Hi all, we are in the final stage of implementing PCI DSS in our organization. We have been following the various documents made by PCI Security Standard Council (primarily all PCI PA-DSS related docs) and Tessitura Network (Tessitura PA-DSS Implementation Guide) in addition to other related documents available from Visa, Master Card etc. while working on this project. Now we would like to make sure that we have covered all possible areas and met all the requirements to become PCI compliant. Is there anyone out there who became/soon will become PCI compliant and is willing to share their documentation with us? It will be great if you have a custom checklist and a general guideline used by your organization. I know the requirements may vary wildly depending on individual organization’s size, IT setup, business practice and client base. That’s why we are mostly interested in the documentation made by other NA based arts organizations and Tessitura licensees since most of us will have the similar setup. Anyway, anything – any general comment, direction or link to any other helpful doc in addition to the above – anyone can share will also be very helpful .
Thanks in advance for your any help.
Mo
Business AnalystThe National Ballet of Canada
Hi Mo,
We've been hard at work on PCI Compliance as well. I can send you the (20 page mammoth) policy we've come up with. I'll email it separately because I'm not comfortable putting it in the forum directly. As for a checklist we just used the PCI SAQ and made a Microsoft Project plan with the items we weren't currently compliant on so we could figure out how to get there. Our scale is larger than many because we're a level 3 merchant and we accept credit cards through avenues other than just Tessitura so there was a lot to do.
Best of luck! We're nearly there and planning a fun party once we finish this up.
Kjersten,
Could I get a copy of your policy also?
Thanks, Trudy Guest,
ArtTix Systems Administrator
801.323.6969
From: Tessitura Technical Forum [mailto:forums-technical@tessituranetwork.com] On Behalf Of Kjersten Schladetzky Sent: Thursday, May 12, 2011 10:57 AM To: Trudy Guest Subject: Re: [Tessitura Technical Forum] PCI DSS Requirements and Documentation
From: Mohiuddin Faruqe <bounce-mohiuddinfaruqe8297@tessituranetwork.com> Sent: 5/11/2011 10:16:47 AM
Business Analyst The National Ballet of Canada
This message was sent automatically to you by www.tessituranetwork.com because you subscribed to the Tessitura Technical Forum. You may reply to this message to post to the Technical forum or visit the site to search, read and post to the forums. In the interest of keeping the forum posts from becoming cluttered, we encourage you to delete previous message text from your reply before sending. Thank you!
Thanks Kjersten for sharing the info. Now I know where we are. No planning of fun party for us yet J
Best,
From: Tessitura Technical Forum [mailto:forums-technical@tessituranetwork.com] On Behalf Of Kjersten Schladetzky Sent: Thursday, May 12, 2011 12:57 PM To: Mohiuddin Faruqe Subject: Re: [Tessitura Technical Forum] PCI DSS Requirements and Documentation
Could I also receive a copy of your policy? We have the pleasure of going though PCI-DSS as well as SAS70.
Thanks,
Mike Tiernan
Systems Administrator
The Pittsburgh Cultural Trust
Hi, Kjersten, I’d love a copy as well.
Jeanne DeVore Technology Manager Chicago Shakespeare Theater jdevore@chicagoshakes.com 312 595-5603 www.chicagoshakes.com
From: Tessitura Technical Forum [mailto:forums-technical@tessituranetwork.com] On Behalf Of Kjersten Schladetzky Sent: Thursday, May 12, 2011 11:57 AM To: Jeanne DeVore Subject: Re: [Tessitura Technical Forum] PCI DSS Requirements and Documentation
I would love the document as well.
Dave AltonCIOCenter Theatre Groupdalton@centertheatregroup.org
I would like the document also.
