Book description
This book is your go-to reference on how to achieve PCI compliance. With more than 400 PCI requirements, the updated PCI Data Security Standard (PCI DSS) v4.0 does not detail the specific documentation that a PCI auditor—known as a Qualified Security Assessor (QSA)—needs to know. This book is the first reference to detail the specific documentation needed for every PCI requirement. The authors provide real-world examples of complying with the 12 main PCI requirements and clarify many of the gray areas within the PCI DSS.PCI DSS v4.0 has a transition period in which PCI DSS version 3.2.1 will remain active for two years from the v4.0 publication date. Although the transition period ends on March 31, 2024, and may seem far away, those tasked with PCI compliance will need every bit of the time to acquaint themselves with the many news updates, templates, forms, and more, that PCI v4.0 brings to their world.
What You’ll Learn
- Know what it takes to be PCI compliant
- Understand and implement what is in the PCI DSS
- Get rid of cardholder data
- Everything you need to know about segmenting your cardholder data network
- Know what documentation is needed for your PCI compliance efforts
- Leverage real-world experience to assist PCI compliance work
Who This Book Is For
Compliance managers and those tasked with PCI compliance, information security managers, internal auditors, chief security officers, chief technology officers, and chief information officers. Readers should have a basic understanding of how credit card payment networks operate, in addition to basic security concepts.Table of contents
- Cover
- Front Matter
- 1. A Brief History of PCI
- 2. Install and Maintain Network Security Controls
- 3. Apply Secure Configurations to All System Components
- 4. Protect Stored Account Data
- 5. Protect Cardholder Data with Strong Cryptography During Transmission Over Open, Public Networks
- 6. Protect All Systems and Networks from Malicious Software
- 7. Develop and Maintain Secure Systems and Software
- 8. Restrict Access to System Components and Cardholder Data by Business Need to Know
- 9. Identify Users and Authenticate Access to System Components
- 10. Restrict Physical Access to Cardholder Data
- 11. Log and Monitor All Access to System Components and Cardholder Data
- 12. Test Security of Systems and Networks Regularly
- 13. Support Information Security with Organizational Policies and Programs
- 14. How to Read a Service Provider Attestation of Compliance
- 15. Segmentation and Tokenization
- 16. The Customized Approach, Compensating Controls, and the Targeted Risk Analysis
- Back Matter
Product information
- Title: The Definitive Guide to PCI DSS Version 4: Documentation, Compliance, and Management
- Author(s):
- Release date: May 2023
- Publisher(s): Apress
- ISBN: 9781484292884
You might also like
book
PCI DSS: An Integrated Data Security Standard Guide
Gain a broad understanding of how PCI DSS is structured and obtain a high-level view of …
book
PCI DSS: A pocket guide, sixth edition
This pocket guide is perfect as a quick reference for PCI professionals, or as a handy …
book
Securing Cloud Services - A pragmatic approach, second edition
Securing Cloud Services – A pragmatic guide gives an overview of security architecture processes and explains …
book
Understand, Manage, and Measure Cyber Risk®: Practical Solutions for Creating a Sustainable Cyber Program
When it comes to managing cybersecurity in an organization, most tussle with basic foundational components. This …