PCI DSS

This page tries to capture the sites and links that can help organisations gather the information they need to understand the Payment Card Industry Data Security Standards.

UPDATE IN PROGRESS – 11th April 2024

PCI (DSS, PA, SSF, P2PE, SSC) Reference sites and documents

Industry Sites

If you see a broken link, noticed something missing, or think something needs to be added please tell me.

.

55 responses to “PCI DSS”

  1. PCI SSC’s insights on mobile, encryption and payment security following the North American community meeting « Brian Pennington Avatar

    […] Pennington HomeAbout Brian PenningtonPCI DSS Resources « Data Protection Advice for schools and just about […]

    Like

  2. Feedback requested from PCI community on best practices to help prevent card data compromise at ATMs « Brian Pennington Avatar

    […] Pennington HomeAbout Brian PenningtonPCI DSS Resources « PCI Security Standards Council releases best practices for mobile […]

    Like

  3. PCI Security Standards Council releases best practices for mobile software developers « Brian Pennington Avatar

    […] Pennington HomeAbout Brian PenningtonPCI DSS Resources « The average cost of a breach event is $7.2 million or $214 per […]

    Like

  4. The average cost of a breach event is $7.2 million or $214 per compromised record « Brian Pennington Avatar

    […] Pennington HomeAbout Brian PenningtonPCI DSS Resources « Almost 50% of organizations report 10 or more significant data breaches […]

    Like

  5. PCI Security Standard Council releases summary of feedback on PCI standards « Brian Pennington Avatar

    […] Pennington HomeAbout Brian PenningtonPCI DSS Resources « Advance malware threats are growing at an […]

    Like

  6. 65% of businesses do not protect their customers’ private data « Brian Pennington Avatar

    […] Pennington HomeAbout Brian PenningtonPCI DSS Resources « Counting the cost of e-crime to retailers. Actually it’s £205.4 million […]

    Like

  7. PCI Security Standards Council’s Qualified Integrators and Resellers program is now live « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « Who is responsible for data protection in […]

    Like

  8. The Information Commissioner’s 5 Tips on how to better protect personal information « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « Torbay Care Trust (NHS) fined £175,000 for breaching the Data […]

    Like

  9. PCI Security Standards Council Internal Security Assessor (ISA) training now available as an eLearning course « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « Information Commissioners reaction to Google and their retention of Street […]

    Like

  10. Criminal logic; follow the money and find easy targets « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « PCI Security Standards Council releases Point-to-Point encryption […]

    Like

  11. PCI Security Standards Council releases Point-to-Point encryption (p2pe) resources « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « Network Barometer Report 2012 – a Dimension […]

    Like

  12. PCI Security Standards Council releases Point-to-Point encryption (p2pe) resources « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « Network Barometer Report 2012 – a Dimension […]

    Like

  13. Preet Avatar

    Cloud computing, vizrtaliuation, and other technologies are perfectly acceptable as long as your systems are properly configured and satisfy the PCI DSS requirements. It’s not about the technology it’s about the configuration, written agreements, and scope.Thank you for the link to PCIAnswers.com!

    Like

  14. Database security and SIEM are the top Risk and Compliance converns « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « Proposed European wide Data Protection Act – […]

    Like

  15. Guidance for merchants on how to securely accept mobile payments « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « The good old fashion way to breach the Data Protection Act – lose […]

    Like

  16. […] applications into merchant environments in a manner that supports PCI DSS compliance. The PCI SSC will maintain a global list of QIRs, ensuring merchants a trusted resource for selecting PCI […]

    Like

  17. PCI Point-to-Point Encryption Solution Requirements and Testing Procedures v1.1 « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « The PCI SSC has opened its registration for the 2012 PCI […]

    Like

  18. The PCI SSC has opened its registration for the 2012 PCI Community Meetings « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « 2012 Application Security Gap Study: A Survey of IT Security […]

    Like

  19. 2012 Application Security Gap Study: A Survey of IT Security & Developers « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « PCI Security Standards Council pushing for feedback as window starts […]

