Educause Security Discussion mailing list archives

Re: PCI compliance question


From: "Barrera, Connie" <clbarrera () MIAMI EDU>
Date: Thu, 8 Jul 2010 14:51:27 -0400

It is my understanding that vending machines are definitely part of your in-scope devices, especially based on the fact 
that they are connected to your LAN.

Good luck with this.


Connie Barrera, MCSE, CCNA, CCM, CISSP
University of Miami
Director of Information Security and Compliance
Gables One Tower 11th Floor, Suite 1100F
1320 S Dixie Hwy
Coral Gables, FL 33146-2500
O&F:  305-284-2773
connie () miami edu<mailto:connie () miami edu>



From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Smith, 
Bob
Sent: Thursday, July 08, 2010 2:47 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] PCI compliance question

We are struggling with a PCI compliance issue and have been asked to query this list.  We have vending machines (drink, 
snack, laundry, etc.) on our network that are being setup for use with our university "one card" system.  The readers 
on these machines will transmit and process our cards just fine.  However, when someone uses a CC it is transmitted to 
the card system/server, but the system ignores it and does not process the transaction.

The big question:  are the vending machines considered in-scope for PCI?  If so, that means a lot of other things will 
be too.

Thanks.

Bob Smith
AVP IITS & Information Security Officer
Longwood University


Current thread: