< Back | A to Z Index | Search | Home
PURPOSE
The purpose of this policy is to define the guidelines for accepting and processing credit cards and storing personal cardholder information. The policy will help to ensure that cardholder information supplied to The College of Saint Benedict is secure and protected. The College is complying with credit card company requirements and the Payment Card Industry Data Security Standard.
SCOPE
This policy applies to all College of Saint Benedict employees. The policy pertains to all departments that process, transmit, or handle cardholder information. The cardholder information may be in a physical or an electronic format.
POLICY
All transactions that the College processes must meet the standards outlined in the policy.
https://www.pcisecuritystandards.org/tech/download_the_pci_dss.htm
PROCEDURES
All credit card and debit card transaction acceptance, including web based transactions, must be initiated and controlled through the College Controller. Because the sale of goods and services to entities outside the college community may raise special considerations, questionable sales issues should be reviewed by the Controller’s Office.
Departments, who need to accept credit/debit cards and obtain a physical terminal to either swipe or key transactions, need to contact the Controller’s Office to execute the required paper work, obtain a Merchant Number, and be given direction as how to process those transactions for accounting purposes.
Departments wishing to engage in electronic transactions are required to use the College of St. Benedict’s Touchnet credit card processing system. Touchnet is a safe and secure electronic payment mechanism. All servers and computers used for electronic transactions will be secure and Payment Card Industry compliant. After contacting the College of St. Benedict’s Controller, a specialized Merchant Number can be established, and the department will be provided with contacts to receive technical instruction. The department will be responsible for creating its own web site and integrating to the Touchnet system. Once the web site passes the required payment parameters, secure payment will be executed, and approval codes, and other related elements will be returned to the originating web site.
Under no circumstance will it be permissible to obtain or send credit card information, or transmit credit card information by e-mail.
The only approved payment mechanism for electronic transactions on the web at the College of St. Benedict is the Touchnet system. Exceptions to this procedure may be granted only after a request from the department has been reviewed and approved by the College of St. Benedict’s Controller.
SANCTIONS
If the requirements of the policy are not followed, suspension of physical and/or electronic payment options will result. Fines may also be imposed by the affected credit card company.
Minimum fines from VISA for violation of the Payment Card Industry Data Security Standard begin at $50,000. The College may be required to report violations to the appropriate authorities.
Copyright © 2009 College of Saint Benedict (37 South College Avenue, St. Joseph, Minnesota 56374; 320-363-5011) and
Saint John's University (P.O. Box 2000, Collegeville, Minnesota 56321; 320-363-2011). All rights reserved.
Affirmative Action/Equal Opportunity Employers. E-mail the CSB/SJU Web Coordinator.