UCSB Credit Card Processing and PCI Compliance

Slides:



Advertisements
Similar presentations
Surviving the PCI Self -Assessment James Placer, CISSP West Michigan Cisco Users Group Leadership Board.
Advertisements

Payment Card Industry Data Security Standard AAFA ISC/SCLC Fall 08.
October 28, Who? What? When? Why? Comply with PCI compliance policies set forth by industry Create internal policies and procedures to protect.
Evolving Challenges of PCI Compliance Charlie Wood, PCI QSA, CRISC, CISA Principal, The Bonadio Group January 10, 2014.
2013 AUXILIARY FORUM INDIANA UNIVERSITY Ruth Harpool Director Treasury Operations Indiana University.
The Payment Card Industry Data Security Standard (PCI DSS)
PCI DSS for Retail Industry
Payment Card Industry Data Security Standard Tom Davis and Chad Marcum Indiana University.
PCI Compliance: The Gateway to Paradise PCI Compliance: The Gateway to Paradise.
Navigating the New SAQs (Helping the 99% validate PCI compliance)
Complying With Payment Card Industry Data Security Standards (PCI DSS)
2014 PCI DSS Meeting OSU Business Affairs Process Improvement Team (PIT) Robin Whitlock & Dan Hough 10/28/2014.
JEFF WILLIAMS INFORMATION SECURITY OFFICER CALIFORNIA STATE UNIVERSITY, SACRAMENTO Payment Card Industry Data Security Standard (PCI DSS) Compliance.
Property of CampusGuard Compliance With The PCI DSS.
Navigating the trustkeeper.net Portal 2011 PCI:DSS Compliance Validation UCSF Controller’s Office.
Credit Card Compliance Regulations Mandated by the Payment Card Industry Standards Council Accounting and Financial Services.
Presented by : Vivian Eberhardt, Supervisor Cash and Credit Operations
PCI Compliance Forrest Walsh Director, Information Technology California Chamber of Commerce.
Data Security Standard. What Is PCI ? Who Does It Apply To ? Who Is Involved With the Compliance Process ? How We Can Stay Compliant ?
Jeff Williams Information Security Officer CSU, Sacramento
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Commonwealth of Massachusetts Office of the State Comptroller March 2007.
GPUG ® Summit 2011 November 8-11 Caesars Palace – Las Vegas, NV Payment Processing Online and Within Dynamics GP PCI Compliance and Secure Payment Processing.
CSE 4482, 2009 Session 21 Personal Information Protection and Electronic Documents Act Payment Card Industry standard Web Trust Sys Trust.
Why Comply with PCI Security Standards?
Northern KY University Merchant Training
Security & PCI Compliance The Future of Electronic Payments Security & PCI Compliance Greg Grant Vice President – Managed Security Services.
Web Advisory Committee June 17,  Implementing E-commerce at UW  Current Status and Future Plans  PCI Data Security Standard  Questions.
SAS 112: The New Auditing Standard Jim Corkill Controller Accounting Services & Controls.
Payment Card Industry Data Security Standard (PCI DSS) By Roni Argetsinger
PCI DSS Managed Service Solution October 18, 2011.
The influence of PCI upon retail payment design and architectures Ian White QSA Head of UK&I and ME PCI Team September 4, 2013 Weekend Conference 7 & 8.
An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.
BZUPAGES.COM Electronic Payment Systems Most of the electronic payment systems on internet use cryptography in one way or the other to ensure confidentiality.
Teresa Macklin Information Security Officer 27 May, 2009 Campus-wide Information Security Activities.
PCI requirements in business language What can happen with the cardholder data?
Date goes here PCI COMPLIANCE: What’s All the Fuss? Mark Banbury Vice President and CIO, Plan Canada.
Credit Card Processing Gail “Montreal” Shoffey Keeler August 14, 2007.
Introduction to Payment Card Industry Data Security Standard
Introduction To Plastic Card Industry (PCI) Data Security Standards (DSS) April 28,2012 Cathy Pettis, SVP ICUL Service Corporation.
Traditional and Electronic Payment Methods Chapter 3.
Smart Payment Processing ™ Recur} Happen again. Persist. Return. Come back. Reappear. Come again.
PCI Compliance: The Gateway to Paradise PCI Compliance: The Gateway to Paradise.
Data Security and Payment Card Acceptance Presented by: Brian Ridder Senior Vice President First National September 10, 2009.
Payment Card PCI DSS Compliance SAQ-B Training Accounts Receivable Services, Controller’s Office 7/1/2012.
ThankQ Solutions Pty Ltd Tech Forum 2013 PCI Compliance.
1 Payment Card Industry (PCI) Security Standard Developed by the PCI Security Council formed by major card issuers: Visa, MasterCard, American Express,
North Carolina Office of the State Controller
Jon Bonham, CISA, QSA Director, ERC
Fall  Comply with PCI compliance policies set forth by industry  Create internal policies and procedures to protect cardholder data  Inform and.
Standards in Use. EMV June 16Caribbean Electronic Payments LLC2.
By: Matt Winkeler.  PCI – Payment Card Industry  DSS – Data Security Standard  PAN – Primary Account Number.
The Payment Card Industry Data Security Standard (PCI DSS) is a proprietary information security standard for organizations that handle branded credit.
North Carolina Office of the State Controller
Credit Card Compliance
MARTA’s Road to PCI Compliance
Payment Card Industry (PCI) Rules and Standards
Performing Risk Analysis and Testing: Outsource or In-house
PCI-DSS Security Awareness
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Payment card industry data security standards
Internet Payment.
Session 11 Other Assurance Services
UGA Extension Credit Card Processing Training
Switchover from Teledeposit to VIRTUAL TERMINAL Moneris Solutions
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
PCI Compliance : Whys and wherefores
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
MARTA’s Road to PCI Compliance
Ski Clubs and E-Commerce
Presented by: Jeff Soukup
Presentation transcript:

UCSB Credit Card Processing and PCI Compliance Sandra Featherson Associate Director of Controls Campus Credit Card Coordinator May 2010

Agenda Campus Credit Card Process Overview PCI Compliance Terminology Approval/Acceptance Process Policy and Procedures PCI Compliance Department Responsibilities Questions

Credit Card Terminology Acquiring Bank: The bank or financial institution that holds the merchant’s bank account that is used for collecting the proceeds for credit card processing. UCSB: Bank of America Merchant Services Processor: Handles the posting of transactions for authorization, clearing and settlement UCSB: First Data Merchant Services (FDMS) Gateway: Allows merchants to electronically submit payment transactions UCSB: Authorize.net or Cybersource PCI DSS: Payment Card Industry Data Security Standard

Credit Card Approval Process Meeting with Campus Credit Card Coordinator Discuss needs, policies, fees, security, internal controls, vendors and reconciliation process Potential issues include UBIT, or activities not approved by the Rate and Recharge Committee Letter to Chancellor Routed through Accounting – Campus Credit Card Coordinator

Credit Card Acceptance Process Review of Potential Vendors Evaluate PCI and/or PA DSS Compliance Establish Appropriate Merchant/Gateway Accounts and User Access Establishment of Clearing account and possible Revenue accounts with General Accounting

Campus Policy and Procedures UC Business and Finance Bulletin, BUS-49, Policy for Cash and Cash Equivalents Received (http://www.ucop.edu/ucophome/policies/bfb/bus49.html) Outlines UC Policy for Acceptance of Cash, Cash Equivalents, and Credit/Debit Cards Department needs to ensure secure storage and protection of sensitive data, and/or personal data (SB 1386)

Credit Card Models Storing the Credit Card information – build/buy a solution that collects credit card information, and sends to processor for payment Click to Pay – Build/buy a solution, collect demographic information, and then transfer to a Gateway for collection of payment information and processing 3rd Party Vendor

Merchant Accounts Merchant Accounts are requested by Campus Credit Card Coordinator Separate merchant accounts are required for web/ecommerce and retail/card present transactions

