Banking information (Direct Debit/Credit Card etc.)
In today’s environment, card data security has become important for every type of business that accepts card payments. If a school accepts card payments, whether in a face-to-face or card-not-present environment, it must secure all card information using the global industry standards.
The Payment Card Industry Data Security Standards (PCI DSS) are global information security standards which include a set of comprehensive requirements for enhancing payment account data security.
Requirements for all schools/ETBs that accept card payments
The PCI DSS include 12 key requirements which apply to schools/ETBs that accept or process card payments. These are:
- Installation and maintenance of a firewall configuration to protect data
- Do not use vendor-supplied defaults for passwords or other security parameters
- Protect stored data
- Encrypt the transmission of cardholder data and sensitive information
- Use and regularly update anti-virus software
- Develop and maintain secure systems and applications
- Restrict access to data by business need-to-know
- Assign a unique ID to each person with computer access
- Restrict physical access to cardholder data
- Track and monitor all access to network resources and cardholder data
- Regularly test security systems and processes
- Maintain a policy that addresses information security
These requirements apply to all schools/ETBs that store, transmit or process payment card data.