<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://forums.blackbaud.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>PCI DSS Compliance</title><link>http://forums.blackbaud.com/forums/199.aspx</link><description>A dedicated discussion platform for the Payment Card Industry Data Security Standard</description><dc:language>en</dc:language><generator>CommunityServer 2007 SP2 (Debug Build: 20611.960)</generator><item><title>PCI DSS Compliance Policies</title><link>http://forums.blackbaud.com/forums/thread/45578.aspx</link><pubDate>Wed, 14 Oct 2009 19:32:44 GMT</pubDate><guid isPermaLink="false">f90a95a0-00e2-4810-8af8-0bbdde08f853:45578</guid><dc:creator>Sarah Coco</dc:creator><slash:comments>0</slash:comments><comments>http://forums.blackbaud.com/forums/thread/45578.aspx</comments><wfw:commentRss>http://forums.blackbaud.com/forums/commentrss.aspx?SectionID=199&amp;PostID=45578</wfw:commentRss><description>&lt;p&gt;Can anyone share their internal PCI DSS compliance document that relates to employee use and security of the system? I am starting one from scratch and thought it would be helpful to see written policies.&lt;/p&gt;
&lt;p&gt;Thanks for your help&lt;/p&gt;
&lt;p&gt;Sarah&lt;/p&gt;</description></item><item><title>Storing Hard copies of Credit Card Info</title><link>http://forums.blackbaud.com/forums/thread/44808.aspx</link><pubDate>Fri, 02 Oct 2009 20:57:22 GMT</pubDate><guid isPermaLink="false">f90a95a0-00e2-4810-8af8-0bbdde08f853:44808</guid><dc:creator>Mary Pelikan</dc:creator><slash:comments>1</slash:comments><comments>http://forums.blackbaud.com/forums/thread/44808.aspx</comments><wfw:commentRss>http://forums.blackbaud.com/forums/commentrss.aspx?SectionID=199&amp;PostID=44808</wfw:commentRss><description>&lt;p&gt;Hello&lt;/p&gt;
&lt;p&gt;with the new PCI standards that have come into place, is there somewhere in these policies that addresses the storing of Hard Copy Credit Card info? I can&amp;#39;t seem to find much infor,atopm pertaining to these controls, other than cross-shredding. please email me at &lt;a href="mailto:mpelikan@redemptorists-denver.org"&gt;mpelikan@redemptorists-denver.org&lt;/a&gt;. Thanks, &lt;/p&gt;</description></item><item><title>Changes in The Raiser's Edge 7.91</title><link>http://forums.blackbaud.com/forums/thread/42845.aspx</link><pubDate>Tue, 14 Jul 2009 14:37:48 GMT</pubDate><guid isPermaLink="false">f90a95a0-00e2-4810-8af8-0bbdde08f853:42845</guid><dc:creator>Douglas Clinton</dc:creator><slash:comments>0</slash:comments><comments>http://forums.blackbaud.com/forums/thread/42845.aspx</comments><wfw:commentRss>http://forums.blackbaud.com/forums/commentrss.aspx?SectionID=199&amp;PostID=42845</wfw:commentRss><description>&lt;p&gt;There&amp;#39;ve been a lot of changes in The Raiser&amp;#39;s Edge 7.91 and we know there are a lot of questions. Here are a few we&amp;#39;ve been hearing a lot.&lt;/p&gt;
&lt;p&gt;One of the first changes you&amp;#39;ll notice is that we&amp;#39;ve made changes to passwords. After you update to 7.91 or higher, you&amp;#39;ll have to enter your password using all capital letters (e.g., ADMIN1 instead of admin1. After you log in using all capital letters, we recommend that you change your password by going to Edit, Change Password. If you don&amp;#39;t change your password, you&amp;#39;ll have to keep using all capital letters to log in. The password changes are a requirement of the &lt;a href="http://www.blackbaud.com/esupport/esupport.asp?resource=&amp;amp;number=0&amp;amp;id=BB490172" target="_new"&gt;Payment Card Industry Data Security Standard&lt;/a&gt; (PCI DSS). Check out Knowledgebase solution &lt;a href="http://www.blackbaud.com/esupport/esupport.asp?resource=&amp;amp;number=0&amp;amp;id=BB608912" target="_new"&gt;BB608912&lt;/a&gt; for more info.&lt;/p&gt;
&lt;p&gt;Another big change is the 15 minute inactivity setting, which is another change made in accordance with PCI DSS, which requires users to re-enter passwords when a session has been idle for more than 15 minutes. When someone is locked out due to inactivity, processes like reports, mailings, exports, and queries will continue to run, and the user license will still be used. Knowledgebase solution &lt;a href="http://www.blackbaud.com/esupport/esupport.asp?resource=&amp;amp;number=0&amp;amp;id=BB620558" target="_new"&gt;BB620558&lt;/a&gt; has more on this setting.&lt;/p&gt;
