PCI DSS
What is PCI DSS?
The Payment Card Industry Data Security Standard is a set of security requirements for organizations that handle credit card information to protect cardholder data.
Terms that appear alongside pci dss
Each of these is named in at least one of the same controls as pci dss. The number is how many controls name both.
- nist 14 shared controls
- compliance 12 shared controls
- cybersecurity 9 shared controls
- iso 27001 8 shared controls
- integrity 7 shared controls
- soc 2 7 shared controls
- iec 27001 6 shared controls
- authentication 6 shared controls
Frameworks that govern pci dss
What the standards actually require on pci dss
Requirements naming pci dss across 6 standards, quoted from the control text.
PCI DSS scope is documented and confirmed at least once every 12 months by identifying all data flows, system components, and segmentation controls in use.
12.5.2 · PCI DSS scope documented and confirmed annually →Operate payment card data protection per the NRF framework + PCI DSS v4.0.1 + card brand operating rules (Visa + Mastercard + American Express + Discover + JCB + UnionPay + regional schemes).
NRFCS-3 · Payment Card Data Protection and PCI DSS Scope Management →GLI-33 crosswalk to adjacent standards + state-specific technical standards. PCI DSS (Payment Card Industry Data Security Standard) v4.0 - applies to card-not-present payments in event wagering systems; required for any operator handling cards directly;
GLI33-Crosswalk-PCI-NIST-ISO-StateStandards · GLI-33 Crosswalk to PCI DSS, NIST CSF, ISO 27001, State Technical Standards →Upon completion of a significant change, all applicable PCI DSS requirements are confirmed to be in place on all new or changed systems and networks, and documentation is updated as applicable
6.5.2 · Upon completion of a significant change, all applicable PCI DSS requirements are confirmed to be in place on all new or changed systems and networks, and documentation is updated as applicable →Implement Online Financial Services Authentication + Payment Card Security per MAS TRM Chapters 12 + 13. Chapter 12 Online Financial Services Authentication - Two-Factor Authentication (2FA) for customer-facing online services + Strong Customer Authentication...
MAS-TRM-Online-Authentication-Payment-Card-Chapters-12-13-2FA-Strong-Customer-Authentication-PCI-DSS · MAS TRM Online Authentication + Payment Card + Chapters 12-13 + 2FA + Strong Customer Authentication + PCI DSS →Security Dimension 1 Access Control per X.805 Clause 6.1: Access Control protects against unauthorized use of network resources. Access Control ensures that only authorized personnel or devices are allowed access to network elements + stored information + info...
X805-Dim1-Access-Control-RBAC-Authorization-Resources-Network-Elements-Services-Applications · ITU-T X.805 Security Dimension 1 - Access Control + Role-Based Access Control (RBAC) + Authorization + Resources + Network Elements + Services + Applications + Access Limitations + Authorized Personnel + Discretionary + Mandatory Access Control →Questions people ask about pci dss
What is PCI DSS?
Why is PCI DSS important for compliance?
Which compliance frameworks address PCI DSS?
Where can I learn more about PCI DSS?
See how PCI DSS applies across compliance frameworks
Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.