Information Security Policy (ISP) – GB Members CRM (Payment Card Data)

3 min. readlast update: 06.13.2025

This policy defines the guidelines and procedures GB Members CRM follows under Gracie Barra North America (GBNA) to protect payment cardholder data and comply with PCI DSS standards. This policy ensures the secure handling, transmission, and storage of cardholder data processed through the GB Members CRM and its integration with Bambora/Worldline.


CONTENTS

  1. Scope
  2. Key Policies and Procedures
  3. Responsibilities
  4. Policy Review
  5. Summary of Key Changes
  6. February, 2025

Scope

This policy applies to:

  • The GB Members CRM software, licensed to schools across North America.

  • All employees, contractors, and vendors who access or interact with cardholder data through GBNA systems.

  • Systems and networks involved in the processing of payment card data.


Key Policies and Procedures

  1. Access Control:

    • Access to cardholder data is limited to authorized personnel only.

    • Access to the GB Members Software is limited to invited users only. 

  2. Data Protection:

    • Cardholder data is processed and stored securely by Bambora/Worldline; full card numbers or sensitive authentication data are not stored within GBNA systems.

    • All reports and records display truncated or tokenized card information.

  3. Network Security:

    • Secure encryption (e.g., TLS 1.2 or higher) is required for all transmissions of payment card data.

    • Systems are monitored for vulnerabilities, and patches are applied promptly.

  4. Employee Training:

    • Employees and school staff are trained on PCI DSS compliance and secure handling of cardholder data.

    • Training includes recognizing and reporting potential security threats or incidents.

  5. Incident Response Plan:

    • A documented plan is in place to respond to cardholder data security incidents.

    • Incidents are reported immediately to GBNA Compliance and addressed per PCI DSS guidelines.

  6. Vendor Management:

    • GBNA ensures that all third-party vendors (e.g., Bambora/Worldline) provide valid PCI DSS Attestations of Compliance (AoC).

    • Vendor services are reviewed annually to confirm continued compliance.

  7. Audit and Review:

    • The ISP is reviewed annually or when significant changes to systems or processes occur.

    • Compliance with PCI DSS is verified through internal assessments and third-party audits.


Responsibilities

  • GBNA Compliance Team: Maintains and enforces the Information Security Policy.

  • Schools: Follow the guidelines provided by GBNA for secure CRM usage.

  • Vendors: Maintain compliance with PCI DSS for services provided to GBNA.


Policy Review

The GBNA Compliance Team reviews this policy annually and updates it as needed to reflect changes in PCI DSS requirements or organizational operations.


Summary of Key Changes


February, 2025

  • Created

 


This document was written by: Veronica Street (Roni)

Email: veronica.street@graciebarra.com

Current Version: 1.0

Last Updated: Feb 10, 2025

 

Was this article helpful?