PURPOSE
The purpose of this policy is to establish business processes and procedures for accepting payment cards at Oktafonia Sagl that will minimize risk and provide the
greatest value, security of data, and availability of services to each user account within the rules and regulations established by the Payment Card Industry (PCI)
and articulated in the PCI Data Security Standards (DSS). Additionally, these processes are intended to ensure that payment card acceptance procedures are appropriately
integrated with the Company’s financial and other systems.
BACKGROUND
In response to increasing incidents of identity theft, the major payment card companies created the Payment Card Industry Data Security Standard (PCI DSS) to help prevent
theft of customer data. PCI DSS applies to all businesses that accept payment cards to procure goods or services. Compliance with this Standard is enforced by the payment
card companies and generally, noncompliance is discovered when an organization experiences a security breach that includes cardholder data.
Security breaches can result in serious consequences for the Company, including release of
confidential information, damage to reputation, the assessment of substantial fines, possible legal
liability and the potential loss of the ability to accept payment card and eCommerce payments.
DEFINITIONS
Cardholder
The customer to whom a payment card has been issued or the individual authorized to use the card.
Cardholder Data
All personally identifiable data about the cardholder (i.e., account number, expiration date, cardholder name.)
Encryption
The process of converting information into an unintelligible form to anyone except holders of a specific cryptographic key. Use of encryption protects information between the encryption
process and the decryption process against unauthorized disclosure.
Merchant or Merchant Department
For the purposes of the PCI DSS and this policy, a merchant is defined as any entity that accepts payment cards bearing the logos of any of the five members
of the Payment Card Industry Security Standards Council (American Express, Discover, JCB, MasterCard or VISA) as payment for goods and/or services, or to accept donations.
Merchant Department Responsible Person (MDRP)
A management employee within a department who has primary authority and responsibility for payment card and eCommerce transaction processing within that department.
Payment Card
Any payment card/device that bears the logo of American Express, Discover Financial Services, JCB International, MasterCard Worldwide, or VISA, Inc.
Payment Card Account Change
Any change in the payment account including, but not limited to:
the use of existing payment card accounts for new purposes;
the alternation of business processes that involve payment card processing activities;
the addition or alteration of payment systems;
the addition or alternation of relationships with third-party payment card service providers, and
the addition or alternation of payment card processing technologies or channel
Payment Card Industry (PCI) Data Security Standard (DSS)
A multi-faceted security standard that includes requirements for security management, policies, procedures, network architecture, software design and other critical protective measures.
Sensitive Authentication Data
Security-related information (card validation codes/values, full magnetic-stripe data, or personal identification number (PIN)) used to authenticate cardholders, appearing in plain-text or otherwise unprotected form.
APPLICABILITY
This policy applies to all Oktafonia Sagl web sites, applications, processes or services in general who accept, process, transmit, or otherwise handle cardholder information in electronic format.
This policy applies to all Oktafonia Sagl employees, contractors or other entity who accept, process, transmit, or otherwise handle cardholder information in physical or electronic format.
ACCEPTABLE PAYMENT CARDS
Oktafonia Sagl currently accepts VISA, MasterCard, Discover, Diners and American Express Card and has negotiated contracts for processing payment card transactions.
PROHIBITED PAYMENT CARD ACTIVITIES
Oktafonia Sagl prohibits certain credit card activities that include, but are not limited to:
using a paper imprinting system
REFUNDS
When a good or service is purchased using a payment card and a refund is necessary, the refund must be credited back to the account that was originally charged.
Refunds in excess of the original sale amount or cash refunds are prohibited. In accordance with the CardHolder refunds could be made by bank transfer.
MAINTAINING SECURITY
Departments and administrative areas, applications and services accepting payment cards on behalf of Oktafonia Sagl are subject to the Payment Card Industry Data Security Standards (PCI DSS).
Oktafonia Sagl prohibits the transmission of cardholder data or sensitive authentication data via email or by mail.
Oktafonia Sagl requires that all external services providers that handle payment card information be PCI compliant.
Oktafonia Sagl restricts access to cardholder data to those with a business "need to know".
For electronic media, cardholder data shall not be stored on local hard drives, or external (removable) media including floppy discs, CDs or thumb (flash) drives unless encrypted
and otherwise in full compliance with PCI DSS.
For paper media, cardholder data shall not be stored.
RESPONSIBILITIES
Merchant Department Responsible Persons (MDRPs) are responsible for:
Executing on behalf of the relevant Merchant Department, Payment Card Account Acquisition or Change Procedures.
Ensuring that all employees (including the MDRP), contractors and agents with access to payment card data within the relative Merchant Department acknowledge
on an annual basis and in writing that they have read and understood this Policy.
Ensuring that all payment card data collected by the relevant Merchant Department in the course of performing Company business, regardless of whether the data is stored physically or electronically is secured.
Data is considered to be secured only if all of the following criteria are met:
Only those with a "need-to-know" are granted access to payment card and electronic payment data;
Email should not be used to transmit credit card or personal payment information.
If it should be necessary to transmit credit card information via email only the last four digits of the credit card number can be displayed;
Credit card or personal information is never downloaded onto any portable devices or media such as USB flash drives, compact disks, laptop computers or personal digital assistants;
The processing and storage of personally identifiable credit card or payment information on University computers and servers is prohibited;
Only secure communication protocols and/or encrypted connections to the authorized vendor are used during the processing of eCommerce transactions;
The full contents of any track data from the magnetic stripe are never stored in any form;
The personal identification number (PIN) or encrypted PIN block are never stored in any form;
The primary account number (PAN) is rendered unreadable anywhere it is stored;
All but the last four digits of any credit card account number are masked when it is necessary to display credit card data;
Information Technology Services shall regularly monitor and test the Company Network and coordinate the Company’s compliance with the PCI Standard’s
technical requirements and verify the security controls of systems authorized to process credit cards.
The Director, Information Security Management and Compliance shall maintain currency with the
requirements of the PCI DSS and related requirements to ensure that this policy remains current and
shall coordinate and lead any response to a security breach involving cardholder data.
TRAINING
Employees who are expected to be given access to cardholder data shall be required to complete upon hire, and at least annually thereafter, security awareness training focused on cardholder data security.
Employees shall be required to acknowledge at least annually that they have received training, understand cardholder security requirements, and agree to comply with these requirements.
FURTHER INFORMATION
Oktafonia Sagl - Administration and Financial Services
Via Serafino Balestra, 22 - 6600 Locarno CH
email: amministrazione@oktafonia.ch