Global · PCI Security Standards Council · PCI DSS 4.0

Payment Card Industry Data Security Standard

The global standard that sets security requirements for any entity that stores, processes or transmits payment-card data.

What it is

PCI DSS is the payment-card industry's mandated baseline for protecting cardholder data. v4.0 introduced 64 new or clarified requirements, including targeted risk analysis, DMARC-style phishing controls, client-side script-integrity monitoring (6.4.3) and detection of payment-page script tampering (11.6.1). Merchants and service providers are required to comply; levels of validation depend on annual transaction volumes and scheme requirements.

Who it applies to

All entities that store, process or transmit cardholder data and/or sensitive authentication data - merchants, service providers, acquirers, issuers and processors.

Requirements

Build and maintain secure networks

Install and maintain network security controls; apply secure configurations to system components.

Protect account data

Protect stored account data and protect it with strong cryptography during transmission over open networks.

Maintain a vulnerability management program

Protect against malicious software, and develop and maintain secure systems and software.

Implement strong access control

Restrict access to system components and cardholder data by business need-to-know; identify users; restrict physical access.

Regularly monitor and test networks

Log and monitor access, and test the security of systems and networks regularly.

Maintain an information-security policy

Support information security with organisational policies and programs.

Read next

Other places this turns up on the site.

Security, engineered around you.

Talk to an engineer - not a call centre. Most Vectra conversations start with a 30-minute technical briefing and end with a written plan.