e-Learning Module Credit/Debit Payment Card Acceptance and Security

35
e-Learning Module Credit/Debit Payment Card Acceptance and Security OBFS-Treasury Operations- Merchant Card Services February 26, 2011 Instructor and Moderator, Rebecca Kornegay

description

e-Learning Module Credit/Debit Payment Card Acceptance and Security. OBFS-Treasury Operations-Merchant Card Services February 26, 2011 Instructor and Moderator, Rebecca Kornegay. Welcome. Introduction. - PowerPoint PPT Presentation

Transcript of e-Learning Module Credit/Debit Payment Card Acceptance and Security

Page 1: e-Learning Module Credit/Debit Payment Card Acceptance and Security

e-Learning ModuleCredit/Debit Payment Card

Acceptance and SecurityOBFS-Treasury Operations-Merchant

Card ServicesFebruary 26, 2011

Instructor and Moderator, Rebecca Kornegay

Page 2: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Welcome

Page 3: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Introduction

• University of Illinois departments accepts and processes thousands of credit or debit card payment sales daily.

• Departments are required to comply with payment card industry data security standards (PCI DSS) of Visa, MasterCard, American Express, and Discover to secure cardholder information at all times.

Page 4: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Why Are We Doing This?

• University students, parents, and customers trust that their card information will be protected at the University of Illinois.

• To protect the University from a card security breach and monetary fines.

Page 5: e-Learning Module Credit/Debit Payment Card Acceptance and Security

What Will You Learn?

• Anatomy of a Payment Card • Required Guidelines as Best Practices for

Handling Payment Card Information• Payment Card Security

Page 6: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Anatomy of a Payment Card

Credit/Debit Card –Data Embossed Front

Account Number

Cardholder Name

Bank Card Brand

Bank Card Logo

Verification Number(American Express Only)

Expiration Date

Page 7: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Anatomy of a Credit/Debit Payment Card

Credit/Debit Card –Data Imprinted Back

Magnetic Stripe

Signature Panel Security Code

(Visa, MasterCard, Discover)

Page 8: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Payment Card Acceptance and Processing

Payment card transactions must be accepted using one of the following methods and technologies,

• Methods– Face to Face (card present)– Mail, Telephone or Fax (card NOT present)– University-approved internet application (card NOT

present)• Technologies– Terminal– Point-of-Sale (POS) system– e-Commerce

Page 9: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Secure Methods

PhoneMail

Fax

Mail or Telephone Orders (MOTO)

Page 10: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Not Secure Methods

PDA Device

Wireless Devices

Staff entering a cardholder’s card information into computer or a website from their workstation computer.

Instant Messaging or Chat

Page 11: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Email Not A Secure Method

If a customer sends their card information via email,

• Delete the email from your inbox and deleted box, then send a message of response.

• If you reply to the original email, remove the card information before sending the message.

• Send a response that the card information is not accepted via email and provide alternative methods for sending their card information by fax, mail, phone, etc.

Page 12: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Card Present Transactions

Accepting a payment card from face-to-face

Page 13: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Card Present Transactions

If You Handle Card Present Transactions, • The payment card must be swiped through

the terminal or POS system card magnetic stripe reader.

• Do not keep any card information after the transaction has been authorized.

• Keep the payment card within the customer’s view and shield from the view of others.

Page 14: e-Learning Module Credit/Debit Payment Card Acceptance and Security

• The physical payment card is not provided for processing.

• Requires manual entry of the card number into a processing technology.

Card NOT Present Transaction

Page 15: e-Learning Module Credit/Debit Payment Card Acceptance and Security

In addition to manually entering the Cardholder Account Number, for card NOT present transactions you must enter,

• EXPIRATION DATE, 02/14• CARD BILLING ADDRESS STREET NUMBER, 3775• ZIP CODE, 61821• VERIFICATION NUMBER (FRONT OF AMEX CARD)• SECURITY CODE, CVS, CVV2, CID (VISA,

MASTERCARD, & DISCOVER CARDS)

Card NOT Present Transaction

Page 16: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Card NOT Present Transaction

