PCI DSS Foundation: Understanding the Payment Card Data Security Standard
Protecting payment data is central to customer trust and your obligations. Understand PCI DSS by connecting its requirements with systems, processes and responsibilities. Develop an operational understanding of the framework to contribute to compliance work.
- Duration
- 2 days 14 hours
- Code
- PCIF2FR Code
Presentation
Preparation for PCI DSS Foundation certification (IBITGQ)
Payment card data—card numbers, expiry dates and security codes—has become a prime target for cyberattackers, making information system security essential for e-commerce and financial organisations. The global PCI DSS standard sets strict technical and organisational requirements that entities storing or processing this information must meet, or face penalties.
This 2-day course takes you into the heart of electronic payments and the PCI DSS v4 security standard ecosystem. You will explore the 6 control domains and 12 fundamental requirements, while addressing the practical management of a compliance project, required document templates and common pitfalls to avoid.
By the end of the programme, you will be able to protect sensitive data and confidently manage compliance for your electronic payment system. You will also be ready to prepare your application for the official PCI DSS Foundation certification (see the certification tab for details).
Objectives
By the end of this PCI DSS v4 course, you will be able to:
- understand electronic payment fundamentals and master the associated security challenges;
- understand the overall PCI DSS ecosystem and its rigorous compliance process;
- master the 6 control domains and 12 technical requirements imposed by the standard;
- identify practical security measures to implement, best practices to adopt and mistakes to avoid;
- plan an effective certification pathway by mastering self-assessment questionnaires (SAQs) and documentation;
- prepare effectively for the PCI DSS Foundation certification exam.
Program
Module 1: understanding the PCI DSS standard and ecosystem
- The context and benefits of PCI DSS compliance.
- Electronic payment roles and stakeholders: merchants, acquirers and issuers.
- The payment flow and electronic payment process.
- Payment fraud and risks.
- The PCI Security Standards Council (PCI SSC) and other standards it publishes: PCI PTS and PCI P2PE.
- The history and objectives of PCI DSS.
- The pillars of information security: confidentiality, integrity and availability.
- The relationship between PCI DSS and other standards such as ISO 27001 and ISO 27002.
- Payment card data: distinguishing confidential data from sensitive data.
- Merchant types, self-assessment questionnaires (SAQs) and compliance documentation (AOC and ROC).
- Applicability and scope of the standard: organisational and technical.
Practical exercises
- Identify the scope and applicable SAQ type for a given case.
Module 2: understanding the standard's 6 domains and 12 requirements
- Domain 1: build and maintain a secure network and systems
- installing and maintaining network security controls (requirement 1);
- applying secure configurations to all system components (requirement 2).
- Domain 2: protect account data
- protecting stored card data (requirement 3);
- protecting data with strong cryptography during transmission over open, public networks (requirement 4).
- Domain 3: maintain a vulnerability management programme
- protecting all systems and networks from malicious software (requirement 5);
- developing and maintaining secure systems and software (requirement 6).
- Domain 4: implement strong access control measures
- restricting access to system components and data according to business need (requirement 7);
- identifying users and authenticating access (requirement 8);
- restricting physical access to cardholder data (requirement 9).
- Domain 5: regularly monitor and test networks
- logging and monitoring all access to system components (requirement 10);
- regularly testing system and network security (requirement 11).
- Domain 6: maintain an information security policy
- supporting information security through organisational policies and programmes (requirement 12).
- Overview of the standard's appendices.
Case study
- Analyse real-world risk and threat scenarios affecting payment systems.
Module 3: mastering the compliance process and documentation
- The role of Qualified Security Assessors (QSAs) and Internal Security Assessors (ISAs) in the annual assessment process.
- The PCI DSS project: nature, challenges, governance, roles and responsibilities, success factors, plan, scope, technologies and required documentation.
- Actions to avoid in a compliance project.
- The certification pathway and associated practical advice.
- New features of PCI DSS v4 and comparison with version 3.2.1.
- Introduction to document templates: gap analysis, information security policy, incident response plan and flow diagrams.
Case study
- Analyse document templates and develop a compliance action plan.
Module 4: preparing for the PCI DSS Foundation exam
- In-depth review of the key concepts covered across all modules.
- Official PCI SSC documents and methodological guidance for reading them.
- Strategies to maximise your chances of exam success.
Practical exercises
- Complete a practice quiz to validate your learning before taking the official exam.
Audience
Designed for cybersecurity and compliance professionals, this course is intended for people involved in electronic payments, particularly:
- managers and staff involved in payment security or PCI DSS compliance;
- members of CISO teams, security engineers and security architects, as well as consultants and technical or business project managers who want to work with PCI DSS;
- anyone involved in an electronic payment system, such as a bank or service provider, or seeking to comply with the standard.
Prerequisites
This course requires the following prerequisites:
- Technical knowledge: sound general knowledge of information system security management.
- Language skills: an understanding of technical English, as the certification exam is available in English.
- Recommendation: reading PCI DSS A Pocket Guide beforehand is helpful for becoming familiar with the terminology.
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Quiz / multiple-choice questions
- Practical exercises
- Case study
Course highlights
- Expert PCI DSS instructors: benefit from instructors with expertise in PCI DSS v4.0.1, providing a thorough, practical understanding of the latest payment security requirements.
- Comprehensive, practical course materials: access detailed learning materials in digital PDF format, designed to support learning and serve as a reference after the course, helping you apply key concepts.
- Focused certification preparation: this course prepares you directly for the official PCI DSS Foundation exam, arranged separately with IBITGQ.
- Case studies and quizzes: strengthen your understanding and analytical skills through practical learning. Numerous case studies and regular quizzes let you test your knowledge and consolidate it in realistic situations.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
Session alerts
PCI DSS is a registered trademark of the PCI Security Standards Council, LLC.
IBITGQ is a registered trademark of the International Board for IT Governance Qualifications Corp.
fr
en