Blink Home > Finance > Accepting Credit Cards: How to Comply with Data Security Standards
Accepting Credit Cards: How to Comply with Data Security Standards  
 
Summary: If your department accepts credit cards for goods or services, learn about data security requirements you must follow.
Requirement Action to take
Comply with general guidelines.

Note: You also need to read and understand Guidelines for UCSD Departments Accepting Credit Cards and Implementation Guide for UCSD Departments Accepting Credit Cards.

UCSD as a whole must comply with the Payment Card Industry (PCI) data security standard. See details at Visa's Web site.
  • UCSD, or any third-party processors (TPP) or data storage entities (DSEs) that process, store, or transmit cardholder account data on behalf of UCSD, must follow PCI data security standards.
  • This requirement also applies to any computer connected to the UCSD network that has an outward-facing IP address.
  • Never store complete credit card information on a University system.
Annual PCI compliance certification

Departments accepting credit cards must be in compliance with the Payment Card Industry Data Security Standards (PCI).

PCI compliance is mandatory for all units accepting credit cards (merchants). Periodically, merchants are required to ensure they have adequate network security related to credit card processing and are responsibly protecting personal credit card information at all times. All compliance certifications are facilitated through Ambiron Trust Wave (ATW), which is under contract with UC for PCI certification support at all UC campuses. Merchants authorized to accept credit card payments are pre-registered at ATW. An annual $59 ATW charge is passed on to the department.


  • Terminal based merchants: These are merchants that do not store credit card data in any form (paper, or electronic). They operate via dial-up terminals or Internet secured processing through the payment gateway (Authorize.net). Terminals, computers, and other hardware resources must be physically isolated and accessible only to authorized personnel. To be certified by ATW, the department must successfully complete a self-assessment PCI questionnaire at ATW's Web site. ATW contacts each merchant to provide guidelines to access the questionnaire.
  • Full scan merchants: There are more strict — and costly — requirements for merchants operating an internal database or system (Web application, mail system, point of sale, file server, etc.) that collects, stores and transmits credit card data; or merchants operating outside of UCSD's computer networks. These merchants are required to complete a self-assessment PCI questionnaire, and periodic external electronic scanning of their systems is conducted by ATW.

See current PCI security requirements (PCI DSS, version 1.1.) (PDF).

Follow these University policies. In addition to industry requirements, your department must follow these University policies when accepting credit cards:


Questions? Contact Armando Carlsson, (858) 822-0247.



  Print
Print
this page
  Email
Share
this page
  Add to MyBlink
Save
this link
  Get notified when this page is updated
Notify
on change
  Add a sticky note to this page
Add
a note
 
Get what you wanted?    yes   no   Comments.


Last reviewed/updated on July 04, 2007 (see more info)
Blink A-Z Index:   0-9  A B C D E F G H  I  J K L M N O P Q R S T U V W X Y Z 


Blink Home  Site Map  Help  Accessibility Tips  Privacy Statement  Content Manager  RSS Feed 


Copyright ©2008 Regents of the University of California. All rights reserved.
Official Web Page of the University of California, San Diego

Blink version 1.7 12-17/2007 Blink Usability Group