Browsers that can not handle javascript will not be able to access some features of this site.
Skip Navigation
Department of Information TechnologyMichigan.gov
Michigan.gov Home Home | Contact Us | Useful Links | FAQ
Printer Friendly Version Printer Friendly   Text Only Version Text Version  Share this page.
Michigan Maintains Certification for Payment Card Security Standards

Contact:  Kurt Weiss (517) 335-0050
Agency: Information Technology


Michigan Government Earns Rigorous 'PCI Compliance' Again

Lansing   , MI -   Michigan government has again been certified that it is compliant with the Payment Card Industry's (PCI) strict standards for ensuring that cardholder information is protected and secure.  The PCI Data Security Standards apply to financial institutions, Internet vendors and retail merchants and detail the security measures and auditing procedures required to protect private cardholder information during payment card transactions.  All major card brands require these Data Security Standards to assure the protection of cardholder data gathered during transactions. 

"This is a big win for us and I am proud of the collaboration and teamwork that took place to get this done for all of state government," said Ken Theis, Director of the Michigan Department of Information Technology (MDIT) and CIO for the State of Michigan.  "We have a responsibility to meet the strict standards for safe and secure transactions when citizens share their payment card information with the state, and we take that responsibility very seriously."

The effort to get Michigan recertified has eliminated fines the state would have had to pay for being out of compliance, and it also reduces costs for the state through reduced transaction fees.  Many state governments do not have centralized management of credit cards like Michigan, which means Michigan is one of the few states to have PCI compliance for all state credit card applications. 

"Compliance with the Payment Card Industry's strict security standards is no small feat," added State Treasurer Robert Kleine.  "I am extremely proud of what we have done to get to this point, proud of our partnership with MDIT, and proud that we are living up to the trust that our citizens place in the hands of their government."

One of the major accomplishments in achieving compliance was installing new credit card readers in all of the Secretary of State Branch Offices that accept credit cards, which included making programming changes to the branch office system to allow for the encryption and de-encryption of the data.  MDIT worked in close collaboration with the Department of Treasury to ensure success.

Some of the other major steps required for compliance include:

·         Maintaining a firewall configuration to protect cardholder data

·         Not using vendor-supplied defaults for system passwords

·         Protecting stored cardholder data

·         Encrypting transmission of data across open/public networks

·         Using and updating anti-virus software

·         Developing and maintaining secure systems and applications

·         Restricting access to cardholder data to the need-to-know business

·         Assigning a unique ID to each person with computer access

·         Restricting physical access to cardholder data

·         Tracking and monitoring access to network resources

·         Regularly testing security systems and processes

·         Maintaining a policy focused on information security

"Our goal is to keep citizen information safe and secure," added Trent Carpenter, Chief Information Security Officer for MDIT.  "This effort is a prime example of the importance we place on doing everything possible to meet that goal."

For more information about PCI security standards, please visit:

https://www.pcisecuritystandards.org/

 

Michigan Business One Stop
Link to Department and Agencies Web Site Index
Link to Statewide Online Services Index
Link to Statewide Web-based Surveys
Link to RSS feeds available on this site
Related Content
 •  Michigan Government Earns Coveted 'PCI Compliance'
 •  Students Connected to Free Lunches
 •  Michigan E-Store Gets a New Look
 •  Governor Appoints Kenneth Theis Director of Department of Information Technology
 •  Three More National Awards for Michigan Government Technology
 •  Brown University Names Michigan as One of Best in American e-Government
 •  Google, State of Michigan Announce Partnership to Enhance Internet Search Capabilities
 •  Michigan Receives Statewide Leadership Advocacy Award
 •  Efficiency Gains Continue Through Closing of Computer Centers
 •  E-mail Consolidation Reduces Cost of Michigan Government
 •  State of Michigan Web Site Now Offers Eight Foreign Languages
 •  CyberMichigan Set for Transition
 •  Michigan Technology Leader Recognized for Excellence
 •  Michigan Web Site Receives the Only A+
 •  Michigan Recognized for Outstanding Achievement in Technology
 •  Excellence in Technology Awards Presented at Digital Summit
 •  State of Michigan Launches Computer Security Center
 •  Michigan Retains Number One Ranking in Digital Government
 •  Citizens Reminded to Take Precaution While Online
 •  Partnership Leads to More Online Communities

Michigan.gov Home | Home | Sitemap | State Web Sites
Privacy Policy | Link Policy | Accessibility Policy | Security Policy | Michigan News | Michigan.gov Survey

Copyright © 2001-2009 State of Michigan