openskills.info
PCI DSS logoCourse Preview

PCI DSS

PCI DSS is the payment-card industry's security standard for organizations whose people, systems, or services handle payment account data or can affect its security. It turns protecting that data into defined technical, operational, and assessment work.

itCybersecurity fundamentals and governance

PCI DSS

PCI DSS is a baseline of technical and operational requirements for protecting payment account data. It applies to more than the database that holds card numbers. It applies to entities that store, process, or transmit cardholder data or sensitive authentication data, and to systems and services that can affect the security of that environment.

The useful first question is not "Which requirement applies?" It is "Where can payment account data go, and what can reach or affect it?" Your answer defines the cardholder data environment, or CDE. The CDE includes people, processes, and system components that handle cardholder data or sensitive authentication data. It also includes components with unrestricted connectivity to them.

Start with scope

Continue the course

This section is part of the paid course.

See pricing to subscribe, or log in if you already have access.

Where this skill leads

Relevant careers

See how this topic contributes to broader role-level skill maps.