E-Commerce
Internal Security and Responsibility Matrix
Last modified 4/9/2024
The Internal Security and Responsibility Matrix RACI chart documents the compliance responsibilities of departments on campus as they relate to overall PCI compliance.
Category | Task | Responsible | Accountable | Consulted |
Compliance | File SAQ's, obtain AOC's | ISO, Comptrollers | E-Commerce Committee | |
Plan, lead, and manage AT compliance improvement and maintenance projects | ISO | E-Commerce Committee | Comptrollers | |
Risk assessment | ISO | ISO | AT, Foundation/Alumni, Merchants | |
Compliance validation and testing | ISO | ISO | Comptrollers | |
Policies, procedures, and acceptable use | E-Commerce Committee, University Leadership | E-Commerce Committee, University Leadership | Comptrollers, ISO | |
Documentation management | E-Commerce Committee, ISO, AT, Foundation/Alumni, Comptrollers | E-Commerce Committee, ISO, AT, Foundation/Alumni, Comptrollers | ||
Cardholder data flow diagrams - Terminals | AT Endpoint | AT Endpoint | ISO | |
Application cardholder data flow diagrams - Pay | AT Web | AT Web | ISO | |
Application cardholder data flow diagrams - Agilon | AT App Admins | AT App Admins | ISO | |
Onboarding and Offboarding management | AT Endpoint | AT Endpoint | ISO | |
Pre-hire personnel screening | HR | VPFP | ISO | |
Training | Annual End User training- Terminal and virtual terminal | AT Endpoint | E-Commerce Committee | Comptrollers, ISO |
Annual End User training- Technical staff | AT Endpoint | E-Commerce Committee | ISO | |
Annual End User training- ePay website | AT Endpoint | E-Commerce Committee | Comptrollers, ISO | |
Annual End User training- Touchnet | AT Endpoint | E-Commerce Committee | Comptrollers | |
Annual End User training - General PCI Compliance training | AT Endpoint | E-Commerce Committee | Comptrollers, ISO | |
Cardholder Data Environment | Maintain master inventory log of all terminals, virtual terminals, REDs, and printers | AT Endpoint | AT Endpoint | |
Provide support for cardholder data environment devices including terminals, virtual terminals, REDs, and printers | AT Endpoint, ISO | AT Endpoint | Comptrollers | |
Inspection of devices for tampering, skimmers, and device damage | AT Endpoint, Merchants | AT Endpoint, Merchants | ISO | |
Physical security of terminals, virtual terminals, REDs and printers | AT Endpoint, Merchants | E-Commerce Committee, Merchants | ISO | |
Virtual Terminal Active Directory Account Management | AT Endpoint | AT Endpoint | AT CCA, ISO | |
Client anti-virus management | AT Endpoint | AT Endpoint | ISO | |
Secure lifecycle management of written cardholder data media | Merchants | E-Commerce Committee, Merchants | Comptrollers, ISO | |
Connected-To/Security-Impacting Environment | Touchnet uStore and uPay Management | Comptrollers, AT App Admins | Comptrollers, AT App Admins | |
Application support - Pay | AT Web | AT Web | AT CCA, ISO | |
Application support - Agilon, Agresso | AT App Admins, Foundation/Alumni | AT App Admins, Foundation/Alumni | AT CCA, ISO | |
Application Support - Tripwire, InsightVM | ISO | ISO | AT CCA | |
Amazon Web Services IAM Management | AT CCA | AT CCA | ISO | |
Amazon Web Services Workspaces Management | AT CCA | AT CCA | ISO | |
Active Directory Management | AT CCA | AT CCA | AT Endpoint, ISO | |
Server Operating System Management | AT CCA | AT CCA | ISO | |
Database Administration | AT DBA | AT DBA | AT CCA, ISO | |
Server anti-virus management | AT CCA | AT CCA | ISO | |
| Network design and documentation | AT Networking, ISO | AT Networking | |
Firewall and AWS Security Group management and review | AT CCA, ISO | AT CCA | ||
Internal and external penetration testing | ISO | ISO | AT, Foundation/Alumni | |
Internal vulnerability scans | ISO | ISO | AT, Foundation/Alumni | |
Manage and monitor Trustwave external vulnerability scans | ISO | Comptrollers | AT CCA, AT App Admins | |
Log management and review | ISO | ISO | AT CCA, AT App Admins, AT DBA, AT Web, AT Endpoint, Foundation/Alumni | |
Security alert monitoring and incident response | ISO | ISO | AT CCA, AT App Admins, AT DBA, AT Web, AT Endpoint, Foundation/Alumni | |
Sophos UTM Management | AT Endpoint, AT Networking, ISO | ISO | ||
Vendor Management | Manage contracts - Touchnet, JetPay, Heartland, Trustwave | Comptrollers, Purchasing | Comptrollers, Purchasing | E-Commerce Committee |
Manage contracts - Sophos, Tripwire, InsightVM | ISO, Purchasing | ISO, Purchasing | E-Commerce Committee | |
Manage contracts - Agilon, Agresso | Foundation/Alumni, Purchasing | Foundation/Alumni, Purchasing | E-Commerce Committee | |
Manage contracts - Amazon Web Services | AT BAC, Purchasing | AT BAC, Purchasing | E-Commerce Committee | |
Manage contracts - Paciolan | Athletics, Purchasing | Athletics, Purchasing | E-Commerce Committee | |
Approval for methods of taking digital payments | E-Commerce Committee, Comptrollers, ISO | E-Commerce Committee | ||
Approval for contracts related to E-Commerce | E-Commerce Committee, Comptrollers, ISO | E-Commerce Committee | Purchasing | |
Review and recommend language in University contracts | Purchasing, ISO | Purchasing | Comptrollers | |
Maintain list and manage annual compliance certification of 3rd party vendors | ISO | ISO | E-Commerce Committee, Comptrollers, Purchasing | |
Accounting and Business Processes | Annual Business process updates by department | Comptrollers | Comptrollers | |
Accounting and reconciliation of credit card revenue and fees | Comptrollers | Comptrollers |