payment card industry - compliance readiness at b.c.'s post-secondary institutions panel

13
Payment Card Industry - Compliance Readiness at B.C.'s Post-secondary Institutions panel

Upload: rachelle-earle

Post on 31-Mar-2015

212 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Payment Card Industry - Compliance Readiness at B.C.'s Post-secondary Institutions panel

Payment Card Industry - Compliance Readiness at B.C.'s Post-secondary Institutions panel

Page 2: Payment Card Industry - Compliance Readiness at B.C.'s Post-secondary Institutions panel

PanelUniversity of British Columbia

• Larry Carson, Associate Director, Information Security Management• Ray McNichol, Director of Financial Services

Bell Canada• Ed Rebane, M.ENG, B.ENG, CISSP, CISM, Senior Security and PCI Advisor, Bell Security

Practice Leader

Simon Fraser University• Keir Novik, Network Security Analyst

University of Victoria• Robert E. Elves, Assistant to the Controller• Eric van Wiltenburg, Manager of Information Security

Page 3: Payment Card Industry - Compliance Readiness at B.C.'s Post-secondary Institutions panel

PCI-DSS & Higher Education

• A whole lot of weight• VISA • MasterCard • American Express• Discover• JCB (Japan Credit Bureau)

Payment Card Industry – Data

Security Standard

• Ministries• Universities & Colleges• Etc.

Mandated by BC Government

for public bodies

Page 4: Payment Card Industry - Compliance Readiness at B.C.'s Post-secondary Institutions panel

Why do we need credit cards?

Tuition Fees• Domestic

• InternationalFines Food

Residences/Hoteling Bookstore Athletics

Parking ConferencesContinuing

Professional Development

Page 5: Payment Card Industry - Compliance Readiness at B.C.'s Post-secondary Institutions panel

What is PCI-DSS compliance about?

Jumping

through

“hoops”

Dotting the “i”s and crossing

the “t”sRisk

Management

Page 6: Payment Card Industry - Compliance Readiness at B.C.'s Post-secondary Institutions panel

Panel Questions

Questions for the panel

Discussion amongst the panel

10-15 mins for questions at the end

Page 7: Payment Card Industry - Compliance Readiness at B.C.'s Post-secondary Institutions panel

Questions for the Panel

1. Institutions in BC are in various stages of PCI compliance, what is the single best lesson your institute has learned to-date, which you could share with other institutions?

Page 8: Payment Card Industry - Compliance Readiness at B.C.'s Post-secondary Institutions panel

Questions for the Panel

2. What has been the most challenging part of PCI compliance for your institute and if you have been able to overcome that, could you tell us how? If not, could you share how you are addressing it.

Page 9: Payment Card Industry - Compliance Readiness at B.C.'s Post-secondary Institutions panel

Questions for the Panel

3. What has been the most beneficial part of PCI compliance for your institution and how has that benefit been relayed to the stakeholders?

Page 10: Payment Card Industry - Compliance Readiness at B.C.'s Post-secondary Institutions panel

Questions for the Panel

4. If an institution were to start on PCI Compliance today, where/what do you recommend that they start with?

Page 11: Payment Card Industry - Compliance Readiness at B.C.'s Post-secondary Institutions panel

Questions for the Panel

5. If governance plays a role in your compliance efforts can you tell us how you have addressed it and the value that has been seen?

Page 12: Payment Card Industry - Compliance Readiness at B.C.'s Post-secondary Institutions panel

Questions?

Page 13: Payment Card Industry - Compliance Readiness at B.C.'s Post-secondary Institutions panel

Contacts Us…University of British Columbia

• Larry Carson, Associate Director, Information Security Management: [email protected] • Ray McNichol, Director of Financial Services: [email protected]

Bell Canada• Ed Rebane, M.ENG, B.ENG, CISSP, CISM, Senior Security and PCI Advisor, Bell Security

Practice Leader: [email protected]

Simon Fraser University• Keir Novik, Network Security Analyst: [email protected]

University of Victoria• Robert E. Elves, Assistant to the Controller: [email protected] • Eric van Wiltenburg, Manager of Information Security: [email protected]