<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Techcafeteria Blog &#187; Retail</title>
	<atom:link href="http://techcafeteria.com/blog/category/retail/feed/" rel="self" type="application/rss+xml" />
	<link>http://techcafeteria.com/blog</link>
	<description></description>
	<lastBuildDate>Mon, 05 Dec 2011 15:39:52 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/>		<item>
		<title>Putting The Tech Back In Nonprofit Technology</title>
		<link>http://techcafeteria.com/blog/2010/04/22/putting-the-tech-back-in-nonprofit-technology/</link>
		<comments>http://techcafeteria.com/blog/2010/04/22/putting-the-tech-back-in-nonprofit-technology/#comments</comments>
		<pubDate>Thu, 22 Apr 2010 15:10:21 +0000</pubDate>
		<dc:creator>Peter Campbell</dc:creator>
				<category><![CDATA[10ntc]]></category>
		<category><![CDATA[idealware]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[nptech]]></category>
		<category><![CDATA[Retail]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[strategy]]></category>
		<category><![CDATA[techcafeteria]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[virtualization]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[linkedin]]></category>

		<guid isPermaLink="false">http://techcafeteria.com/blog/?p=665</guid>
		<description><![CDATA[We're all back from the Nonprofit Technology Conference, where nine of the ten Idealware bloggers congregated, along with some 1,440 of our peers in the nptech community. What a gas! NTC, as we call the conference, is what high school would have been like if everyone had been a member of the popular clique. The combination of peer education and celebration of our common interest in saving the world with heart and technology make for an exuberant occasion. And I can't say enough about the awe and appreciation I have for Holly, Anna, Annaliese, Brett, Sarah and Karl, and the amazing event that they recreate year after year for us.

But, enough gushing.]]></description>
			<content:encoded><![CDATA[	<p><img style="float: left; padding: 5px 10px 5px 5px;" src="http://www.idealware.org/sites/idealware.org/files/images/nten_logo.gif" alt="" />We&#8217;re all back  from the <a href="http://nten.org/ntc">Nonprofit Technology Conference</a>,  where nine of the ten Idealware bloggers congregated, along with some  1,440 of our peers in the nptech community. What a gas! <span class="caps">NTC</span>, as we call  the conference, is what high school would have been like if everyone had  been a member of the popular clique.  The combination of peer education  and celebration of our common interest in saving the world with heart  and technology make for an exuberant occasion. And I can&#8217;t say enough  about the awe and appreciation I have for <a href="http://www.nten.org/Staff">Holly, Anna, Annaliese, Brett,  Sarah and Karl</a>, and the amazing event that they recreate year after  year for us.</p>

	<p>But, enough gushing. One of my (many) rants regards  my concern that, although the biggest group of people that we call  &#8220;nptechies&#8221; are the ones who support technology in their organizations,  our biggest nptech conferences focus heavily on social media and the web  (<a href="http://nten.org/ntc"><span class="caps">NTC</span></a>,  <a href="http://www.netsquared.org/">Netsquared</a>, and now <a href="http://sxsw.com/"><span class="caps">SXSW</span></a>). It is  true that the advent of social media and the interactive web is  spawning a revolution in the way that we do advocacy and fundraising.  But there is no less of a revolution in our server rooms, where <a href="http://www.idealware.org/blog/2008/11/lean-green-virtualized-machine.html">virtualization</a>,  <a href="http://www.idealware.org/blog/2009/11/cloud-computing-and-taming-desktop.html">cloud  computing</a> and <a href="http://mobileactive.org/">wireless devices</a> are  changing the entire way that we manage and deliver applications.</p>

	<p>Our  System Administrators, Support Specialists and <a href="http://www.nphd.org/home/accidental-techies/">Accidental  Techies</a> need to share in the peer support that can inform their  efforts and help them feel more connected, both to their missions and  the broader community. This year, in deference to a throat getting  hoarse from ranting, I took a first stab at addressing this gap.</p>

