Raiser's Edge NXT, PCI, validated P2PE integration for significant scope reduction and cost savings - anyone interested?

Options
Hi all,


Our Advancement offices recently signed a contract to implement Raiser's Edge NXT. Upon review by our PCI Compliance Team, we realized that Blackbaud CRM had integrated a validated P2PE solution, however, Raiser's Edge NXT had not. We have enquired about a validated P2PE integration date and have been told this will be on the 2018 roadmap. We are looking for a definitive date when the RE integration will take place so we can plan our project timeline. 


Are any other institutions struggling with PCI compliance, specifically securing the workstations used to enter payment card data? It is extremely expensive to provision dedicated purpose computers, perform File Integrity Monitoring, Logging, Alerting, Vulnerability scans and penetration tests for these workstations. We have implemented validated P2PE solutions, across our campuses, for all card-present and card not-present transactions. If we implement Raiser's Edge NXT without P2PE, it will cost us several thousands of dollars per year to secure.


I'm wondering if other institutions are in this same situation? If so, have you received a definitive date (and commitment) from BB to integrate Raiser's Edge NXT with a validated P2PE solution? 


Best regards,


Jane Aube

Loan Programs & PCI Compliance Specialist

Middlebury College


 

Comments

  • Jane, most people here, including me, don't know what P2PE is and have been led by BB to believe RE is fully PCI compatible in all regards it could be.  Could you please explain what P2PE is, why it matters, and if you can, how BB CRM has this and RE NXT does not?  Thank you.


  • Bill,



    My apologies for assuming members were
    familiar with PCI acronyms. 



    I want to note that I am not a
    Qualified Security Assessor (QSA) and the information provided
    below is my understanding of the Payment Card Industry Data
    Security Standards (PCI DSS). My experience comes from managing the
    PCI compliance at our institution and working with industry
    professionals for the past few years.



    Blackbaud -Internet Services (Hosting
    Provider) and Blackbaud Payment Services (gateway/switch, payment
    processing) are PCI Service Provider Level 1 validated. This means
    that the solution itself is compliant to the Payment Card Industry
    Data Security Standards (PCI DSS). The card brands and the
    Payment Card Industry Security Standards Council (PCI SSC) require
    the solution to be implemented, and utilized, in accordance with
    the PCI DSS. 



    For e-commerce transactions
    (constituents making a charitable donation or registering for an
    event), the solution is compliant. The constituent is performing
    the transaction in Raiser's Edge-hosted by Blackbaud which is
    compliant (*does not include Online Express which is embedded on
    the client's website). 



    For mail order, telephone order and
    card present transactions (staff entering payment card data into
    Raiser's Edge) the client must secure, to the PCI DSS, the
    workstation(s) they are entering payment card data on. This is
    where it gets complex and very expensive=
    PCI Scope
    . The workstations need to be segmented off the campus
    network with firewall and switches, locked down (dedicated purpose)
    to only allow access to specific URL/IP addresses (no email, no web
    browsing), all traffic monitored, logged, alerted and alerts acted
    on, Anti-virus, security updates, internal and external
    vulnerability scans and penetration testing. Not only is the
    workstation in PCI scope (known as the Cardholder Data Environment
    CDE) but also the system components that have controlled access to
    the CDE. These system components could provide security services,
    can initiate inbound connection to the CDE, can receive a
    connection from the CDE etc. Examples are system management console
    for a log management server, active directory, antivirus.



    This is where Point
    to Point Encryption (P2PE) validated solutions
     come into
    play. A validated
    P2PE solution 
     can reduce the PCI scope from the work
    station, network, connected system components to the P2PE device
    and staff entering the payment card data. Middlebury has saved over
    $50,000 per year by replacing legacy solutions and implementing
    only validated P2PE solutions on our campuses. We have worked with
    our service providers over the years to integrate P2PE validated
    solutions; including iModules,
    Ruffalo Noel Levitz Campus Call and MBS Books. 



    If/when Blackbaud integrates a
    validated P2PE solution with Raiser's Edge, clients will be able to
    purchase an IDTECH
    SRED P2PE device 
    that plugs into a workstation with a USB
    cord. This device is the CDE, the workstation and campus network is
    no longer in PCI scope. The staff would still log into Raiser's
    Edge as they do now, however, the field they currently enter
    payment card data into would only accept encrypted data from the
    IDTECH SRED device. 



