Section:
Effective: 12/13/2023
Supersedes: 11/09/2020
Next Review Date: 12/13/2026
Issuance Date: 12/13/2023
Issuing Office:  Business & Financial Services, General Accounting Division

Payment Card Processing and Compliance Policy

 
 
 

 

SCOPE

 

This policy applies to any person or entity that, on behalf of UC SanDiego, handles, processes, transmits, or stores Cardholder data (CHD) in aphysical or electronic format.  

 

POLICY SUMMARY

 

ThePayment Card Industry Security Standards Council (PCI SSC) maintains strictsecurity requirements to safeguard credit or debit payment CHD through mandatedPayment Card Industry Data Security Standards (PCI DSS).

 

Compliancewith PCI DSS is required by the PCI SSC and by University of CaliforniaBusiness and Finance Bulletin No. BUS-49, Policy for Cash and Cash EquivalentsReceived.

 

DEFINITIONS

 

Attestationof Scan Compliance (AOSC) - TheAttestation of Scan Compliance is an overall summary that shows whether thescan customer's infrastructure received a passing scan and met the scanvalidation requirement. An AOSC is part of the annual Payment Card Industry(PCI) report and is also done periodically throughout the year.

 

Cardholderdata (CHD)is any personally identifiable data associated with a payment cardholder.Examples include but are not limited to: account number, expiration date, cardtype, name, address, social security number, and Card Validation Code - athree-digit or four-digit value printed on the front or back of a payment cardreferred to as CAV, CVC, CVV, or CSC depending on the payment card brand.

 

Merchant refers to any UC SanDiego department or operating unit that has applied for and been approved toaccept credit/debit card payments for goods and/or services.

 

PaymentCardrefers to both credit and debit cards. This policy does not apply to the UC SanDiego P-card or corporate card programs.

 

PaymentCard Processing- The use of any application or device to process a credit/debit cardtransaction as payment for goods or services purchased from a Merchant.

 

PCIDSS -Payment Card Industry Data Security Standard.

 

PCISecurity Standards Council (PCI SSC) - The Security Standards Council definescredentials and qualifications for assessors and vendors and maintains thePCI-DSS.

 

QualifiedSecurity Assessor (QSA) - A companythat is an independent security organization certified by the PCI SecurityStandards Council to validate an entity&s adherence to PCI DSS.

 

QSA Employees areindividuals employed by a QSA that have satisfied and continue to satisfy allQSA Requirements.

 

PCISelf-Assessment Questionnaire (SAQ) - a questionnaire promulgated by the PCI,which Merchants use to demonstrate compliance to the PCI DSS and to the paymentprocessor.

 

UC SanDiego- UC San Diego campus, UC San Diego locations, and UC San Diego Health.

 

 

POLICY STATEMENT

 

It is in the best interests of, andoperationally vital for, UC San Diego and our customers to continuously complywith PCI DSS. 

This policy is structured to:

1.     Define requirements and responsibilitiesto establish and maintain a UC San Diego merchant account to process paymentcards and remain in compliance with PCI DSS.

UC SanDiego has a responsibility to our customers and payment card processors tocomply with the PCI DSS when processing payment card transactions.Non-compliance with PCI-DSS can result in serious consequences for UC SanDiego, including reputational damage, loss of customers, litigation, andfinancial costs.

 

Thepurpose of this policy is to:

 

1.     Ensureongoing compliance with PCI DSS and other applicable policies and standards,

 

2.     Establishthe governance structure for payment card processing and compliance activitiesat UC San Diego,

 

3.     Defineresponsibilities for payment card services to various UC San Diegoconstituents, and

 

4.     Providegeneral guidelines regarding the handling of CHD.

 

Alltechnical and operational system components involved in processing CHD aresubject to PCI DSS and to this policy. These include owned or leased software,hardware, computers and wired or wireless electronic devices.

 

 

RESPONSIBILITIES

 

The ViceChancellor - Chief Financial Officer (CFO) has overall PCI DSS complianceauthority for the UC San Diego. The CFO hereby delegates to the Controller the authorityto define responsibilities for payment card services to UC San Diegoconstituents.

 

UC SanDiego&s PCI DSS compliance is a consolidated attestation of compliance.Consequently, one Merchant who fails to meet PCI DSS requirements causes theentire institution to be out of compliance. Therefore, failure of any singleMerchant to maintain continuous PCI-DSS compliance will result in immediatecancellation of that merchant account to preserve and allow continuousoperations for other critical business functions dependent on payment cards.