	<p><strong>The  Tech Track</strong></p>

	<p>The tech track was conceived as a six  session &#8220;mini&#8221; track; five of the proposed sessions made the cut. The  topics went from the basics to the broad overview:<br />
<ul></p>
	<p><li><a href="https://www.ntenonline.org/eweb/DynamicPage.aspx?webcode=SessionDetails&#038;ses_key=da29ceb2-f2b0-452c-a1a9-92b172f8e8cb">Tech  Track 1:</a> Working Without a Wire (But With a Net): Dealing with  Wireless Networks, Laptops, and Cell Phones</li><br />
<li><a href="https://www.ntenonline.org/eweb/DynamicPage.aspx?webcode=SessionDetails&#038;ses_key=05c67e40-ec13-45a1-a0ac-ef63939f1e8d">Tech  Track 2:</a> Proper Plumbing: Virtualization and Networking  Technologies</li><br />
<li><a href="https://www.ntenonline.org/eweb/DynamicPage.aspx?webcode=SessionDetails&#038;ses_key=3140015b-7cf0-4f70-97d1-4c44c70003b0">Tech  Track 3:</a> Earth to Cloud: When, Why and How to Outsource  Applications</li><br />
<li><a href="https://www.ntenonline.org/eweb/DynamicPage.aspx?webcode=SessionDetails&#038;ses_key=8356a755-0f42-422d-bcdc-f49f3fa02c2c">Tech  Track 4:</a> Budget vs Benefits: Providing Top Class Technology in  Constrained Resource Environments</li><br />
<li><a href="https://www.ntenonline.org/eweb/DynamicPage.aspx?webcode=SessionDetails&#038;ses_key=cc5f3108-06b7-467f-993d-b7fa9e127b29">Tech  Track 5:</a> Articulating Tech: How to Win Friends and Influence  Luddites.</li><br />
</ul></p>
	<p>Joining me in these sessions were  fellow blogger <a href="http://www.idealware.org/users/johanna-bates">Johanna  Bates</a> of <a href="http://openissue.com/">OpenIssue</a>, <a href="http://www.citidc.com/detail/person.cfm?person_id=208">Matt  Eshleman</a> of <a href="http://www.citidc.com"><span class="caps">CITIDC</span></a>, <a href="http://www.arc.org/content/view/39/">Tracy Kronzak</a> of <a href="http://www.arc.org">Applied  Research Center</a>, <a href="http://www.nten.org/node/7570">John Merritt</a> of the <a href="http://ymca.org/">San Diego <span class="caps">YMCA</span></a>,  <a href="http://zenofnptech.org/about-me">Michelle Murrain</a> of <a href="http://openissue.com/">OpenIssue</a>,  <a href="http://blogs.nwf.org/.a/6a00d8341ca02253ef011570e5330b970c-800wi">Michael  Sola</a> of <a href="http://www.nwf.org/">National Wildlife Federation</a> and <a href="https://www.philaculture.org/about/staff/thomas-taylor">Thomas  Taylor</a> of the <a href="https://www.philaculture.org/">Greater Philadelphia  Cultural Alliance</a>.</p>

	<p><strong>Subject Matter</strong></p>

	<p>Instead  of doing the usual Powerpoint presentations and talking to the crowd,  we pulled the chairs into circles for these sessions and put the session  agenda up for grabs, asking each group what issues, related to the  session topic, were foremost in their minds. The conversation was rich,  and served as a healthy catalogue of the challenges facing nonprofit  technology practitioners.  Some highlights:<br />
<ul></p>
	<p><li>Supporting  remote laptop use in a western state with very little wireless bandwidth  available</li><br />
<li>Securing our networks while making network data  accessible on mobile devices</li><br />
<li>Supporting use of and crafting  fair policies to address the boom in mobile devices</li><br />
<li>Understanding  the risks and benefits of virtualizing servers and desktops</li><br />
<li>Knowing  how and when to virtualize, and how <a href="http://en.wikipedia.org/wiki/Storage_area_network">Storage  Area Networks</a> fit in the big picture</li><br />
<li>Weighing the risk  of cloud computing, which also entails weighing the risks of our  non-cloud networks</li><br />
<li>Knowing what to ask a cloud provider to  insure that data is safe, even in the case of the provider going out of  business</li><br />
<li>Assessing the cost of owned vs service-provided  applications</li><br />
<li>Assessing the readiness of Cloud Computing, and  moving large, complex server rooms to the cloud</li><br />
<li>Chickens and  eggs: what to do when IT is asked to budget, but is not part of the  planning process prior?</li><br />
<li>What strategies can be applied to  provide good technology with limited budgets?</li><br />
<li>What tools and  resources are available to help with the budgeting process?</li><br />
<li>How  can we engage our users when we roll out new technology?</li><br />
<li>How  do we get them to attend training?</li><br />
</ul></p>
	<p>Next week,  I&#8217;ll follow this up with some of the answers we came up with for these  questions.<strong>Similar Posts:</strong><ul class="similar-posts"><li><a href="http://techcafeteria.com/blog/2011/07/26/the-evolution-of-the-nten-tech-track/" rel="bookmark" title="July 26, 2011">The Evolution Of The <span class="caps">NTEN </span>Tech Track</a></li></p>