Sensitive Security Authentication Data,must NEVER be stored after the transactionauthorized.• Security Code and Verification Number• PIN Numbers• Expiration Date• Payment Card Full Magnetic Stripe Data

Page 17: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Card NOT Present Transaction By Phone

Payment Card Data Acceptance Requirements• Phone

Page 18: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Card NOT Present Transaction By Phone

Payment Card Data Acceptance Requirements• Phone

Page 19: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Card NOT Present Transaction By FAX

Payment Card Data Acceptance Requirements• Fax

Page 20: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Card NOT Present Transaction By FAX

Payment Card Data Acceptance Requirements• Treat a fax the same way as you would treat

cash

$100 Bills

Page 21: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Card NOT Present Transaction By Mail

Payment Card Data Acceptance Requirements• Mail

$100 Bills

Page 22: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Card NOT Present TransactionBy Paper Based Forms

Payment Card Data Acceptance Requirements• Paper Based Forms

Page 23: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Card NOT Present TransactionBy Paper Based Forms

If paper records containing card account numbers,

• Remove all but the last four digits to be rendered unreadable by blackening the numbers with china marker grease pencil or with character replacements of *, #, X.

Page 24: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Card NOT Present TransactionBy Paper Based Forms

Designing Order, Registration, or Invoice Forms• Form area capturing card information must be,– Placed at bottom of form– Remove card information– After processing payment, cut or tear form bottom to

be shredded– Printed receipts or invoices distributed outside the

unit must show only the last four digits of account number.

Page 25: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Card NOT Present TransactionBy Paper Based Forms

If paper records containing card account numbers,

• Disposing of Paper Based Forms

Page 26: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Accessing and Storing Payment Card Information

Required Procedures for Accessing Card Information

• Limit access to documents and reports• Never share logins and/ or passwords with

others, including coworkers.

Page 27: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Accessing and Storing Payment Card Information

Required Procedures for Storing Card Information

• Databases, spreadsheets and other electronic systems must ONLY store the last four digits of the card account number.

• NEVER store the card expiration date, verification number, or security code in ANY electronic spreadsheet, database or system.

Page 28: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Accessing and Storing Payment Card Information

Required Procedures for Storing Card Information

• Store all materials containing cardholder account information in a secure and restricted area.

Page 29: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Payment Card Transactions Delayed Processing

Best practice is to process payment card information immediately for the transaction to be authorized.

• If a delay is required,– Do not store the card information in electronic

format.– Card information must be kept secure and with

restricted access until the payment is processed for authorization.

Page 30: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Payment Card Transactions Delayed Processing

• Secure the paper form containing payment card information following the same guidelines used for securing cash transactions.

• Treat delayed processing paper containing card information as if it were cash.

Page 31: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Security ReminderPhishing

Securing Payment Card Information• Be aware of phishing methods that attempt to

trick you into providing card data for malicious purposes.

• Never provide a customer’s payment card information to anyone.

• Merchant Card Services and the University’s bank processor, Global Payments, will never contact a department to request for you to provide card information.

Page 32: e-Learning Module Credit/Debit Payment Card Acceptance and Security

What Happens if Payment Card Information is Lost or Stolen?

• Stolen card data might be used to make counterfeit cards.

• Can be sold for illegal purposes, such as facilitating identity theft.

• An expensive forensic investigation may result.• The University will be fined for the breach and

other associated costs, such as the forensic investigation.

Page 33: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Payment Card Security Breach Consequences

The consequences of a security breach,• A forensic investigation will determine the

amount of data lost and how the loss occurred. • All fines, monetary penalties, and other

associated costs related to the breach are paid by the department merchant that experienced the breach.

• Increased processing restrictions or loss of processing privileges for the department.

Page 34: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Payment Card Security Breach Consequences

Breach in security could result in,• Significant monetary fines to the University.• Potential loss of reputation and trust from

students, parents, and customers.• The entire University could lose the privilege

to accept and process credit/debit cards due to a department’s payment card security breach.

Page 35: e-Learning Module Credit/Debit Payment Card Acceptance and Security

Thank you!Questions, contact Rebecca Kornegay at University of Illinois Merchant Card Services Office, by PHONE: 217-244-9384 or E-MAIL: [email protected]