Presented by : Vivian Eberhardt, Supervisor Cash and Credit Operations

Slides:



Advertisements
Similar presentations
Surviving the PCI Self -Assessment James Placer, CISSP West Michigan Cisco Users Group Leadership Board.
Advertisements

National Bank of Dominica Ltd Merchant Seminar Facilitator: Janiere Frank Fraud & Compliance Analyst June 16, 2011.
Evolving Challenges of PCI Compliance Charlie Wood, PCI QSA, CRISC, CISA Principal, The Bonadio Group January 10, 2014.
Mobile Payment Security The Good, the Bad and the Ugly
PCI DSS for Retail Industry
UCSB Credit Card Processing and PCI Compliance
Navigating the New SAQs (Helping the 99% validate PCI compliance)
Complying With Payment Card Industry Data Security Standards (PCI DSS)
This refresher course will:
JEFF WILLIAMS INFORMATION SECURITY OFFICER CALIFORNIA STATE UNIVERSITY, SACRAMENTO Payment Card Industry Data Security Standard (PCI DSS) Compliance.
1 Credit card operation and the recent CardSystems incident HONG KONG MONETARY AUTHORITY 4 July 2005.
Credit Card Compliance Regulations Mandated by the Payment Card Industry Standards Council Accounting and Financial Services.
Credit / Debit Card Electronic Payments Industry Update on Convenience Fees, Utility Program and More! Presented by: Presented by: Michael Hodge, Regional.
PCI Compliance Forrest Walsh Director, Information Technology California Chamber of Commerce.
Data Security Standard. What Is PCI ? Who Does It Apply To ? Who Is Involved With the Compliance Process ? How We Can Stay Compliant ?
Visa Cemea Account Information Security (AIS) Programme
Beta Program for The Raiser’s Edge 7.86 PA DSS version Anne McDonell & Bucky Wall Corporate Readiness.
Credit Card Changes that Impact You! Changes to Accounts Receivable, Cash Receipts and Student Billing 7.77 Wanda Mahon & Bucky Wall Corporate Readiness.
Mitigating Risk and Improving Efficiency with Third Party Vendors – When is enough… enough? Paul Aries, RVP, Nelnet Business Solutions Ann Holland, Associate.
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Commonwealth of Massachusetts Office of the State Comptroller March 2007.
1 Consolidated Billing Project UCSB / UCLA Financial Systems Conversion Project Web Management, Hosting and Consulting Service February 8, 2011 CITI.
GPUG ® Summit 2011 November 8-11 Caesars Palace – Las Vegas, NV Payment Processing Online and Within Dynamics GP PCI Compliance and Secure Payment Processing.
Around the World, Around the Corner WorldPay for Small Business.
PCI's Changing Environment – “What You Need to Know & Why You Need To Know It.” Stephen Scott – PCI QSA, CISA, CISSP
Web Advisory Committee June 17,  Implementing E-commerce at UW  Current Status and Future Plans  PCI Data Security Standard  Questions.
WHAT IS A CREDIT CARD.. A credit card is part of a system of payments named after the small plastic card issued to users of the system. It is a card entitling.
Payment Card Industry Data Security Standard (PCI DSS) By Roni Argetsinger
MasterCard Site Data Protection Program Program Alignment.
An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.
DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program.
PCI DSS Readiness Presented By: Paul Grégoire, CISSP, QSA, PA-QSA
Payment Card PCI DSS Compliance SAQ-A Training Accounts Receivable Services, Controller’s Office 7/1/2012.
Identity Protection (Red Flag/PCI Compliance/SSN Remediation) SACUBO Fall Workshop Savannah, GA November 3, 2009.
Credit Card Merchant Training PCI Why Now? In October 2015, there will be a fraud liability shift that will affect merchants not able to accept.
Smart Payment Processing ™ Recur} Happen again. Persist. Return. Come back. Reappear. Come again.
Data Security and Payment Card Acceptance Presented by: Brian Ridder Senior Vice President First National September 10, 2009.
Payment Card PCI DSS Compliance SAQ-B Training Accounts Receivable Services, Controller’s Office 7/1/2012.
ThankQ Solutions Pty Ltd Tech Forum 2013 PCI Compliance.
e-Learning Module Credit/Debit Payment Card Acceptance and Security
1 Payment Card Industry (PCI) Security Standard Developed by the PCI Security Council formed by major card issuers: Visa, MasterCard, American Express,
PAYPAL PRESENTED TO:SIR ADNAN PRESENTED BY:SAIMA ASGHAR
Langara College PCI Awareness Training
Jon Bonham, CISA, QSA Director, ERC
Statewide Electronic Commerce Program North Carolina Office of the State Controller March 2016 Fayetteville Fort Bragg.
Credit Card. Basic Knowledge about Credit Card A Credit card is a plastic card that provides a cardholder electronic access to his / her bank account.
Standards in Use. EMV June 16Caribbean Electronic Payments LLC2.
By: Matt Winkeler.  PCI – Payment Card Industry  DSS – Data Security Standard  PAN – Primary Account Number.
A Brief Introduction Radiant Pay, a global provider of payment processing services to all kinds of business, Radiant Pay Services.
Washington State Auditor’s Office Third Party Receipting Presented to Washington Public Ports Association June 2016 Peg Bodin, CISA.
PCI COMPLIANCE & A/R AUTOMATION 101 Nodus Technologies, Inc.
Credit Card Compliance
PCI DSS Improve the Security of Your Ecommerce Environment
In the red bar you will see the place to enter your web portal credentials USER NAME = Your Student ID #
PCI-DSS Security Awareness
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Payment card industry data security standards
Internet Payment.
Session 11 Other Assurance Services
Switchover from Teledeposit to VIRTUAL TERMINAL Moneris Solutions
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
PCI Compliance : Whys and wherefores
Presentation Title Here
Presentation Title Here
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Event Management Registration System
Presentation Title Here
Electronic Services from a School's Perspective PESC Annual Conference on Standards in Higher Education Judith Nemerovski Flink Director of Student Financial.
Marketplace FAQs Treasury 5/1/2019.
Online Payment Options for Government
Event Management Registration System
Presentation transcript:

