What is PCI DSS?
PCI DSS (Payment Card Industry Data Security Standard) is a global security standard developed by major card brands (Visa, Mastercard, American Express, Discover, JCB) to protect cardholder data. Any organization that handles payment card data must comply.
The 12 Requirements
Build and Maintain Secure Network
- Install and maintain firewall configuration
- Don't use vendor-supplied defaults
Protect Cardholder Data 3. Protect stored cardholder data 4. Encrypt transmission across open networks
Maintain Vulnerability Management 5. Protect against malware 6. Develop secure systems and applications
Implement Strong Access Control 7. Restrict access on need-to-know basis 8. Identify and authenticate access 9. Restrict physical access
Monitor and Test Networks 10. Track and monitor all access 11. Regularly test security systems
Maintain Information Security Policy 12. Maintain security policy for all personnel
Compliance Levels
| Level | Transaction Volume | Validation |
|---|---|---|
| 1 | 6M+ annually | On-site audit (QSA) |
| 2 | 1M-6M annually | SAQ |
| 3 | 20K-1M e-commerce | SAQ |
| 4 | <20K e-commerce | SAQ |
PCI DSS v4.0 Changes
- Customized approach option
- Enhanced authentication requirements
- Stronger encryption standards
- Focus on continuous security