Educause Security Discussion mailing list archives

PCI DSS compliance challenges


From: "Basgen, Brian" <bbasgen () PIMA EDU>
Date: Wed, 10 Jun 2009 08:35:08 -0700

Hi Everyone,

 Our Finance department has been considering a new model of handling credit cards on our campuses that would involve 
cashiering stations that track credit card data through a desktop PC and send it over the internet.

 The interesting challenge for this model is complying with the PCI DSS. Our perception is that these kinds of 
deployments are becoming fairly common in higher-ed, so it would be interesting to hear the experiences of some other 
institutions with DSS. Are you segregating card holder data networks? What IT cost was incurred to setup a compliant 
environment for deployments your institution has done?

 I welcome any responses on or off list. Thanks! :)

~~~~~~~~~~~~~~~~~~
Brian Basgen
Information Security
Pima Community College
Office: 520-206-4873

Current thread: