PCI Fundamentals
Timothy M. Virtue · 2012
This chapter provides an introduction to the Payment Card Industry Data Security Standards (PCI DSS) and focuses on how it is important to an organization. Fundamentally, many of the methodologies and specific requirements associated with PCI DSS are actually industry standards or best practices. Any organization that can implement and manage the components of PCI DSS will significantly improve its overall security posture and fortify its protection of sensitive cardholder data. Also, PCI DSS compliance offers many organizational benefits and specific risk mitigation solutions. The cardholder data environment has an aggregated risk based on the subrisk categories of reputation, financial, compliance, and operational. The chapter represents how each category of risk is tied together to create an overall level of risk for the cardholder data environment. The PCI Security Standards Council has established 12 detailed control objectives, which are grouped into six broader categories—build and maintain a secure network, protect cardholder data, maintain a vulnerability management program, implement strong access control measures, regularly monitor and test networks, and maintain an information security policy.