Educause Security Discussion mailing list archives

Re: PCI compliance question


From: Jon Hanny <jehanny () GWU EDU>
Date: Thu, 8 Jul 2010 15:30:34 -0400

It is my understanding that in your case with the Red Box, that the Red
Box vendor would be bound by PCI, NOT you. Your network is a
transmission medium. The endpoint systems need to  secure the data prior
to transmission.

It is also my understanding that in the previous discussion, as long as
invalid swipes do not store the CC numbers, PCI should not apply. If
however, they do store the invalid card numbers, PCI would apply. The
system should be able to be configured reject and not store invalid card
numbers.

This is my $.02

Respectfully,

----------------------------------
Jon Hanny CISSP, GSLC
IT Risk Management
Application Security Specialist
The George Washington Universtiy
703-726-4469
jehanny () gwu edu
----------------------------------


On 7/8/2010 3:08 PM, Jeff Kell wrote:
 On 7/8/2010 3:01 PM, Lazarus, Carolann wrote:
  
My issue with this is that he said the machines transmit the CC to the server.  I'm not an expert, but I believe any 
transmission of CC falls under PCI, even if the transaction is rejected.  The transmission has to be secure.  IMO
    

Along a similar vein...

I caught the tail-end of a committee meeting request to put a "Red Box"-like machine on
campus to rent DVDs and video games.  It takes [real] credit cards.  They wanted an
"Internet" connection from us.

Is the PCI responsibility on the box-owner/vendor, or will we become the unwilling
participant in a PCI network by providing such a connection?

Not sure where "the buck stops" with respect to a turnkey appliance sort of device, nor
exactly how it technically differs from a user doing CC transactions from their own
computer (over our network).

Jeff

  


Current thread: