PCI DSS
PCI DSS is the payment-card industry's security standard for organizations whose people, systems, or services handle payment account data or can affect its security. It turns protecting that data into defined technical, operational, and assessment work.
itCybersecurity fundamentals and governance | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Intro
PCI DSS
PCI DSS is a baseline of technical and operational requirements for protecting payment account data. It applies to more than the database that holds card numbers. It applies to entities that store, process, or transmit cardholder data or sensitive authentication data, and to systems and services that can affect the security of that environment.
The useful first question is not "Which requirement applies?" It is "Where can payment account data go, and what can reach or affect it?" Your answer defines the cardholder data environment, or CDE. The CDE includes people, processes, and system components that handle cardholder data or sensitive authentication data. It also includes components with unrestricted connectivity to them.
Start with scope
Continue the course
This section is part of the paid course.
See pricing to subscribe, or log in if you already have access.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://www.pcisecuritystandards.org/standards/pci-dss/
Supports
- PCI DSS as a baseline of technical and operational requirements designed to protect payment account data
- Intended audience including entities that store, process, transmit, or can impact the security of cardholder data or sensitive authentication data
- QSA and ASV roles and the fact that compliance validation obligations are determined by payment brands, acquirers, or other compliance-program managers
- https://www.pcisecuritystandards.org/glossary/
Supports
- Definitions of CHD, SAD, CDE, PAN, segmentation, scoping, QSA, SAQ, and ROC
- CDE membership for components with unrestricted connectivity to components that handle CHD or SAD
- Definitions of payment channels and payment processors
- https://www.pcisecuritystandards.org/faqs/1115/
Supports
- Systems are considered part of the CDE unless adequate segmentation isolates systems that handle cardholder data from those that do not
- Segmentation used to reduce scope must be verified as effective and working as intended
- https://www.pcisecuritystandards.org/faqs/1580/
Supports
- Scope for service providers that can impact payment account data security without directly handling that data
- Need to confirm applicable requirements from the services and access involved, and document not-applicable determinations
- https://blog.pcisecuritystandards.org/pci-ssc-publishes-new-guidance-on-compensating-controls-and-the-customized-approach
Supports
- Defined and customized approaches as distinct implementation and validation paths
- Compensating controls as a defined-approach option for legitimate technical or business constraints
- Customized approach expectations for risk maturity, documentation, testing, and maintenance
