Back to books home
Volume 3 - Building a PCI DSS Information Security Program (PCI DSS 4.0.1 edition)
Volume 3 - Building a PCI DSS Information Security Program
- 3.1 Volume Introduction
- 3.2 The High-Level PCI DSS requirements
- 3.3 Building a PCI DSS Information Security Program
- 3.3.1 Where you come from matters
- 3.3.2 Information Security Programs are meant to address Risks
- 3.3.3 Information Security Frameworks
- 3.4 Considerations for an Information Security Program
- 3.4.1 Recapping the PCI DSS data elements
- 3.4.2 Data Classification
- 3.4.3 Examples of data classification
- 3.4.4 Governance
- 3.5 The PCI DSS Information Security Program Structure (the head of the program)
- 3.5.1 (Information Security) Policies (Sections 12.1, 12.2, X.1)
- 3.5.2 Responsibilities for the program (Section 12.1)
- 3.5.3 Targeted Risk Assessments (TRA, Section 12.3)
- 3.5.4 PCI DSS Program and Monitoring (Service Provider, Section 12.4)
- 3.5.5 Scope : Documenting usage of card information (Section 12.5)
- 3.5.6 Security awareness (Section 12.6)
- 3.5.7 Human Resource Security (Section 12.7)
- 3.5.8 Managing Third-party service providers (TPSP) (Section 12.8)
- 3.5.10 Incident Response Management (Section 12.10)
- 3.6 The body of the program
- 3.6.1 Objective 1: Build and Maintain a Secure Network and Systems
- 3.6.2 Objective 2: Protect Account Data
- 3.6.3 Objective 3: Maintain a Vulnerability Management Program
- 3.6.4 Objective 4: Implement Strong Access Control Measures
- 3.6.5 Objective 5: Regularly Monitor and Test Networks
- 3.7 Additional Requirements
- 3.7.1 Requirement Appendix A1:Multi-tenant service provider (previously called shared service provider) requirements
- 3.7.2 Requirement Appendix A2: Secure transmission of CHD from payment devices (cryptography for data in motion)
- 3.7.3 Requirement Appendix A3: Designated Entities Supplemental Validation (DESV)
- 3.8 Controls to consider when using, and to protect from, genAI/LLM
- 3.8.1 Controls when using genAI
- 3.8.2 Use of genAI to supplement controls
- 3.8.3 Impact of genAI and similar tools on the threat landscape
- 3.9 Addressing compliance gaps - prioritization
- 3.10 When you cannot meet the “defined approach” as is
- 3.10.1 Compensating Controls - the old way
- 3.10.2 Customized Approach - the new way
- 3.11 Total Cost of Ownership (TCO) and Return-on-Investment (ROI)
- End Notes - Volume 3
- Appendix 3A - Network Primer
- Appendix 3B - A primer on encryption