What is PCI DSS and how did it evolve

As described in the Introduction to Superior Card Processor, Inc., you are an employee of SCP’s Chief Information Officer and head of IT in charge of encryption and data security. You have accepted the position of Project Manager for the Information Governance Team tasked with designing and implementing companywide an Information Governance Plan or Program for the organization that will address the concerns expressed in the company introduction.

1. You will need to discuss with your IG Team the different organizations, associations, affiliates and agencies who provide standards, oversight and accountability for credit card processing organizations such as yourself, as well as for the Merchants and Merchant Banks that you service. You will need to discuss with your team the significance of PCI DSS. In order to be enlighten your team members, conduct the necessary research to be able to respond to the following questions.

a. Who, or what organizations, bodies, associations, affiliates, etc., are responsible for setting standards, providing oversight and insuring accountability for data security and information governance in the credit card processing industry;

b. What is PCI DSS and how did it evolve;

c. Which player(s) in the credit card processing industry are affected or impacted by PCI DSS and in what way;

d. Who is responsible for setting standards and insuring compliance with PCI DSS;

e. Specifically how PCI DSS and the associated topics researched will impact SCP’s Information Governance design and implementation plan/program.

2. You, as Project Manager, are ready to select the members of your Information Governance Team who will be responsible for the design and implementation of the company wide Information Governance Plan or Program. Collectively, including yourself, the Project Manager, the Board of Directors for SCP have informed you that IG design and implementation team will consist of 10 representative from the different functional units of MBA. You have been told by the Board of Directors that you may hand pick 5 members of your team, and that after you have selected those you deem most important to the success of the project, that the Board of Directors, with input from SCP’s executive officers will appoint the remaining four (4) members of your team. Explain which five (5) representatives you would request be a member of your team. For each member selected, explain why you chose that representative.

3. You have been asked by the Board of Directors and Executive Officers to identify what

you expect (at this early stage in the process) to be the major tasks, steps or milestones

(whichever you choose to call it) in the design and implementation for the Information

Governance Plan or Program for SCP. Explain the order in which each of these major

tasks or steps will be taken, whether any can be performed at the same time, which must

be completed before beginning the next task or step, and try to project roughly how long

each will take. For each major task or step in this design and implementation process,

describe generally for the Board of Directors and Executive Officers what will take place

in task or step. That is, you are being asked to develop a high level plan that sets out the

major tasks to be accomplished, the order (steps) in which the tasks will need to be

performed, and an estimate of the time frame for accomplishing each step, in order to

complete the design and implement for the IG Plan or Program for SCP. This should be

the blueprint that you and your team will follow. In other words, explain how you and

your team will go about the business of designing and implementing the IG program for

the company. It is NOT the IG Program itself. This should be something that you will give

the Board of Directors and Executive Officers, as well as your team members, as the

“master plan” for accomplishing the goal of IG at Superior Card Processing, Inc. You may

use as many lists, diagrams, tables, drawings, illustrations or charts that will facilitate your

explanation. However, you are not to substitute these aids for your narrative explanation.

Further, in your narrative explanation, do not rely on bulleted items. You may include

bullet points, but they must have complete explanations in sentence form.

Please refer to the documents attached plus support your answers with peer reviewed articles or genuine sources. It should be a 5 page paper.

