Educause Security Discussion mailing list archives
Re: PCI compliance question
From: Joel Rosenblatt <joel () COLUMBIA EDU>
Date: Thu, 8 Jul 2010 15:10:23 -0400
Still not the point .. the system does not take credit cards .. it takes One Cards --- it would be treated as an invalid transaction and ignored by the system. If your not accepting Credit Cards, then you can't be fined by PCI. Joel --On Thursday, July 08, 2010 3:04 PM -0400 Michael Benedetto <mbenedetto () amnh org> wrote:
The question would be whether or not those swipes of an invalid card on your university "one card" system cause that data to be stored on your server or if the server discards any invalid swipe data. If your system stores my credit card data even though my credit card information is invalid in terms of your "one card" system, then your one card system is therefore storing credit card data and would therefore be in scope. If the one card system drops the invalid card data without storing it, you should be ok. Mike Benedetto American Museum of Natural History -----Original Message----- From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Joel Rosenblatt Sent: Thursday, July 08, 2010 2:58 PM To: SECURITY () LISTSERV EDUCAUSE EDU Subject: Re: [SECURITY] PCI compliance question I am not a PCI expert, but I have been up to my eye balls in PCI stuff for a while :-) If you are not accepting CC, then the fact that the miss guided person sticks his card in your device does not put that device in scope for PCI. If someone were to swipe their Visa card in your controlled access door swipes, and this were the case, then every door on your campus would suddenly become in scope for PCI. The ultimate responsibility for PCI belongs to the organization that owns the MID for the account that will receive the income from that transaction - since there is no MID (Merchant ID) attached to your vending machines, there can be no PCI compliance. In my opinion, I believe, and any other disclaimer :-) My 2 cents Joel Rosenblatt Joel Rosenblatt, Manager Network & Computer Security Columbia Information Security Office (CISO) Columbia University, 612 W 115th Street, NY, NY 10025 / 212 854 3033 http://www.columbia.edu/~joel --On Thursday, July 08, 2010 2:46 PM -0400 "Smith, Bob" <smithrj () LONGWOOD EDU> wrote:We are struggling with a PCI compliance issue and have been asked to querythis list. We have vending machines (drink, snack, laundry, etc.) on our networkthat are being setup for use with our university "one card" system. Thereaders on these machines will transmit and process our cards just fine. However,when someone uses a CC it is transmitted to the card system/server, butthe system ignores it and does not process the transaction.The big question: are the vending machines considered in-scope for PCI?If so, that means a lot of other things will be too.Thanks. Bob Smith AVP IITS & Information Security Officer Longwood UniversityJoel Rosenblatt, Manager Network & Computer Security Columbia Information Security Office (CISO) Columbia University, 612 W 115th Street, NY, NY 10025 / 212 854 3033 http://www.columbia.edu/~joel
Joel Rosenblatt, Manager Network & Computer Security Columbia Information Security Office (CISO) Columbia University, 612 W 115th Street, NY, NY 10025 / 212 854 3033 http://www.columbia.edu/~joel
Current thread:
- Re: PCI compliance question, (continued)
- Re: PCI compliance question Joel Rosenblatt (Jul 08)
- Re: PCI compliance question Sarazen, Daniel (Jul 08)
- Re: PCI compliance question Joel Rosenblatt (Jul 08)
- Re: PCI compliance question Kevin Hayes (Jul 08)
- Re: PCI compliance question Eric C. Lukens (Jul 08)
- Re: PCI compliance question Jeff Kell (Jul 08)
- Re: PCI compliance question Joel Rosenblatt (Jul 08)
- Re: PCI compliance question Jon Hanny (Jul 08)
- Re: PCI compliance question Marley, Tim (Jul 08)
- Re: PCI compliance question Joel Rosenblatt (Jul 08)
- Re: PCI compliance question Paul Kendall (Jul 09)
- Re: PCI compliance question Joel Rosenblatt (Jul 09)
- Re: PCI compliance question Kelley Bogart (Jul 08)