Educause Security Discussion mailing list archives

PCI DSS University-Wide Compliance


From: Carlos Lobato <clobato () NMSU EDU>
Date: Wed, 30 Jan 2013 18:12:28 +0000

Hello All,



For those PCI DSS Compliance Gurus, how do you assure University-Wide PCI DSS compliance?



  1.  Do you ensure PCI DSS compliance for each merchant ID individually or do you take all merchant IDs for the 
University?
  2.  If individually, do you ONLY consider those transactions for compliance purposes?
  3.  How do you ensure/assure compliance for your University as a whole?

I would really appreciate any feedback I can get from experts as Audit Committees have a tendency to ask basic 
compliance questions and request global assurance.



I would also appreciate approches used at your University to address global compliance assurance or other general 
opinions, comments, etc.



Carlos



Carlos S. Lobato, CISA, CIA

IT Compliance Officer



New Mexico State University

Information and Communication Technologies

MSC 3AT PO Box 30001

Las Cruces, NM  88003



Phone (575) 646-5902

Fax (575) 646-5278

Current thread: