University at Buffalo logo
Computer Security Home > Payment Card Industry Compliance Information

Quick Links

PCI Data Security Standard (DSS)
PCI Self Assessment
Questionnaire

PCI Security Scanning Procedures
UBlearns PCI Tutorial
& Assessment

Step-By-Step Instructions for Accessing the PCI Tutorial


UB Financial Services
Credit/Debit Card
Merchant Requirments

UB Policy for the
Protection of Regulated
Private Data

Standards for Securing Regulated Private Data

PCI DSS News

Hot Topics

Basic Cybersecurity and Online Safety Tips for College Students (StaySafeOnline.org)

Would You Send This Postcard in the Mail? Think Twice About Sending Private Info in E-mail

Cyber Security Channel (YouTube)

SANS Webcasts -- Free Live Web Broadcasts on Security Topics

Critical Alerts

Current UB Phishing Alerts

US-CERT Current High Impact Security Incidents

Subscribe to
US-CERT RSS Feed
RSS fee button

Resources
Security News

UB_Secure Launched

System Updates

Microsoft

Apple

Best Practices

Facebook Privacy & Security Guide

Identity Theft: How to Freeze Your Credit Report

Top 10 Ways to Lock Down Your Data

Important Links

UB IT Policies

FTC Identity Theft Site

OnGuard Online

StaySafe Online

National Center for Missing and Exploited Children

Share / Bookmark

 
Share on FaceBook
Tweet on Twitter Bookmark on Delicious

 

 

For questions & suggestions about this Web page, please contact the IT Web group

Payment Card Industry Compliance Information

Compliance Requirements for Departments Processing Credit Cards
How Can YOU Protect Cardholder Data?


Introduction to Payment Card Industry Standards and Compliance

The Payment Card Industry Data Security Standard (PCI DSS) version 1.1 is a set of comprehensive requirements for credit card account data security, developed by a council, including American Express, Discover Financial Services, JCB International, MasterCard Worldwide, and Visa, Inc., to help facilitate the broad adoption of consistent data security measures on a global basis.

The PCI DSS security standard includes requirements for security management, policies, procedures, network architecture, software design and other critical protective measures. This comprehensive standard is intended to help organizations proactively protect customer account data.

PCI Data Security rules change over time. Version 1.1 was adopted in October 2006. Future rules will be using a "Do NOT Store" model, and, therefore, our general security recommendations to units is that they do NOT store ANY sensitive Cardholder Data.

The UB Financial Services Office and the Information Security Officer (ISO) work with departments and schools that accept, process, store, and transmit credit card data to ensure that all merchant IDs at UB are in compliance with PCI DSS. PCI standards apply to all types of payments, including in-person, mail, telephone, and Web transactions. UB is committed to maintaining the security of customer information, including payment cardholder number, name, expiration date, and verification number, and follows best practices for protecting payment card information.


Compliance Requirements for Departments Processing Credit Cards

UB departments processing credit cards must comply with the following requirements:


How can YOU protect cardholder data?

Paper Records
If you use Payment Card readers that transmit and receive Cardholder Data via telephone lines and/or store Cardholder Data on paper, comply with the following requirements:


Payment Card Processing with Computers