Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Best Practices.

Slides:



Advertisements
Similar presentations
Weighing the Risks and Benefits of Online Financial Transactions
Advertisements

Surviving the PCI Self -Assessment James Placer, CISSP West Michigan Cisco Users Group Leadership Board.
Payment Card Industry Data Security Standard AAFA ISC/SCLC Fall 08.
Payment Card Industry Data Security Standard Tom Davis and Chad Marcum Indiana University.
UCSB Credit Card Processing and PCI Compliance
PCI Compliance: The Gateway to Paradise PCI Compliance: The Gateway to Paradise.
Navigating the New SAQs (Helping the 99% validate PCI compliance)
Complying With Payment Card Industry Data Security Standards (PCI DSS)
2014 PCI DSS Meeting OSU Business Affairs Process Improvement Team (PIT) Robin Whitlock & Dan Hough 10/28/2014.
JEFF WILLIAMS INFORMATION SECURITY OFFICER CALIFORNIA STATE UNIVERSITY, SACRAMENTO Payment Card Industry Data Security Standard (PCI DSS) Compliance.
GPUG ® Summit 2011 November 8-11 Caesars Palace – Las Vegas, NV Advantages of having integrated ePayments and eCommerce By Fauwaz Hussain Nodus Technologies.
Property of CampusGuard Compliance With The PCI DSS.
Centralizing Commerce for the Campus Community. Goals & Objectives Overview of contracted services Benefits for your member institutions Action Plan for.
Creating a Winning E-Business Second Edition
Creating a Winning E-Business Second Edition Operating Your E-Business Chapter 5.
Online Banking Fraud Prevention Recommendations and Best Practices This document provides you with fraud prevention best practices that every employee.
PCI Compliance Forrest Walsh Director, Information Technology California Chamber of Commerce.
Data Security Standard. What Is PCI ? Who Does It Apply To ? Who Is Involved With the Compliance Process ? How We Can Stay Compliant ?
Jeff Williams Information Security Officer CSU, Sacramento
Property of the University of Notre Dame Navigating the Regulatory Maze: Notre Dame’s PCI DSS Solution EDUCAUSE Midwest Regional Conference March 17, 2008.
Mitigating Risk and Improving Efficiency with Third Party Vendors – When is enough… enough? Paul Aries, RVP, Nelnet Business Solutions Ann Holland, Associate.
1 Goal is protection of sensitive data New Rice policy calls for protection of sensitive personally identifying information Confidential information includes:
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Commonwealth of Massachusetts Office of the State Comptroller March 2007.
GPUG ® Summit 2011 November 8-11 Caesars Palace – Las Vegas, NV Payment Processing Online and Within Dynamics GP PCI Compliance and Secure Payment Processing.
CSE 4482, 2009 Session 21 Personal Information Protection and Electronic Documents Act Payment Card Industry standard Web Trust Sys Trust.
Why Comply with PCI Security Standards?
Northern KY University Merchant Training
Disclaimer Copyright Michael Chapple and Jane Drews, This work is the intellectual property of the authors. Permission is granted for this material.
Web Advisory Committee June 17,  Implementing E-commerce at UW  Current Status and Future Plans  PCI Data Security Standard  Questions.
Payment Card Industry Data Security Standard (PCI DSS) By Roni Argetsinger
MasterCard Site Data Protection Program Program Alignment.
Electronic Payment Systems University of Palestine University of Palestine Eng. Wisam Zaqoot Eng. Wisam Zaqoot March 2010 March 2010 ITSS 4201 Internet.
PCI DSS Managed Service Solution October 18, 2011.
EDUCAUSE Security Conference Denver, Colorado April 10 to 12, 2006 Bob Beer Biggs Engineering 117 (419)
An Introduction to PCI Compliance. Data Breach Trends About PCI-SSC 12 Requirements of PCI-DSS Establishing Your Validation Level PCI Basics Benefits.
Teresa Macklin Information Security Officer 27 May, 2009 Campus-wide Information Security Activities.
PCI requirements in business language What can happen with the cardholder data?
DATE: 3/28/2014 GETTING STARTED WITH THE INTEGRITY EASY PCI PROGRAM Presenter : Integrity Payment Systems Title: Easy PCI Program.
PCI: As complicated as it sounds? Gerry Lawrence CTO
Credit Card Processing Gail “Montreal” Shoffey Keeler August 14, 2007.
1 The Networked Transaction Environment. 2 Blackboard’s Product Strategy Leading institutions are wiring their campuses to connect people and resources.
E-commerce Vocabulary Terms. E-commerce Buying and selling of goods, services, or information via World Wide Web, , or other pathways on the Internet.
E-commerce Vocabulary Terms By: Laura Kinchen. Buying and selling of goods, services, or information via World Wide Web, , or other pathways on the.
Introduction To Plastic Card Industry (PCI) Data Security Standards (DSS) April 28,2012 Cathy Pettis, SVP ICUL Service Corporation.
1 Capability Set - Detail. 2 Common Online Problems Desire to generate additional revenue –Must allow for guest deposits to student accounts –Need way.
Management Information Systems The Islamia University of Bahawalpur Delivered by: Tasawar Javed Lecture 17.
PCI Compliance: The Gateway to Paradise PCI Compliance: The Gateway to Paradise.
Data Security and Payment Card Acceptance Presented by: Brian Ridder Senior Vice President First National September 10, 2009.
Information Security 2013 Roadshow - PCI. Roadshow Outline  What IS PCI  Why we Care about PCI  What PCI Means to You and Me.
ThankQ Solutions Pty Ltd Tech Forum 2013 PCI Compliance.
1 Payment Card Industry (PCI) Security Standard Developed by the PCI Security Council formed by major card issuers: Visa, MasterCard, American Express,
BUSINESS CLARITY ™ PCI – The Pathway to Compliance.
Standards in Use. EMV June 16Caribbean Electronic Payments LLC2.
By: Matt Winkeler.  PCI – Payment Card Industry  DSS – Data Security Standard  PAN – Primary Account Number.
The Payment Card Industry Data Security Standard (PCI DSS) is a proprietary information security standard for organizations that handle branded credit.
PCI COMPLIANCE & A/R AUTOMATION 101 Nodus Technologies, Inc.
Payment Card Industry (PCI) Rules and Standards
Performing Risk Analysis and Testing: Outsource or In-house
PCI-DSS Security Awareness
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Payment card industry data security standards
Internet Payment.
Switchover from Teledeposit to VIRTUAL TERMINAL Moneris Solutions
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Connor Griesemer and Kevin Wu
Sage Programs Check Jeff Bryson November 10, 2018.
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Electronic Services from a School's Perspective PESC Annual Conference on Standards in Higher Education Judith Nemerovski Flink Director of Student Financial.
Presented by: Jeff Soukup
Online Payment Options for Government
Presentation transcript:

