Pregunta #1
List your business premises type(s) and a summary of locations that are relevant to your PCI DSS assessment (eg, retail outlets, corporate offices, data centres, call centres etc..)
Respuesta Sugerida
Our institution operates as a private school with a primarily digital payment infrastructure. The relevant locations for this assessment are:
Our office manages student records and accounting but does not physically store or process raw cardholder data.
We utilize a cloud-based Software-as-a-Service (SaaS) platform, CollegeOne, which is hosted in secure data centers and uses Authorize.net gateway.
Authorized administrative staff may access the payment management dashboard via secure multi-factor authentication (MFA).
Pregunta #2
How and in what capacity does your business store, process and/or transmit cardholder data?
Respuesta Sugerida
Our business follows a non-storage policy for sensitive authentication data. We utilize the CollegeOne platform, which is integrated with Authorize.net using a secure tokenization method.
Parents or legal guardians enter their payment information directly into the CollegeOne portal. This is handled via secure web technologies that transmit data directly from the user's browser to Authorize.net's servers.
Cardholder data does not pass through or sit on our local school servers. All communication is encrypted via TLS 1.2 or higher.
We do not store Credit Card Numbers, CVV codes, or magnetic stripe data. We only store a unique token provided by Authorize.net, which is used to reference future transactions or recurring tuition payments without exposing sensitive card details.
Pregunta #3
Provide a high level description of your overall business environment, applicable to your PCI DSS assessment. For example describe the type of equipment you use for card processing, storage and transmission; such as POS devices, any databases and webservers, include a description as to how they connect both externally and any internal connections.
Respuesta Sugerida
Our business environment is designed to minimize the scope of PCI DSS by outsourcing the handling of sensitive data to a specialized provider.
We use the CollegeOne School Management System as our primary interface. We do not maintain local databases that store cardholder data or physical POS terminals that handle unencrypted card info.
Our internal school network (used by staff) is logically segmented from the student/guest Wi-Fi networks via a firewall.
All payment-related traffic is routed externally to the Authorize.net Payment Gateway via secure APIs.
Access to the financial module of our system is strictly limited to authorized personnel only, requiring unique credentials and two-factor authentication (2FA) to ensure a secure administrative environment.