 

1.    Cash& Merchant Services within BFS-Financial Operations Division:

 

a.      The UC SanDiego Payment Card Coordinator within Cash & Merchant Services isresponsible for initiating and overseeing the annual PCI DSS validation, makingappropriate revisions to this policy as needed, and coordinating anyremediation activities as required by PCI DSS or other applicable policies andstandards.

b.      The UC SanDiego Payment Card Coordinator is responsible for supporting and approvinginitial setup and ongoing administration of PCI DSS compliance for all UC SanDiego merchant accounts. Key responsibilities include approval of merchantapplications, facilitating procurement of credit card terminals and otherequipment, and operational liaison to UC San Diego&s third-party credit cardprocessing vendor, QSA, and forensics vendor.

 

c.      The UC SanDiego Payment Card Coordinator will certify overall UC San Diego PCI DSS complianceto the QSA on behalf of UC San Diego after individual Merchants successfullycomplete their PCI DSS attestations on or before the annual PCI DSScertification due date as established by Bank of America Merchant Services.

 

d.      The UC SanDiego Payment Card Coordinator will notify each Merchant with reasonable noticeto complete and submit the annual departmental PCI DSS assessment. Accurate andtimely completion of this assessment is the responsibility of the PCIDepartment Coordinator. The PCI Department Coordinator must complete the SAQannually, after remediation of a breach of data, or anytime a credit cardrelated system or process changes.

 

2.    InformationTechnology Services (ITS):

 

a.      Responsiblefor maintaining and disseminating security policies and procedures that addressPCI DSS requirements, establishing and testing UC San Diego&s infrastructureand network environment, and assisting the Payment Card Coordinator and UC SanDiego merchants in completing the technical sections of the annual SAQ. ITSwill work closely with the UC San Diego QSA to interpret PCI DSS requirementsand to communicate and facilitate overall security and technical compliancewith Merchants.

 

b.      Responsiblefor configuration and maintenance of centralized IT systems, facilitatingmerchant hardware and software configurations, and providing oversight of allcomputer systems and other IT resources to support compliance with PCI DSS andUC security requirements. ITS will manage and provide training and tools tolimit access to IT resources and CHD, and assist the Cash & MerchantServices Office and individual Merchants in completing the technical sectionsof the annual SAQ.

 

c.      ITS, shallprovide information technology sufficient to fully support enforcement of thispolicy. Additionally, ITS will support investigation conducted by a third-partyforensics vendor and remediation of any reported violations of this policy, andwill lead investigations about credit card security breaches with support fromUC San Diego&s on-call forensics contractor and may terminate access toprotected information of any users who fail to comply with the policy.

 

3.    Business& Financial Services Procurement & Contracts Division:

 

Is responsible for ensuringinclusion of appropriate PCI DSS requirements clauses in all vendor andexternal entity contracts to ensure assignment of accountability for thesepolicy requirements where PCI DSS applies for the goods or services beingacquired by UC San Diego or its agents. See the University&s Data Security andPrivacy Appendixaspart of the UC Systemwide Templates &Documents

 

4.    Merchants:

 

a.      Areresponsible for ensuring that all business processes, IT environments andassociated systems for accepting, processing, retaining, and disposing of CHDcomply with PCI DSS.

b.      Areresponsible for performing an annual SAQ in partnership with Cash &Merchant Services and ITS. Departmental employees who handle CHD must attend aUC San Diego annual security awareness & training program and sign thePayment Card Merchant Compliance Statement (Appendix A). Merchant accountholders who fail to comply are subject to:

 

i.      Any finesimposed by the payment card industry;

 

ii.     Any additional monetary costs associatedwith remediation, assessment, forensic analysis or legal fees; and

 

iii.    Suspension of the merchant account.

 

c.      Who arerequired by PCI DSS to conduct periodic vulnerability scans shall download,review and retain the Attestation of Scan Compliance (AOSC) as evidence of scanpass and immediately apply resolution processes to bring the Merchantenvironment back into compliance if the AOSC fails. Only if required by PCIrules for the specific method of processing.

 

d.      Arerequired to conduct penetration testing as defined by PCI DSS. The Merchantwill complete relevant components of the rules of engagement and/or penetrationtest charter requirements by the due dates provided by the QSA. Additionally,affected Merchants will perform due diligence checks on the inclusion/exclusionlists, ensuring these lists are accurate and properly vetted. Anyvulnerabilities identified by the penetration tests will be reviewed forfurther action. Absence of compensating controls or those deemed inadequate,will require the Merchant to patch the vulnerability in a timely fashion.Evidence of remediation will be made available to the penetration testers andis subject to independent verification. Only if required by PCI rules for thespecific method of processing.

