PCI Standard & Your Professional Role Flashcards
An independent industry standards body providing oversight of the development and management of Payment Card Industry Data Security Standards on a global basis.
PCI SSC
PCI SSC founding payment brands include:
- American Express
- Discover Financial
- JCB International
- MasterCard
- Visa
The resources provided by PCI SSC:
- PCI DSS, PA-DSS, P2PE, PTS(POI, HSM and PIN),Card Production, and supporting documents - PCI Security Standards Council FAQs
- Education and outreach programs
- Roster of QSAs, PA-QSAs, PCIPs, ASVs, validated payment applications, PTS Devices, and P2PE solutions
- Participating organization membership, community meetings, feedback
Each payment brand develops and maintain its own ————— programs in accordance with its own security risk management policies
PCI DSS compliance
Data Security Operating Policy (DSOP)
American Express
Discover Information Security Compliance (DISC)
Discover
Data Security Program
JCB
Site Data Protection(SDP)
MasterCard
Cardholder Information Security Program (CISP) Account Information Security (AIS) Program
VISA
Payment brands’ compliance programs include:
- Tracking and enforcement - Penalties, feed, compliance deadlines
- Validation process and who needs to validate
- Definition of merchant and service provider levels
Payment brands are also responsible for:
- Defining rules for forensic investigations and responding to account data compromises
- Monitoring and facilitating investigations of account data compromises to completion
Covers Security of the environments that store, process, or transmit account data
PCI DSS
Covers secure payment applications to support PCI DSS compliance
PCI PA-DSS
Covers encryption, decryption, and key management requirements for point-to-point encryption solutions
PCI P2PE
Covers the protection of sensitive data at point-of-interaction devices and their secure components
PCI PTS-POI
Covers secure management,processing and transmission of personal identification number (PIN) data
PCI PTS-PIN Security
Covers physical,logical,and device security requirements for securing Hardware Security Modules (HSM)
PCI PTS-HSM
Covers physical and logical security requirements for entities involved in producing payment cards
PCI Card Production
Covers physical and logical security requirements for Token Service Providers that generate and issue EMV Payment Tokens
PCI Token Service Provider Requirements (TSP)
Covers the risk framework to protect the confidentiality and integrity of sensitive payment information captured and processed on a cardholder verification method (CVM) solution
PCI Software-Based PIN Entry on COTS Security Requirements (SPoC)
Covers the secure design and development processes of payment software. (Transition Plan for PA-DSS)
PCI Software Security Standard (S3)
Covers the security requirements for assessing 3-D Secure (3DS) entities that perform the following 3DS functions:
- Access Control Server(ACS)
- Directory Server (DS)
- 3DS Server (3DSS)
PCI 3DS Core Security Standard
Covers the security requirements for “app based” 3-D Secure Software Development Kits(SDK) as defined in the 3-D Secure SDL Specification managed and maintained by EMVCo
PCI 3DS SDK Standard
Functions of Payment Application Data Security Standard (PA-DSS)
- Provides a list of validated applications to choose from
- Validated applications are proven to facilitate PCI DSS compliance
- Does it guarantee compliance?
- For applications that are sold/licensed to others
- Must have a PA-DSS Implementation Guide