| |
 |
Payment Credit Card Industry Data
Security Standard (PCI DSS)
Training
The Payment Card Industry Security Standards Council, an
independent council originally formed by American Express,
Discover Financial Services, JCB, MasterCard Worldwide and Visa
International on Sept. 7, 2006, with the goal of managing the
ongoing evolution of the Payment Card Industry Data Security
Standard.
The standard specifies 12 requirements for compliance, organized
into 6 logically related groups, which are called "control
objectives."
The control objectives and their requirements are:
Build and Maintain a Secure Network
Requirement 1: Install and maintain a firewall configuration to
protect cardholder data
Requirement 2: Do not use vendor-supplied defaults for system
passwords and other security parameters
Protect Cardholder Data
Requirement 3: Protect stored cardholder data
Requirement 4: Encrypt transmission of cardholder data across
open, public networks
Maintain a Vulnerability Management Program
Requirement 5: Use and regularly update anti-virus software
Requirement 6: Develop and maintain secure systems and
applications
Implement Strong Access Control Measures
Requirement 7: Restrict access to cardholder data by business
need-to-know
Requirement 8: Assign a unique ID to each person with computer
access
Requirement 9: Restrict physical access to cardholder data
Regularly Monitor and Test Networks
Requirement 10: Track and monitor all access to network resources
and cardholder data
Requirement 11: Regularly test security systems and processes
Maintain an Information Security Policy
Requirement 12: Maintain a policy that addresses information
security
-----------------------------------------------------------------------------------------------------------------------------------------------------------------------
PCI Training -
1
Complying with the Payment Card Industry Data Security Standard
- ITP311

Strategies for Protecting and Auditing Payment Card Information
Applications and Achieving PCI DSS Compliance - from the MIS
Training Institute
The Payment Credit Card Industry Data Security Standard (PCI DSS)
is designed to
protect credit card information wherever and whenever it is
processed, stored, or transmitted, and to ensure that members,
merchants, and service providers maintain the highest security
standards.
Meeting the 12 requirements of this evolving standard, however,
can be a daunting challenge, and non-compliance can result in
costly fines and loss of valuable retail customers.
In this timely, three-day seminar, you will gain solid familiarity
with the current PCI DSS and any recent significant changes, and
get proven tips on how best to overcome compliance challenges.
You will examine and interpret each of the 12 compliance
requirements and cover practical solutions, potential issues, and
common pitfalls.
You will identify, organize, and address the full spectrum of
physical, administrative, and technical controls necessary to meet
or exceed PCI DSS requirements using a practical, commonsense
method that emphasizes a structured implementation approach to
day-to-day business operations.
You will explore how to leverage your experience with other key
industry information security standards and regulations to
minimize costly “re-inventions of the wheel.”
You will focus on the use of practical, cost-effective safeguards
and auditing/self assessment tools and techniques, and learn how
you can leverage safeguards that are already on-hand with
essential add-ons that can often be acquired from open source
technology.
www.misti.com
----------------------------------------------------------------------------------------------------------------------------------------------------------------------
PCI Training -2
Training
from the PCI Security Standards Council
The PCI
Security Standards Council is an open global forum, launched in
2006, that is responsible for the development, management,
education, and awareness of the PCI Security Standards, including:
the Data Security Standard (DSS), Payment Application Data
Security Standard (PA-DSS), and Pin-Entry Device (PED)
Requirements.
All of the five founding members have agreed to incorporate the
PCI DSS as the technical requirements of each of their data
security compliance programs. Each founding member also recognizes
the QSAs and ASVs certified by the PCI Security Standards Council
as being qualified to validate compliance to the PCI DSS.
A Limited Liability Corporation (LLC) chartered in Delaware, USA,
the PCI Security Standards Council was founded by American
Express, Discover Financial Services, JCB International,
MasterCard Worldwide, and Visa Inc.
All five
payment brands share equally in the council's governance, have
equal input to the PCI Security Standards Council and share
responsibility for carrying out the work of the organization.
Other industry stakeholders are encouraged to join the group and
review proposed additions or modifications to the standards.
The PCI
Security Standards Council is an open global forum for the ongoing
development, enhancement, storage, dissemination and
implementation of security standards for account data protection.
The Council
provides a variety of resources to the marketplace in order to
further security awareness within the payment card industry. These
resources include:
-
Training for
Qualified Security Assessors (QSAs) and Payment Application
Qualified Security Assessors (PA-QSAs)
-
Fact Sheets
-
Information
Supplements
-
Frequently
Asked Questions
www.pcisecuritystandards.org
-----------------------------------------------------------------------------------------------------------------------------------------------------------------------
|
|
Keywords
PCI Training,
Payment Card Industry Data Security Standard, Payment Card
Industry Data Security Standard Training, Payment Card Industry
Training
Return to
Index
Privacy/Legal
 | |