Pill Reminder Service Information Security Policy
OverviewThis policy is intended to relay the importance of security and protecting cardholder data.Purpose- To establish the Pill Reminder Service’s policy for the secure handling of sensitive card holder data including but not limited to magnetic strip data, Cardholder name, Primary Account Numbers (PAN’s), expiration date, and service code
- To establish the policies and procedures to manage the relationship(s) with Service Providers.
- Media is classified and clearly marked as confidential
- Media is sent by secured courier or other delivery method that can be accurately tracked
- Paper materials are to be shredded, incinerated, or pulped so that cardholder data cannot be reconstructed.
- The general rule is that media containing cardholder date will be destroyed when over 180 days old. Exceptions to the rule must be approved by senior management.
- A visit to the Service Providers physical offices to discuss security practices and procedure with their management and staff.
- A written statement acknowledging their responsibilities to securely process, handle and transmit cardholder data.
- Written proof that the Service Provider is PCI compliant.
- Request reliable industry references.