PCI DSS Flashcards
(8 cards)
What does PCI DSS stand for?
Payment Card Industry Data Security Standard
What is PCI DSS?
Proprietary standard for organisations who handle payment cards associated with: Visa, MasterCard, American Express, etc.
Who administers the PCI standard?
Payment Card Industry Security Standards Council
Who performs validation compliance?
A Qualified Security Assessor (QSA), who creates a Report Of Compliance (ROC), or through a Self Assessment Questionnaire (SAQ).
What is the latest version?
Version 3.1, released in 2015.
How many requirements are specified by the standard?
12 requirements, organised into 6 groups of control objectives.
What are the control objectives?
- Build an maintain a secure network (firewalls and default passwords).
- Protect card holder data (storage and transmission).
- Maintain a vulnerability management programme (AV and secure development).
- Implement strong access control measures (need to know, unique ID, physical access).
- Regularly monitor and test networks (monitor access, test systems).
- Maintain an information security policy (policy).
What kind of supplementary information is provided?
- Penetration testing
- Code reviews and firewall management.
- PCI DSS wireless guidelines.
- Call centre management - can’t digitally record conversations that include card numbers.