PCI DSS
PCI DSS is the payment-card industry's security standard for organizations whose people, systems, or services handle payment account data or can affect its security. It turns protecting that data into defined technical, operational, and assessment work.
itCybersecurity fundamentals and governance | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic — PCI DSS
PCI DSS is a baseline for protecting payment account data. It is not a product, a badge, or a ceremonial folder of policies that gets dusted off when someone says assessment. It is a way to make payment security describe what the systems actually do.
The useful starting point is the cardholder data environment, or CDE. Follow the payment data through the payment page, processor, application, storage, support channels, and the odd places data might arrive by accident. Then follow the influence: administrators, identity services, monitoring systems, and service providers can all affect the security of the route. Payment data has an impressive talent for acquiring neighbours.
The surprise is that a system does not need to store a primary account number to become important. A component with unrestricted connectivity to something that handles cardholder data or sensitive authentication data can belong in the CDE too. Segmentation can reduce that boundary, but a diagram is not proof. The test is whether real paths into the CDE are actually blocked.
Once the boundary is honest, the work becomes less mystical. Protect data and access. Maintain configurations. Monitor and test. For each control, name the owner, the expected state, the frequency, and the evidence. A policy explains what should happen; records from the environment show what did happen. The distinction is small on paper and rather large when the paper meets a real system.
Service providers do not remove the question. They move part of it into a shared-responsibility arrangement. A provider can affect payment security without holding the data itself, so the useful answer names who performs each control and what evidence each party provides.
There are also two implementation paths. The defined approach follows the stated requirement. The customized approach uses another design to meet the stated objective, with risk management, documentation, testing, and maintenance. It is not a trapdoor beneath a missing control.
Read the Intro when you need the full model of scope and responsibility. Use the Slides to keep the data path and evidence loop in view. Keep the Cheatsheet nearby while mapping systems and providers. Then take the Exercise with fictional systems only, and turn the boundary into something that can be tested rather than merely admired.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://www.pcisecuritystandards.org/standards/pci-dss/
Supports
- PCI DSS as a baseline of technical and operational requirements designed to protect payment account data
- Intended audience including entities that store, process, transmit, or can impact the security of cardholder data or sensitive authentication data
- QSA and ASV roles and the fact that compliance validation obligations are determined by payment brands, acquirers, or other compliance-program managers
- https://www.pcisecuritystandards.org/glossary/
Supports
- Definitions of CHD, SAD, CDE, PAN, segmentation, scoping, QSA, SAQ, and ROC
- CDE membership for components with unrestricted connectivity to components that handle CHD or SAD
- Definitions of payment channels and payment processors
- https://www.pcisecuritystandards.org/faqs/1115/
Supports
- Systems are considered part of the CDE unless adequate segmentation isolates systems that handle cardholder data from those that do not
- Segmentation used to reduce scope must be verified as effective and working as intended
- https://www.pcisecuritystandards.org/faqs/1580/
Supports
- Scope for service providers that can impact payment account data security without directly handling that data
- Need to confirm applicable requirements from the services and access involved, and document not-applicable determinations
- https://blog.pcisecuritystandards.org/pci-ssc-publishes-new-guidance-on-compensating-controls-and-the-customized-approach
Supports
- Defined and customized approaches as distinct implementation and validation paths
- Compensating controls as a defined-approach option for legitimate technical or business constraints
- Customized approach expectations for risk maturity, documentation, testing, and maintenance
- https://www.pcisecuritystandards.org/documents/PCI-DSS-v3_2-SAQ-B-rev1_1.pdf
Supports
- PCI DSS v1.1, v1.2, v2.0, v3.1, and v3.2 dates in the SAQ revision history
- Alignment of SAQ reporting artifacts with PCI DSS revisions
- https://listings.pcisecuritystandards.org/minisite/en/docs/PCI_DSS_v3_Summary_of_Changes.pdf
Supports
- PCI DSS v3.0 publication in November 2013
- Addition of an in-scope system-component inventory requirement in v3.0
- https://www.pcisecuritystandards.org/about_us/press_releases/pci-council-releases-pci-data-security-standard-version-3-2/
Supports
- PCI DSS v3.2 replacing v3.1 to address growing threats to payment information
- https://www.pcisecuritystandards.org/about_us/press_releases/securing-the-future-of-payments-pci-ssc-publishes-pci-data-security-standard-v4-0/
Supports
- PCI DSS v4.0 publication on 31 March 2022
- v4.0 changes for emerging threats, technologies, network security controls, and flexibility in meeting objectives
- https://blog.pcisecuritystandards.org/just-published-pci-dss-v4-0-1
Supports
- PCI DSS v4.0.1 publication on 11 June 2024
- v4.0.1 as a limited revision with corrections and clarifications and no added or deleted requirements
- https://drata.com/products
Supports
- Drata compliance automation, evidence collection, and control monitoring with PCI DSS support
- https://www.vanta.com/
Supports
- Vanta compliance automation and continuous monitoring with PCI DSS support
- https://support.secureframe.com/en/articles/15111445-faqs-pci-dss-scope-evidence-and-common-scenarios
Supports
- Secureframe PCI DSS scope and evidence resources
- https://sprinto.com/frameworks/pci-dss/
Supports
- Sprinto PCI DSS scope, setup, evidence collection, and continuous monitoring
- https://hyperproof.io/
Supports
- Hyperproof GRC workflows for controls, risks, and evidence
