FundSvcs Community

 View Only
  • 1.  PCI Compliance

    Posted 01-11-2024 01:30 PM

    Good afternoon,

     

    It's me again. Are any universities represented here PCI compliant AND processing credit card gifts (or tuition payments for that matter) on their own? I am clearly torn between two VPs on this end regarding what is normal and expected, particularly by our older donor base.

     

    If you are PCI compliant, how difficult was that process, and if you are only contracting out (as we mostly do now), I would like to know that as well.

     

    I appreciate your help.

     

    Thank you.

     

    Denise Mattie

    Director of Advancement Services

    T: 325.793.4750   |   M: 720.480.9369   |   mattie.denise@mcm.edu

    Institutional Advancement

    1 McMurry University

    #938

    Abilene, TX 79697

    give.mcm.edu

    McMurry University

    1400 Sayles Blvd.

    Abilene, TX 79697

    www.mcm.edu

       

     

     



  • 2.  RE: PCI Compliance

    Posted 01-11-2024 01:37 PM
    PCI compliance can mean multiple things, and it depends on perspective. Virtually every credit card processor out there will claim PCI compliance. But not all solutions have been vetted through the PCIDSS group.  Some organizations will insist this is a requirement. 

    Then it comes to your local self assessment questionnaire. It depends on what solution you are using. The questions and requirements on the self assessment questionnaire will be different   

    That being said it is not difficult to attain a self attestation of compliance. 

    Dave Woodley
    Unlock*Share*Connect
    Chief Data Officer
    University of Alaska Foundation





  • 3.  RE: PCI Compliance

    Posted 01-12-2024 10:24 AM

    Hi Denise....

    I agree with Dave that there are many "flavors" to PCI compliance.   It actually is something that changes very frequently.  I managed a credit card processing server at one point, and we frequently had to apply patches to maintain compliance.  The University had a scan that ran to alert us to these changes - otherwise it would be difficult to keep track of all of them. 

    Essentially, this is something that is better left to the experts.  I would not recommend running your own server, especially with the myriad options available.  

    Terry Callaghan 

    Zuri Group

    aasp Executive Board Members



    ------------------------------
    Terry Callaghan
    Zuri Group
    terry@zurigroup.com
    ------------------------------