PCI Program Overview
Compliance with Payment Card Industry Data Security Standards (PCI-DSS)
The payment card industry has established standards for the secure handling and transmission of cardholder data, commonly referred to as PCI-DSS. Georgetown University is committed to handling confidential cardholder information in accordance with PCI-DSS, and therefore requires any department that accepts credit cards as a form of payment to operate in compliance with both PCI-DSS and the University’s information security policy.
Anyone in a department that handles credit cards must be authorized by the administrative manager and must complete the University’s PCI compliance training course each year. Authorized individuals should review University procedure and the Card Processor Handbook to understand how to securely accept, process, handle and store confidential cardholder data in accordance with PCI-DSS requirements.
PCI Compliance is managed centrally by the Office of the Chief Financial Officer through the accomplishment of our PCI-DSS Annual Activities. Service Center Coordinators are tasked with the oversight and management of PCI Compliance at the department level. Service Center Coordinators are directly responsible for the day-to-day operations of payment acceptance programs within their respective departments. A Service Center Coordinator directory can be found on our Contacts page under Collaborative Partners.