PCI DSS Flashcards
What does PCI DSS stand for?
Payment Card Industry Data Security Standard
What is PCI DSS?
Proprietary standard for organisations who handle payment cards associated with: Visa, MasterCard, American Express, etc.
Who administers the PCI standard?
Payment Card Industry Security Standards Council
Who performs validation compliance?
A Qualified Security Assessor (QSA), who creates a Report Of Compliance (ROC), or through a Self Assessment Questionnaire (SAQ).
What is the latest version?
Version 3.1, released in 2015.
How many requirements are specified by the standard?
12 requirements, organised into 6 groups of control objectives.
What are the control objectives?
- Build an maintain a secure network (firewalls and default passwords).
- Protect card holder data (storage and transmission).
- Maintain a vulnerability management programme (AV and secure development).
- Implement strong access control measures (need to know, unique ID, physical access).
- Regularly monitor and test networks (monitor access, test systems).
- Maintain an information security policy (policy).
What kind of supplementary information is provided?
- Penetration testing
- Code reviews and firewall management.
- PCI DSS wireless guidelines.
- Call centre management - can’t digitally record conversations that include card numbers.