| Title: | E-Commerce and the Cardholder Information Security Program (CISP) (ID: EPS280) |
| Author(s): | Connie J. Sadler (Brown University) |
| Topics: | Data Security, E-Commerce, PCI DSS, Security Risk Assessment and Analysis |
| Origin: | Contributed by Organizations or Campuses (2005) |
| Type: | Effective Practices |
| Abstract: | This submission provides basic information important for universities that sell products or services online and collect fees via credit card. The approach is meant to help institutions of higher education get started in assessing their responsibilities with regard to cardholder data that they may process or otherwise come in contact with, and help institutions determine whether there are regulatory obligations, what those obligations are, and some steps to take to help meet those obligations. |
| View this resource: | |
IT Governance have released PCI DSS: A Practical Guide to Implementation.
It is available through their US website 27001.com.