PCI DSS

Posts by Month
Jul 2008
Jul 1998
This EDUCAUSE Taxonomy Term has 39 items and was last updated on July 7th, 2008 (2 days ago).
Also known as: Payment Card Industry Data Security Standard

Primary Publications

Recent

ER

About EDUCAUSE Review

EDUCAUSE Review takes a broad look at current developments and trends in information technology,
what these mean for higher education, and how they may affect the college/university as a whole.

Recent Articles from EDUCAUSE Review about PCI DSS

EDUCAUSE | EDUCAUSE Review Articles and PCI DSS

Multimedia

Podcasts tagged with this topic

EDUCAUSE | Podcasts and PCI DSS

Community Resources

Wiki

PCI DSS

Introduction

The Payment Card Industry Data Security Standard (PCI DSS) first came on the scene in 2005 as a set of comprehensive requirements for enhancing payment account data security, was developed by the founding payment brands of the PCI Security Standards Council, including American Express, Discover Financial Services, JCB, MasterCard Worldwide and Visa International, to help facilitate the broad adoption of consistent data security measures on a global basis. The PCI DSS is a multifaceted security standard that includes requirements for security management, policies, procedures, network architecture, software design and other critical protective measures. This comprehensive standard is intended to help organizations proactively protect customer account data.

To the extent that colleges and universities accept credit card payments for tuition, fees, conference registrations, or other services, institutions of higher education will have contractual obligations to fulfill the data security standards established by the payment card industry. Some colleges and universities have begun to consider the standards as a potential model for the handling of all types of sensitive data at their institutions and are exploring the extension of the standards to other types of information collected, stored, and distributed on campus networks.

Background

The Treasury Institute for Higher Education has been the focal point for helping colleges and universities to become PCI DSS compliant, hosting two workshops for the higher education community. In partnership with the National Association of College and University Business Officers (NACUBO), the Treasury Institute represent the business and financial interests of institutions of higher education. Additionally, information security officers and other IT staff from colleges and universities have attended the workshops and several institutions have been actively pursuing PCI DSS compliance for their institution. The Treasury Institute has also published a whitepaper for higher education and a checklist of best practices.

The PCI Security Standards Council is an open global forum for the ongoing development, enhancement, storage, dissemination and implementation of security standards for account data protection. The PCI Security Standards Council’s mission is to enhance payment account data security by fostering broad adoption of the PCI Security Standards. The organization was founded by American Express, Discover Financial Services, JCB, MasterCard Worldwide, and Visa International.

Current Status

The EDUCAUSE/Internet2 Computer and Network Security Task Force has established a technical advisory group on PCI DSS that is coordinating its activities closely with the Effective IT Security Practices and Solutions Group of the task force.

Roadmaps

Members are also encouraged to contribute to the following pages aimed at collecting knowledge and insight into how various groups are responding to this challenge. Currently three areas are being profiled.

Getting Started

Implementing the Standard

Compliance Maintenance

For More Information

Contact the EDUCAUSE/Internet2 Security Task Force at 202-872-4200 or security-task-force@educause.edu

Articles

Recent Community Articles

EDUCAUSE | Contributed by Organizations or Campuses; Articles, Papers, and Reports; and PCI DSS

Conference Resources

National Events

EDUCAUSE Annual

EDUCAUSE | Presented at EDUCAUSE Annual Conferences and PCI DSS

Web Events

Web Seminars and Events

EDUCAUSE | Web Seminars Contributed by EDUCAUSE and PCI DSS