Table of Content - Volume 3 (PCI DSS 4.0.1 edition)


Back to books home

Volume 3 - Building a PCI DSS Information Security Program (PCI DSS 4.0.1 edition)

Volume 3 - Building a PCI DSS Information Security Program

  • 3.1 Volume Introduction
  • 3.2 The High-Level PCI DSS requirements
  • 3.3 Building a PCI DSS Information Security Program
    • 3.3.1 Where you come from matters
    • 3.3.2 Information Security Programs are meant to address Risks
    • 3.3.3 Information Security Frameworks
  • 3.4 Considerations for an Information Security Program
    • 3.4.1 Recapping the PCI DSS data elements
    • 3.4.2 Data Classification
    • 3.4.3 Examples of data classification
    • 3.4.4 Governance
  • 3.5 The PCI DSS Information Security Program Structure (the head of the program)
    • 3.5.1 (Information Security) Policies (Sections 12.1, 12.2, X.1)
    • 3.5.2 Responsibilities for the program (Section 12.1)
    • 3.5.3 Targeted Risk Assessments (TRA, Section 12.3)
    • 3.5.4 PCI DSS Program and Monitoring (Service Provider, Section 12.4)
    • 3.5.5 Scope : Documenting usage of card information (Section 12.5)
    • 3.5.6 Security awareness (Section 12.6)
    • 3.5.7 Human Resource Security (Section 12.7)
    • 3.5.8 Managing Third-party service providers (TPSP) (Section 12.8)
    • 3.5.10 Incident Response Management (Section 12.10)
  • 3.6 The body of the program
    • 3.6.1 Objective 1: Build and Maintain a Secure Network and Systems
    • 3.6.2 Objective 2: Protect Account Data
    • 3.6.3 Objective 3: Maintain a Vulnerability Management Program
    • 3.6.4 Objective 4: Implement Strong Access Control Measures
    • 3.6.5 Objective 5: Regularly Monitor and Test Networks
  • 3.7 Additional Requirements
    • 3.7.1 Requirement Appendix A1:Multi-tenant service provider (previously called shared service provider) requirements
    • 3.7.2 Requirement Appendix A2: Secure transmission of CHD from payment devices (cryptography for data in motion)
    • 3.7.3 Requirement Appendix A3: Designated Entities Supplemental Validation (DESV)
  • 3.8 Controls to consider when using, and to protect from, genAI/LLM
    • 3.8.1 Controls when using genAI
    • 3.8.2 Use of genAI to supplement controls
    • 3.8.3 Impact of genAI and similar tools on the threat landscape
  • 3.9 Addressing compliance gaps - prioritization
  • 3.10 When you cannot meet the “defined approach” as is
    • 3.10.1 Compensating Controls - the old way
    • 3.10.2 Customized Approach - the new way
  • 3.11 Total Cost of Ownership (TCO) and Return-on-Investment (ROI)
  • End Notes - Volume 3
  • Appendix 3A - Network Primer
  • Appendix 3B - A primer on encryption