Campus ID News
Card, mobile credential, payment and security

PCI on campus

Zack Martin   ||   Jan 14, 2009  ||   , ,

Universities need to be aware of security requirements for payment card data

College and university campuses need to be aware that different portions of their computer networks may need to be secured because of requirements from the payment card industry. Payment Card Industry Data Security Standards (PCI DSS) are some times overlooked by campuses, but the National Association of Campus Card Users hosted two Web conferences to bring some of the issues to light.

PCI DSS pertains to anyone who accepts credit or debit cards and how that information is stored and transmitted. If organizations don’t protect payment card information and a breach occurs it could result in fines from the card associations, says J. Ashley Ewing, director of information security and compliance at the University of Alabama. In 2006 alone Visa issued merchant fines totaling $4.4 million across all industries.

The fines from the payments card associations aren’t the only costs associated with data breaches, Ewing says. The average higher education breach involved 5,000 to 50,000 accounts. A small breach can cost an initiation $1 million, but the average cost is $182 per account. This includes the cost of notifying those affected, paying for credit monitoring and unauthorized charges. “There’s also the additional cost of unfavorable publicity and significant brand damage to the institution,” he says.

Educational institutions seem to be particularly vulnerable to some of these breaches. Thirty-three percent of data breaches were at educational institutions, Ewing says. “There’s a lot more businesses out there than educational institutions,” he says. “We have a disproportionately high hit rate.”

There are a number of ways campuses can be impacted by PCI, Ewing says. Anyone or any system that deals with payment cards must know how to handle the information. So not only do the point-of-sales terminals in cafeterias need to be secured but the individual taking donations over the phone from alumni also needs to know how to securely handle payment card data. “Everyone who takes credit cards on behalf of the institution is affected by PCI,” he says.

Depending on what type of ID the campus issues, that could fall under PCI too, says Joel Weidner, director of information systems for Penn State auxiliary and business services. If the card has a MasterCard or Visa logo PCI standards have to be met. If a campus ID is tied to a bank account but a PIN is necessary the regulations are different and PCI doesn’t apply.

But even if it doesn’t, PCI may pertain to areas where the student ID is used, Weidner says. If a point-of-sales terminal accepts both student IDs and credit and debit cards PCI regulations need to be followed. “Understanding your environment is critical to compliance, he says. “Campuses need to understand what parts of the infrastructure need to be protected.”

Even if a campus outsources all of its card processing, officials need to make sure that vendors are complying with PCI regulations or they can still be held liable, Ewing says.

Campuses that enable students to use IDs at off-campus merchants need to perform due diligence too, Ewing says. Those vendors need to be questioned on how they handle payment card information to make sure they comply with security standards or the university could be held liable if there’s a breach.

Related Posts

Subscribe to our weekly newsletter


facial recognition in college classroon

Is facial recognition on campus moving from access control to the classroom?

Facial recognition already unlock phones, expedites airport passage, and replaces IDs for door access, but now it’s efficacy is being testing in college classrooms. Chafic Bou-Saba teaches information systems at Guilford College. He believes he can improve student academic performance via cameras and AI. He and a team of students are designing a facial recognition […]
Feb 28, 24 /

Cal Poly pilots reusable dining containers to curb waste

Students at Cal Poly have been pushing for green initiatives on the San Luis Obispo campus, and dining services is listening. A new pilot program will test reusable containers in an effort to reduce waste from disposable take-out boxes. “The program greatly reduces resource consumption on campus while diverting single-use containers from landfills,” says a […]
Door access reader
Feb 23, 24 /

Migrating from prox to contactless from a student perspective

At the end of 2023, the Elizabethtown College campus card was upgraded from proximity to contactless technology. As campus card, security, and auxiliary service professionals, we understand that this is positive step to replace an outdated technology with a modern, secure option. It is a mistake, however, to assume that students have the same level […]
CIDN logo reversed
The only publication dedicated to the use of campus cards, mobile credentials, identity and security technology in the education market. CampusIDNews – formerly CR80News – has served more than 6,500 subscribers for more than two decades.

Feb. 1 webinar explores how mobile ordering enhanced campus life, increased sales at UVA and Central Washington @Grubhub @CBORD

Join Jeff Koziol and Robert Gaulden from @AllegionUS as we explore how mobile credentials and proptech are changing on- and off-campus housing.

Load More...
CampusIDNews is published by AVISIAN Publishing
315 E. Georgia St.
Tallahassee, FL 32301[email protected]
Use our contact form to submit tips, corrections, or questions to our team.
©2024 CampusIDNews. All rights reserved.