PCI Data Security Standard (DSS)
What is the Payment Card Industry Data Security Standard?
The Payment Card Industry Data Security Standard (PCI DSS) is an evolving global framework for safeguarding payment card data, such as the primary account number (the credit card number), expiration date, card verification code, and other associated data. The Payment Card Industry Security Standards Council (PCI SSC) publishes and maintains it along with other standards and supplemental resources. Payment brands such as Visa, MasterCard, Discover, and American Express enforce PCI DSS contractually, as do the financial institutions that process payment transactions on behalf of merchants. PCI DSS defines 12 high-level requirements for protecting payment card data, each with multiple sections, requirements, testing procedures, and supporting guidance.
Who is the intended audience?
Per PCI DSS v4.0, the standard is intended for all entities that store, process, or transmit cardholder data (CHD) or sensitive authentication data (SAD), or that could affect the security of the cardholder data environment (CDE). That covers every entity involved in payment card account processing: merchants, processors, acquirers, issuers, and other service providers. Whether a given entity must comply with PCI DSS, or validate its compliance, is up to the organizations that manage compliance programs, such as payment brands and acquirers.
Where can I find more information?
The PCI Security Standards Council website publishes these resources:
How can runZero help me with these controls?
For the latest on how runZero can help with PCI DSS, see runZero’s PCI DSS compliance page.