Blackboard Updates Transact Commerce App for Compliance with PCI Standards

Blackboard has released version 3.5 of Blackboard Transact, a set of applications that provides commerce and security management for campuses. The primary focus of the new edition is its compliance with the Payment Application Data Security Standard (PA-DSS), which enables the institutions that use it to comply with the Payment Card Industry Data Security Standard (PCI-DSS). The goal of PA-DSS is to help software vendors and others develop secure payment applications that don't store prohibited data and ensure their payment applications support compliance with the PCI DSS. Campuses are encouraged to use PA-DSS-compliant applications in their payment environments or risk eventually being denied the ability to access credit services by their credit card companies.

According to the company, release 3.5 received validation from Trustwave, a security assessor company, and acceptance from the PCI Security Standards Council.

"Payment application security compliance is a very important initiative for our university," said Stacie Gomm, associate vice president for IT at Utah State University. "Our Controller's office is driving this initiative to ensure that all of our financial systems and processes are PCI compliant. The enhanced security features of the Blackboard Transact platform are an important step towards compliance for our campus-wide ID card solution."

The Blackboard Transact platform has two primary modules. The Commerce Management module facilitates campus ID card issuance; on-campus, off-campus, and online commerce; cashless payment processing for dining, bookstore, vending, laundry, copy, print and parking services; financial reporting; and self-service account management. The Security Management module provides features to monitor door access control, manage video surveillance, and perform mass notification capabilities.

The new version also introduces capabilities to support enterprise-wide compliance policies and risk management; adds improved database audit logging; provides user account and password features including forced complex passwords, limited repeat access attempts, and account deactivation after 90 days of no use; and includes rewritten user documentation.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • row of students using computers in a library

    A Return to Openness: Apereo Examines Sustainability in Open Source

    Surprisingly, on many of our campuses, even the IT leadership responsible for the lion's share of technology deployments doesn't realize the extent to which the institution is dependent on open source. And that lack of awareness can be a threat to campuses.

  • abstract pattern of cybersecurity, ai and cloud imagery

    OpenAI Report Identifies Malicious Use of AI in Cloud-Based Cyber Threats

    A report from OpenAI identifies the misuse of artificial intelligence in cybercrime, social engineering, and influence operations, particularly those targeting or operating through cloud infrastructure. In "Disrupting Malicious Uses of AI: June 2025," the company outlines how threat actors are weaponizing large language models for malicious ends — and how OpenAI is pushing back.

  • cloud icon with a padlock overlay set against a digital background featuring binary code and network nodes

    New Cloud Security Auditing Tool Utilizes AI to Validate Providers' Security Assessments

    The Cloud Security Alliance has announced a new artificial intelligence-powered system that automates the validation of cloud service providers' (CSPs) security assessments, aiming to improve transparency and trust across the cloud computing landscape.

  • geometric grid of colorful faculty silhouettes using laptops

    Top 3 Faculty Uses of Gen AI

    A new report from Anthropic provides insights into how higher education faculty are using generative AI, both in and out of the classroom.