PCI DSS – Payment Card Industry Data Security Standard

PCI DSS – Payment Card Industry Data Security Standard

Security for international card-based payment transactions

The PCI DSS is a set of rules developed by the international payment systems Visa, MasterCard, American Express, Discover and JCB International (united in the PCI Security Standards Council) to ensure the security of payments with their payment cards.

Merchants who accept payments with such cards and service providers who support them in doing so must comply with the PCI DSS regulations. The regulations cover IT security best practices:

  • Network security
  • System hardening
  • Encryption
  • Vulnerability management
  • Access and access control
  • Monitoring, logging and regular checks of the network
  • Information security management, processes and policies

So that your customers have confidence in you

Compliance with the PCI DSS requirements makes it much more difficult for attackers to obtain payment data. This ensures a secure payment system and maintains customer confidence.

By complying with the PCI DSS, companies are also already implementing measures to ensure compliance with other compliance requirements, such as the PCI DSS. Facilitate requirements from the EU General Data Protection Regulation (DSGVO) or the IT Security Act, bank regulatory requirements for IT (BAIT) or requirements from international standards such as ISO/IEC 27001.

PCI DSS v4.0 is approaching – we support you in your preparations

The PCI DSS is a mature standard that defines requirements for the secure processing of card data of international payment systems.

Version 3 of the PCI DSS, which – with various updates – has been valid since 2014, will finally expire at the end of March 2024 and will be supplemented by the new version 4.0.

We take the final steps with you to migrate to PCI DSS v4.0.

Please feel free to take advantage of our offers:

1. monthly blog articles, each highlighting a PCI DSS v4.0 topic in more detail.

  • September 2023: Timeline for PCI DSS v4.0 migration – What are my next steps?
  • October 2023: Roles and responsibilities in PCI DSS v4.0 – How can I meet the new documentation requirements?
  • more you will find updated at this place

2. free webinars summarising the changes from PCI DSS v3.2.1 to v4.0 for you once again.

As soon as the exact dates are fixed and the registration is activated, you will find the corresponding links here:

  • Webinar on the full PCI DSS scope (January 2023)
  • Webinar for Card-Present merchants with SAQ B-IP or P2PE scope (January 2023)
  • Webinar for e-commerce merchants with SAQ A scope (January 2023)
  • PCI DSS v4.0 workshops tailored to you, in which we specifically present and discuss the requirements relevant to you.
    Please contact Ms Jana Ehlers, see contact info.
  • A gap analysis for your environments and processes. You will receive a list of all open points in your company for PCI DSS v4.0 compliance.
    Please contact Ms Jana Ehlers, see contact info.
  • Consultation packages of your choice, of which you can call up quotas at any time if you have specific queries – by telephone, e-mail, web conference, or in on-site meetings.
    Please contact Ms Jana Ehlers, see contact info.

 

Links on the topic of PCI DSS

Your contact

Please use our general contact form:

Are you looking for a specific certification?

Find out which certifications SRC GmbH can offer in this area.

We have the perfect solution for you

Find out about the solutions we offer in this subject area.

PCI Card Production

PCI P2PE

PCI PTS

PCI PA DSS

PCI DSS Audit

Penetration test

Training on this topic

Experience exciting talks and networking at our event. Register now and become part of the community!

Our partners in this area

Your career at SRC - Discover your opportunities!