PCI Compliance - storing cc numbers

Hello Tessitura folk, 

We have been approached by a major Australian bank who is selling the idea that they can be in charge of PCI (Payment Card Industry) compliance for our organisation so that we don't have to store credit cards in Tessitura, saving us the time and money in regards to quarterly policy checks.

This particular bank has stated that their system is compatible with Tessitura and everything will run the same, only their system will host the credit cards and 'bank' transactions for both ticketing and donations. 

I'm curious to know which organisation has a major bank working with them on this front and what are the issues and implications of this?

Your thoughts are gratefully appreciated. 

Kind regards, 

Katherine

  • Hi Katherine,

    In the UK Tessitura have been working with our payment company (TNS) and have recently implemented a solution that allows us to authorise our credit cards directly with TNS using their Virtual Payment Client, works similar to our Chip and Pin machines, which m,eans we do not store full credit cards in Tessitura but it has been implemented in such a way that the first 6 and last 4 digits are present so should still work with our Kiosk Ticket Collection.

    Notice there was also a thread that said Tessitura are implementing tokenisation, however, that looked like it would initially be US only

    Mark

  • Hi Mark,

     

    Thank you for your response, it looks as though the bank is trying to implement something similar while taking care of PCI compliance checks for us.

     

    It would seem as though we are the only arts organisation in the Asia-Pacific region that will be attempting this with a major commercial bank so fingers crossed it doesn’t all go belly-up.

     

    I take your point about the last 4 digits still being present on our system in order for the Box Office staff to manage ticket collections. This is something we will need to further consider.

     

    Cheers,
    Katherine

     

     

    From: Mark Ridley [mailto:bounce-markridley2246@tessituranetwork.com]
    Sent: Friday, 9 May 2014 7:36 PM
    To: Katherine Chien
    Subject: Re: [Tessitura Finance Forum] PCI Compliance - storing cc numbers

     

    Hi Katherine,

    In the UK Tessitura have been working with our payment company (TNS) and have recently implemented a solution that allows us to authorise our credit cards directly with TNS using their Virtual Payment Client, works similar to our Chip and Pin machines, which m,eans we do not store full credit cards in Tessitura but it has been implemented in such a way that the first 6 and last 4 digits are present so should still work with our Kiosk Ticket Collection.

    Notice there was also a thread that said Tessitura are implementing tokenisation, however, that looked like it would initially be US only

    Mark

    From: Katherine Chien <bounce-katherinechien6297@tessituranetwork.com>
    Sent: 5/8/2014 6:53:40 PM

    Hello Tessitura folk, 

    We have been approached by a major Australian bank who is selling the idea that they can be in charge of PCI (Payment Card Industry) compliance for our organisation so that we don't have to store credit cards in Tessitura, saving us the time and money in regards to quarterly policy checks.

    This particular bank has stated that their system is compatible with Tessitura and everything will run the same, only their system will host the credit cards and 'bank' transactions for both ticketing and donations. 

    I'm curious to know which organisation has a major bank working with them on this front and what are the issues and implications of this?

    Your thoughts are gratefully appreciated. 

    Kind regards, 

    Katherine




    This message was sent automatically to you by www.tessituranetwork.com because you subscribed to the Tessitura Finance Forum. You may reply to this message to post to the Finance forum or visit the site to search, read and post to the forums. In the interest of keeping the forum posts from becoming cluttered, we encourage you to delete previous message text from your reply before sending. Thank you!

  • Hello,

    Just wanted to provide an update to this thread. The major Australian bank that had approached us with the idea of hosting PCI compliance has unfortunately overestimated its capabilities of facilitating this.

    Which is a shame because I'm sure every Australian arts organisation would be very interested in the prospect of not having to deal with the overly bureaucratic process of PCI quarterly checks.

    Perhaps it'll all happen in the distant future then...

    Cheers,

    Katherine