View this resource:

PCI Compliance in the University Setting

Added by the EDUCAUSE Librarian
Title:PCI Compliance in the University Setting (ID: EDU07285)
Author(s):John Chapman (Washington State University), Jay Maylor (Washington State University), and Sandie Rosko (University of Washington)
Origin:Presented at EDUCAUSE Annual Conferences (10/23/2007)
Type:Presentations/Speeches
Abstract:

In 2004, Visa and MasterCard collaboratively developed the Payment Card Industry Data Security Standard (PCI DSS) to create common industry security requirements. This session will share the campus perspectives and approaches of Washington State University and the University of Washington in addressing the standard.

View this resource:

Secure Data Exchange

Added by the EDUCAUSE Librarian
Title:Secure Data Exchange (ID: EDU07037)
Author(s):Theresa Rowe (Oakland University)
Origin:Presented at EDUCAUSE Annual Conferences (10/23/2007)
Type:Presentations/Speeches
Abstract:

How do you know that your data exchange is secure? Our campuses exchange data daily, much of it critical and confidential. Is your banking relationship supporting secure data exchange? How secure are your retirement file feeds? Can anyone on campus initiate data exchange? If so, are they trained to make the exchange secure? Discuss challenges and solutions for making data exchanges secure.

View this resource:

Lessons Learned on the Road to PCI Compliance

Added by the EDUCAUSE Librarian
Title:Lessons Learned on the Road to PCI Compliance (ID: LIVE0717)
Author(s):Mark S. Welch (University of Notre Dame) and Walter Conway (Walter Conway Associates, LLC)
Origin:EDUCAUSE Live!, Web Seminars Contributed by EDUCAUSE (09/05/2007)
Type:Presentations/Speeches
Abstract:

Many of us are working within our institutions to achieve Payment Card Industry (PCI) compliance. We see a number of merchants on campuses with different business needs, systems, and vendor relationships in place. In many cases, achieving compliance with PCI DSS, the Data Security Standard, is proving difficult.

The presenters will share experiences and valuable lessons learned in implementing PCI DSS, including merchant levels (does it matter?), limiting the scope of the PCI effort (yes, it can be done), the Payment Applications Best Practices list (is it required?), and recent findings on information security breaches.

Welch and Conway will represent NACUBO and all of higher education at the first PCI Security Standards Council meeting of participating organizations to be held in Toronto next month. Bring your questions, suggestions, and observations to share with them in advance of that meeting.

View this resource:

Tune In September 5: Free Web Seminar on Payment Card Industry (PCI) Compliance in Higher Education

Created by Colleen Luckett (EDUCAUSE) on August 28, 2007

Many of us are working within our institutions to achieve Payment Card Industry (PCI) compliance. We see a number of merchants on campuses with different business needs, systems, and vendor relationships in place. In many cases, achieving compliance with PCI DSS, the Data Security Standard, is proving difficult. In this free Sept. 5 EDUCAUSE Live! Web seminar, Lessons Learned on the Road to PCI Compliance, Mark Welch, project coordinator for the Credit Card Support Program at University of Notre Dame, and Walt Conway, president of Walter Conway Associates, LLC, will share experiences and valuable lessons learned in implementing PCI DSS, including merchant levels (does it matter?), limiting the scope of the PCI effort (yes, it can be done), the Payment Applications Best Practices list (is it required?), and recent findings on information security breaches.

Bankcard Information Security Requirements

Added by the EDUCAUSE Librarian
Title:Bankcard Information Security Requirements (ID: CSD5049)
Source:Oakland University
Origin:Contributed by Organizations or Campuses (09/13/2006)
Type:Policies and Procedures
Abstract:

Oakland University is subject to rules, regulations, and contractual provisions regarding the handling of Bankcards and Cardholder Information, as those terms are defined in this document.  This Policy provides mandatory security measures and procedures for University departments accepting Bankcards for payment.

View this resource:

Duke University: The Payment Card Industry (PCI) Data Security Standard

Added by the EDUCAUSE Librarian
Title:Duke University: The Payment Card Industry (PCI) Data Security Standard (ID: CSD5047)
Source:Duke University
Origin:Contributed by Organizations or Campuses (08/01/2007)
Type:Policies and Procedures
Abstract:

This document outlines Duke University's expectations of departments accepting credit card payments as related to the Payment Card Industry Data Security Standard (http://www.visa.com/cisp), which has been designed to safeguard sensitive data for all card brands.

View this resource:

Policy Coverage Matrix for Payment Card Industry

Added by the EDUCAUSE Librarian
Title:Policy Coverage Matrix for Payment Card Industry (ID: CSD5048)
Source:Information Shield
Origin:Contributed by Organizations or Campuses (08/13/2007)
Type:Policies and Procedures
Abstract:

This table provides a high-level mapping between the security requirements of the Payment Card
Industry Data Security Standard and the information security policies found within ISPME V10. ISPME
also provides policy coverage for many areas not specifically mentioned in the high-level requirements,
but specified in the detailed requirements of the standard.

View this resource: