Thank you for sending your enquiry! One of our team members will contact you shortly.
Thank you for sending your booking! One of our team members will contact you shortly.
Course Outline
Introduction
Foundations of PCI-DSS
- Introduction to the PCI-DSS framework
- Significance of maintaining PCI-DSS compliance for government
- Core strategic objectives of the PCI-DSS standard
PCI-DSS Standards and Regulatory Requirements
- Comprehensive overview of PCI-DSS mandates
- The 12 fundamental PCI-DSS requirements
- Establishing and sustaining a secure network and system infrastructure
- Safeguarding sensitive cardholder information
- Implementing a robust vulnerability management program
- Enforcing rigorous access control protocols
- Consistent monitoring and testing of network environments
- Maintaining a formal information security policy
PCI-DSS Compliance Validation and Assessment
- The PCI-DSS compliance workflow
- Defined roles and accountability structures in PCI-DSS compliance
- Categories of PCI-DSS assessments (SAQ, ROC)
- Collaboration with Qualified Security Assessors (QSAs)
Scope Definition and Network Segmentation
- Identifying the cardholder data environment (CDE)
- Strategic scoping of PCI-DSS applicability
- Network segmentation strategies and their operational importance
Securing Network Architecture and Infrastructure
- Configuration of firewalls and routing devices
- Harden network component security postures
- Implementing secure wireless networking controls
Protection of Cardholder Data
- Techniques for data encryption and masking
- Securing stored cardholder data repositories
- Ensuring secure transmission of sensitive payment data
Vulnerability Management and System Resilience
- Consistent patching and system update protocols
- Detection and mitigation of security vulnerabilities
- Deployment of anti-virus and anti-malware defenses
Access Control and Identity Management
- Establishing access control policies and operational procedures
- Administration of user access and authentication mechanisms
- Implementation of physical security controls
Network Monitoring and Security Testing
- Oversight of network traffic and audit logs
- Execution of automated vulnerability scans
- Best practices for conducting penetration tests
Information Security Policy and Governance
- Formulation and execution of security policies
- Workforce security awareness training programs
- Development of incident response plans
Audit Preparation and Readiness
- Compilation of documentation and evidentiary records
- Execution of internal audit procedures
- Resolution of compliance deficiencies
Conclusion and Strategic Recommendations
Requirements
- Conceptual understanding of online payment systems
- Foundational knowledge of network fundamentals
- Basic principles of information security
- Professional experience in an IT or related technical role
14 Hours
Testimonials (2)
The trainer was helpful..
Attila - Lifial
Course - Compliance and the Management of Compliance Risk
Speed of response and communication