PCIP Exam
PCI Data Security Standard (PCI DSS)
The PCI DSS applies to all entities that save, manner, and/or transmit cardholder statistics. It
covers technical
and operational gadget components protected in or linked to cardholder information. If you
receive or method price cards, PCI DSS applies to you.
Sensitive Authentication Data
Merchants, carrier carriers, and different
entities involved with price card processing ought to by no means store sensitive authentication
information after
authorization. This consists of the three- or 4- digit security code imprinted on the front or lower
back of a card (CVD), the facts stored on a card's magnetic stripe or chip (also known as "Full
Track Data") - and personal identity numbers (PIN) entered through the cardholder.
Card Verification Data Codes (CVD)
3 or 4 digit code that in addition authenticates a now not-present cardholder
Visa-CVV2
MC- CVC2
Discover- CVD
JCB-CAV2
AmEx- CID
Requirement 1
Install and keep a firewall configuration to protect cardholder records
,Network devices in scope for Requirement 1
Firewalls and Routers- Routers connect visitors among networks, Firewalls control the site
visitors between networks and within internal network
QIR Qualified Integrators & Resellers
Qualified Integrators & Resellers- authorized with the aid of the SSC to enforce, configure
and/or guide PA-DSS price programs. Visa calls for all level 4 merchants use QIRs for POS
application and terminal installation and servicing
Compensating Controls
An opportunity control, installed vicinity to meet the requirement for a security degree that is
deemed too difficult or impractical to implement at the prevailing time.
Permitted reasons for the use of Compensating Controls
Organizations desiring an alternative to safety requirements that couldn't be met because of
legitimate technological OR documented business constraints, however has sufficiently
mitigated the risk associated with the requirement via implementation of different compensating
controls
Examples of Compensating Controls
(i) Segregation of Duties (SOD) and (ii) Encryption
Compensating Controls must:
1) Meet the motive and rigor of the unique said requirement;
2) Provide a comparable stage of defense because the unique said requirement;
three) Be "above and beyond" different PCI DSS necessities (not virtually in compliance with
other PCI DSS requirements); and
4) Be commensurate with the extra threat imposed with the aid of no longer adhering to the
authentic said requirement.
,Compensating Controls Worksheet
1) Constraint; 2) Objective; three) Identified Risk; 4) Define Compensating Control; 5)Validate
Controls; 6) Maintenance (COIDVM)
Card Data that can not be stored by means of Merchants, Service carriers after authorization
Sensitive Authentication Data. I) 3- or 4- digit safety code printed on the the front or returned of
a card, ii) information saved on a card's magnetic stripe or chip (additionally known as "Full
Track Data"), and iii) private identification
numbers (PIN) entered by using the cardholder
Card Data that MAY be stored
i) cardholder name, ii) service code (identifies industry iii) Personal Account Number (PAN)
iv) expiration date can be saved.
Network Segmentation
The manner of keeping apart the cardholder statistics environment from the remainder of an
entity's network
Not a demand however strongly recommended.
Report on Compliance (ROC)
Prepared on the time of the assessment of PCI compliance and comprehensively provides
details about the evaluation technique and compliance status towards every PCI DSS
requirement
What is blanketed inside the Report on Compliance (ROC)?
ROC includes (1) Executive precis, (2) description of scope of work and technique taken, (3)
details about reviewed environment, (4) contact information and record date, (5) quarterly test
outcomes and (6) findings and observations.
Steps to take for a PCI Assessment (hint: SARA's Remediation)
1. Scope - decide which system components and networks are in scope for PCI DSS
2. Assess - take a look at the compliance of machine additives in scope following the trying out
techniques for every PCI DSS requirement
three. Report - assessor and/or entity completes required documentation (e.G. Self-Assessment
, Questionnaire (SAQ) or Report on Compliance (ROC)), along with documentation of all
compensating controls
4. Attest - complete the proper Attestation of Compliance (AOC)
five. Submit - post the SAQ, ROC, AOC and other requested helping documentation inclusive of
ASV experiment reviews to the acquirer (for merchants) or to the charge logo/requestor (for
provider
vendors)
6. Remediate - if required, carry out remediation to deal with requirements that aren't in vicinity,
and
Who can entire a Self Assessment Questionnaire (SAQ)?
I) the enterprise themselves, or ii) with the aid of a 3rd celebration (e.G. IBM)
Who MUST entire a Report on Compliance?
It MUST be finished via an authorized Qualified Security Assessor (QSA) through the PCI
Security Standards Council
What is protected in PCI Scope Review?
1) Document the cardholder statistics waft; 2)expand a community diagram that files all the
firewalls, routers, switches, access points, servers and other network devices and the way
they're architected; 3) experiment your whole network to verify that cardholder records isn't
always stored anywhere out of doors of the CDE (Generally, you want to identify all places and
flows and make sure that they're covered in scope.)
Steps to lessen scope of Cardholder Data Environment ("CDE")
1. Consolidation: Identifying and removing redundant information sets and consolidating
packages and information garage can lessen scope.
