Course Outline
Introduction
Understanding PCI-DSS
- Introduction to PCI-DSS
- Importance of PCI-DSS compliance
- Key objectives of PCI-DSS
PCI-DSS Standards and Requirements
- Overview of PCI-DSS requirements
- The 12 PCI-DSS requirements
- Build and maintain a secure network and systems
- Protect cardholder data
- Maintain a vulnerability management program
- Implement strong access control measures
- Regularly monitor and test networks
- Maintain an information security policy
PCI-DSS Compliance and Assessment
- PCI-DSS compliance process
- Roles and responsibilities in PCI-DSS compliance
- Types of PCI-DSS assessments (SAQ, ROC)
- Working with Qualified Security Assessors (QSAs)
Scoping and Segmentation
- Defining the cardholder data environment (CDE)
- Scoping PCI-DSS
- Network segmentation and its importance
Building and Maintaining a Secure Network
- Firewalls and router configurations
- Securing network components
- Wireless networking security
Protecting Cardholder Data
- Data encryption and masking techniques
- Protecting stored cardholder data
- Secure transmission of cardholder data
Maintaining a Vulnerability Management Program
- Regular updates and patch management
- Identifying and mitigating vulnerabilities
- Anti-virus and anti-malware solutions
Implementing Strong Access Control Measures
- Access control policies and procedures
- Managing user access and authentication
- Physical security controls
Regularly Monitoring and Testing Networks
- Monitoring network traffic and logs
- Conducting vulnerability scans
- Penetration testing best practices
Maintaining an Information Security Policy
- Developing and implementing security policies
- Security awareness training for employees
- Incident response planning
Preparing for a PCI-DSS Audit
- Preparing documentation and evidence
- Conducting internal audits
- Addressing non-compliance issues
Summary and Next Steps
Requirements
- Understand the online payment concept
- Network Fundamentals
- Basics of Information Security
- Work experience in an IT or IT-related role
Testimonials (3)
The fact that there were practical examples with the content
Smita Hanuman - Standard Bank of SA Ltd
Course - Basel III – Certified Basel Professional
The trainer was extremely clear and concise. Very easy to understand and absorb the information.
Paul Clancy - Rowan Dartington
Course - CGEIT – Certified in the Governance of Enterprise IT
I genuinely enjoyed the real examples of the trainer.