Bobby Moseley
Computer Services Manager
601 Preston St.
Houston, TX 77002
713-535-3253
From: Tessitura Technical Forum [mailto:forums-technical@tessituranetwork.com] On Behalf Of Dave AltonSent: Thursday, May 12, 2011 9:32 PMTo: Moseley, BobbySubject: Re: [Tessitura Technical Forum] PCI DSS Requirements and Documentation
From: Mohiuddin Faruqe <bounce-mohiuddinfaruqe8297@tessituranetwork.com>Sent: 5/11/2011 10:16:47 AM
Could I also receive a copy?
Thanks
Dave
David Armstrong
Information Technology Manager
Cincinnati Symphony and Pops Orchestras
Riverbend Music Center
May Festival
Taft Theatre
513-621-1919 -- Main
|Cincinnati Symphony | Cincinnati Pops | Riverbend Music Center | May Festival |Taft Theatre |
From: Lee Schlosser [mailto:bounce-leeschlosser6477@tessituranetwork.com] Sent: Friday, May 13, 2011 10:32 AMTo: David ArmstrongSubject: RE: [Tessitura Technical Forum] PCI DSS Requirements and Documentation
We would appreciate receiving a copy also.
Thank you,
Lee Schlosser
IT/Business Manager
Florida Studio Theatre, Inc.
1241 North Palm Avenue
Sarasota, FL 34236
Phone: 941-366-9017 ext 328
Fax: 941-955-4137
email: lschlosser@floridastudiotheatre.org
website: www.floridastudiotheatre.org
From: Tessitura Technical Forum [mailto:forums-technical@tessituranetwork.com] On Behalf Of Kjersten SchladetzkySent: Thursday, May 12, 2011 12:57 PMTo: Lee SchlosserSubject: Re: [Tessitura Technical Forum] PCI DSS Requirements and Documentation
Hi Kjersten,
I'd appreciate a copy of the policy as well. Thanks so much for your willingness to share with everyone. I'm sure many of us are sharing the same compliance pains.
-David
Normal 0 false false false EN-US X-NONE X-NONE
David Wolfinbarger
Director of Technology and IS
Kansas City Repertory Theatre
4825 Troost Avenue Suite 212
Kansas City, MO 64110-2229
Office: 816-235-5559
E-Mail: wolfinbargerd@umkc.edu
Oops, meant to send that out directly. Due to the large demand I will post a very cleaned up version of the doc to my profile. It would be great if others would offer to share what they've put together as well - obviously this is a hot topic!
Got it! Thanks again and if you need anything please don’t hesitate to ask.
Cheers,
From: Tessitura Technical Forum [mailto:forums-technical@tessituranetwork.com] On Behalf Of Kjersten SchladetzkySent: Monday, May 16, 2011 9:32 AMTo: Tiernan, MichaelSubject: RE: [Tessitura Technical Forum] PCI DSS Requirements and Documentation
Here you go!
Kjersten Schladetzky
Project Manager, Information Technology Services
Science Museum of Minnesota
ph: 651-221-2507
From: Tessitura Technical Forum [mailto:forums-technical@tessituranetwork.com] On Behalf Of David ArmstrongSent: Friday, May 13, 2011 10:02 AMTo: kschladetzky@smm.orgSubject: RE: [Tessitura Technical Forum] PCI DSS Requirements and Documentation
SpamNot spamForget previous vote
Thank you for sending me the docs unfortunately I did not receive any attachments.
From: Kjersten Schladetzky [mailto:bounce-kjerstenschladetzky7557@tessituranetwork.com] Sent: Monday, May 16, 2011 9:32 AMTo: David ArmstrongSubject: RE: [Tessitura Technical Forum] PCI DSS Requirements and Documentation
Hello we too here at Boston Ballet are working through the Questionnaire D of the PCI standards. I would love to receive a copy of your 20 page report.
I was also wondering if anyone would want to have a group conference to discuss this most important initiative. If people are willing to discuss the PCI process at their organization I will host the conference call and lead the discussion. Please let me know of anyone's interest. Thanks.
As noted above, it is now saved to my profile so you download it directly. :-)