PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) is an international data security standard for the payment card industry. It was developed by leading payment systems (Visa, MasterCard, MIR and others) and is mandatory for all organizations that store, transmit or process bank card data.
Contents
What is PCI DSS in simple words
PCI DSS (Payment Card Industry Data Security Standard) is a set of security rules for companies that accept payment by bank cards. These rules are designed to protect cardholder data from theft and fraud.
Imagine that you are opening a store and want to accept card payments. You cannot simply start processing card data — you must prove that your system is secure. PCI DSS is like a technical regulation that says: “Here is what you must do to keep your customers' data safe”.
The standard was developed by the PCI Security Standards Council (PCI SSC), which was founded by Visa, MasterCard, American Express, Discover and JCB. Today PCI DSS is mandatory for all organizations that store, process or transmit payment card data — from large banks to small online stores.
In Russia, the PCI DSS standard applies to all organizations working with Mir cards, as well as with international payment systems. Read about how payment security is ensured in the article Fintech.
12 PCI DSS requirements
The standard consists of 12 main requirements grouped into 6 key goals:
Goal 1: Network protection
- Requirement 1: Installation and maintenance of firewalls to protect card data.
- Requirement 2: Refusal of factory passwords on equipment. All passwords must be changed to unique ones.
Goal 2: Protection of card data
- Requirement 3: Protection of stored card data (PAN, CVV/CVC) with encryption.
- Requirement 4: Encryption of card data transmission over open networks (internet).
Goal 3: Vulnerability management
- Requirement 5: Use and regular update of antivirus software.
- Requirement 6: Development and support of secure systems and applications.
Goal 4: Access control
- Requirement 7: Access to card data only for employees who need it for their work.
- Requirement 8: Identification and authentication of access to systems (mandatory multi-factor authentication).
- Requirement 9: Restriction of physical access to card data.
Goal 5: Monitoring and testing
- Requirement 10: Monitoring and auditing of all user actions.
- Requirement 11: Regular testing of security systems.
Goal 6: Information security
- Requirement 12: Implementation of information security policies.
Read about how these requirements are implemented in practice in the article Cloud security.
How to get a PCI DSS certificate
The process of obtaining a PCI DSS certificate depends on the compliance level (Level 1-4), which is determined by the number of transactions processed per year:
- Level 1: More than 6 million transactions per year. An external audit (QSA audit) and a Report on Compliance (ROC) are required.
- Level 2: From 1 to 6 million transactions. A Self-Assessment Questionnaire (SAQ) and quarterly network scanning are required.
- Level 3: From 20,000 to 1 million transactions. Filling out the SAQ and quarterly scanning are required.
- Level 4: Less than 20,000 transactions. Filling out the SAQ is required.
To pass certification, it is necessary to:
- Determine your compliance level.
- Fill out the appropriate Self-Assessment Questionnaire (SAQ) or undergo an external audit.
- Eliminate all identified vulnerabilities.
- Conduct quarterly ASV network scanning.
- Prepare the documents (AoC — Attestation of Compliance).
Read about how to prepare for an information security audit in the article Certification testing.
Frequently asked questions
What is PCI DSS in simple words?
PCI DSS is an international set of security rules for companies that accept payment by bank cards. These rules protect customer data from theft and fraud. If your business accepts cards, you are obliged to comply with PCI DSS. Read about payment security in the article Fintech.
Who needs PCI DSS?
PCI DSS is needed by all organizations that accept, transmit or store payment card data. These are banks, online stores, payment systems, delivery services, hotels, restaurants — any business that works with cards. Even if you have a small online store, you are obliged to comply with PCI DSS.
What are the 12 PCI DSS requirements?
12 requirements cover six areas: network protection (firewalls, changing passwords), protection of card data (encryption), vulnerability management (antiviruses, updates), access control (authentication, restriction of rights), monitoring and testing, information security policies. The full list of requirements is in the article Cloud security.
How long is the PCI DSS certificate valid?
The PCI DSS certificate is valid for 12 months. After 10 months, you need to start the renewal procedure — undergo a repeated audit or fill out a new self-assessment questionnaire and conduct a quarterly network scan. The certificate must be renewed every year.
What happens if you do not comply with PCI DSS?
Non-compliance with PCI DSS entails serious consequences: fines from payment systems (up to $100,000 per month), suspension of payment acceptance, lawsuits from affected customers and reputational losses. In some cases — revocation of the payment acceptance license. Read about security risks in the article Fraud.
How to prepare for a PCI DSS audit?
To prepare for the audit, it is necessary: to conduct an internal security review (you can order certification testing), implement encryption of card data, set up firewalls and a monitoring system, train employees in security rules, prepare documentation on security policies. It is recommended to involve a qualified specialist (QSA).
How does PCI DSS differ from ISO 27001?
PCI DSS is a specialized security standard for payment data. ISO 27001 is a general information security management standard that is suitable for any data. PCI DSS is mandatory for companies that accept cards. ISO 27001 is voluntary, but is often required for large clients and tenders. They can complement each other.
Other terms in «Information Security»
Was this information helpful?
Protect your network today
Leave a request — our information security specialists will help you select, configure and integrate pci dss into your infrastructure. We will protect your data from threats.