	<p><li><a href="http://techcafeteria.com/blog/2009/02/11/the-sky-is-calling/" rel="bookmark" title="February 11, 2009">The Sky is Calling</a></li></p>

	<p><li><a href="http://techcafeteria.com/blog/2010/03/29/where-ill-be-at-the-10-ntc/" rel="bookmark" title="March 29, 2010">Where I&#8217;ll Be At The 10 <span class="caps">NTC</span></a></li></p>

	<p><li><a href="http://techcafeteria.com/blog/2011/01/31/why-i-wont-be-at-ntc-and-why-you-should-be/" rel="bookmark" title="January 31, 2011">Why I Won&#8217;t Be At <span class="caps">NTC </span>(And Why You Should Be)</a></li></p>

	<p><li><a href="http://techcafeteria.com/blog/2011/03/28/ntc-wrap-up/" rel="bookmark" title="March 28, 2011"><span class="caps">NTC </span>Wrap-up</a></li><br />
</ul><!-- Similar Posts took 8.894 ms --></p>
 ]]></content:encoded>
			<wfw:commentRss>http://techcafeteria.com/blog/2010/04/22/putting-the-tech-back-in-nonprofit-technology/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pop Quiz: PCI Compliance</title>
		<link>http://techcafeteria.com/blog/2009/08/13/pop-quiz-pci-compliance/</link>
		<comments>http://techcafeteria.com/blog/2009/08/13/pop-quiz-pci-compliance/#comments</comments>
		<pubDate>Thu, 13 Aug 2009 23:24:42 +0000</pubDate>
		<dc:creator>Peter Campbell</dc:creator>
				<category><![CDATA[ecommerce]]></category>
		<category><![CDATA[idealware]]></category>
		<category><![CDATA[Management]]></category>
		<category><![CDATA[nptech]]></category>
		<category><![CDATA[Retail]]></category>
		<category><![CDATA[software]]></category>
		<category><![CDATA[techcafeteria]]></category>
		<category><![CDATA[Web]]></category>
		<category><![CDATA[linkedin]]></category>

		<guid isPermaLink="false">http://techcafeteria.com/blog/?p=297</guid>
		<description><![CDATA[The credit card industry is doing the right thing by consumers and enforcing proper security measures regarding the handling of credit card information.  You might have heard about this - a number of the popular vendors of donor databases are recommending upgrades based on their compliance with these regulations. The "Payment Card Industry Data Security Standard", commonly known as <a href="https://www.pcisecuritystandards.org/">PCIDSS</a>, is a set of guidelines for securely handling credit card information.  The standard has been around for about four years, but early enforcement efforts focused on companies with a high volume of credit card transactions.  Now that they're all in compliance, they've set their sites on smaller businesses and nonprofits. So, what does this mean?]]></description>
			<content:encoded><![CDATA[	<p>The credit card industry is doing the right thing by consumers and enforcing proper security measures regarding the handling of credit card information.&#160; You might have heard about this &#8211; a number of the popular vendors of donor databases are recommending upgrades based on their compliance with these regulations. The &#8220;Payment Card Industry Data Security Standard&#8221;, commonly known as <a href="https://www.pcisecuritystandards.org/"><span class="caps">PCIDSS</span></a>, is a set of guidelines for securely handling credit card information.&#160; The standard has been around for about four years, but early enforcement efforts focused on companies with a high volume of credit card transactions.&#160; Now that they&#8217;re all in compliance, they&#8217;ve set their sites on smaller businesses and nonprofits. So, what does this mean? Here&#8217;s the simplest F.A.Q. that you&#8217;re likely to find on the topic:</p>

	<p><ul><li>Do you ever process online, phoned in, or mailed-in credit card donations in-house? e.g., do you maintain the credit card number, expiration date and name of a donor?</li></ul></p>

	<p>If no, you don&#8217;t have to worry about this.</p>

	<p><ul><li>If yes, do you have more than 20,000 such transactions annually?</li></ul></p>

	<p>Well, if you do, congratulations!&#160; Most nonprofits don&#8217;t, so they qualify for level 4 of the <span class="caps">PCI </span>Compliance scale. That results in a Self Assessment Questionnaire (SAQ) Validation type of &#8220;4&#8221;.&#160; Higher validation types are subject to stricter security standards.</p>

