Policy Category | Policy Owner | Version Effective Date | Review Cycle | Policy Contact |
X. Information Governance, Security & Technology | Chief Transformation Officer | October 7, 2024 | Annual | infosec@umgc.edu |
Purpose
The purpose of this Policy is to establish information security standards for Payment Card Industry – Data Security Standards (“PCI-DSS”) compliance relevant to University of Maryland Global Campus ("UMGC" or "University") Information Technology Resources.
Scope and Applicability
This Policy applies to all University Information Systems and Information Technology Resources. All Users are responsible for adhering to this Policy.
Definitions
Defined terms are capitalized throughout this Policy and can be found in the Information Governance Glossary.
Information Technology PCI-DSS Compliance
All Users must adhere to the requirements of the Information Technology PCI-DSS Compliance Policy to ensure safe-handling of sensitive information related to credit/debit card transactions that are supported by any University Information Technology Resources.
UMGC must comply with the complete PCI DSS requirements which can be referenced at the PCI SSC website.
Exceptions
Exceptions to this policy should be submitted to Information Security for review and approval. If an exception is requested, a compensating control or safeguard should be documented and approved.