Educause Security Discussion mailing list archives

Re: EMV Credit Card Oct. 1 2015 Compliance


From: "McClenon, Brady" <Brady.McClenon () ONEONTA EDU>
Date: Fri, 20 May 2016 13:47:01 +0000

Also, EMV isn’t a requirement.  It is a shift in liability in the case of card fraud.  We had offices that did so few 
card-present transactions that it made little sense to buy or lease them a new POS device with a chip reader they’d 
hardly ever use.  So that’s something to consider as well.


Brady McClenon
Information Technology Security Administrator
Information Technology Services - IT Security
B237 Milne Library
SUNY College at Oneonta
607-436-3203




From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Rich 
Graves
Sent: Thursday, May 19, 2016 11:49 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] EMV Credit Card Oct. 1 2015 Compliance

The practical effect of the "deadline" is small.

If at all possible, roll out EMV and P2PE (end-to-end encryption, which magically removes almost everything from PCI 
DSS scope) together. Depending on your vendor you might still need to wait a while on that. You should also ask if your 
vendor is ready to support "quick chip," which eliminates most of the customer-unfriendly wait time.

One of my schools outsourced dining and bookstore in part for PCI reasons. The other will convert to EMV, P2PE, and 
"quick chip" in late June.

Current thread: