Office of Business Operations

Cashiering | Payment Card Industry (PCI) Security Standards

The PCI Security Standards Council’s was established in 2005 by American Express, Discover Financial Services, JCB International, MasterCard Worldwide, and Visa, Inc. The council’s mission is to promote credit card data security through education and awareness of the PCI Security Standards.

These standards are identified as the PCI DSS or Payment Card Industry Data Security Standards (PCI DSS), a set of comprehensive requirements to ensure data security. Areas of focus include: security management, policies, procedures, network architecture, software design, and other critical security areas. These requirements are designed to help organizations proactively protect customer account data.

PCI Data Security Standards:

 

GoalsRequirements
Build and Maintain a Secure Network1: Install and maintain a firewall configuration to protect cardholder data
2: Do not use vendor-supplied defaults for system passwords and other security parameters
Protect Cardholder Data3: Protect stored cardholder data
4: Encrypt transmission of cardholder data across open, public networks
Maintain a Vulnerability Management Program5: Use and regularly update anti-virus software
6: Develop and maintain secure systems and applications
Implement Strong Access Control Measures7: Restrict access to cardholder data by business need-to-know
8: Assign a unique ID to each person with computer access
9: Restrict physical access to cardholder data
Regularly Monitor and Test Networks10: Track and monitor all access to network resources and cardholder data
11: Regularly test security systems and processes
Maintain an Information Security Policy12: Maintain a policy that addresses information security