PCI DSS Foundation: Master the Standard for Protecting Payment Card Data
Protecting payment data is central to customer trust and your obligations. Understand PCI DSS by connecting its requirements to systems, processes and responsibilities. Develop an operational understanding of the framework to contribute to compliance activities.
- Duration
- 4 days 28 hours
- Code
- PCIF4FR Code
Presentation
Payment card data, including card numbers, expiry dates and security codes, is a prime target for cyberattacks worldwide. As fraudsters become increasingly inventive, PCI DSS version 4 has become an essential requirement for banks and merchants seeking to secure their information systems.
This advanced 4-day course immerses you in the PCI DSS regulatory ecosystem. You will study the 12 technical and organisational requirements and identify appropriate security solutions. You will also learn to prepare essential documentation, including gap analyses, incident response plans and compliance evidence.
By the end of this intensive programme, you will be ready to take the PCI DSS Foundation examination and have the operational skills to lead a compliance project. You will know how to ensure that controls are not only in place but genuinely effective in protecting your organisation's payment card data over the long term.
Objectives
By the end of this 4-day PCI DSS course, you will be able to:
- understand payment card fundamentals and master security issues relating to electronic payment systems;
- understand the overall PCI DSS v4 ecosystem, its key stakeholders and compliance processes;
- identify how PCI DSS complements other security standards such as ISO 27001;
- define the technical and organisational scope precisely within the company;
- master the 6 control objectives and all 12 detailed requirements in depth;
- assess technical solutions and security measures to implement while identifying critical mistakes to avoid;
- lead a PCI DSS compliance project end to end and establish an effective path to annual certification;
- use and prepare standard documents, including a security policy, flow diagram and incident response plan, to demonstrate compliance;
- prepare effectively for the official PCI DSS Foundation certification examination.
Program
Module 1: Master the payment card context and PCI DSS ecosystem
- Benefits of compliance, roles and stakeholders in card payments.
- The payment cycle, card payment process and fraud risk analysis.
- Introduction to the PCI SSC and other standards issued by the council (PCI PTS, PCI P2PE).
- Standard applicability, organisational and technical scope, and merchant types (SAQ).
Case study
- Analyse risk and threat scenarios affecting payment systems.
Module 2: Implement technical requirements and data protection
- Implementation approaches and detailed coverage of the six control domains.
- Install and maintain network security controls.
- Apply secure configurations to all system components.
- Protect stored card data.
- Protect cardholder data with strong cryptography during transmission.
Module 3: Manage access control and network monitoring
- Protect against malicious software and develop secure systems.
- Restrict access to system components and data according to business needs.
- Identify users and authenticate access to components.
- Restrict physical access to cardholder data.
- Log and monitor all access and test security regularly.
Module 4: Lead governance and the compliance project
- Strengthen information security through organisational policies and programmes.
- Manage the PCI DSS project: challenges, governance, responsibilities and success factors.
- Analyse new features in PCI DSS v4 and compare them in detail with v3.2.1.
- Introduction to standard documents: gap analysis, security policy and incident response plan.
Case study
- Analyse standard documents and develop a compliance action plan.
Audience
Designed for cybersecurity and compliance professionals, this course is intended for stakeholders involved in electronic payments, particularly:
- managers and employees involved in payment card security or PCI DSS compliance;
- information security team members, including security engineers and security architects;
- consultants and project managers on the technical delivery or business side specialising in security and seeking to work with PCI DSS;
- anyone working within an electronic payment system, such as a bank or service provider, or seeking to comply with the standard.
Prerequisites
The following prerequisites apply:
- Technical knowledge: good general knowledge of information systems security management.
- Language: understand technical English, as the certification examination is in English.
- Recommendation: reading PCI DSS A Pocket Guide beforehand is helpful for familiarising yourself with the terminology.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Quiz / multiple-choice questions
- Case study
Course highlights
- Expert PCI DSS trainers: benefit from trainers with extensive PCI DSS v4.0.1 expertise, ensuring a thorough, practical understanding of the latest payment security requirements.
- Comprehensive, practical course materials: access extensive digital learning resources (PDF), designed to support learning and serve as a reference after the course, helping you put key concepts into practice.
- Case studies and quizzes: strengthen understanding and analytical skills through practical application. Numerous case studies and regular quizzes allow you to test and consolidate knowledge in realistic situations.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
Session alerts
PCI DSS is a registered trademark of the PCI Security Standards Council, LLC
IBITGQ is a registered trademark of the International Board for IT Governance Qualifications Corp.
fr
en