Gateway Providers UC contracts with Authorize.net and Cybersource Accounts are setup by Accounting Department needs technical support to integrate the Gateway with their web page

Credit Card Fees Fees to Accept Credit Cards Gateway Fees Processor Fee: Charged and collected by FDMS Access & Assessments: Collected by FDMS and forwarded to VISA & Mastercard Interchange: Collected by FDMS and forwarded to the bank that issued the credit card Gateway Fees Usually charged by month and per transaction

Gateway Example

3rd Party Vendors Vendors that provide a service, such as selling tickets or advertising, and that will be accepting credit cards on behalf of the University (UC Regents)

Using 3rd Party Vendors Must be PCI Compliant and/or PA DSS Compliant depending on situation Must allow use of the University merchant account Must be certified to the FDMS “North” platform All contracts for 3rd Party Vendors must be reviewed at the campus level, and then approved by UC Office of the President

Vendor Contracts May require additional review by Audit and Advisory Services, the campus Policy Coordinator, and campus counsel The UC Data Security and IT Security language will need to be incorporated Other issues include late fees and automatic renewal options

UC Agreements and Policies UC has negotiated contracts with Authorize.net, Cybersource and others BUS 49 mandates use of those contracts Use of 3rd party vendors requires a full review of the contract Exception process requires letter from Campus Credit Card Coordinator and Controller; has to be approved by UCOP

Use of University Logo Can I post a credit card logo on a University Web page? Yes. Where? On the Web page that lists payment options, as near to the purchase transaction as possible.

Use of University Logo NEVER post a vendor’s or credit card’s name or logo on your department’s main Web page. For more information on acknowledging, advertising, or sponsors see http://www.policy.ucsb.edu/policies/policy-docs/advertising-guide.pdf

Use of Vendor Logo If you post a credit card logo, you must have permission (a written agreement) with the credit card company to post their copyrighted mark. If you post a credit card logo that links to the credit company, you must have a “Terms of Use” link on either your department’s main Web page or on the page on which the logo/link appears.

Use of Vendor Logo For “Terms of Use” see: http://www.policy.ucsb.edu/terms_of_use/

Use of University Name The University’s name or “brand” is teaching, research, and public service. The University’s name is not for endorsing, advertising, or promoting commercial companies, products, or services. If a credit card company or vendor wants to use the University’s name, they must obtain written approval from the University’s delegated authority. Contact policy@ucsb.edu.

Reconciliation Process Based on the Bank of America statement, Accounting clears the UCSB bank account by crediting for the deposits/debiting for the fees associated with credit cards on the campus. Accounting e-mails to the department the Bank of America merchant statement on the first business day of the month.

Reconciliation Process Accounting debits the department/merchant’s clearing account for the deposits and credits the department/merchant’s clearing account for the fees.

Reconciliation Process The department debits their clearing account, and credits the appropriate department account for the income. The department credits their clearing account, and debits the appropriate department account for the fees.

Reconciliation Process The department should reconcile the transactions between the Bank of America statement, the First Data Merchant Services statement and any internal records, such as 3rd party vendor reports, or reports from Authorize.net, etc. Approval of balance sheet reconciliation must be done in the online GL, due to SAS 112 requirements.

Credit Card Processing - Retail Card Present Examples Industry: Department store UCSB: Bookstore Merchant has a POS system, and some type of terminal device to swipe cards

Credit Card Processing - Ecommerce Card Not Present Examples Industry: Amazon.com UCSB: Conference Registrations Merchant has a website and sells goods or services. Often utilizes the “Click to Pay” model.