2.Centralization:Encrypted records saved in a relatively steady on-website online significant
information vault. The fee card numbers are changed with tokens in different packages or
databases. Since cardholder statistics is handiest stored in a single important area, PCI DSS
Scope is minimized
PCI Data Security Standard (PCI DSS)
The PCI DSS applies to all entities that save, manner, and/or transmit cardholder statistics. It
covers technical
and operational gadget components protected in or linked to cardholder information. If you
receive or method price cards, PCI DSS applies to you.
Sensitive Authentication Data
Merchants, carrier carriers, and different
entities involved with price card processing ought to by no means store sensitive authentication
information after
authorization. This consists of the three- or 4- digit security code imprinted on the front or lower
back of a card (CVD), the facts stored on a card's magnetic stripe or chip (also known as "Full
Track Data") - and personal identity numbers (PIN) entered through the cardholder.
Card Verification Data Codes (CVD)
3 or 4 digit code that in addition authenticates a now not-present cardholder
Visa-CVV2
MC- CVC2
Discover- CVD
JCB-CAV2
AmEx- CID
Requirement 1
Install and keep a firewall configuration to protect cardholder records
,Network devices in scope for Requirement 1
Firewalls and Routers- Routers connect visitors among networks, Firewalls control the site
visitors between networks and within internal network
QIR Qualified Integrators & Resellers
Qualified Integrators & Resellers- authorized with the aid of the SSC to enforce, configure
and/or guide PA-DSS price programs. Visa calls for all level 4 merchants use QIRs for POS
application and terminal installation and servicing
Compensating Controls
An opportunity control, installed vicinity to meet the requirement for a security degree that is
deemed too difficult or impractical to implement at the prevailing time.
Permitted reasons for the use of Compensating Controls
Organizations desiring an alternative to safety requirements that couldn't be met because of
legitimate technological OR documented business constraints, however has sufficiently
mitigated the risk associated with the requirement via implementation of different compensating
controls
Examples of Compensating Controls
(i) Segregation of Duties (SOD) and (ii) Encryption
Compensating Controls must:
1) Meet the motive and rigor of the unique said requirement;
2) Provide a comparable stage of defense because the unique said requirement;
three) Be "above and beyond" different PCI DSS necessities (not virtually in compliance with
other PCI DSS requirements); and
4) Be commensurate with the extra threat imposed with the aid of no longer adhering to the
authentic said requirement.
,Compensating Controls Worksheet
1) Constraint; 2) Objective; three) Identified Risk; 4) Define Compensating Control; 5)Validate
Controls; 6) Maintenance (COIDVM)
Card Data that can not be stored by means of Merchants, Service carriers after authorization
Sensitive Authentication Data. I) 3- or 4- digit safety code printed on the the front or returned of
a card, ii) information saved on a card's magnetic stripe or chip (additionally known as "Full
Track Data"), and iii) private identification
numbers (PIN) entered by using the cardholder
Card Data that MAY be stored
i) cardholder name, ii) service code (identifies industry iii) Personal Account Number (PAN)
iv) expiration date can be saved.
Network Segmentation
The manner of keeping apart the cardholder statistics environment from the remainder of an
entity's network
Not a demand however strongly recommended.
Report on Compliance (ROC)
Prepared on the time of the assessment of PCI compliance and comprehensively provides
details about the evaluation technique and compliance status towards every PCI DSS
requirement
What is blanketed inside the Report on Compliance (ROC)?
ROC includes (1) Executive precis, (2) description of scope of work and technique taken, (3)
details about reviewed environment, (4) contact information and record date, (5) quarterly test
outcomes and (6) findings and observations.
Steps to take for a PCI Assessment (hint: SARA's Remediation)
1. Scope - decide which system components and networks are in scope for PCI DSS
2. Assess - take a look at the compliance of machine additives in scope following the trying out
techniques for every PCI DSS requirement
three. Report - assessor and/or entity completes required documentation (e.G. Self-Assessment
, Questionnaire (SAQ) or Report on Compliance (ROC)), along with documentation of all
compensating controls
4. Attest - complete the proper Attestation of Compliance (AOC)
five. Submit - post the SAQ, ROC, AOC and other requested helping documentation inclusive of
ASV experiment reviews to the acquirer (for merchants) or to the charge logo/requestor (for
provider
vendors)
6. Remediate - if required, carry out remediation to deal with requirements that aren't in vicinity,
and
Who can entire a Self Assessment Questionnaire (SAQ)?
I) the enterprise themselves, or ii) with the aid of a 3rd celebration (e.G. IBM)
Who MUST entire a Report on Compliance?
It MUST be finished via an authorized Qualified Security Assessor (QSA) through the PCI
Security Standards Council
What is protected in PCI Scope Review?
1) Document the cardholder statistics waft; 2)expand a community diagram that files all the
firewalls, routers, switches, access points, servers and other network devices and the way
they're architected; 3) experiment your whole network to verify that cardholder records isn't
always stored anywhere out of doors of the CDE (Generally, you want to identify all places and
flows and make sure that they're covered in scope.)
Steps to lessen scope of Cardholder Data Environment ("CDE")
1. Consolidation: Identifying and removing redundant information sets and consolidating
packages and information garage can lessen scope.
2.Centralization:Encrypted records saved in a relatively steady on-website online significant
information vault. The fee card numbers are changed with tokens in different packages or
databases. Since cardholder statistics is handiest stored in a single important area, PCI DSS
Scope is minimized