PCI-DSS - Payment Card Industry Data Security Standard
Payment Card Industry Data Security Standard for securely processing, storing, or transmitting payment card account data. PCI-DSS is established by leading payment card brands and maintained by the PCI Security Standard Council (PCI SSC).
The PCI-DSS have following compliance levels:
- Level 1: Merchants or Service Providers processing over 6 million card transactions annually.
- Level 2: Merchants or Service Providers processing 1 to 6 million transactions annually.
- Level 3: Merchants or Service Providers processing 20,000 to 1 million transactions annually.
- Level 4: Merchants or Service Providers processing fewer than 20,000 transactions annually.
PCI-DSS Requirements
CONTROL OBJECTIVES | REQUIREMENTS |
---|---|
Build And Maintain A Secure Network |
|
Protect Cardholder Data |
|
Maintain A Vulnerability Management Program |
|
Implement Strong Access Control Measures |
|
Regularly Monitor And Test Network |
|
Maintain An Information Security Policy |
|
PCI Council Guidance on BAU
Monitoring of security controls |
|
---|---|
Periodic Review |
|
Review changes to environment |
|
Ensuring failures in security controls are detected and responded |
|
PCI DSS Roadmap
Visit following sections for more information’s on next step for getting certified from INTERCERT