Presentation is loading. Please wait.

Presentation is loading. Please wait.

Payment card industry data security standards

Similar presentations


Presentation on theme: "Payment card industry data security standards"— Presentation transcript:

1 Payment card industry data security standards
Protecting your college via information technology security

2 What is pci-dss? The Payment Card Industry Data Security Standard (PCI DSS) was developed to encourage and enhance cardholder data security and facilitate the broad adoption of consistent data security measures globally. PCI DSS provides a baseline of technical and operational requirements designed to protect account data. PCI DSS applies to all entities involved in payment card processing of- American Express, Discover, JCB, MasterCard and Visa.

3 Why is pci-dss important?
PCI-DSS Standard is necessary to provide an active data security process to protect all cardholder data that is received by the college through the different channels of MOTO, Ecommerce and in-person. This includes monitoring, detecting and protecting the data and following proper security guidelines. PCI-DSS applies to ANY organization, regardless of size or number of transactions, that accepts, transmits or stores any cardholder data. Adherence to the PCI-DSS is a requirement of the Washington State’s contract for Merchant Bankcard Services with Bank of America Merchant Services (BAMS).

4 What role does i.t. play? The IT department at the college has a significant role in the PCI-DSS compliance as IT is often responsible for areas: Build and Maintain a Secure Network (i.e. firewalls, web security) Protect Cardholder Data (i.e. encrypt transmission of data across networks) Maintain a Vulnerability Management Program (i.e. anti-virus checks) Implement Strong Access Control Measures (i.e. restrict access to cardholder data) Regularly Monitor and Test Networks (i.e. testing all networks) Maintain an Information Security Policy (i.e. contribute to personnel security policies)

5 What role does business finance play?
The Business Finance department at the college has a specific role in the PCI-DSS compliance as it is responsible for physical cardholder data and security: Protect Cardholder Data (i.e. protect and secure cardholder data) Implement Strong Access Control Measures (i.e. restrict public access to cardholder data) Maintain an Information Security Policy (i.e. contribute to personnel security policies)

6 How do you stay secure? PCI-DSS also requires quarterly external vulnerability scans to ensure safety of your internet-facing components and network. Vulnerability scans help identify weaker areas within the infrastructures and can provide valuable information that supports efficient patch management to help improve protection from data breaches at all levels. Approved Scan Vendors are listed at the PCI Security website.

7 What else do we need to know?
PCI-DSS Self-Assessment Compliance is required annually PCI-DSS is a college wide effort and yours may have dedicated PCI-DSS staffing to help complete and comply the SAQ’s A data breach can happen to anyone and its important to have secure measures in place to ensure no loss of customers, reputation or finances occur within your institution More information at

8 Mandy Kaplan Reach out anytime! 360-902-8906 mandy.kaplan@tre.wa.gov
Bankcard Services Coordinator Office of the State Treasurer


Download ppt "Payment card industry data security standards"

Similar presentations


Ads by Google