    Like

  20. PCI Security Standards Council pushing for feedback as window starts to close « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « 2,000 lost Medical Records leads to an investigation by the […]

    Like

  21. Verizon 2012 Data Breach Investigation Report – a summary « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « UK Card Fraud losses fall because of technology and […]

    Like

  22. UK Card Fraud losses fall because of technology and risk awareness « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « RSA’s March Online […]

    Like

  23. 03/26/2012: Facebook, PCI Security Standards Council (PCI SSC), AcceptEmail | SociallyPay Avatar

    […] The PCI Security Standards Council (PCI SSC) is participating in a Congressional hearing titled “The Future of Money: How Mobile Payments Could Change Financial Services,” held by the Subcommittee on Financial Institutions and Consumer Credit. […]

    Like

  24. PCI Security Standards Council continues focus on mobile payment acceptance security « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « Police fined by the Information Commissioner. If the Police can lose sensitive that […]

    Like

  25. Page not found « Brian Pennington Avatar

    […] Brian Pennington HomeAboutPCI DSS Resources […]

    Like

  26. PCI SSC announces formal training in Europe (London) « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « Is the Information Commissioner having a purge […]

    Like

  27. PayPal, Payments and PCI « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « E*Trade Securities Ltd falls foul of the ICO after losing […]

    Like

  28. Raj Gna Avatar
    Raj Gna

    Hi Brian

    I am going to develop a PCI DSS Complaince project which will be helpful for the Banks to control their merchants who handles the Credit cards. My project takes care of

    – Merchant’s SAQ Compliance
    – Merchant’s PCI Level
    -Merchant’s scan status and scan
    -Merchant Validation
    -Acquirer (Banks) can view all the merchant details
    – and few more options

    My question is: To develop a project, should I get any confirmation from PCI DSS Organisation? Please clarify my doubt. If anyone answer my question, I will be grateful to you

    Regards
    Raj Gna
    Email: littlegroup555@gmail.com

    Like

  29. Security is still the biggest technology challenge for retailers « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « Data Security Survey to gauge organisations’ perception of their own […]

    Like

  30. Eight Ways to Reduce PCI DSS Audit Scope by Tokenizing Cardholder Data « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « 7 experts predict the IT security and compliance issues and trends of 2012 Data […]

    Like

  31. Tokenization for Dummies a Free eBook « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « Illicit access of medical records leads to a breach of the Data […]

    Like

  32. Last chance to review your PCI readiness before the holiday season « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « RSA’s November Online […]

    Like

  33. Only 21% of merchants were compliant and other startling PCI DSS facts from the coal face « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « Gambling takes on a new meaning when someone steals your […]

    Like

  34. Merchants are more concerned about their brand than PCI fines « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « Five Ways to Fall Victim to Credit […]

    Like

  35. PCI DSS – updated guidelines for WiFi and new guidance on Bluetooth « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « Information rights should be embedded in schools, […]

    Like

  36. 25% of Mobile Network Operators are not PCI DSS Compliant « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « Fraudsters steal $1.4 Billion […]

    Like

  37. PCI Compliance Risks for Small Merchants and where they are failing « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « Study: Consumers’ Reaction to […]

    Like

  38. Call Centre Security and PCI Compliance « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « Epsilon admits to a data breach that could […]

    Like

  39. Comparison Of Cost Of Ownership Between In-House And Managed Pay « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « How to Choose a QSA […]

    Like

  40. Benefits of PCI Compliance – direct and indirect « Brian Pennington Avatar

    […] Pennington HomeAboutPCI DSS Resources « Cloud Computing Risk Assessment […]

    Like

  41. Eight must-fix flaws prior to an application penetration test | Brian Pennington Avatar

    […] Pennington A blog about IT Security & Compliance Skip to content HomeAboutPCI DSS Resources ← Wells Fargo Offers Online and Mobile Fraud […]

    Like

Leave a comment