	<p>The <a href="https://www.pcisecuritystandards.org/saq/instructions_dss.shtml">Self-Assessment Questionnaire</a> will ask you all sorts of technical questions about your network and security procedures.&#160; Do you have a firewall?&#160; Are all of your transactions encrypted?&#160; Do you use anti-virus software?&#160; Is credit card information properly restricted to authorized staff?</p>

	<p>Depending on your network, you might already comply with a lot of the requirements.&#160; If you don&#8217;t, then it might require a significant investment to get there.</p>

	<p><ul><li>What will happen if I ignore this?</li></ul></p>

	<p>This isn&#8217;t government regulation (although your state might have <a href="http://www.idealware.org/blog/2008/11/complying-with-data-security-regulation.html">laws in place</a> that do mandate some similar response). participation is mandatory.&#160; But, should your security be breached, two things will happen:</p>

	<p>1. The compliance requirements for your organization will be reassessed to level one or two, and they&#8217;ll be much more costly and complicated to meet.&#160; The credit card companies might decline to do business with you if you don&#8217;t comply.&#160; Can you afford to not take Visa?</p>

	<p>2. You will likely be indirectly fined for non-compliance.&#160; The credit card companies will hold your bank liable for losses due to credit card theft in situations where your security was substandard.&#160; Your bank will likely pass that fine on to you.</p>

	<p><ul><li>So what&#8217;s the easiest way to deal with this?</li></ul></p>

	<p>Simple: <strong>don&#8217;t handle credit cards</strong>.&#160; There are a number of services that, for a price, will do this for you, from <a href="https://www.paypal.com/">Paypal</a> and <a href="https://checkout.google.com/seller/?hl=en&#038;gl=GB">Google Checkou</a>t to <a href="http://www.charityweb.net/">CharityWeb</a> and <a href="http://www.bbnow.org/">Blackbaud&#8217;s BBNow</a>. Outsourced <span class="caps">ECRM</span> software (<a href="http://www.blackbaud.com/netcommunity/">NetCommunity</a>, <a href="http://www.convio.com/">Convio</a>, <a href="http://www.democracyinaction.org/">Democracy in Action</a>, etc.) will also handle it. The cost is likely not as significant as that of maintaining compliance or suffering the consequences of a non-compliant breach.</p>

	<p>I&#8217;ll share that, at the <a href="http://www.sfgoodwill.org">Goodwill</a> where I used to work, outsourcing wasn&#8217;t an option, because we were both a charity and a retailer. Our frustration was not that we didn&#8217;t have good security in place.&#160; It was that there were differences in how we had set up our security and the <span class="caps">PCIDSS</span> requirements.&#160; So, while we had done a lot of work and made significant investments, we still had to reconfigure things and spend more in order to be compliant.&#160; In addition to making our internal IT changes, we had to switch software programs in order to avoid storing credit cards unencrypted in our database, a typical problem.&#160; We also engaged a consultant.&#160; Once you are reasonably sure that you comply, then you must pay a security service to verify your efforts, another non-trivial expense.</p>

	<p>Blackbaud has put together some <a href="http://www.blackbaud.com/company/pci/faq.aspx#5">good further reading</a> on this topic (and they are one of the vendor&#8217;s whose latest software is compliant; ask your eCRM vendor!).<strong>Similar Posts:</strong><ul class="similar-posts"><li><a href="http://techcafeteria.com/blog/2008/11/29/complying-with-data-security-regulation/" rel="bookmark" title="November 29, 2008">Complying with Data Security Regulation</a></li></p>

	<p><li><a href="http://techcafeteria.com/blog/2009/09/16/swept-up-in-a-google-wave/" rel="bookmark" title="September 16, 2009">Swept Up in a Google wave</a></li></p>

	<p><li><a href="http://techcafeteria.com/blog/2009/08/27/evaluating-wikis/" rel="bookmark" title="August 27, 2009">Evaluating Wikis</a></li></p>

	<p><li><a href="http://techcafeteria.com/blog/2009/08/10/my-full-nptech-dance-card/" rel="bookmark" title="August 10, 2009">My Full NPTech Dance Card</a></li></p>

	<p><li><a href="http://techcafeteria.com/blog/2009/12/29/wont-you-let-me-take-you-on-a-sea-change/" rel="bookmark" title="December 29, 2009">Won&#8217;t You Let me Take You On A Sea Change?</a></li><br />
</ul><!-- Similar Posts took 8.236 ms --></p>
 ]]></content:encoded>
			<wfw:commentRss>http://techcafeteria.com/blog/2009/08/13/pop-quiz-pci-compliance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

