Start learning!  (0% complete)

quiz close icon

module menu icon What is the Payment Card Industry Data Security Standard?

What is the Payment Card Industry Data Security Standard?

The Payment Card Industry Data Security Standard (PCI DSS) is a set of rules to help protect businesses and shoppers from data theft and fraud.

The rules apply to any company that accepts payment by card and/or processes, stores or transmits payment card data.

When businesses follow these rules we say they are PCI DSS compliant.

Being compliant with PCI DSS is important because:

  • It protects customer data
  • It helps businesses avoid fines and penalties
  • It maintains customer trust

Compliance with PCI DSS is monitored by the PCI Security Standards Council. They have 12 requirements that all businesses must meet:

  1. Install and maintain a secure network

  2. Do not use vendor-supplied defaults for system passwords and other security parameters

  3. Protect stored card holder data

  4. Encrypt transmission of cardholder data across open, public networks

  5. Use and regularly update anti-virus software or programs

  6. Develop and maintain secure systems and applications

  7. Restrict access to cardholder data by business need-to-know

  8. Assign a unique id to each person with computer access

  9. Restrict physical access to cardholder data

  10. Track and monitor all access to network resources and cardholder data

  11. Regularly test security systems and processes

  12. Maintain a policy that addresses information security for all personnel