Body
Overview
This standard defines Oakland University’s responsibilities, controls, and approved implementation models for the Cardholder Data Environment (CDE) and the protection of payment card data.
It aligns with:
- OU Policy 212 – Bankcard Information Security
- The current Payment Card Industry Data Security Standard (PCI DSS)
The purpose of this standard is to ensure that payment card data is processed, stored, and transmitted securely, minimizing risk to the University, cardholders, and affiliated entities while maintaining regulatory compliance.
Scope
This standard applies to all:
- Systems and applications
- Networks and infrastructure
- Personnel and departments
- Vendors, contractors, and affiliated entities
that process, store, transmit, or can impact the security of payment card data, or that connect to systems that do.
Standard
PCI compliance requirements vary depending on transaction type, architecture, and vendor solution. This standard outlines Oakland University’s preferred and approved implementation models.
Important:
All PCI implementations are subject to review. In all cases, the Oakland University PCI Addendum must be completed and is considered authoritative, regardless of implementation model.
Partnership Models and Requirements
OU is the Merchant — On-Premises Card Processing
Description:
Oakland University is the merchant of record. Payment card transactions are processed on-site using OU-managed workstations or physical payment devices (e.g., card readers).
Examples:
- Credit card transactions entered on an OU workstation
- Physical point-of-sale (POS) devices located on campus
Preferred Implementation (P2PE)
- Vendor provides a PCI P2PE-certified solution
- Equipment is placed on a dedicated, segmented network
- Vendor provides annual PCI attestation
- Department completes annual PCI training
Alternate Implementation (When P2PE Is Not Available)
- Vendor provides equipment eligible for SAQ B-IP
- Equipment is placed on a dedicated network segment, isolated by a firewall
- Vendor provides annual PCI attestation
- Department completes annual PCI training
Non–Card-Present Transactions (Phone, Mail)
Telephone Payments
- Card data must be entered directly into the payment device.
- Cardholder data must not be written down.
- If written temporarily:
- Enter into the device immediately
- Destroy promptly using a crosscut shredder in accordance with Records Retention Policy
Mail Payments
- Card data received by mail must be entered into the payment device as soon as possible.
- Any written cardholder data must then be crosscut shredded immediately.
Prohibited Methods
- No credit card payments may be accepted via fax or email.
- If unsolicited card data is received via fax or email:
- Do not process the transaction
- Destroy the data (crosscut shred or securely delete)
- Notify the customer of acceptable payment methods
- Request that card data not be sent via fax or email again
Contractor is the Merchant — On-Premises
Description:
A contractor is the merchant of record and processes payments using equipment located on OU property.
Contractor Requirements
The contractor must:
- Provide independent network connectivity
- If OU network connectivity is required:
- Architecture must be approved in advance and in writing by the University’s Qualified Security Assessor (QSA)
- Provide annual PCI attestation
Contractor is the Merchant — Cloud-Hosted
Description:
Payment processing occurs entirely in a contractor-managed cloud environment (e.g., virtual storefront).
Contractor Requirements
The contractor must:
- Obtain approval before requesting payment links be added to OU services
- Provide annual PCI attestation
- Notify Oakland University within 24 hours of any known or suspected intrusion or data compromise
Non-OU Affiliate Using OU Space
Examples:
- Fairs
- Markets
- Temporary events hosted on University property
Affiliate Requirements
Affiliates must:
- Use independent network connectivity (e.g., cellular data)
- Utilize P2PE-approved payment equipment
- Provide written acknowledgment that:
- Oakland University has no PCI responsibility for their transactions
Roles and Responsibilities
Chief Information Security Officer (CISO)
- Administers and enforces this standard
- Oversees PCI compliance activities and risk management
Individuals and Entities with Access to OU Information Resources Must:
- Comply with this standard and all related policies
- Follow departmental and UTS security procedures
- Complete required PCI training when applicable
Vendor / Solution Provider
Responsible for providing:
- Technical documentation (e.g., network requirements, reference architectures)
- Compliance documentation (e.g., PCI SAQ, ROC, attestations)
- Ongoing compliance with PCI DSS and industry best practices
Definitions
Cardholder Data Environment (CDE)
The devices, Payment Card Systems, applications, and networks identified as in scope for PCI compliance.
Cardholder Data
Card holder’s name, contact information, Payment Card number, Primary Account Number (PAN), expiration date, validation code, transaction data, or any information that can identify a payment card account or holder.
Contractor
As defined in the Oakland University PCI Addendum; any individual or entity providing goods or services to the University or selling goods or services on University property.
Payment Card
A credit card, debit card, prepaid card, or similar card issued by a financial institution to initiate a payment transaction.
PCI Compliance
Compliance with standards set forth by the PCI Security Standards Council (PCI-SSC).
Payment Card System
Any system, device, application, hosted service, or technology used to process, transmit, or store cardholder data.
Payment Card Validation Code
Also known as CVV, CVV2, or CV2; the three- or four-digit security code on a payment card.
Primary Account Number (PAN)
The card identifier printed or stored on payment cards.
Qualified Security Assessor (QSA)
A third-party security professional certified to evaluate PCI DSS compliance.
Related Documents, Forms, and Tools
- OU Policy 212 – Bankcard Information Security
- 86X Information Security Policy
- Oakland University Cybersecurity Incident Program
- IT Risk and Security / Compliance Governance Charter
- UTS Registration and Protection of Systems Standard
- UTS Registration and Protection of Endpoints Standard
Additional Support
- OU Technology Center
- 44 Oakland Center
- Rochester, MI 48309-4479
- Phone: (248) 370-4357
- Email: support@oakland.edu
- Office Hours: M-F 8:00am - 5:00pm
Last Modified: 8/26/2026
Authority: Approved by University Technology Services (UTS) Chief Information Officer
Category: Security Standards
Status: Approved