Compliance Requirements
RIT PCI DSS Compliance Standard
RIT is committed to conducting its academic and administrative activities ethically and in compliance with applicable laws and regulations. When the University accepts payment for goods or services by means of a credit or debit card (collectively, payment cards), it has a responsibility to protect the personal financial information of the individual making the payment. This document outlines operational governance and technical standards required for all RIT Business Units accepting payment card transactions (in-person, phone, or online). All RIT Merchants must comply with Payment Card Industry Data Security Standards (PCI DSS) to maintain card processing authorization; compliance is not optional, as RIT must comply with the standards in order to continue to accept payment cards. Merchant compliance workflows are centrally managed via Eramba. In addition, any supplier/contractor with whom RIT engages to accept, capture, store, transmit or process payment card information must also be compliant with the PCI DSS. Any unauthorized exposure of credit or debit card information could subject the University to significant financial penalties and reputational damage. It is therefore the responsibility of all RIT departments who accept, capture, store, transmit, or process credit or debit card payments, to ensure compliance with PCI DSS. To ensure compliance, all employees processing credit or debit payments must be officially trained and must satisfy such compliance on annual basis.
RIT Merchants do not submit manual or paper SAQs. All compliance tasks, document access, and annual attestations are conducted through the eramba portal. Merchant Managers must complete and upload the following required items annually:
Required Deliverable |
Operational Requirements & Submission Method |
|
1. Annual Business Unit Agreement & Attestation |
Access, complete, and upload the signed annual agreement and compliance attestation document directly via the eramba portal. |
|
2. Terminal Characteristics & POI Inventory Log |
Maintain an up-to-date Point-of-Interaction (POI) device inventory tracking serial numbers, models, locations, and routine physical inspection logs checking for tamper evidence or skimmers. Upload into eramba. |
|
3. Third-Party Service Provider (TPSP) Proof |
Collect and upload current Attestations of Compliance (AoC) for all third-party gateways, software vendors, and web hosts. Confirm an active Information Access and Protection Questionnaire (IAPQ) is registered in eramba. |
|
4. PCI Awareness Training & Log |
Ensure all staff, faculty, and student workers complete annual PCI Security Awareness Training via Skillsoft / RIT Talent Roadmap. Upload verified training completion logs into eramba. |
|
5. Secure Storage Review Log |
Document physical security reviews and verified storage practices for paper cardholder receipts or physical records. Upload completed review log to eramba. |
|
Mandatory Operational Actions (DO) |
Strict Operational Prohibitions (DON'T) |
||||||
|
|
|
Information Security Office & Controller's Office Support
Have more questions? Visit our FAQs on the PCI DSS page, or feel free to contact us:
- Tina Oware (aaoiso@rit.edu)
- Nicole Reinhart (nmcto@rit.edu)
- Treasury Office (treasury@rit.edu)