Home » Training » Payment Card Industry Data Security Standard (PCI-DSS)

Title

Payment Card Industry Data Security Standard (PCI-DSS)




To be updated....


To be updated...

To be updated...

To be updated...

Day 1
I.    PCI DSS Overview
I.1.     Session - 1: 08:00  -  10:10 

Introduction to PCI DSS:  

  • What is Payment Card Industry, Risk, Fraud Modes  
  • What is PCI DSS, other PCI DSS standards  
  • Structure of PCI DSS, payment cycle  

 

Coffee Break : 20 Mins 

 

I.2.    Session – 2:  10:30 – 12:00

  • Card Structure  
  • Cardholder Data  

 

Lunch Time   90 Mins

 

I.3.    Session – 3: 13:30 – 15:30 

  • Qualified Security Assessors  
  • Approved Scanning Vendors  

 

Coffee Break  20 Mins

 

I.4.    Session – 4:  15:50 – 17:00 

  • Self-Assessment Questionnaire (SAQ)  

 

Day 2
II.    Requirements of PCI DSS
II.1.    Session – 1  : 08:00  -  10:10

Requirements of PCI DSS  

  • Requirement 1: Install and maintain a firewall configuration to protect cardholder data  
  • Requirement 2: Do not use vendor-supplied defaults for system passwords and  other security parameters  

 

Coffee Break  20 Mins

 

II.2.    Session – 2  : 10:30 – 12:00

  • Requirement 3: Protect stored cardholder data  

 

Lunch Time   90 Mins

 

II.3.    Session – 3  13:30 – 15:30

  • Requirement 4: Encrypt transmission of cardholder data across open, public  networks  
  • Requirement 5: Use and regularly update anti-virus software or programs  

 

Coffee Break  20 Mins

 

II.4.    Session – 3  15:50 – 17:00

  • Requirement 6: Develop and maintain secure systems and applications  

 

Day 3
II.5.    Session – 1  08:00  -  10:10

Requirements of PCI DSS.

  • Requirement 7: Restrict access to cardholder data by business need-to-know 
  • Requirement 8: Assign a unique ID to each person with computer access  

 

Coffee Break : 20 Mins 

 

II.6.    Session – 2:  11:00 – 12:00

  • Requirement 9: Restrict physical access to cardholder data  

 

Lunch Time   90 Mins

 

II.7.    Session – 3  : 13:30 – 15:30 

  • Requirement 10: Track and monitor all access to network resources and cardholder data  
  • Requirement 11: Regularly test security systems and processes  

 

II.8.    Session – 4  : 15:50 – 17:00 

  • Requirement 12: Maintain a policy that addresses information security

 

Day 4

II.9.    Session – 6 8:00 – 12:00

  • Case Study - PCI DSS Implementation for Banks
  • Scoping

 

Lunch Time   90 Mins 

 

II.10.    Session – 7  13:30 – 15:00 

  • Continual Compliance & PCI DSS Pit Falls

 

Coffee Break  20  Mins 

 

II.11.    Session – 8  15:30 – 16:30 

  • Group Activity 
  • Final Test    
Updating ....