 

e.      Arerequired to adopt PCI DSS validated Point-to-Point Encryption Technologies(P2PE). UC San Diego&s preferred P2PE solution is provided by BluefinPayment Systems. And with the Cash& Merchant Services Office approval through consultation with the ChiefInformation Officer(s) for UC San Diego, other PCI DSS validated P2PE solutionsmay be adopted to support unique merchant payment processing requirements.Alternatives to the preferred solution may bring more risk to UC San Diego, andtherefore will be highly scrutinized.

 

f.        Arerequired to protect CHD on paper. Physical, unsecured storage of CHD on paperis prohibited. Once the credit card payment is processed, CHD may only bestored for as long as is necessary to meet legal, regulatory, or businessrequirements and only on paper in a locked drawer or safe. After the storageperiod or if not stored, all paper CHD shall immediately be destroyed. CHD willnot be transmitted or received by email, fax or text messaging.

 

 

PROCEDURES

 

UC San Diego&s procedures for establishing a merchant account andmaintaining PCI compliance equipped to accept and process payment cards at UCSan Diego are maintained on our Blink pages here. Procedures detailed on Blink provide a wide range ofinformation, guidelines, and resources related to credit and debit cardprocessing at UC San Diego. Blink provides Merchants with the information andresources needed to support this policy and process credit and debit cardpayments in compliance with current PCI DSS.

 

 

FORMS

 

AppendixA: Payment Card Merchant Compliance Statement

 

 

RELATED INFORMATION

 

A.    University of California Business and Finance Bulletin - Policyfor Cash and Cash Equivalents Received(BUS-49)

 

B.    Universityof California Business and Finance Bulletin IS-3 Electronic Information Security

 

C.   UC San DiegoPPM 135-3 Network Security Policy

 

D.   UCSan Diego Implementation Plan for Protection of ElectronicPersonal Identity Information

 

E.     Blink - Credit & Debit Card Processing at UC San Diego

 

F.    The PCISecurity Standards Council

 

 

REVISION HISTORY

 

10/17/2017None new policy

 

11/09/2020Policy was reviewed by policy owner. Minor updates - name changes todepartments. Formatted.

 

12/13/2023Policy was reviewed by policy owner. Minor updates - name change to departments,section 4f updated. Formatted.

 


Payment Card Merchant Compliance Statement

 

As a UC San Diego employee withresponsibilities for handling payment cards and Cardholder data (CHD), I recognizethat I have access to sensitive and confidential information. I will strive toprotect UC San Diego and its customers at all times when making decisionsconcerning payment cards and CHD, and I agree with the following statements:

 

       I have read, understand,and agree to abide by UC San Diego&s Payment Card Processing and CompliancePolicy, related guidelines in Blink, and other related policies, including: Network Security Policies, Electronic PersonalIdentity Information, BUS-49 Policy for Cash and Cash EquivalentsReceived, IS-3 Electronic Information Security.

 

       I will continuallystrive to ensure our merchant Cardholder dataenvironment (CDE) is in continuous compliance with laws, rules, and policiesgoverning the processing of card payments, including PCI DSS requirements.

 

       I will provide the Payment Card Coordinator with all requesteddocumentation for verification of ongoing PCI DSS compliance.

 

      Iwill inform the Payment Card Coordinator promptly of any changes to the CDE.

 

      Iwill maintain an accurate equipment inventory log for equipment associated withthe CDE.

 

         I will utilize CHD forUC San Diego business purposes only.

 

         I will not use ordistribute CHD for personal purposes. I understand that such actions areillegal and grounds for prosecution.

 

        I understand that in cases where I suspecta breach of security, including the suspicion that CHD has been exposed, lost,stolen, or misused, I must immediately contact UC San Diego Cash & MerchantServices and ITS Information Security.

 

        Iunderstand that I must maintain effective businessprocesses for accepting, processing, retaining, and disposing of CHD.

 

        Iunderstand that failure to comply with this policy and applicable policies, standards,and procedures may include loss of the ability to process payment cardtransactions and disciplinary action, which can include termination ofemployment.

Employee Name:

 

 

 

Print Name

Signature

Date

Employee ID Number:

Department Name:

 

 

Department Manager Approver:

 

 

 

Print Name

Signature

Date