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Best Practices In Campus-wide eCommerce STRAIGHT TALK ON CAMPUS COMMERCE

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. TouchNet ●Established in 1989 ●Specializing in Self Service ●Serving Higher Education since 1993 ●Specializes in Higher Education 700 Users ●Partnerships: SunGard, Datatel, PeopleSoft ●Payment Card Industry (PCI) Certified ●Member of NACHA ●Foundation: Payment Gateway –Credit Card, ACH Engine, Debit Cards

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Agenda ●Common Practices in eCommerce ●Discuss Best Practices ●Payment Card Industry (PCI) Standards ●Summary ●Questions and Maybe Some Answers

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. What are Your Commerce Initiatives? ●Tickets ●T-shirts ●Tuition ●Textbooks ●Donations ●Event Registration ●Non-Credit Classes ●Athletics ●Central Stores ●ACH (Electronic Checks) ●Electronic Billing ●Camps ●Parking ●Cashiering ●Fundraising ●More…

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. eCommerce Is More Than Tuition ●Athletics: Game Tickets, Logo Wear ●Alumni: Donations, Events ●Theatre: Tickets, Fund Raising ●Bookstore: Books, Merchandise ●Admissions: Application Fees ●Parking: Permits, Fines

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Current Practices ●Multiple Payment Pages ●Multiple Security Burdens ●Disparate Systems ●Separate Reconciliation ●Rogue Processors ●Absence of a Central Administration

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Common Practice: Typical Campus

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Best Practice One Payment Engine for the Entire Enterprise –Control: Piece of Mind; PCI Compliance –Costs: Collective Volumes Reduces Costs –Efficiency: Managing multiple systems drains time and resources –Real-time Payment Processing –Brand Management

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Centralized Commerce Model

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Administrative Management

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Track Tender Types

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Best Practice Campus Commerce Management ●Common Infrastructure: Synch In-line and Online Channels ●Process Payments from a Variety of Departments and Systems ●Single & Recurring Payments ●Manage Processing and Reconciliation Costs ●Leverage Existing Business Applications ●Compliance Control: –PCI, FERPA, GLB, PABP, NACHA ●Central Accountancy: Integration with Finance Systems

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Simplifying Campus Commerce Single Gateway Secure Payment Processing Single Framework Needed Websites Store Existing Websites Pay

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. The “Mall” View The “Store” View Sample of School Shopping Site

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Integrating Payment Functionality to an Existing Web Site Existing Web Page Link out to a Secure Payment Page

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Best Practice Operations Centralized Control / Decentralized Management –Common Technical Environment –Reduces IT Overhead –Individual Departments Manage Online Presence –Able to serve existing web applications

