08 - Admin - Campus Closure

UNO Alert: Due to the forecasted weather and out of an abundance of caution, UNO will move to remote operations on Friday, Feb. 20.

Skip to main content
University of Nebraska at Omaha logo University of Nebraska at Omaha
REQUEST INFO VISIT APPLY

MY UNO DIRECTORY
REQUEST INFO VISIT APPLY
MY UNO DIRECTORY
  • About Backback to Main menu
    • About
    • Mission and Strategic Plan
    • Leadership
    • Community Engagement
    • Buildings and Maps
    • Parking and Transit
    • Accreditation
    • News
    • Events
  • Admissions Backback to Main menu
    • Admissions
    • Undergraduate Admissions
    • Graduate Admissions
    • Transfer Students
    • Online Admissions
    • International Admissions
    • New Student Resources
    • Cost and Aid
  • Academics Backback to Main menu
    • Academics
    • Majors & Programs
    • Colleges
    • Academic Support
    • Library
    • Class Search
    • Course Catalogs
    • Academic Calendar
    • Advising
  • Student Life Backback to Main menu
    • Student Life
    • Student Leadership and Involvement
    • Spirit and Tradition
    • The Maverick Store
    • Student Housing
    • Campus Dining
    • Campus Recreation & Wellness
    • Health Services
    • Career Services & Internships
    • Student Events
  • Research Backback to Main menu
    • Research
    • Research Support
    • Centers and Institutes
    • Research News
  • Athletics
  • Alumni & Giving Backback to Main menu
    • Alumni Association
    • Thompson Center
    • NU Foundation

University of Nebraska Omaha logoUNO Campus Policies

Campus Policies

Primary Account Number (PAN) Data Security

  1. UNO
  2. University Policies
  3. Primary Account Number (PAN) Data Security

Policy Contents

  • Scope
  • Policy Statement
  • Reason for Policy
  • Procedures
  • Definitions
  • Additional Contacts
  • Related Information
  • History
  • Effective: 01-31-2015
  • Last Revised: 08-01-2016
  • Responsible University Administrator: Chief Information Officer
  • Responsible University Office: Information Security
  • Policy Contact: Information Security • security@unomaha.edu

Scope

This policy applies to all university personnel and entities responsible for managing and supporting systems within the scope of PCI, as well as those responsible for the acceptance and processing of payment card transactions.

This policy affects those PCI identified systems along with campus-wide implemented systems. Systems that are not centrally managed are to use this policy as best practice for information systems security within their respective information systems environments.

Policy Statement

The University of Nebraska Omaha (UNO) will ensure that unencrypted Primary Account Numbers (PAN) are not sent via end-user messaging technologies and that they adhere to the following conditions for purposes of complying with the Payment Card Industry Data Security Standards (PCI-DSS) initiatives.

Primary Account Numbers (PAN) will not be sent unencrypted via the following:

  • Email
  • Instant Messaging
  • Chat forums
  • Other applicable end-user technology

Cardholder data sent across open, public networks must be protected through the use of strong cryptography or security protocols such as AES-128 encryption and the TLS 1.2 network protocol.

 

Reason for Policy

In accordance with PCI-DSS requirements, UNO has established a formal policy supporting procedures regarding the encryption of PAN that are sent via electronic transmission.

Procedures

The procedures, which ensure that the unencrypted Primary Account Numbers (PAN) policy adheres to the requirements set forth for PCI-DSS compliance require observance of the aforementioned policies.

Definitions

Primary Account Number (PAN): Acronym for primary account number and also referred to as account number. Unique payment card number (typically for credit or debit cards) that identifies the issuer and the particular cardholder account.

Cardholder Data: Cardholder data is any personally identifiable information associated with a user of a credit/debit. Primary account number (PAN), name, expiry date, and card verification value 2 (CVV2) are included in this definition.

Encryption: Process of converting information into an unintelligible form except to holders of a specific cryptographic key. Use of encryption protects information between the encryption process and the decryption process (the inverse of encryption) against unauthorized disclosure.

Related Information

UNO Systems Access Control Policy

UNO Retention and Destruction/Disposal of Regulated Information Policy


 

References

This policy covers the following sections of PCI-DSS 3.2:

  • 3.4 Render PAN unreadable anywhere it is stored

History

This policy is an update to the Primary Account Number (PAN) Data Security Policy that was previously updated in 2015.

Services and Resources

  • Academic Calendar
  • Course Catalogs
  • MavCARD Services
  • MavLINK
  • my.unomaha.edu
  • UNO Brand Guide

Related Links

  • A-Z List
  • Employment
  • University of Nebraska System

Campus Links

  • Accessibility
  • Billing Office
  • Buildings and Maps
  • Campus Directory
  • Campus Safety
  • Events
  • Human Resources
  • Library
  • Military-Connected Resource Center
  • News
  • Registrar
  • Samuel Bak Museum: The Learning Center

Policies and Reporting

  • Emergency Information Alert
  • MavsReport
  • Notice of Nondiscrimination
  • NU Foundation
  • Privacy Statement
  • University Policies
  1. Privacy Statement
  2. Accessibility
  1. 402.554.2800

University of Nebraska at Omaha
University of Nebraska at Omaha, 6001 Dodge Street, Omaha, NE, 68182
  • ©  

Social Media


Omaha Skyline

Our Campus. Otherwise Known as Omaha.

The University of Nebraska does not discriminate based on race, color, ethnicity, national origin, sex, pregnancy, sexual orientation, gender identity, religion, disability, age, genetic information, veteran status, marital status, and/or political affiliation in its education programs or activities, including admissions and employment. The University prohibits any form of retaliation taken against anyone for reporting discrimination, harassment, or retaliation for otherwise engaging in protected activity. Read the full statement.