Credit Card Processing - Ecommerce Becoming an Ecommerce Merchant (not using a 3rd party vendor) Approval from the Chancellor Complete PCI Questionnaire Establish a new merchant account with CPS Choose Gateway and establish account Establish clearing/balance sheet account within Accounting

PCI Data Security Standards What is it? SAQs Security Scanning Penetration Testing Trustkeeper Virtual Terminals

Payment Card Industry Data Security Standards Developed by the major Card brands to reduce the amount of fraud PCI now overseen by the Payment Card Industry Security Standards Council Holds the merchants accountable by requiring specific levels of security

Payment Card Industry Compliance New PCI Data Security Standards, v 1.2, eff. October 1, 2008 All merchants required to complete a “Self Assessment Questionnaire (SAQ)”. Four SAQ categories, A, B, C, or D UC Office of the President requires all campuses to be compliant

PCI Core Standards Build and Maintain a Secure Network Requirement 1: Install and maintain a firewall configuration to protect cardholder data Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters

PCI Core Standards Protect Cardholder Data Requirement 3: Protect stored cardholder data Requirement 4: Encrypt transmission of cardholder data across open, public networks Maintain a Vulnerability Management Program Requirement 5: Use and regularly update anti-virus software Requirement 6: Develop and maintain secure systems and applications

PCI Core Standards Implement Strong Access Control Measures Requirement 7: Restrict access to cardholder data by business need-to-know Requirement 8: Assign a unique ID to each person with computer access Requirement 9: Restrict physical access to cardholder data

PCI Core Standards Regularly Monitor and Test Networks Requirement 10: Track and monitor all access to network resources and cardholder data Requirement 11: Regularly test security systems and processes Maintain an Information Security Policy Requirement 12: Maintain a policy that addresses information security

Self Assessment Questionnaires SAQ Validation Type Description SAQ 1 Card-not-present (e-commerce or mail/telephone-order) merchants, all cardholder data functions outsourced This would not apply to 100% face to face merchants A 2 Imprint-only merchants with no electronic cardholder data storage B 3 Stand-alone terminal merchants, no electronic cardholder data storage 4 Merchants with POS systems connected to the Internet, no electronic cardholder data storage C 5 All other merchants (not included in Types 1-4 above) and all service providers defined by a payment brand as eligible to complete an SAQ D

Security Scanning PCI Security Scans are scans conducted over the Internet by an ASV Scans help identify vulnerabilities and misconfigurations Scan results provide valuable information PCI Security Scans may apply to all merchants with Internet-facing IP addresses Even if an entity does not offer Internet-based transactions, other services may make systems Internet accessible The PCI DSS requires all Internet-facing IP addresses to be scanned for vulnerabilities In some instances, companies may have a large number of IP addresses available In these cases, scan vendors can help merchants define the appropriate scope of the scan required In general, the following segmentation methods can be used to reduce the scope of the Security Scan Providing physical segmentation between the segment handling cardholder data and other segments Employing appropriate logical segmentation Merchants have the ultimate responsibility for defining the scope of their PCI Security Scan, though they may seek expertise from ASVs

Penetration Testing Required for all SAQ “D” merchants Can be done in-house or by an Approved Scanning Vendor (ASV)

Trustkeeper Trustwave provides a way to monitor and track PCI Compliance. All UCSB Merchants are registered in the program, Trustkeeper. Annual fee is recharged to departments. www.trustkeeper.net

Virtual Terminals First Data has indicated that merchants using Virtual Terminals functions of gateways, such as Authorize.net or Cybersource will be required to complete SAQ C.

Data Security Do not accept credit card information via fax or email. All authorization forms that include customer account information should be stored securely Restrict access to cardholder data Develop/maintain security policies

New Services and Equipment Conference Registrations Regonline PCI Compliant, Uses UCSB Merchant Account Reporting Access to Clientline Reports New Variety of Terminals

Suspected Breach of Credit Card Data Notify Campus Credit Card Coordinator, Sandra Featherson, x7667 Notify Campus Chief Information Security Officer, Karl Heins, x8843

Consequences of Breach of Credit Card Data Fines levied by Card Brands and/or acquiring Bank As example, fines could be up to $500K just from Visa if found not compliant at time of breach.

Next Steps Campus PCI Work Group SAQ Review for Merchants Trustkeeper Annual Update Site Visits to Merchants Credit Card Web Page

Department Responsibilities Understand the Credit Card process Understand and implement BUS 49 procedures and guidelines Maintain PCI Compliance Monthly reconciliation of accounts

Questions?