PCI DSS Self-Assessment Questionnaire (SAQ)
October 17, 2016
Dear Credit Card Merchant:
It’s time again for the PCI DSS Self-Assessment Questionnaire (SAQ).
As you know, the questionnaire is a crucial part of the University of Florida’s continuing compliance with the PCI Data Security Standard. Please respond to the SAQ’s questions 100% accurately. If necessary, seek assistance from your IT contact(s).
SAQs will once again be administered by CampusGuard Inc., our Qualified Security Assessor (QSA).
Prior to taking the assessment, review the login and password management procedures by watching the video tutorial at: https://mediasite.video.ufl.edu/Mediasite/Play/695a52fc6f9e4e64a9027143c2b235b91d.
Then, sign on to CampusGuard’s portal at https://www.campusguard.com/login.
Your user name is your UF email address and your password remained unchanged since last year. If you have difficulties logging in, click ‘Get help logging in’ on the login screen. From there, click ‘Forgot Password.’ When prompted, enter your email address.
We have concluded that the questionnaire applicable to your payment card operation will be SAQ B (41 questions or controls). This particular SAQ will be pre-populated when you sign in.
Please be aware that any “NO” response means non-compliance and thus will have to be addressed. For any “N/A” response, please use Appendix C, “Explanation of Non-Applicability” of your SAQ to describe why the related requirement does not apply to your merchant location.
Prior to the completion of the questionnaire, please make sure that the following items have been addressed:
- Completion of PCI online awareness training (TRM100 or TRM150)
- Submission of Ethics Certifications to Payment Card Operations
- Submission of current Departmental Procedures to Payment Card Operations
The deadline to complete the SAQ is Friday, Nov. 18.
Attached, please find:
- Guidelines v3.2
- PCI SAQ Worksheet 2016, which provides additional information on how to complete the initial sections and merchant information
Completion of the survey is mandatory in order to continue accepting credit card payments at your location. Non-compliance can result in substantial fines as well as restrictions on the merchant account. We will conduct visits with our merchants upon completion of this project to confirm the accuracy of their SAQ and to assist with future completions.
If you have any questions, please feel free to contact us. We thank you for your cooperation!
Banking & Merchant Services • Payment Card Operations • Treasury-CreditCards@ad.ufl.edu • 352.392.9057