&lt;p&gt;The most significant change is that The Raiser&amp;#39;s Edge 7.91 now integrates with the &lt;a href="http://www.blackbaud.com/esupport/esupport.asp?resource=&amp;amp;number=0&amp;amp;id=BB548354" target="_new"&gt;Blackbaud Payment Service&lt;/a&gt; (BBPS) to store credit card numbers. Credit card numbers will be replaced with reference tokens and credit card information is kept in this secure, PCI DSS-compliant environment and only the last four credit card digits will display in The Raiser&amp;#39;s Edge. When you process credit card transactions, your software will connect to the BBPS service. The reference token in your database will summon the stored credit card number to be used in the transaction.&lt;/p&gt;
&lt;p&gt;Check out the &lt;a href="http://www.blackbaud.com/support/faqs/re7.aspx#791" target="_new"&gt;Version 7.91 FAQs&lt;/a&gt; and post any questions you have here! I&amp;#39;ll be answering questions all day &lt;img src="http://forums.blackbaud.com/emoticons/emotion-1.gif" alt="Smile" /&gt;&lt;/p&gt;</description></item><item><title>Policy and Procedure </title><link>http://forums.blackbaud.com/forums/thread/42229.aspx</link><pubDate>Sun, 14 Jun 2009 23:36:37 GMT</pubDate><guid isPermaLink="false">f90a95a0-00e2-4810-8af8-0bbdde08f853:42229</guid><dc:creator>Josh Culver</dc:creator><slash:comments>0</slash:comments><comments>http://forums.blackbaud.com/forums/thread/42229.aspx</comments><wfw:commentRss>http://forums.blackbaud.com/forums/commentrss.aspx?SectionID=199&amp;PostID=42229</wfw:commentRss><description>&lt;p&gt;I am currently updating are policy and procedure manule to include PCI Compliance. In hope that I will not have to start from scrach I was wondering If any one would be willing to share, what they have put together so far. I have a basic outline from other sources and I would look as though I would have to pull from policies that are all ready inplace. But a template would be nice.&lt;/p&gt;</description></item><item><title>FE and RE interaction with PCI</title><link>http://forums.blackbaud.com/forums/thread/38163.aspx</link><pubDate>Fri, 21 Nov 2008 03:39:53 GMT</pubDate><guid isPermaLink="false">f90a95a0-00e2-4810-8af8-0bbdde08f853:38163</guid><dc:creator>Peter Scott</dc:creator><slash:comments>0</slash:comments><comments>http://forums.blackbaud.com/forums/thread/38163.aspx</comments><wfw:commentRss>http://forums.blackbaud.com/forums/commentrss.aspx?SectionID=199&amp;PostID=38163</wfw:commentRss><description>&lt;p&gt;We will be running RE7.85 after this weekend. This version is not complient with PCI.&lt;/p&gt;&lt;p&gt;There is also a new version of FE7.77 just released which is compliant with PCI.&lt;/p&gt;&lt;p&gt;What will the affect be on any postings, transactions and the like if FE is the recipient of the data, but you wish to view the revenue component in RE? What happens to the Credit Card number? &lt;br /&gt;&lt;/p&gt;</description></item><item><title>Credit Card use in Raiser's Edge</title><link>http://forums.blackbaud.com/forums/thread/33878.aspx</link><pubDate>Mon, 08 Sep 2008 17:47:36 GMT</pubDate><guid isPermaLink="false">f90a95a0-00e2-4810-8af8-0bbdde08f853:33878</guid><dc:creator>Stu Pattison</dc:creator><slash:comments>0</slash:comments><comments>http://forums.blackbaud.com/forums/thread/33878.aspx</comments><wfw:commentRss>http://forums.blackbaud.com/forums/commentrss.aspx?SectionID=199&amp;PostID=33878</wfw:commentRss><description>&lt;p&gt;Two questions:&lt;/p&gt;
&lt;p&gt;1)&amp;nbsp; How is credit card information stored in the Raiser&amp;#39;s Edge database?&amp;nbsp; Has this method been proven to be secure enough to meet the PCI Standard requirements?&lt;/p&gt;
&lt;p&gt;2)&amp;nbsp; We are setting up our firewall.&amp;nbsp; What port(s) and protocol(s) does Raiser&amp;#39;s Edge use to transmit and receive Credit Card information from IATS for processing?&amp;nbsp; We want to block all internet traffic except for this function.&lt;/p&gt;
&lt;p&gt;Thanks!&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Stu Pattison&amp;nbsp; WCPE-FM Radio - Wake Forest NC&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description></item><item><title>New Forums</title><link>http://forums.blackbaud.com/forums/thread/31571.aspx</link><pubDate>Fri, 20 Jun 2008 20:34:47 GMT</pubDate><guid isPermaLink="false">f90a95a0-00e2-4810-8af8-0bbdde08f853:31571</guid><dc:creator>Douglas Clinton</dc:creator><slash:comments>1</slash:comments><comments>http://forums.blackbaud.com/forums/thread/31571.aspx</comments><wfw:commentRss>http://forums.blackbaud.com/forums/commentrss.aspx?SectionID=199&amp;PostID=31571</wfw:commentRss><description>&lt;p&gt;Welcome to the PCI-DSS Forums, your place to discuss the new Payment Card Industry Data Security Standards with the rest of your online community.&amp;nbsp; You can also check out our &lt;a href="http://forums.blackbaud.com/blogs/pci/default.aspx" target="_new"&gt;PCI Compliance Blog&lt;/a&gt;!&lt;/p&gt;</description></item></channel></rss>