Educause Security Discussion mailing list archives

Re: PCI DSS Review - 40 Hours?


From: Rich Graves <rgraves () CARLETON EDU>
Date: Tue, 24 Apr 2012 14:21:56 -0500

It depends. 

Brandeis has a policy that cardholder data must not be stored, transmitted, or processed on University systems. Given 
recent legislation in Massachusetts, this is a good plan. 

PCI has made the full ROC questionnaire available. You ought to be able to cover the relevant parts in 40 hours. If you 
find that the outsourcing policy is not effectively documented or enforced, then fail the audit and start over with an 
assessment, as other commenters in this thread have assumed; but if the policy holds, then it's mostly an exercise of 
ticking off boxes for policy and awareness training. 

Current thread: