SlideShare uma empresa Scribd logo
1 de 2
Baixar para ler offline
December 15, 2005                                    Page 1 of 2                    Administrative Guide Memo 65


                                           Electronic Commerce


Authority         This Guide Memo was approved by the Vice President for Business Affairs and Chief Financial
                  Officer.
Applicability     This policy applies to all Stanford entities that generate revenue through fundraising or the
                  provision of goods or services.
Summary           This policy provides guidelines on the use of electronic commerce at Stanford. Section headings
                  are:
                  1.   DEFINITION
                  2.   PURPOSE
                  3.   POLICY
                  4.   IMPLEMENTATION GUIDELINES
                  5.   SOURCES OF MORE INFORMATION

 1.   DEFINITION
      For purposes of this policy, electronic commerce is defined as the use of electronic ordering and payment
      mechanisms via an interactive electronic mechanism such as the World Wide Web to effect remote payment
      for Stanford University goods or services. This policy does not cover business-to-business e-commerce
      pursuant to which the University purchases goods or services or to electronic ordering and payment
      mechanisms that are typically used between other businesses or institutions and Stanford University,
      usually referred to as Electronic Data Interchange (EDI) or Electronic Funds Transfer (EFT).

 2.   PURPOSE
      Electronic commerce provides a convenient way to handle business transactions such as conference
      registration or the purchase of course materials. However, reasonable steps should be taken to protect the
      personal information and privacy of purchasers. It is also in the University’s best interest to facilitate the
      transfer of electronic commerce transaction data to its financial systems. The purpose of this policy is to
      establish guidelines for electronic commerce.

 3.   POLICY
      a.   Relation to University Mission — Any use of electronic commerce at Stanford must be consistent with
           Guide Memo 15.3, Unrelated Business Activity, http://adminguide.stanford.edu/15_3.pdf, which
           prohibits the use of Stanford resources for any activity not related to the University’s mission.
      b. Authorized Vendor — Stanford has contracted with an internet commerce transaction services vendor
         to handle the authorization and management of electronic orders. This arrangement allows the
         University to:
           •    Consistently require the vendor to take necessary and reasonable steps to ensure that transactions
                are secure,
           •    Assure appropriate integration with University financial systems,
           •    Ensure that parties comply with Stanford name use and privacy policies,
           •    Use tested emergency response and recovery procedures,
           •    Leverage University transactions to reduce costs, and
           •    Provide current technology and support for developing applications.




                                                 Stanford University
December 15, 2005                                   Page 2 of 2                   Administrative Guide Memo 65


           Departments wishing to engage in electronic commerce must either use the authorized vendor to
           provide online order management services or offer evidence to the Controller, or his/her designee, that
           the selected vendor cannot meet the department’s business needs and that an alternative vendor meets
           University requirements for security and for integrating transaction information into Stanford financial
           systems. Note that all such agreements should be in accordance with Guide Memo 14, Academic and
           Business Relationships with Third Parties, http://adminguide.stanford.edu/14.pdf.
      c.   Confidentiality of Data — Departments are responsible for safeguarding the confidentiality of
           restricted and sensitive data related to purchases of goods or services as stated in Guide Memo 63,
           Information Security, http://adminguide.stanford.edu/63.pdf . Specific eCommerce guidelines are:
           (1)   Use secure and/or encrypted connections to the transaction service vendor (such as the one
                 provided to Stanford by its authorized vendor).
           (2)   Do not store any restricted electronic payment information (e.g., credit card numbers or PINs)
                 locally, without prior authorization from the risk assessment workgroup designated by
                 eCommerce Strategic Advisory Committee, (eSAC).
           (3)   If gathering other information about purchasers, protect this information in a secure manner,
                 restricting access to those who have a valid need to know.
           Departments should adhere to Stanford’s e-commerce privacy guidelines and security procedures,
           linking to the guidelines/procedures at each point-of-sale. If a valid business reason dictates departure
           from privacy guidelines, departments should explicitly advise customers at the point(s) of sale of how
           their practice departs from University guidelines.
      d. Advertising Policy — Departments are responsible for creating the web interface to the vendor's on-
         line order management system. If the website is in the stanford.edu domain, no third-party advertising
         is allowed.
 4.   IMPLEMENTATION GUIDELINES

      a.   Stanford eCommerce stores must meet the Payment Card Industry Customer Information Security
           Program (PCI-CISP) standards.

      b. Additional assistance on setting up and running an electronic commerce store is available on the
         eCommerce @ Stanford site. Departments should work with representatives of the eCommerce
         Technical Team, their applications development support team, Controller’s Office and Procurement to
         create their electronic commerce-enabled website.

 5.   SOURCES OF MORE INFORMATION
      •    Administrative Guide Memo 14, Academic and Business Relationships with Third Parties,
             http://adminguide.stanford.edu/14.pdf
      •    Administrative Guide Memo 15.3, Unrelated Business Activity,
            http://adminguide.stanford.edu/15_3.pdf
      •    Administrative Guide Memo 63, Information Security, http://adminguide.stanford.edu/63.pdf
      •    eCommerce @ Stanford, http://ecommerce.stanford.edu/
      •    Payment Card Industry - Customer Information Security Program (VISA),
            http://usa.visa.com/business/accepting_visa/ops_risk_management/cisp.html
      •    Information Security Office, http://security.stanford.edu
      •    Additional information security guidelines, procedures, standards, and practices can be found at
           http://securecomputing.stanford.edu




                                                Stanford University

Mais conteúdo relacionado

Semelhante a E Com

Navigating the expanding compliance perimeter smarsh 2016_notes_20 04 16_video
Navigating the expanding compliance perimeter smarsh 2016_notes_20 04 16_videoNavigating the expanding compliance perimeter smarsh 2016_notes_20 04 16_video
Navigating the expanding compliance perimeter smarsh 2016_notes_20 04 16_videoSmarsh
 
Fitsum ristu lakew transaction security on e-commerce
Fitsum ristu lakew transaction security on e-commerceFitsum ristu lakew transaction security on e-commerce
Fitsum ristu lakew transaction security on e-commerceFITSUM RISTU LAKEW
 
Wollmuth Maher & Deutsch LLP -Takeaways From The SEC Cybersecurity Examinatio...
Wollmuth Maher & Deutsch LLP -Takeaways From The SEC Cybersecurity Examinatio...Wollmuth Maher & Deutsch LLP -Takeaways From The SEC Cybersecurity Examinatio...
Wollmuth Maher & Deutsch LLP -Takeaways From The SEC Cybersecurity Examinatio...Jason Glass, CFA, CISSP
 
DATA Working Group - Consumer Best Practices
DATA Working Group - Consumer Best PracticesDATA Working Group - Consumer Best Practices
DATA Working Group - Consumer Best PracticesDataSecretariat
 
Upgrade Your Banking Experience with Advanced Core Banking Applications
Upgrade Your Banking Experience with Advanced Core Banking ApplicationsUpgrade Your Banking Experience with Advanced Core Banking Applications
Upgrade Your Banking Experience with Advanced Core Banking ApplicationsIntellect Design Arena Ltd
 
E-business application in the Supermarket sector
E-business application in the Supermarket sectorE-business application in the Supermarket sector
E-business application in the Supermarket sectorManish Ragoobeer
 
FTC overview on glba final rule on safeguards 2010 Compliance Presentation
FTC overview on glba final rule on safeguards 2010 Compliance PresentationFTC overview on glba final rule on safeguards 2010 Compliance Presentation
FTC overview on glba final rule on safeguards 2010 Compliance PresentationBrent Hillyer
 
PCI Certification and remediation services
PCI Certification and remediation servicesPCI Certification and remediation services
PCI Certification and remediation servicesTariq Juneja
 
Streamlining Success Mastering the Merchant Onboarding Process.pptx
Streamlining Success Mastering the Merchant Onboarding Process.pptxStreamlining Success Mastering the Merchant Onboarding Process.pptx
Streamlining Success Mastering the Merchant Onboarding Process.pptxmohakbariatric
 
What Strategies Are Crucial for Ensuring eCommerce Security in the Digital Era?
What Strategies Are Crucial for Ensuring eCommerce Security in the Digital Era?What Strategies Are Crucial for Ensuring eCommerce Security in the Digital Era?
What Strategies Are Crucial for Ensuring eCommerce Security in the Digital Era?Lucy Zeniffer
 
Introduction-to-M-commerce Mobile Apps.pptx
Introduction-to-M-commerce Mobile Apps.pptxIntroduction-to-M-commerce Mobile Apps.pptx
Introduction-to-M-commerce Mobile Apps.pptxVLink Inc
 
Steps To Create Your Own Payment Gateway
Steps To Create Your Own Payment GatewaySteps To Create Your Own Payment Gateway
Steps To Create Your Own Payment GatewayITIO Innovex
 
Data engineering Use Cases in financial industry.pdf
Data engineering Use Cases in financial industry.pdfData engineering Use Cases in financial industry.pdf
Data engineering Use Cases in financial industry.pdfshreyathaker
 

Semelhante a E Com (20)

Aggregation Platforms-White Paper
Aggregation Platforms-White PaperAggregation Platforms-White Paper
Aggregation Platforms-White Paper
 
Navigating the expanding compliance perimeter smarsh 2016_notes_20 04 16_video
Navigating the expanding compliance perimeter smarsh 2016_notes_20 04 16_videoNavigating the expanding compliance perimeter smarsh 2016_notes_20 04 16_video
Navigating the expanding compliance perimeter smarsh 2016_notes_20 04 16_video
 
Fitsum ristu lakew transaction security on e-commerce
Fitsum ristu lakew transaction security on e-commerceFitsum ristu lakew transaction security on e-commerce
Fitsum ristu lakew transaction security on e-commerce
 
E-Commerce
E-CommerceE-Commerce
E-Commerce
 
Wollmuth Maher & Deutsch LLP -Takeaways From The SEC Cybersecurity Examinatio...
Wollmuth Maher & Deutsch LLP -Takeaways From The SEC Cybersecurity Examinatio...Wollmuth Maher & Deutsch LLP -Takeaways From The SEC Cybersecurity Examinatio...
Wollmuth Maher & Deutsch LLP -Takeaways From The SEC Cybersecurity Examinatio...
 
Unit i
Unit iUnit i
Unit i
 
DATA Working Group - Consumer Best Practices
DATA Working Group - Consumer Best PracticesDATA Working Group - Consumer Best Practices
DATA Working Group - Consumer Best Practices
 
Upgrade Your Banking Experience with Advanced Core Banking Applications
Upgrade Your Banking Experience with Advanced Core Banking ApplicationsUpgrade Your Banking Experience with Advanced Core Banking Applications
Upgrade Your Banking Experience with Advanced Core Banking Applications
 
E-business application in the Supermarket sector
E-business application in the Supermarket sectorE-business application in the Supermarket sector
E-business application in the Supermarket sector
 
E commerce
E commerceE commerce
E commerce
 
FTC overview on glba final rule on safeguards 2010 Compliance Presentation
FTC overview on glba final rule on safeguards 2010 Compliance PresentationFTC overview on glba final rule on safeguards 2010 Compliance Presentation
FTC overview on glba final rule on safeguards 2010 Compliance Presentation
 
PCI Certification and remediation services
PCI Certification and remediation servicesPCI Certification and remediation services
PCI Certification and remediation services
 
Paps 1013
Paps 1013Paps 1013
Paps 1013
 
Streamlining Success Mastering the Merchant Onboarding Process.pptx
Streamlining Success Mastering the Merchant Onboarding Process.pptxStreamlining Success Mastering the Merchant Onboarding Process.pptx
Streamlining Success Mastering the Merchant Onboarding Process.pptx
 
What Strategies Are Crucial for Ensuring eCommerce Security in the Digital Era?
What Strategies Are Crucial for Ensuring eCommerce Security in the Digital Era?What Strategies Are Crucial for Ensuring eCommerce Security in the Digital Era?
What Strategies Are Crucial for Ensuring eCommerce Security in the Digital Era?
 
Introduction-to-M-commerce Mobile Apps.pptx
Introduction-to-M-commerce Mobile Apps.pptxIntroduction-to-M-commerce Mobile Apps.pptx
Introduction-to-M-commerce Mobile Apps.pptx
 
SEC440: Incident Response Plan
SEC440: Incident Response PlanSEC440: Incident Response Plan
SEC440: Incident Response Plan
 
Steps To Create Your Own Payment Gateway
Steps To Create Your Own Payment GatewaySteps To Create Your Own Payment Gateway
Steps To Create Your Own Payment Gateway
 
Master Class Cyber Compliance
Master Class Cyber Compliance Master Class Cyber Compliance
Master Class Cyber Compliance
 
Data engineering Use Cases in financial industry.pdf
Data engineering Use Cases in financial industry.pdfData engineering Use Cases in financial industry.pdf
Data engineering Use Cases in financial industry.pdf
 

Mais de Nirmal Pandya

Mais de Nirmal Pandya (10)

Crm Project
Crm ProjectCrm Project
Crm Project
 
Crm
CrmCrm
Crm
 
Credit Policy Of Icici
Credit Policy Of IciciCredit Policy Of Icici
Credit Policy Of Icici
 
Credit Policy Of Hdfc
Credit Policy Of HdfcCredit Policy Of Hdfc
Credit Policy Of Hdfc
 
Credit Policy Of Rbi
Credit Policy Of RbiCredit Policy Of Rbi
Credit Policy Of Rbi
 
Credit Policies
Credit PoliciesCredit Policies
Credit Policies
 
Co Operative Marketing
Co Operative MarketingCo Operative Marketing
Co Operative Marketing
 
Buy Back Of Shares
Buy Back Of SharesBuy Back Of Shares
Buy Back Of Shares
 
Bosnia and Herzegovina Financial Sector Report
Bosnia and Herzegovina Financial Sector ReportBosnia and Herzegovina Financial Sector Report
Bosnia and Herzegovina Financial Sector Report
 
Business Ethics
Business EthicsBusiness Ethics
Business Ethics
 

Último

The Most Excellent Way | 1 Corinthians 13
The Most Excellent Way | 1 Corinthians 13The Most Excellent Way | 1 Corinthians 13
The Most Excellent Way | 1 Corinthians 13Steve Thomason
 
Software Engineering Methodologies (overview)
Software Engineering Methodologies (overview)Software Engineering Methodologies (overview)
Software Engineering Methodologies (overview)eniolaolutunde
 
Accessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactAccessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactdawncurless
 
Ecosystem Interactions Class Discussion Presentation in Blue Green Lined Styl...
Ecosystem Interactions Class Discussion Presentation in Blue Green Lined Styl...Ecosystem Interactions Class Discussion Presentation in Blue Green Lined Styl...
Ecosystem Interactions Class Discussion Presentation in Blue Green Lined Styl...fonyou31
 
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxSOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxiammrhaywood
 
Nutritional Needs Presentation - HLTH 104
Nutritional Needs Presentation - HLTH 104Nutritional Needs Presentation - HLTH 104
Nutritional Needs Presentation - HLTH 104misteraugie
 
BAG TECHNIQUE Bag technique-a tool making use of public health bag through wh...
BAG TECHNIQUE Bag technique-a tool making use of public health bag through wh...BAG TECHNIQUE Bag technique-a tool making use of public health bag through wh...
BAG TECHNIQUE Bag technique-a tool making use of public health bag through wh...Sapna Thakur
 
Disha NEET Physics Guide for classes 11 and 12.pdf
Disha NEET Physics Guide for classes 11 and 12.pdfDisha NEET Physics Guide for classes 11 and 12.pdf
Disha NEET Physics Guide for classes 11 and 12.pdfchloefrazer622
 
Arihant handbook biology for class 11 .pdf
Arihant handbook biology for class 11 .pdfArihant handbook biology for class 11 .pdf
Arihant handbook biology for class 11 .pdfchloefrazer622
 
Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..Disha Kariya
 
Z Score,T Score, Percential Rank and Box Plot Graph
Z Score,T Score, Percential Rank and Box Plot GraphZ Score,T Score, Percential Rank and Box Plot Graph
Z Score,T Score, Percential Rank and Box Plot GraphThiyagu K
 
Class 11th Physics NEET formula sheet pdf
Class 11th Physics NEET formula sheet pdfClass 11th Physics NEET formula sheet pdf
Class 11th Physics NEET formula sheet pdfAyushMahapatra5
 
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...EduSkills OECD
 
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Krashi Coaching
 
A Critique of the Proposed National Education Policy Reform
A Critique of the Proposed National Education Policy ReformA Critique of the Proposed National Education Policy Reform
A Critique of the Proposed National Education Policy ReformChameera Dedduwage
 
9548086042 for call girls in Indira Nagar with room service
9548086042  for call girls in Indira Nagar  with room service9548086042  for call girls in Indira Nagar  with room service
9548086042 for call girls in Indira Nagar with room servicediscovermytutordmt
 
Introduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The BasicsIntroduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The BasicsTechSoup
 
Unit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptxUnit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptxVishalSingh1417
 
Interactive Powerpoint_How to Master effective communication
Interactive Powerpoint_How to Master effective communicationInteractive Powerpoint_How to Master effective communication
Interactive Powerpoint_How to Master effective communicationnomboosow
 

Último (20)

INDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptx
INDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptxINDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptx
INDIA QUIZ 2024 RLAC DELHI UNIVERSITY.pptx
 
The Most Excellent Way | 1 Corinthians 13
The Most Excellent Way | 1 Corinthians 13The Most Excellent Way | 1 Corinthians 13
The Most Excellent Way | 1 Corinthians 13
 
Software Engineering Methodologies (overview)
Software Engineering Methodologies (overview)Software Engineering Methodologies (overview)
Software Engineering Methodologies (overview)
 
Accessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impactAccessible design: Minimum effort, maximum impact
Accessible design: Minimum effort, maximum impact
 
Ecosystem Interactions Class Discussion Presentation in Blue Green Lined Styl...
Ecosystem Interactions Class Discussion Presentation in Blue Green Lined Styl...Ecosystem Interactions Class Discussion Presentation in Blue Green Lined Styl...
Ecosystem Interactions Class Discussion Presentation in Blue Green Lined Styl...
 
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptxSOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
SOCIAL AND HISTORICAL CONTEXT - LFTVD.pptx
 
Nutritional Needs Presentation - HLTH 104
Nutritional Needs Presentation - HLTH 104Nutritional Needs Presentation - HLTH 104
Nutritional Needs Presentation - HLTH 104
 
BAG TECHNIQUE Bag technique-a tool making use of public health bag through wh...
BAG TECHNIQUE Bag technique-a tool making use of public health bag through wh...BAG TECHNIQUE Bag technique-a tool making use of public health bag through wh...
BAG TECHNIQUE Bag technique-a tool making use of public health bag through wh...
 
Disha NEET Physics Guide for classes 11 and 12.pdf
Disha NEET Physics Guide for classes 11 and 12.pdfDisha NEET Physics Guide for classes 11 and 12.pdf
Disha NEET Physics Guide for classes 11 and 12.pdf
 
Arihant handbook biology for class 11 .pdf
Arihant handbook biology for class 11 .pdfArihant handbook biology for class 11 .pdf
Arihant handbook biology for class 11 .pdf
 
Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..
 
Z Score,T Score, Percential Rank and Box Plot Graph
Z Score,T Score, Percential Rank and Box Plot GraphZ Score,T Score, Percential Rank and Box Plot Graph
Z Score,T Score, Percential Rank and Box Plot Graph
 
Class 11th Physics NEET formula sheet pdf
Class 11th Physics NEET formula sheet pdfClass 11th Physics NEET formula sheet pdf
Class 11th Physics NEET formula sheet pdf
 
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
 
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
Kisan Call Centre - To harness potential of ICT in Agriculture by answer farm...
 
A Critique of the Proposed National Education Policy Reform
A Critique of the Proposed National Education Policy ReformA Critique of the Proposed National Education Policy Reform
A Critique of the Proposed National Education Policy Reform
 
9548086042 for call girls in Indira Nagar with room service
9548086042  for call girls in Indira Nagar  with room service9548086042  for call girls in Indira Nagar  with room service
9548086042 for call girls in Indira Nagar with room service
 
Introduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The BasicsIntroduction to Nonprofit Accounting: The Basics
Introduction to Nonprofit Accounting: The Basics
 
Unit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptxUnit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptx
 
Interactive Powerpoint_How to Master effective communication
Interactive Powerpoint_How to Master effective communicationInteractive Powerpoint_How to Master effective communication
Interactive Powerpoint_How to Master effective communication
 

E Com

  • 1. December 15, 2005 Page 1 of 2 Administrative Guide Memo 65 Electronic Commerce Authority This Guide Memo was approved by the Vice President for Business Affairs and Chief Financial Officer. Applicability This policy applies to all Stanford entities that generate revenue through fundraising or the provision of goods or services. Summary This policy provides guidelines on the use of electronic commerce at Stanford. Section headings are: 1. DEFINITION 2. PURPOSE 3. POLICY 4. IMPLEMENTATION GUIDELINES 5. SOURCES OF MORE INFORMATION 1. DEFINITION For purposes of this policy, electronic commerce is defined as the use of electronic ordering and payment mechanisms via an interactive electronic mechanism such as the World Wide Web to effect remote payment for Stanford University goods or services. This policy does not cover business-to-business e-commerce pursuant to which the University purchases goods or services or to electronic ordering and payment mechanisms that are typically used between other businesses or institutions and Stanford University, usually referred to as Electronic Data Interchange (EDI) or Electronic Funds Transfer (EFT). 2. PURPOSE Electronic commerce provides a convenient way to handle business transactions such as conference registration or the purchase of course materials. However, reasonable steps should be taken to protect the personal information and privacy of purchasers. It is also in the University’s best interest to facilitate the transfer of electronic commerce transaction data to its financial systems. The purpose of this policy is to establish guidelines for electronic commerce. 3. POLICY a. Relation to University Mission — Any use of electronic commerce at Stanford must be consistent with Guide Memo 15.3, Unrelated Business Activity, http://adminguide.stanford.edu/15_3.pdf, which prohibits the use of Stanford resources for any activity not related to the University’s mission. b. Authorized Vendor — Stanford has contracted with an internet commerce transaction services vendor to handle the authorization and management of electronic orders. This arrangement allows the University to: • Consistently require the vendor to take necessary and reasonable steps to ensure that transactions are secure, • Assure appropriate integration with University financial systems, • Ensure that parties comply with Stanford name use and privacy policies, • Use tested emergency response and recovery procedures, • Leverage University transactions to reduce costs, and • Provide current technology and support for developing applications. Stanford University
  • 2. December 15, 2005 Page 2 of 2 Administrative Guide Memo 65 Departments wishing to engage in electronic commerce must either use the authorized vendor to provide online order management services or offer evidence to the Controller, or his/her designee, that the selected vendor cannot meet the department’s business needs and that an alternative vendor meets University requirements for security and for integrating transaction information into Stanford financial systems. Note that all such agreements should be in accordance with Guide Memo 14, Academic and Business Relationships with Third Parties, http://adminguide.stanford.edu/14.pdf. c. Confidentiality of Data — Departments are responsible for safeguarding the confidentiality of restricted and sensitive data related to purchases of goods or services as stated in Guide Memo 63, Information Security, http://adminguide.stanford.edu/63.pdf . Specific eCommerce guidelines are: (1) Use secure and/or encrypted connections to the transaction service vendor (such as the one provided to Stanford by its authorized vendor). (2) Do not store any restricted electronic payment information (e.g., credit card numbers or PINs) locally, without prior authorization from the risk assessment workgroup designated by eCommerce Strategic Advisory Committee, (eSAC). (3) If gathering other information about purchasers, protect this information in a secure manner, restricting access to those who have a valid need to know. Departments should adhere to Stanford’s e-commerce privacy guidelines and security procedures, linking to the guidelines/procedures at each point-of-sale. If a valid business reason dictates departure from privacy guidelines, departments should explicitly advise customers at the point(s) of sale of how their practice departs from University guidelines. d. Advertising Policy — Departments are responsible for creating the web interface to the vendor's on- line order management system. If the website is in the stanford.edu domain, no third-party advertising is allowed. 4. IMPLEMENTATION GUIDELINES a. Stanford eCommerce stores must meet the Payment Card Industry Customer Information Security Program (PCI-CISP) standards. b. Additional assistance on setting up and running an electronic commerce store is available on the eCommerce @ Stanford site. Departments should work with representatives of the eCommerce Technical Team, their applications development support team, Controller’s Office and Procurement to create their electronic commerce-enabled website. 5. SOURCES OF MORE INFORMATION • Administrative Guide Memo 14, Academic and Business Relationships with Third Parties, http://adminguide.stanford.edu/14.pdf • Administrative Guide Memo 15.3, Unrelated Business Activity, http://adminguide.stanford.edu/15_3.pdf • Administrative Guide Memo 63, Information Security, http://adminguide.stanford.edu/63.pdf • eCommerce @ Stanford, http://ecommerce.stanford.edu/ • Payment Card Industry - Customer Information Security Program (VISA), http://usa.visa.com/business/accepting_visa/ops_risk_management/cisp.html • Information Security Office, http://security.stanford.edu • Additional information security guidelines, procedures, standards, and practices can be found at http://securecomputing.stanford.edu Stanford University