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Best Practice Embrace PCI ●Understand the Requirements ●Face Reality: Your Merchants Have Issues ●Accept Responsibility: Form A Team ●Create eCommerce Policy ●Identify & Educate Campus Merchants ●Raise Awareness ●Set Requirements for Campus Merchants ●Budget (work into current projects)

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. PCI Merchant Levels Merchant Level 1 ●Any merchant-regardless of acceptance channel-processing over 6,000,000 transactions per year. ●Any merchant that has suffered a hack or an attack that resulted in an account data compromise. ●Any merchant that any of the Payment Card Brands, at their sole discretion, determines should meet the Level 1 merchant requirements to minimize risk to the respective card system. Merchant Level 2 Any merchant processing 150,000 to 6,000,000 e-commerce transactions per year. Merchant Level 3 Any merchant processing 20,000 to 150,000 e-commerce transactions per year. Merchant Level 4 Any merchant processing fewer than 20,000 e-commerce transactions per year, and all other merchants processing up to 6,000,000 transactions per year.

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Face Reality… “Your campus merchants have issues!” ●Single Location or Multiple Campuses ●Tens or Hundreds of Merchants ID’s ●Unknown online activity ●Multiple Payment Methods ●Multiple Banking/Processor Relationships ●Multiple Payment Gateways in use ●Little to no knowledge of PCI requirements

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Accept Responsibility: Form a Project Team ●Treasurer ●Controller ●Bursar ●IT Appoint a Team Leader

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Create eCommerce Policy ●If starting from scratch –Look for examples online –Ask your favorite listserv ●If one currently exist –Include PCI requirements

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Identify & Educate Campus Merchants ●Identify Merchants –Include Online and In-line Merchants –Across the entire enterprise  ERP Systems: SIS, Finance  Departments: Athletics, Alumni, Theatre, etc. ●Survey Merchants ●Google your “.edu” domain

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Raise Awareness ●Get the word out… - - Newsletters - Meetings - Advertisements - Broadcast ●Fear Factor - show them why...

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Why the Control? ● Two West Coast Universities – 178,000 former and current students, applicants and employees – 59,000 students, staff and faculty ● Three Northeast Schools – 2,100 students, alumni and professors – 120,000 individuals ● Two Southwest Universities – 5,000 International Students – 55,200 students, faculty and staff ● Two Southern Universities – 30,000 students, faculty and staff – 57,000 patrons of the Arts & Theater The Headlines! PCI - #1 ISSUE

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Source: Privacy Rights Clearinghouse, Feb. 15, 2005 through June 14, PCI - #1 ISSUE Why Should You Care?

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Merchant Liability for improper storage of credit card data ●If cardholder data is compromised, you may be subject to the following liabilities and fines associated with non- compliance: –Potential fines of up to $500,000 –All fraud losses incurred from the use of the compromised account numbers from the date of compromise forward –Cost of re-issuing cards associated with the compromise –Cost of any additional fraud prevention/detection activities required by the card associations (i.e. a forensic audit) or costs incurred by credit card issuers associated with the compromise –Average cost of rectifying breech = $2 Million - Ambrion TrustWave

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Design Enterprise Architecture ●Standardize – Build or Buy a Gateway as a foundation for campus commerce –Enterprise Payment Gateway –PCI Self Assessment or Certified Provider –Consolidate Acquiring Banks and Processors –Open to campus vendors i.e., Parking, Collections, Alumni, etc.

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Self Assessment Questionnaire ●Complete PCI Internal Assessment ●10 Pages (Microsoft Word format) ● ●12 Requirements

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. PCI Data Security Standards (often referred to as the “Digital Dozen”) 1Install and maintain a working firewall 2Do not use vendor-supplied default passwords 3Protect stored data 4Encrypt data sent across public networks 5Use and update anti-virus software 6Develop and maintain secure systems and applications

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. PCI Data Security Standards 7 Restrict access to data by “need to know” 8 Assign unique ID to each person with access 9 Restrict physical access to cardholder data 10 Track and monitor all access to network resources and cardholder data 11 Regularly test security systems and processes 12 Maintain a policy that addresses information security

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information.

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. What’s One More Certification? PCI - #1 ISSUE Payment Application Best Practices [PABP]

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Best Practices: Summary ●One Payment Engine for Enterprise ●Consolidate ALL Payments ●Control and Manage Costs ●PCI Preparedness ●Conduct Self Assessments ●Create Awareness ●Form a Team ●Educate Merchants ●Document, document, document

Straight Talk on Campus Commerce 2007 © 2007 TouchNet Information Systems, Inc. All rights reserved. TouchNet Confidential Information. Questions? Thank you! Dave Swan Regional Manager TouchNet Information Systems