Laserfiche WebLink
problems,departments should notify the Treasurer of problems within a reasonable amount of time in order <br />to obtain assistance in a resolution and satisfy accounting requirements. <br />2)If a customer files a chargeback,the department from which the original charge was initiated will research <br />and dispute the charge in a timely manner.Hopefully,it was not a fraudulent charge and the customer <br />seeking the refund simply does not recognize the charge and may need more documentation. <br />Section 8:Confidentiality and Security of Account Information <br />In order to maintain confidentiality of data the following processes must be abided by: <br />1)Credit card information shall not be stored for future use such as periodic billing or partial payments.The <br />County shall not store credit card account numbers. <br />2)Only the last four digits of any credit card shall appear on a receipt or document where credit card <br />informationis displayed. <br />3)Any electronic media containing cardholder information shall be securely collected and held as <br />confidential. <br />4)The three digit card validation code printed on the signature panel of a credit card is never to be stored in <br />any form. <br />5)All transactions shall occur at workstations that have antivirus software installed and updated regularly. <br />6)Terminals shall be located in secure area during and after work hours to prevent unauthorized access. <br />Employees shall ensure logging off at the conclusion of the workday. <br />7)Background checks shall be performed prior to hiring or promoting any position with unrestricted access to <br />credit cardholder information. <br />Section 9:Process for Responding to a Security Breach <br />In the event of a security breach or suspected security breach the Department must do the following: <br />1)Comply with County Policy 17 Identity Theft Prevention Program. <br />2)Contact the IT Director to assure the preservation of any electronic evidence and remediation. <br />3)Alert the merchant bank,payment card association and Sheriff's office.The Department Head will notify <br />the Treasurer who will in turn notify the appropriate officials of any suspected breaches. <br />4)Within 48 hours of the breach the Department Head will provide the affected credit card association with <br />proof of PCI compliance. <br />5)Within 4 business days of the breach the Department Head will provide the affected credit card association <br />with an incident report. <br />6)At the request of the credit card association or depending on the level of risk and data elements <br />compromised the IT Director will arrange for a network system vulnerability scan. <br />7)In the event that personal data is exposed the department shall comply with County Policy 17 Identity Theft <br />Prevention Program. <br />Page 5 of 8 Pages Effective ,2019