Presented by : Vivian Eberhardt, Supervisor Cash and Credit Operations Credit and Debit Card Acceptance Policy and eTransact Informational Session December 3, 2009 Presented by : Vivian Eberhardt, Supervisor Cash and Credit Operations

Agenda Credit and Debit Card Acceptance and Electronic Commerce Policy Why do we need a policy? What is PCI DSS? Highlights of the policy Plan for validating PCI DSS compliance Questions eTransact Overview of eTransact application Benefits of using eTransact How to get started Questions

Why do we need a policy? The use of credit and debit cards as the preferred method of payment continues to grow Schools and departments increasingly want the ability to accept credit and debit cards, particularly by utilizing e-commerce (internet based transactions) Policy provides the guidelines and expectations for schools and departments that accept credit and debit cards as a method of payment including the need for PCI DSS compliance

What is PCI DSS? Payment Card Industry Data Security Standard It is a “set of comprehensive requirements developed by American Express, Discover Financial Services, JCB International, MasterCard Worldwide and Visa Inc. Inc. International, to facilitate the adoption of consistent data security measures on a global basis.” www.pcisecuritystandards.org The PCI DSS is intended to help organizations proactively protect customer account data. The PCI DSS is managed by the PCI Security Standards Council. The Council will modify the PCI DSS as needed to keep pace with emerging payment security risks.

High Level Look at the PCI DSS Requirements At its core, the PCI DSS is really based on the best practices surrounding network security and information security that departments and schools already follow

High Level Look at the SAQs Self-assessment questionnaire – required annually 4 different SAQs, your business process will determine which SAQ you complete A – 13 questions, 2 pages B – 26 questions, 4 pages C – 41 questions, 8 pages D – 222 questions, 21 pages

Policy Highlights Each school or department is responsible for policy compliance. A main contact responsible for compliance must sign the policy acknowledgement form and return to Cash and Credit Operations Merchant ID numbers and/or electronic commerce capabilities must be obtained from Cash and Credit Operations. eTransact is the preferred method of processing electronic commerce transactions Only the Controller’s Office can authorize the use of a convenience fee. The University does not accept credit or debit cards for tuition payments

Policy Highlights (cont.) Complete annual PCI DSS questionnaire (SAQ) Develop remediation plans for any compliance issues Background checks for employees functioning as cashiers with access to one card number at a time while facilitating a transaction is a recommendation only Background checks are required for employees with access to multiple card account numbers at one time Review third party contracts for PCI DSS compliance Report potential security breaches according to the Security Breach Response referenced in the policy Read and enforce the twelve requirements of the PCI DSS

Plan for PCI DSS compliance Finalized credit and debit card acceptance and e-commerce policy Selected an approved scanning vendor (ASV) to perform required quarterly network scans (Coalfire) Selected vendor for eTransact (CASHNet) In 2010, we will require campus merchants to provide us with completed SAQs Once, we have completed SAQs and quarterly scans, we will submit to our merchant bank to validate compliance Questions?

eTransact www.wustl.edu/etransact

eTransact eTransact is the preferred method of electronic commerce at the University. We have partnered with a PCI DSS compliant third party vendor to process credit and debit card transactions for the University. Public Affairs has created a website for eTransact that can provide information to schools and departments as well as to customers. www.wustl.edu/etransact

Benefits of eTransact Transactions processed through eTransact do not require receipt vouchers to be completed. There is a direct feed to AIS overnight to post the income to your general ledger account Storefronts can be setup quickly with little use of your technology resources Reporting tools, report groups, customizable pages Unlimited license for storefronts and checkouts With PayPal or Verisign there is a product and monthly cost Fees are currently around 2% www.wustl.edu/etransact

Benefits of eTransact (cont.) No monthly fee or cost to activate - normal credit card fees still apply Two different types of applications possible Storefront – website/application/form hosted on third party site Checkout – website/application/form hosted on Washington University servers, but customer passed to third party to enter credit card data Helps to achieve PCI DSS compliance by limiting the scope of PCI, keeping sensitive data off WU networks, and not storing cardholder data Great for departments without a web presence or with limited technology resources Reports can be delivered to a report group. Reports are available without having to login to the system www.wustl.edu/etransact

How to get started Read the Credit and Debit Card Acceptance & Electronic Commerce Policy Your department’s business manager (or equivalent) will be responsible for ensuring compliance with the policy and compliance with PCI DSS requirements The business manager (or equivalent) must sign the acknowledgement at the end of the Credit Card Acceptance and Electronic Commerce Policy indicating their understanding of the requirements Complete the application for merchant ID (PDF) found at http://www.cashandcredit.wustl.edu/campuscommerce.html and return to Cash and Credit Operations – Campus Box 1147

Examples and Current Status Ten departments live with eTransact – five storefront and five checkout Five departments under construction Cashiering module is the next phase we will consider. This will allow similar processing only for point of sale machines as opposed to electronic commerce www.wustl.edu/etransact Questions?