Special offers now — see discounted courses.
day
:
hour
:
min
:
sec
See special offers
Working with the PCI DSS 4.0 Compliance Requirements

Working with the PCI DSS 4.0 Compliance Requirements

2h 45mIntermediate2023-04-18

Authors

Laura Louthan

Laura Louthan

Information Security and IT Leader with 20 years of experience

Course details

If you have a business, organization, or entity of any kind that processes, transmits, or stores cardholder data, you need to meet PCI Data Security Standards. In this course, Laura Louthan covers what you need to know to be in compliance and work with PCI DSS—the Payment Card Industry Data Security Standard, focusing specifically on the newest control version 4.0. Laura dives into the 12 main PCI requirements, their child controls (totaling over 300), and how to meet the intent of each control as you work toward full compliance. Whether you’re a merchant, payment processor, data center, or any other business that needs to ensure the security of cardholder data, follow along with Laura’s advice on installing and maintaining security controls; configuring components; protecting data, systems, and networks; securing systems and software; controlling, authenticating, and restricting access; logging and monitoring access; security testing; risk management; and more.

Skills covered

E-Commerce DevelopmentWeb DevelopmentOne-Off

Concepts

0. Introduction

  • 01 - Introduction to PCI 4.0
  • 02 - What you should know as background for this course
  • 03 - How this course is designed to help you learn

1. Requirement 1 - Install and Maintain Network Security Controls

  • 04 - Network security - Creating strong network security controls
  • 05 - Network security - Controlling traffic appropriately

2. Requirement 2 - Apply Secure Configurations to All System Components

  • 06 - Secure configurations - Building hardening standards

3. Requirement 3 - Protect Stored Account Data

  • 07 - Stored PANs - Which data can you store and how
  • 08 - Cryptographic controls for stored PAN data
  • 09 - Key management policies and procedures

4. NAME ADJUSTMENT NEEDED

  • 10 - Safely sending PAN data using strong cryptography

5. Requirement 5 - Protect All Systems and Networks from Malicious Software

  • 11 - Anti-malware options and anti-phishing

6. Requirement 6 - Develop and Maintain Secure Systems and Software

  • 12 - Secure development
  • 13 - Security vulnerabilities and protecting public sites
  • 14 - Change management requirements

7. Requirement 7 - Restrict Access to System Components and Cardholder Data by Business Need to Know

  • 15 - Designing access controls
  • 16 - Access control systems

8. Requirement 8 - Identify Users and Authenticate Access to System Components

  • 17 - Basic user ID requirements
  • 18 - Strong authentication for PCI
  • 19 - Multifactor authentication requirements
  • 20 - System and application account requirements

9. Requirement 9 - Restrict Physical Access to Cardholder Data

  • 21 - Managing physical access
  • 22 - Managing physical media
  • 23 - Managing physical payment devices

10. Requirement 10 - Log and Monitor All Access to System Components and Cardholder Data

  • 24 - Collecting audit logs
  • 25 - Reviewing audit logs
  • 26 - Time synchronization for logs
  • 27 - Critical security control failures

11. Requirement 11 - Test the Security of Systems and Networks Regularly

  • 28 - Protecting wireless access points
  • 29 - Vulnerability scanning
  • 30 - Penetration testing
  • 31 - Network intrusions and unexpected file changes

12. Requirement 12 - Support Information Security with Organizational Policies and Programs

  • 32 - Information security policy and acceptable use
  • 33 - Risk management and tracking PCI compliance
  • 34 - Tracking PCI scope, maintaining awareness, and screening
  • 35 - Third-party service provider risks
  • 36 - Incident response

Conclusion

  • 37 - Next steps to meet PCI 4.0

About us

LyndaKade is a leading learning platform that helps people learn business, software, technology, and creative skills to achieve personal and professional goals.

Phone numberAparat ChannelTelegram SupportTelegram ChannelInstagram Page

All rights to this site belong to LyndaKade.

Terms of Service|Privacy Policy

نماد الکترونیک enamad در صورت اتصال با آی‌پی داخل کشور، نمایش داده خواهد شد.
logo-samandehi - لوگو ساماندهی
Zarinpal
Zibal