New Training for UCSF Merchant Departments Due by January 31, 2025

In December, UCSF Merchant Services announced the release of an updated Payment Card Industry Data Security Standards (PCI DSS) training curriculum. UCSF's new Payment Card Industry (PCI) Security Awareness Training is designed to familiarize employees, merchants, executives, and IT staff with credit card security issues and enhance their skills in maintaining the security and safety of the UCSF payment card environment and cardholder data.

All employees handling payment card and cardholder information and their managers are required to complete training upon hire, and annually thereafter.

Training is segmented into five modules tailored by role and covers the specific responsibilities of merchants, cashiers, IT professionals, and managers. Merchant staff must complete only the modules relevant to their merchant role or roles.

  • PCI for Cashiers: required for all students and cashiers who process card payments one at a time
  • PCI for eCommerce: required for all merchant/department staff and managers responsible for managing and maintaining ecommerce/online stores only
  • PCI for Merchant Process Managers: required for all merchant/department managers
  • PCI for Information Technology Staff: required for all system administrators and IT staff responsible for securing systems within the Cardholder Data Environment
  • PCI for Executives: recommended for all heads of unit (campus) and senior executives/executive directors (UCSF Health) of merchant departments that accept credit cards

All staff, including managers, with a role in your department’s merchant activity must be assigned and complete the new, relevant PCI DSS training module to meet regulatory requirements. Staff managers should complete the steps of assigning their respective staff. The deadline to complete training is January 31, 2025.

Merchant department managers were contacted on December 10, 2024, with instructions for identifying and assigning training for relevant staff. Managers can refer to How to Assign and Monitor Required Controller’s Office Training Available in the UC Learning Center for step-by-step instructions.

For questions or assistance, please email [email protected].