Course Code: pcidss
Duration: 14 hours
Prerequisites:
  • Understand the online payment concept 
  • Network Fundamentals 
  • Basics of Information Security 
  • Work experience in an IT or IT-related role
Overview:

This instructor-led, live Payment Card Industry Professional training (online or onsite) provides an individual qualification for industry practitioners who wish to demonstrate their professional expertise and understanding of the PCI Data Security Standard (PCI DSS).

By the end of this training, participants will be able to:

  • Understand the payment process and the PCI standards designed to protect it.
  • Understand the roles and responsibilities for entities involved in the payment industry.
  • Have deep insight into, and understanding of, the 12 PCI DSS requirements.
  • Demonstrate knowledge of PCI DSS and how it applies to organizations that are involved in the transaction process.

Format of the Course

  • Interactive lecture and discussion.
  • Lots of exercises and practice.
  • Hands-on implementation in a live-lab environment.

Course Customization Options

  • To request a customized training for this course, please contact us to arrange.
Course Outline:

Introduction

Understanding PCI-DSS

  • Introduction to PCI-DSS
  • Importance of PCI-DSS compliance
  • Key objectives of PCI-DSS

PCI-DSS Standards and Requirements

  • Overview of PCI-DSS requirements
  • The 12 PCI-DSS requirements
    • Build and maintain a secure network and systems
    • Protect cardholder data
    • Maintain a vulnerability management program
    • Implement strong access control measures
    • Regularly monitor and test networks
    • Maintain an information security policy

PCI-DSS Compliance and Assessment

  • PCI-DSS compliance process
  • Roles and responsibilities in PCI-DSS compliance
  • Types of PCI-DSS assessments (SAQ, ROC)
  • Working with Qualified Security Assessors (QSAs)

Scoping and Segmentation

  • Defining the cardholder data environment (CDE)
  • Scoping PCI-DSS
  • Network segmentation and its importance

Building and Maintaining a Secure Network

  • Firewalls and router configurations
  • Securing network components
  • Wireless networking security

Protecting Cardholder Data

  • Data encryption and masking techniques
  • Protecting stored cardholder data
  • Secure transmission of cardholder data

Maintaining a Vulnerability Management Program

  • Regular updates and patch management
  • Identifying and mitigating vulnerabilities
  • Anti-virus and anti-malware solutions

Implementing Strong Access Control Measures

  • Access control policies and procedures
  • Managing user access and authentication
  • Physical security controls

Regularly Monitoring and Testing Networks

  • Monitoring network traffic and logs
  • Conducting vulnerability scans
  • Penetration testing best practices

Maintaining an Information Security Policy

  • Developing and implementing security policies
  • Security awareness training for employees
  • Incident response planning

Preparing for a PCI-DSS Audit

  • Preparing documentation and evidence
  • Conducting internal audits
  • Addressing non-compliance issues

Summary and Next Steps

Sites Published:

United Arab Emirates - PCI-DSS Practitioner

Qatar - PCI-DSS Practitioner

Egypt - PCI-DSS Practitioner

Saudi Arabia - PCI-DSS Practitioner

South Africa - PCI-DSS Practitioner

Brasil - PCI-DSS Practitioner

Canada - PCI-DSS Practitioner

中国 - PCI-DSS Practitioner

香港 - PCI-DSS Practitioner

澳門 - PCI-DSS Practitioner

台灣 - PCI-DSS Practitioner

USA - PCI-DSS Practitioner

Österreich - PCI-DSS Practitioner

Schweiz - PCI-DSS Practitioner

Deutschland - PCI-DSS Practitioner

Czech Republic - PCI-DSS Practitioner

Denmark - PCI-DSS Practitioner

Estonia - PCI-DSS Practitioner

Finland - PCI-DSS Practitioner

Greece - PCI-DSS Practitioner

Magyarország - PCI-DSS Practitioner

Ireland - PCI-DSS Practitioner

Luxembourg - PCI-DSS Practitioner

Latvia - PCI-DSS Practitioner

España - PCI-DSS Practitioner

Italia - PCI-DSS Practitioner

Lithuania - PCI-DSS Practitioner

Nederland - PCI-DSS Practitioner

Norway - PCI-DSS Practitioner

Portugal - PCI-DSS Practitioner

România - PCI-DSS Practitioner

Sverige - PCI-DSS Practitioner

Türkiye - PCI-DSS Practitioner

Malta - PCI-DSS Practitioner

Belgique - PCI-DSS Practitioner

France - PCI-DSS Practitioner

日本 - PCI-DSS Practitioner

Australia - PCI-DSS Practitioner

Malaysia - PCI-DSS Practitioner

New Zealand - PCI-DSS Practitioner

Philippines - PCI-DSS Practitioner

Singapore - PCI-DSS Practitioner

Thailand - PCI-DSS Practitioner

Vietnam - PCI-DSS Practitioner

India - PCI-DSS Practitioner

Argentina - PCI-DSS Practitioner

Chile - PCI-DSS Practitioner

Costa Rica - PCI-DSS Practitioner

Ecuador - PCI-DSS Practitioner

Guatemala - PCI-DSS Practitioner

Colombia - PCI-DSS Practitioner

México - PCI-DSS Practitioner

Panama - PCI-DSS Practitioner

Peru - PCI-DSS Practitioner

Uruguay - PCI-DSS Practitioner

Venezuela - PCI-DSS Practitioner

Polska - PCI-DSS Practitioner

United Kingdom - PCI-DSS Practitioner

South Korea - PCI-DSS Practitioner

Pakistan - PCI-DSS Practitioner

Sri Lanka - PCI-DSS Practitioner

Bulgaria - PCI-DSS Practitioner

Bolivia - PCI-DSS Practitioner

Indonesia - PCI-DSS Practitioner

Kazakhstan - PCI-DSS Practitioner

Moldova - PCI-DSS Practitioner

Morocco - PCI-DSS Practitioner

Tunisia - PCI-DSS Practitioner

Kuwait - PCI-DSS Practitioner

Oman - PCI-DSS Practitioner

Slovakia - PCI-DSS Practitioner

Kenya - PCI-DSS Practitioner

Nigeria - PCI-DSS Practitioner

Botswana - PCI-DSS Practitioner

Slovenia - PCI-DSS Practitioner

Croatia - PCI-DSS Practitioner

Serbia - PCI-DSS Practitioner

Bhutan - PCI-DSS Practitioner

Nepal - PCI-DSS Practitioner

Uzbekistan - PCI-DSS Practitioner