Laserfiche WebLink
problems, departments should notify the Treasurer of problems within a reasonable amount of time in order <br />to obtain assistance in a resolution and satisfy accounting requirements. <br />2) If a customer files a chargeback, the department from which the original charge was initiated will research <br />and dispute the charge in a timely manner. Hopefully, it was not a fraudulent charge and the customer <br />seeking the refund simply does not recognize the charge and may need more documentation. <br />Section 8: Confidentiality and Security of Account Information <br />In order to maintain confidentiality of data the following processes must be abided by : <br />I) Credit card information shall not be stored for future use such as periodic billing or partial payments. The <br />County shall not store credit card account numbers. <br />2) Only the last four digits of any credit card shall appear on a receipt or document where credit card <br />information is displayed. <br />3) Any electronic media containing cardholder information shall be securely collected and held as <br />confidential. <br />4) The three digit card validation code printed on the signature panel of a credit card is never to be stored in <br />any form. <br />5) All transactions shall occur at workstations that have antivirus software in stalled and updated regularly. <br />6) Terminals shall be located in secure area during and after work hours to prevent unauthorized access . <br />Employees shall ensure logging off at the conclusion of the workday. <br />7) Background checks shall be performed prior to hiring or promoting any position with unrestricted access to <br />credit cardholder information. <br />Section 9: Process for Responding to a Security Breach <br />In the event of a security breach or suspected security breach the Department must do the following: <br />1) Comply with County Policy 17 Identity Theft Prevention Program . <br />2) Contact the IT Director to assure the preservation of any electronic evidence and remediation. <br />3) Alert the merchant bank, payment card association and Sheriffs office. The Department Head will notify <br />the Treasurer who will in turn notify the appropriate officials of any suspected breaches. <br />4) Within 48 hours of the breach the Department Head will provide the affected credit card association with <br />proof of PCI compliance. <br />5) Within 4 business days of the breach the Department Head will provide the affected credit card association <br />with an incident report . <br />6) At the request of the credit card association or depending on the level ofrisk and data elements <br />compromised the IT Director will arrange for a network system vulnerability scan . <br />7) In the event that personal data is exposed the department shall comply with County Policy 17 Identity Theft <br />Prevention Program . <br />Page 5 of 8 Pages Effective _____ , 2019