Get in Touch

Course Outline

Introduction

Foundations of PCI-DSS

  • Introduction to the PCI-DSS framework
  • Significance of maintaining PCI-DSS compliance for government
  • Core strategic objectives of the PCI-DSS standard

PCI-DSS Standards and Regulatory Requirements

  • Comprehensive overview of PCI-DSS mandates
  • The 12 fundamental PCI-DSS requirements
    • Establishing and sustaining a secure network and system infrastructure
    • Safeguarding sensitive cardholder information
    • Implementing a robust vulnerability management program
    • Enforcing rigorous access control protocols
    • Consistent monitoring and testing of network environments
    • Maintaining a formal information security policy

PCI-DSS Compliance Validation and Assessment

  • The PCI-DSS compliance workflow
  • Defined roles and accountability structures in PCI-DSS compliance
  • Categories of PCI-DSS assessments (SAQ, ROC)
  • Collaboration with Qualified Security Assessors (QSAs)

Scope Definition and Network Segmentation

  • Identifying the cardholder data environment (CDE)
  • Strategic scoping of PCI-DSS applicability
  • Network segmentation strategies and their operational importance

Securing Network Architecture and Infrastructure

  • Configuration of firewalls and routing devices
  • Harden network component security postures
  • Implementing secure wireless networking controls

Protection of Cardholder Data

  • Techniques for data encryption and masking
  • Securing stored cardholder data repositories
  • Ensuring secure transmission of sensitive payment data

Vulnerability Management and System Resilience

  • Consistent patching and system update protocols
  • Detection and mitigation of security vulnerabilities
  • Deployment of anti-virus and anti-malware defenses

Access Control and Identity Management

  • Establishing access control policies and operational procedures
  • Administration of user access and authentication mechanisms
  • Implementation of physical security controls

Network Monitoring and Security Testing

  • Oversight of network traffic and audit logs
  • Execution of automated vulnerability scans
  • Best practices for conducting penetration tests

Information Security Policy and Governance

  • Formulation and execution of security policies
  • Workforce security awareness training programs
  • Development of incident response plans

Audit Preparation and Readiness

  • Compilation of documentation and evidentiary records
  • Execution of internal audit procedures
  • Resolution of compliance deficiencies

Conclusion and Strategic Recommendations

Requirements

  • Conceptual understanding of online payment systems
  • Foundational knowledge of network fundamentals
  • Basic principles of information security
  • Professional experience in an IT or related technical role
 14 Hours

Number of participants


Price per participant

Testimonials (2)

Upcoming Courses

Related Categories