In November 2014, we reported that since 2009, the City was out of compliance with the payment card industry’s data security standard. It had never met the standard – until now. The point of meeting the standard is to protect consumers’ payment card data. The City engages in millions of payment card transactions each year for services ranging from parking to recreation classes. In May, the City announced – and we verified -- it was in full compliance. Council will vote today to adopt the payment card industry data security standard as the City’s comprehensive financial management policy. Setting the payment card standard as policy helps achieve our audit recommendations.
Our 2014 report: https://www.portlandoregon.gov/auditservices/article/509635
Our 2016 follow-up: https://www.portlandoregon.gov/auditservices/article/576245
Council resolution to adopt payment card data security as financial management policy: https://www.portlandoregon.gov/auditor/article/582567
-- Alexandra Fercak, Audit Services