What is PCI DSS (Payment Card Industry Data Security Standard)?
PCI DSS is a set of security standards established by major credit card companies to protect cardholder data, requiring organizations that handle payment card information to meet twelve security requirements.
The Payment Card Industry Data Security Standard (PCI DSS) is a set of security requirements developed and maintained by the PCI Security Standards Council, founded by major payment card brands including Visa, Mastercard, American Express, Discover, and JCB. PCI DSS applies to all organizations that store, process, or transmit cardholder data, regardless of size or transaction volume. The current version, PCI DSS v4.0, introduced significant updates to address emerging threats and technologies.
PCI DSS is organized around twelve requirements grouped into six goals: build and maintain a secure network and systems, protect cardholder data, maintain a vulnerability management program, implement strong access control measures, regularly monitor and test networks, and maintain an information security policy. Compliance validation varies based on transaction volume, with larger merchants requiring external assessments by Qualified Security Assessors (QSAs) and smaller merchants eligible for self-assessment questionnaires.
While not a government regulation, PCI DSS compliance is contractually required by payment card brands and enforced through the merchant's acquiring bank. Non-compliance can result in fines, increased transaction fees, or loss of the ability to process payment cards. Organizations handling cardholder data can use DiscoverIQ to locate cardholder data across their environments and ProtectIQ to implement security controls that meet PCI DSS requirements.
How IQWorks Helps
Related Terms
Data Encryption
Encryption transforms readable data into an unreadable format using cryptographic algorithms, protecting confidentiality by ensuring only authorized parties with the correct key can access the data.
Data Tokenization
Tokenization replaces sensitive data with non-sensitive tokens that can be mapped back to the original data through a secure token vault, protecting data while preserving processability.
Access Control
Access control restricts who can view, modify, or delete data based on identity, role, and authorization policies, ensuring only authorized personnel access personal data.
Encryption at Rest
Encryption at rest protects stored data by encrypting it on disk, in databases, or in storage systems, ensuring data confidentiality even if storage media is physically compromised.
Encryption in Transit
Encryption in transit protects data as it moves between systems using protocols like TLS/SSL, preventing interception and eavesdropping during transmission.