Working with the PCI DSS 4.0 Compliance Requirements
2h 45mIntermediate2023-04-18
Authors

Laura Louthan
Information Security and IT Leader with 20 years of experience
Course details
If you have a business, organization, or entity of any kind that processes, transmits, or stores cardholder data, you need to meet PCI Data Security Standards. In this course, Laura Louthan covers what you need to know to be in compliance and work with PCI DSS—the Payment Card Industry Data Security Standard, focusing specifically on the newest control version 4.0. Laura dives into the 12 main PCI requirements, their child controls (totaling over 300), and how to meet the intent of each control as you work toward full compliance. Whether you’re a merchant, payment processor, data center, or any other business that needs to ensure the security of cardholder data, follow along with Laura’s advice on installing and maintaining security controls; configuring components; protecting data, systems, and networks; securing systems and software; controlling, authenticating, and restricting access; logging and monitoring access; security testing; risk management; and more.
Skills covered
E-Commerce DevelopmentWeb DevelopmentOne-Off
Concepts
Introduction
- Introduction to PCI 4.0
- What you should know as background for this course
- How this course is designed to help you learn
Requirement 1 - Install and Maintain Network Security Controls
- Network security - Creating strong network security controls
- Network security - Controlling traffic appropriately
Requirement 2 - Apply Secure Configurations to All System Components
- Secure configurations - Building hardening standards
Requirement 3 - Protect Stored Account Data
- Stored PANs - Which data can you store and how
- Cryptographic controls for stored PAN data
- Key management policies and procedures
NAME ADJUSTMENT NEEDED
- Safely sending PAN data using strong cryptography
Requirement 5 - Protect All Systems and Networks from Malicious Software
- Anti-malware options and anti-phishing
Requirement 6 - Develop and Maintain Secure Systems and Software
- Secure development
- Security vulnerabilities and protecting public sites
- Change management requirements
Requirement 7 - Restrict Access to System Components and Cardholder Data by Business Need to Know
- Designing access controls
- Access control systems
Requirement 8 - Identify Users and Authenticate Access to System Components
- Basic user ID requirements
- Strong authentication for PCI
- Multifactor authentication requirements
- System and application account requirements
Requirement 9 - Restrict Physical Access to Cardholder Data
- Managing physical access
- Managing physical media
- Managing physical payment devices
Requirement 10 - Log and Monitor All Access to System Components and Cardholder Data
- Collecting audit logs
- Reviewing audit logs
- Time synchronization for logs
- Critical security control failures
Requirement 11 - Test the Security of Systems and Networks Regularly
- Protecting wireless access points
- Vulnerability scanning
- Penetration testing
- Network intrusions and unexpected file changes
Requirement 12 - Support Information Security with Organizational Policies and Programs
- Information security policy and acceptable use
- Risk management and tracking PCI compliance
- Tracking PCI scope, maintaining awareness, and screening
- Third-party service provider risks
- Incident response
Conclusion
- Next steps to meet PCI 4.0