PCI DSS COMPLIANCE

PAYMENT CARD INDUSTRY DATA SECURITY STANDARD “PCI DSS”

PCI DSS is a proprietary information security standard created to increase controls around cardholder data to reduce credit card fraud and regulatory compliance is required.

People place a lot of trust in our organization whenever they provide their payment card data. That’s why it’s important to protect it – and the PCI DSS helps us do that.

How can you help us stay compliant?

  • Follow our policies and data security requirements

  • Report suspected misconduct

  • Ask for help if you’re ever unsure of the proper course of action

  • Keep cardholder data physically and electronically secure

  • Protect our network

PAYMENT CARD INDUSTRY DATA SECURITY STANDARD “PCI DSS” and MASS 201 CMR17

Standards must be met in connection with the safeguarding of personal information contained in both paper and electronic records.

The objectives of these standards are:

  • To ensure the security and confidentiality of customer information in a manner fully consistent with industry standards

  • Protect against anticipated threats or hazards to the security or integrity of such information

  • Protect against unauthorized access to or use of such information that may result in substantial harm or inconvenience to any consumer

Regulations require notification to individual(s) affected, as well as state regulators in the event personal information has been compromised.

Personally identifiable information is defined as:

  • Last name/first name or Last name/First initial plus:

  • Financial account number, State-issued ID/Driver’s License, Credit/Debit card number

If you are aware of or suspect information has been compromised, please contact your Manager immediately