    Blackbaud has already integrated
    Bluefin's validated P2PE solution with Blackbaud
    CRM. 
     Blackbaud has let us know that Raiser's Edge
    NXT P2PE integration is being looked at for the 2018 roadmap- no
    definitive commitment or specific timeline. We are hopeful that
    Blackbaud will integrate Raiser's Edge NXT and Bluefin's P2PE
    validated solution prior to our go live in the fall of 2018. If
    not, we will need to make the decision of whether to delay our go
    live or spend a significant amount of money (and staff resources)
    to secure, and maintain, this secure solution to the PCI
    DSS. 



    Hopefully this makes sense and doesn't
    cause further confusion. I'm happy to discuss further (via this
    forum or offline) if anyone has questions, comments,
    concerns. 





    Best regards,


    Jane


    Jane Aube | Loan Programs and Compliance Specialist | Student
    Financial Services | Middlebury College | 802.443.5790

    Sent from my iPad


  • Jane - I'd be happy to talk to you (and anyone else in this situation) more about this as our campus just completed its submission at the end of May. Since we are looking at a 2-yr timeline for switching to NXT, we worked out a "workaround". We use First Data cellular swipers to take one-time donations over the phone - in our Development office and the Call Center - and we have Bluefin P2PE keypads going through a Bluefin-built gateway for all other needs (multi-payment pledges, recurring gifts etc). Gift entry for these credit card gifts is not as seamless as it could be but is no worse than entering checks or stocks, for example. For the Call Center, we use RNL software, so we get a data feed from them and just use the credit card machines' tapes for reconciliation purposes; so the only manual entry is for gifts over the phone in our Development office or the recurring payments coming through the Bluefin solution  (of which we have none yet).


    Marijana Boone | Director, Advancement Services | College of Charleston 
  • Hi Marijana,


    Thanks so much for the kind offer! I truly appreciate the willingness to help other institutions.


    At this time, Middlebury is all set as we have implemented all P2PE validated solutions. We replaced all of our cellular swipe terminals with either Bluefin PAXS500's (stand-alone swipe terminal) or IDTECH SRED devices. We had worked with RNL (CampusCall SaaS Phonathon) and iModules (charitable donations) to integrate Bluefin's P2PE solution and IDTECH SRED devices-- a huge win for their clients. We currently do all of our recurring gifts in iModules, so the P2PE integration was key. This will all change when Advancement switches to RE. 


    My issue is when we implement RE NXT, without P2PE, staff will be entering CHD into RE from workstations. Our Advancement Office will not want to implement non-integrated work around as they are used to having real-time transactions show in our system. This is especially true at calendar and fiscal year end when they are sending email solitications and want to make certain they aren't soliciting a donor that just gave a gift.


    My quandary is the resources it will take to install dedicated work worstations and secure to the PCI DSS. Our PCI scope will go from only being the P2PE devices and staff, to a segmented network that has to be managed to the standards = several thousand dollars.

     
  • Hi all,


    The Blackbaud Idea's Board has a post on this subject. If you are interested in Raiser's Edge NXT integrating with a validated P2PE solution, please go to https://re7.ideas.aha.io/ideas/RE7-I-2423, to vote and enter a comment if you choose to. 


    Thanks all, have a great weekend!

    Jane
  • Hi all,


    Blackbaud  is moving along with the PCI validated Point-to-Point Encrypted (P2PE) solution integration, with RE NXT/BB Checkout single gift entry and recurring gift entry. Mobile Pay is not currently on the Roadmap for P2PE integration. If you are interested in reducing your PCI scope (potentially saving thousands of dollars in security and compliance costs), please comment on the
    Blackbaud Idea Bank.

    Jane Aube:

    Hi all,


    The Blackbaud Idea's Board has a post on this subject. If you are interested in Raiser's Edge NXT integrating with a validated P2PE solution, please go to https://re7.ideas.aha.io/ideas/RE7-I-2423, to vote and enter a comment if you choose to. 


    Thanks all, have a great weekend!

    Jane

     

Categories