PCI Devices

PCI Compliance Device Services

Request assistance with PCI-compliant endpoint devices, including compliance monitoring, security maintenance, device replacement, and audit support for systems that process, transmit, or store payment card information.

Service Overview

PCI Compliance Device Services support endpoint devices that process, transmit, or store payment card information. These services help ensure devices remain compliant with Payment Card Industry Data Security Standard (PCI DSS) requirements through controlled configurations, security enforcement, continuous monitoring, documentation management, and lifecycle support in accordance with university and regulatory standards.

Only approved PCI-associated systems and devices are supported through this service. Devices handling payment card information must comply with university security standards and PCI DSS requirements.

Available PCI Services

PCI Compliance Monitoring

Request assistance with ongoing monitoring of PCI-associated systems and devices. This service tracks device status, security compliance, and configuration requirements while identifying potential compliance gaps that require remediation.

PCI Security Maintenance

Request support for PCI-related security updates, patch installation, vulnerability remediation, configuration reviews, and enforcement of required security controls to maintain PCI DSS compliance.

PCI Device Replacement

Request evaluation and replacement of PCI devices that are no longer supported, have reached end-of-life, no longer meet compliance requirements, or have experienced hardware failure. Replacement planning helps maintain uninterrupted and secure payment processing.

PCI Audit Support

Request documentation, compliance evidence, technical data, system information, or consultation assistance required during PCI DSS assessments, audits, compliance reviews, or regulatory examinations.

Who Can Submit a Request?

  • University departments responsible for PCI-compliant payment processing systems
  • Authorized employees who manage PCI-associated devices or applications
  • Departmental business officers or payment-processing coordinators
  • ITS staff supporting PCI-compliant environments
  • Individuals participating in PCI audits, reviews, or compliance assessments

Information to Have Ready

Depending on the request type, you may be asked to provide:

  • Device asset tag, serial number, or hostname
  • Department or business unit responsible for the device
  • Physical location of the PCI device
  • Description of the compliance, security, or operational concern
  • Audit, review, or project deadlines
  • Screenshots, error messages, or vulnerability findings
  • Vendor information when applicable
  • Supporting documentation related to PCI processing activities
  • Date the service or resolution is required

Tip: Providing complete device identification information and detailed descriptions of compliance concerns helps expedite review, remediation, and support activities.

What Happens After You Submit?

After your request is submitted, the assigned support team may:

  • Review device and compliance information provided
  • Assess current PCI compliance status and security posture
  • Identify configuration issues, vulnerabilities, or compliance gaps
  • Recommend or implement corrective actions
  • Coordinate device replacement activities when necessary
  • Gather documentation and evidence for audits or assessments
  • Work with other ITS teams, vendors, or departmental contacts
  • Provide status updates throughout the request lifecycle

Some requests may require coordination with Information Security, Internal Audit, Finance, external assessors, vendors, or other university stakeholders.

Important Information

  • PCI devices must comply with university security standards and PCI DSS requirements.
  • Systems processing payment card information are subject to additional security controls and monitoring.
  • Timely remediation of identified vulnerabilities may be required to maintain compliance.
  • Unsupported or end-of-life devices may require replacement to remain compliant.
  • Audit support services provide documentation and technical assistance but do not guarantee audit outcomes.
  • Some requests may require approval or coordination with departmental leadership.
  • Compliance reviews may identify additional actions necessary to meet regulatory requirements.
  • Failure to maintain PCI compliance may impact an area's ability to process payment card transactions.

Security Reminder: Never include full payment card numbers, CVV/CVC security codes, cardholder data, passwords, multifactor authentication codes, or other sensitive credentials in your request.

Ready to Submit Your Request?

Select the request type that best matches your need, gather the required device and compliance information, and use the Request Service button on this page to begin.