Íøºì±¬ÁÏ

UMB is is committed to protecting the privacy and security of individuals who engage in payment card transactions. All units that process, store, or transmit payment card information must comply with the Payment Card Industry Data Security Standards (PCI DSS) and applicable University policies.

PCI compliance protects cardholder data, reduces fraud risk, and safeguards the University from financial penalties and reputational harm.

What Is PCI DSS?

The Payment Card Industry Data Security Standard (PCI DSS) is a mandatory set of security requirements established by major credit card companies and maintained by the PCI Security Standards Council.

All individuals with responsibilities, authority, or stewardship over payment card transactions must comply with federal, state, University System of Maryland (USM), and UMB policies and procedures.

  • Purpose of PCI DSS:

    • Protect cardholder data and prevent unauthorized access
    • Reduce fraudulent transactions
    • Minimize financial and reputational risk
    • Ensure a secure payment environment
  • Consequences of non-compliance:

    • Significant penalties and fines
    • Revocation of merchant account privileges
    • Litigation and regulatory oversight
    • Damage to the University’s reputation

PCI Compliance: Key Responsibilities and Requirements

PCI Compliance is mandatory under UMB Policy VIII-99.08(A).

The policy:

  • Applies to all UMB employees and authorized affiliates
  • Requires documented internal controls at the operational unit level
  • Prohibits storing sensitive authentication data
  • Restricts unauthorized payment methods and processors
  • Requires approval of payment card types and processing equipment
  • Assigns compliance responsibilities to the Office of the Controller and operational units

Cardholder Data (CHD) includes:

  • Primary Account Number (PAN)
  • Cardholder name
  • Expiration date
  • Service code

Sensitive authentication data (which must never be stored) includes:

  • CVV/CVC/CID codes
  • PIN/PIN block
  • Magnetic stripe data

Operational Units that accept payment cards must:

  • Designate a Unit PCI Coordinator
  • Develop and maintain written PCI procedures (template available)
  • Complete the  (via LMS)
  • Submit the annual PCI Self-Assessment Questionnaire (SAQ)
  • Participate in annual PCI compliance surveys
  • Undergo periodic compliance reviews

Payments may only be processed by UMB or authorized affiliate employees. Students may not process payments unless employed in an authorized role.

Only approved bank-issued equipment and approved online gateways may be used. Unauthorized platforms (e.g., unapproved electronic applications or devices) are prohibited.

Cardholder Data Handling

  • Mail and phone payments must be processed within one business day.
  • Cardholder data must be destroyed by close of business, no later than 24 hours.
  • Preferred destruction method: micro cross-cut shredding.
  • Writing over card information with marker is not acceptable.

Best practice: The cardholder should retain possession of the card and initiate the transaction whenever possible.

Departments must document and perform reconciliations at least once per calendar month. Reconciliations must be:

  • Prepared by someone not directly involved in processing transactions
  • Reviewed, signed, and dated by the preparer and department administrator (or designee)

Three required reconciliations:

  1. Sales vs. Batch Report – Sales activity must match the daily batch total.
  2. Batch Report vs. Merchant Bank Activity – The batch total must match the bank funding amount.
  3. Merchant Bank Activity vs. Quantum Analytics – Bank deposits must match the amount recorded in the financial system.

Differences must be investigated immediately. Unresolved discrepancies must be reported in writing to the Operational Unit head, University Controller, and Change Management Advisory Services.

Templates to assist with reconciliations.

Public-facing terminals and kiosks must be inspected daily for signs of tampering, including:

  • Damaged tamper stickers
  • Unusual markings
  • Physical damage

If tampering is suspected:

  1. Discontinue use immediately.
  2. Contact the bank to replace the device.
  3. Notify your supervisor and Unit PCI Coordinator.
  4. The Unit PCI Coordinator must report the issue to the PCI Committee.

Shared devices should be secured in locked locations when not in use.

  • Merchant accounts must be established in accordance with the University procedure.
  • Third-party contractors (e.g., bookstore, parking, vending) must be approved and provide PCI compliance attestation.
  • Personnel changes for merchant accounts must be reported to DL-CITSPCICompliance@umaryland.edu.

Refer to the Procedure on Establishing and Accounting for Payment Card Accounts for setup requirements and accounting guidance.

A security breach is any unauthorized access to data or systems. Fraud involves intentional deception for unauthorized benefit.

If a breach or fraud is suspected:

  1. Immediately notify your supervisor and Unit PCI Coordinator.
  2. The Unit PCI Coordinator must notify the PCI Committee and Change Management and Advisory Services.
  3. If computer-related activity is suspected, contact your IT support team and notify CITS immediately.

Prompt reporting is essential to limit exposure and mitigate risk.