Educause Security Discussion mailing list archives

Re: Merchant services credit card project


From: Willis Marti <wmarti () TAMU EDU>
Date: Mon, 27 Jun 2005 07:23:12 -0500

My understanding is in line with what you have expressed, but with
some extensions.  For example, if the processing system(s) interact
with a database or file server, and store transaction information on
it, then that server is included although it may be separated from
the processing gateway by a firewall.
 In my world, that server must be behind the firewall. Part of the
education process here has been making the business management side
understand all the systems actually involved. A few organizations have
decided to shut down their independent operation and go with a central
service provided by the application folk that can even let the individual
departments have their own "storefront". [Fortunately, we'd started that
even before the PCI requirement]
Cheers,
 Willis Marti
 Associate Director for Networking
 Computing & Information Services
 Texas A&M University

Current thread: