SlideShare a Scribd company logo
1 of 2
Download to read offline
December 15, 2005                                    Page 1 of 2                    Administrative Guide Memo 65


                                           Electronic Commerce


Authority         This Guide Memo was approved by the Vice President for Business Affairs and Chief Financial
                  Officer.
Applicability     This policy applies to all Stanford entities that generate revenue through fundraising or the
                  provision of goods or services.
Summary           This policy provides guidelines on the use of electronic commerce at Stanford. Section headings
                  are:
                  1.   DEFINITION
                  2.   PURPOSE
                  3.   POLICY
                  4.   IMPLEMENTATION GUIDELINES
                  5.   SOURCES OF MORE INFORMATION

 1.   DEFINITION
      For purposes of this policy, electronic commerce is defined as the use of electronic ordering and payment
      mechanisms via an interactive electronic mechanism such as the World Wide Web to effect remote payment
      for Stanford University goods or services. This policy does not cover business-to-business e-commerce
      pursuant to which the University purchases goods or services or to electronic ordering and payment
      mechanisms that are typically used between other businesses or institutions and Stanford University,
      usually referred to as Electronic Data Interchange (EDI) or Electronic Funds Transfer (EFT).

 2.   PURPOSE
      Electronic commerce provides a convenient way to handle business transactions such as conference
      registration or the purchase of course materials. However, reasonable steps should be taken to protect the
      personal information and privacy of purchasers. It is also in the University’s best interest to facilitate the
      transfer of electronic commerce transaction data to its financial systems. The purpose of this policy is to
      establish guidelines for electronic commerce.

 3.   POLICY
      a.   Relation to University Mission — Any use of electronic commerce at Stanford must be consistent with
           Guide Memo 15.3, Unrelated Business Activity, http://adminguide.stanford.edu/15_3.pdf, which
           prohibits the use of Stanford resources for any activity not related to the University’s mission.
      b. Authorized Vendor — Stanford has contracted with an internet commerce transaction services vendor
         to handle the authorization and management of electronic orders. This arrangement allows the
         University to:
           •    Consistently require the vendor to take necessary and reasonable steps to ensure that transactions
                are secure,
           •    Assure appropriate integration with University financial systems,
           •    Ensure that parties comply with Stanford name use and privacy policies,
           •    Use tested emergency response and recovery procedures,
           •    Leverage University transactions to reduce costs, and
           •    Provide current technology and support for developing applications.




                                                 Stanford University
December 15, 2005                                   Page 2 of 2                   Administrative Guide Memo 65


           Departments wishing to engage in electronic commerce must either use the authorized vendor to
           provide online order management services or offer evidence to the Controller, or his/her designee, that
           the selected vendor cannot meet the department’s business needs and that an alternative vendor meets
           University requirements for security and for integrating transaction information into Stanford financial
           systems. Note that all such agreements should be in accordance with Guide Memo 14, Academic and
           Business Relationships with Third Parties, http://adminguide.stanford.edu/14.pdf.
      c.   Confidentiality of Data — Departments are responsible for safeguarding the confidentiality of
           restricted and sensitive data related to purchases of goods or services as stated in Guide Memo 63,
           Information Security, http://adminguide.stanford.edu/63.pdf . Specific eCommerce guidelines are:
           (1)   Use secure and/or encrypted connections to the transaction service vendor (such as the one
                 provided to Stanford by its authorized vendor).
           (2)   Do not store any restricted electronic payment information (e.g., credit card numbers or PINs)
                 locally, without prior authorization from the risk assessment workgroup designated by
                 eCommerce Strategic Advisory Committee, (eSAC).
           (3)   If gathering other information about purchasers, protect this information in a secure manner,
                 restricting access to those who have a valid need to know.
           Departments should adhere to Stanford’s e-commerce privacy guidelines and security procedures,
           linking to the guidelines/procedures at each point-of-sale. If a valid business reason dictates departure
           from privacy guidelines, departments should explicitly advise customers at the point(s) of sale of how
           their practice departs from University guidelines.
      d. Advertising Policy — Departments are responsible for creating the web interface to the vendor's on-
         line order management system. If the website is in the stanford.edu domain, no third-party advertising
         is allowed.
 4.   IMPLEMENTATION GUIDELINES

      a.   Stanford eCommerce stores must meet the Payment Card Industry Customer Information Security
           Program (PCI-CISP) standards.

      b. Additional assistance on setting up and running an electronic commerce store is available on the
         eCommerce @ Stanford site. Departments should work with representatives of the eCommerce
         Technical Team, their applications development support team, Controller’s Office and Procurement to
         create their electronic commerce-enabled website.

 5.   SOURCES OF MORE INFORMATION
      •    Administrative Guide Memo 14, Academic and Business Relationships with Third Parties,
             http://adminguide.stanford.edu/14.pdf
      •    Administrative Guide Memo 15.3, Unrelated Business Activity,
            http://adminguide.stanford.edu/15_3.pdf
      •    Administrative Guide Memo 63, Information Security, http://adminguide.stanford.edu/63.pdf
      •    eCommerce @ Stanford, http://ecommerce.stanford.edu/
      •    Payment Card Industry - Customer Information Security Program (VISA),
            http://usa.visa.com/business/accepting_visa/ops_risk_management/cisp.html
      •    Information Security Office, http://security.stanford.edu
      •    Additional information security guidelines, procedures, standards, and practices can be found at
           http://securecomputing.stanford.edu




                                                Stanford University

More Related Content

Similar to E Com

Navigating the expanding compliance perimeter smarsh 2016_notes_20 04 16_video
Navigating the expanding compliance perimeter smarsh 2016_notes_20 04 16_videoNavigating the expanding compliance perimeter smarsh 2016_notes_20 04 16_video
Navigating the expanding compliance perimeter smarsh 2016_notes_20 04 16_videoSmarsh
 
Fitsum ristu lakew transaction security on e-commerce
Fitsum ristu lakew transaction security on e-commerceFitsum ristu lakew transaction security on e-commerce
Fitsum ristu lakew transaction security on e-commerceFITSUM RISTU LAKEW
 
Wollmuth Maher & Deutsch LLP -Takeaways From The SEC Cybersecurity Examinatio...
Wollmuth Maher & Deutsch LLP -Takeaways From The SEC Cybersecurity Examinatio...Wollmuth Maher & Deutsch LLP -Takeaways From The SEC Cybersecurity Examinatio...
Wollmuth Maher & Deutsch LLP -Takeaways From The SEC Cybersecurity Examinatio...Jason Glass, CFA, CISSP
 
DATA Working Group - Consumer Best Practices
DATA Working Group - Consumer Best PracticesDATA Working Group - Consumer Best Practices
DATA Working Group - Consumer Best PracticesDataSecretariat
 
Upgrade Your Banking Experience with Advanced Core Banking Applications
Upgrade Your Banking Experience with Advanced Core Banking ApplicationsUpgrade Your Banking Experience with Advanced Core Banking Applications
Upgrade Your Banking Experience with Advanced Core Banking ApplicationsIntellect Design Arena Ltd
 
E-business application in the Supermarket sector
E-business application in the Supermarket sectorE-business application in the Supermarket sector
E-business application in the Supermarket sectorManish Ragoobeer
 
FTC overview on glba final rule on safeguards 2010 Compliance Presentation
FTC overview on glba final rule on safeguards 2010 Compliance PresentationFTC overview on glba final rule on safeguards 2010 Compliance Presentation
FTC overview on glba final rule on safeguards 2010 Compliance PresentationBrent Hillyer
 
PCI Certification and remediation services
PCI Certification and remediation servicesPCI Certification and remediation services
PCI Certification and remediation servicesTariq Juneja
 
Streamlining Success Mastering the Merchant Onboarding Process.pptx
Streamlining Success Mastering the Merchant Onboarding Process.pptxStreamlining Success Mastering the Merchant Onboarding Process.pptx
Streamlining Success Mastering the Merchant Onboarding Process.pptxmohakbariatric
 
What Strategies Are Crucial for Ensuring eCommerce Security in the Digital Era?
What Strategies Are Crucial for Ensuring eCommerce Security in the Digital Era?What Strategies Are Crucial for Ensuring eCommerce Security in the Digital Era?
What Strategies Are Crucial for Ensuring eCommerce Security in the Digital Era?Lucy Zeniffer
 
Introduction-to-M-commerce Mobile Apps.pptx
Introduction-to-M-commerce Mobile Apps.pptxIntroduction-to-M-commerce Mobile Apps.pptx
Introduction-to-M-commerce Mobile Apps.pptxVLink Inc
 
Steps To Create Your Own Payment Gateway
Steps To Create Your Own Payment GatewaySteps To Create Your Own Payment Gateway
Steps To Create Your Own Payment GatewayITIO Innovex
 
Data engineering Use Cases in financial industry.pdf
Data engineering Use Cases in financial industry.pdfData engineering Use Cases in financial industry.pdf
Data engineering Use Cases in financial industry.pdfshreyathaker
 

Similar to E Com (20)

Aggregation Platforms-White Paper
Aggregation Platforms-White PaperAggregation Platforms-White Paper
Aggregation Platforms-White Paper
 
Navigating the expanding compliance perimeter smarsh 2016_notes_20 04 16_video
Navigating the expanding compliance perimeter smarsh 2016_notes_20 04 16_videoNavigating the expanding compliance perimeter smarsh 2016_notes_20 04 16_video
Navigating the expanding compliance perimeter smarsh 2016_notes_20 04 16_video
 
Fitsum ristu lakew transaction security on e-commerce
Fitsum ristu lakew transaction security on e-commerceFitsum ristu lakew transaction security on e-commerce
Fitsum ristu lakew transaction security on e-commerce
 
E-Commerce
E-CommerceE-Commerce
E-Commerce
 
Wollmuth Maher & Deutsch LLP -Takeaways From The SEC Cybersecurity Examinatio...
Wollmuth Maher & Deutsch LLP -Takeaways From The SEC Cybersecurity Examinatio...Wollmuth Maher & Deutsch LLP -Takeaways From The SEC Cybersecurity Examinatio...
Wollmuth Maher & Deutsch LLP -Takeaways From The SEC Cybersecurity Examinatio...
 
Unit i
Unit iUnit i
Unit i
 
DATA Working Group - Consumer Best Practices
DATA Working Group - Consumer Best PracticesDATA Working Group - Consumer Best Practices
DATA Working Group - Consumer Best Practices
 
Upgrade Your Banking Experience with Advanced Core Banking Applications
Upgrade Your Banking Experience with Advanced Core Banking ApplicationsUpgrade Your Banking Experience with Advanced Core Banking Applications
Upgrade Your Banking Experience with Advanced Core Banking Applications
 
E-business application in the Supermarket sector
E-business application in the Supermarket sectorE-business application in the Supermarket sector
E-business application in the Supermarket sector
 
E commerce
E commerceE commerce
E commerce
 
FTC overview on glba final rule on safeguards 2010 Compliance Presentation
FTC overview on glba final rule on safeguards 2010 Compliance PresentationFTC overview on glba final rule on safeguards 2010 Compliance Presentation
FTC overview on glba final rule on safeguards 2010 Compliance Presentation
 
PCI Certification and remediation services
PCI Certification and remediation servicesPCI Certification and remediation services
PCI Certification and remediation services
 
Paps 1013
Paps 1013Paps 1013
Paps 1013
 
Streamlining Success Mastering the Merchant Onboarding Process.pptx
Streamlining Success Mastering the Merchant Onboarding Process.pptxStreamlining Success Mastering the Merchant Onboarding Process.pptx
Streamlining Success Mastering the Merchant Onboarding Process.pptx
 
What Strategies Are Crucial for Ensuring eCommerce Security in the Digital Era?
What Strategies Are Crucial for Ensuring eCommerce Security in the Digital Era?What Strategies Are Crucial for Ensuring eCommerce Security in the Digital Era?
What Strategies Are Crucial for Ensuring eCommerce Security in the Digital Era?
 
Introduction-to-M-commerce Mobile Apps.pptx
Introduction-to-M-commerce Mobile Apps.pptxIntroduction-to-M-commerce Mobile Apps.pptx
Introduction-to-M-commerce Mobile Apps.pptx
 
SEC440: Incident Response Plan
SEC440: Incident Response PlanSEC440: Incident Response Plan
SEC440: Incident Response Plan
 
Steps To Create Your Own Payment Gateway
Steps To Create Your Own Payment GatewaySteps To Create Your Own Payment Gateway
Steps To Create Your Own Payment Gateway
 
Master Class Cyber Compliance
Master Class Cyber Compliance Master Class Cyber Compliance
Master Class Cyber Compliance
 
Data engineering Use Cases in financial industry.pdf
Data engineering Use Cases in financial industry.pdfData engineering Use Cases in financial industry.pdf
Data engineering Use Cases in financial industry.pdf
 

More from Nirmal Pandya

More from Nirmal Pandya (10)

Crm Project
Crm ProjectCrm Project
Crm Project
 
Crm
CrmCrm
Crm
 
Credit Policy Of Icici
Credit Policy Of IciciCredit Policy Of Icici
Credit Policy Of Icici
 
Credit Policy Of Hdfc
Credit Policy Of HdfcCredit Policy Of Hdfc
Credit Policy Of Hdfc
 
Credit Policy Of Rbi
Credit Policy Of RbiCredit Policy Of Rbi
Credit Policy Of Rbi
 
Credit Policies
Credit PoliciesCredit Policies
Credit Policies
 
Co Operative Marketing
Co Operative MarketingCo Operative Marketing
Co Operative Marketing
 
Buy Back Of Shares
Buy Back Of SharesBuy Back Of Shares
Buy Back Of Shares
 
Bosnia and Herzegovina Financial Sector Report
Bosnia and Herzegovina Financial Sector ReportBosnia and Herzegovina Financial Sector Report
Bosnia and Herzegovina Financial Sector Report
 
Business Ethics
Business EthicsBusiness Ethics
Business Ethics
 

Recently uploaded

An Overview of Mutual Funds Bcom Project.pdf
An Overview of Mutual Funds Bcom Project.pdfAn Overview of Mutual Funds Bcom Project.pdf
An Overview of Mutual Funds Bcom Project.pdfSanaAli374401
 
Holdier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfHoldier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfagholdier
 
microwave assisted reaction. General introduction
microwave assisted reaction. General introductionmicrowave assisted reaction. General introduction
microwave assisted reaction. General introductionMaksud Ahmed
 
Gardella_Mateo_IntellectualProperty.pdf.
Gardella_Mateo_IntellectualProperty.pdf.Gardella_Mateo_IntellectualProperty.pdf.
Gardella_Mateo_IntellectualProperty.pdf.MateoGardella
 
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...EduSkills OECD
 
PROCESS RECORDING FORMAT.docx
PROCESS      RECORDING        FORMAT.docxPROCESS      RECORDING        FORMAT.docx
PROCESS RECORDING FORMAT.docxPoojaSen20
 
Mixin Classes in Odoo 17 How to Extend Models Using Mixin Classes
Mixin Classes in Odoo 17  How to Extend Models Using Mixin ClassesMixin Classes in Odoo 17  How to Extend Models Using Mixin Classes
Mixin Classes in Odoo 17 How to Extend Models Using Mixin ClassesCeline George
 
Z Score,T Score, Percential Rank and Box Plot Graph
Z Score,T Score, Percential Rank and Box Plot GraphZ Score,T Score, Percential Rank and Box Plot Graph
Z Score,T Score, Percential Rank and Box Plot GraphThiyagu K
 
ICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptxICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptxAreebaZafar22
 
The basics of sentences session 2pptx copy.pptx
The basics of sentences session 2pptx copy.pptxThe basics of sentences session 2pptx copy.pptx
The basics of sentences session 2pptx copy.pptxheathfieldcps1
 
Web & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdfWeb & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdfJayanti Pande
 
How to Give a Domain for a Field in Odoo 17
How to Give a Domain for a Field in Odoo 17How to Give a Domain for a Field in Odoo 17
How to Give a Domain for a Field in Odoo 17Celine George
 
Grant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingGrant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingTechSoup
 
Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..Disha Kariya
 
Ecological Succession. ( ECOSYSTEM, B. Pharmacy, 1st Year, Sem-II, Environmen...
Ecological Succession. ( ECOSYSTEM, B. Pharmacy, 1st Year, Sem-II, Environmen...Ecological Succession. ( ECOSYSTEM, B. Pharmacy, 1st Year, Sem-II, Environmen...
Ecological Succession. ( ECOSYSTEM, B. Pharmacy, 1st Year, Sem-II, Environmen...Shubhangi Sonawane
 
Measures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeMeasures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeThiyagu K
 

Recently uploaded (20)

An Overview of Mutual Funds Bcom Project.pdf
An Overview of Mutual Funds Bcom Project.pdfAn Overview of Mutual Funds Bcom Project.pdf
An Overview of Mutual Funds Bcom Project.pdf
 
Holdier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdfHoldier Curriculum Vitae (April 2024).pdf
Holdier Curriculum Vitae (April 2024).pdf
 
microwave assisted reaction. General introduction
microwave assisted reaction. General introductionmicrowave assisted reaction. General introduction
microwave assisted reaction. General introduction
 
Gardella_Mateo_IntellectualProperty.pdf.
Gardella_Mateo_IntellectualProperty.pdf.Gardella_Mateo_IntellectualProperty.pdf.
Gardella_Mateo_IntellectualProperty.pdf.
 
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
Presentation by Andreas Schleicher Tackling the School Absenteeism Crisis 30 ...
 
PROCESS RECORDING FORMAT.docx
PROCESS      RECORDING        FORMAT.docxPROCESS      RECORDING        FORMAT.docx
PROCESS RECORDING FORMAT.docx
 
Mixin Classes in Odoo 17 How to Extend Models Using Mixin Classes
Mixin Classes in Odoo 17  How to Extend Models Using Mixin ClassesMixin Classes in Odoo 17  How to Extend Models Using Mixin Classes
Mixin Classes in Odoo 17 How to Extend Models Using Mixin Classes
 
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
Mattingly "AI & Prompt Design: Structured Data, Assistants, & RAG"
 
Z Score,T Score, Percential Rank and Box Plot Graph
Z Score,T Score, Percential Rank and Box Plot GraphZ Score,T Score, Percential Rank and Box Plot Graph
Z Score,T Score, Percential Rank and Box Plot Graph
 
ICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptxICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptx
 
The basics of sentences session 2pptx copy.pptx
The basics of sentences session 2pptx copy.pptxThe basics of sentences session 2pptx copy.pptx
The basics of sentences session 2pptx copy.pptx
 
Web & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdfWeb & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdf
 
Advance Mobile Application Development class 07
Advance Mobile Application Development class 07Advance Mobile Application Development class 07
Advance Mobile Application Development class 07
 
Código Creativo y Arte de Software | Unidad 1
Código Creativo y Arte de Software | Unidad 1Código Creativo y Arte de Software | Unidad 1
Código Creativo y Arte de Software | Unidad 1
 
How to Give a Domain for a Field in Odoo 17
How to Give a Domain for a Field in Odoo 17How to Give a Domain for a Field in Odoo 17
How to Give a Domain for a Field in Odoo 17
 
Grant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingGrant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy Consulting
 
Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..
 
Ecological Succession. ( ECOSYSTEM, B. Pharmacy, 1st Year, Sem-II, Environmen...
Ecological Succession. ( ECOSYSTEM, B. Pharmacy, 1st Year, Sem-II, Environmen...Ecological Succession. ( ECOSYSTEM, B. Pharmacy, 1st Year, Sem-II, Environmen...
Ecological Succession. ( ECOSYSTEM, B. Pharmacy, 1st Year, Sem-II, Environmen...
 
Mattingly "AI & Prompt Design: The Basics of Prompt Design"
Mattingly "AI & Prompt Design: The Basics of Prompt Design"Mattingly "AI & Prompt Design: The Basics of Prompt Design"
Mattingly "AI & Prompt Design: The Basics of Prompt Design"
 
Measures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and ModeMeasures of Central Tendency: Mean, Median and Mode
Measures of Central Tendency: Mean, Median and Mode
 

E Com

  • 1. December 15, 2005 Page 1 of 2 Administrative Guide Memo 65 Electronic Commerce Authority This Guide Memo was approved by the Vice President for Business Affairs and Chief Financial Officer. Applicability This policy applies to all Stanford entities that generate revenue through fundraising or the provision of goods or services. Summary This policy provides guidelines on the use of electronic commerce at Stanford. Section headings are: 1. DEFINITION 2. PURPOSE 3. POLICY 4. IMPLEMENTATION GUIDELINES 5. SOURCES OF MORE INFORMATION 1. DEFINITION For purposes of this policy, electronic commerce is defined as the use of electronic ordering and payment mechanisms via an interactive electronic mechanism such as the World Wide Web to effect remote payment for Stanford University goods or services. This policy does not cover business-to-business e-commerce pursuant to which the University purchases goods or services or to electronic ordering and payment mechanisms that are typically used between other businesses or institutions and Stanford University, usually referred to as Electronic Data Interchange (EDI) or Electronic Funds Transfer (EFT). 2. PURPOSE Electronic commerce provides a convenient way to handle business transactions such as conference registration or the purchase of course materials. However, reasonable steps should be taken to protect the personal information and privacy of purchasers. It is also in the University’s best interest to facilitate the transfer of electronic commerce transaction data to its financial systems. The purpose of this policy is to establish guidelines for electronic commerce. 3. POLICY a. Relation to University Mission — Any use of electronic commerce at Stanford must be consistent with Guide Memo 15.3, Unrelated Business Activity, http://adminguide.stanford.edu/15_3.pdf, which prohibits the use of Stanford resources for any activity not related to the University’s mission. b. Authorized Vendor — Stanford has contracted with an internet commerce transaction services vendor to handle the authorization and management of electronic orders. This arrangement allows the University to: • Consistently require the vendor to take necessary and reasonable steps to ensure that transactions are secure, • Assure appropriate integration with University financial systems, • Ensure that parties comply with Stanford name use and privacy policies, • Use tested emergency response and recovery procedures, • Leverage University transactions to reduce costs, and • Provide current technology and support for developing applications. Stanford University
  • 2. December 15, 2005 Page 2 of 2 Administrative Guide Memo 65 Departments wishing to engage in electronic commerce must either use the authorized vendor to provide online order management services or offer evidence to the Controller, or his/her designee, that the selected vendor cannot meet the department’s business needs and that an alternative vendor meets University requirements for security and for integrating transaction information into Stanford financial systems. Note that all such agreements should be in accordance with Guide Memo 14, Academic and Business Relationships with Third Parties, http://adminguide.stanford.edu/14.pdf. c. Confidentiality of Data — Departments are responsible for safeguarding the confidentiality of restricted and sensitive data related to purchases of goods or services as stated in Guide Memo 63, Information Security, http://adminguide.stanford.edu/63.pdf . Specific eCommerce guidelines are: (1) Use secure and/or encrypted connections to the transaction service vendor (such as the one provided to Stanford by its authorized vendor). (2) Do not store any restricted electronic payment information (e.g., credit card numbers or PINs) locally, without prior authorization from the risk assessment workgroup designated by eCommerce Strategic Advisory Committee, (eSAC). (3) If gathering other information about purchasers, protect this information in a secure manner, restricting access to those who have a valid need to know. Departments should adhere to Stanford’s e-commerce privacy guidelines and security procedures, linking to the guidelines/procedures at each point-of-sale. If a valid business reason dictates departure from privacy guidelines, departments should explicitly advise customers at the point(s) of sale of how their practice departs from University guidelines. d. Advertising Policy — Departments are responsible for creating the web interface to the vendor's on- line order management system. If the website is in the stanford.edu domain, no third-party advertising is allowed. 4. IMPLEMENTATION GUIDELINES a. Stanford eCommerce stores must meet the Payment Card Industry Customer Information Security Program (PCI-CISP) standards. b. Additional assistance on setting up and running an electronic commerce store is available on the eCommerce @ Stanford site. Departments should work with representatives of the eCommerce Technical Team, their applications development support team, Controller’s Office and Procurement to create their electronic commerce-enabled website. 5. SOURCES OF MORE INFORMATION • Administrative Guide Memo 14, Academic and Business Relationships with Third Parties, http://adminguide.stanford.edu/14.pdf • Administrative Guide Memo 15.3, Unrelated Business Activity, http://adminguide.stanford.edu/15_3.pdf • Administrative Guide Memo 63, Information Security, http://adminguide.stanford.edu/63.pdf • eCommerce @ Stanford, http://ecommerce.stanford.edu/ • Payment Card Industry - Customer Information Security Program (VISA), http://usa.visa.com/business/accepting_visa/ops_risk_management/cisp.html • Information Security Office, http://security.stanford.edu • Additional information security guidelines, procedures, standards, and practices can be found at http://securecomputing.stanford.edu Stanford University