Home > Security All-in-One Guides > Compliance > Infosec-Related Regs > PCI Data Security Standard > Checklist for meeting the PCI Data Security Standard
All-in-One Guides: Compliance:
EMAIL THIS
 START   SOX SCHOOL   INFOSEC-RELATED REGS   STANDARDS   PROCESS IMPROVEMENT   PEOPLE & POLICY   TECHNOLOGY   AUDITS   
Infosec-Related Regs


PCI Data Security Standard
<< PREVIOUS | NEXT >>: Data Protection, Encryption and the Payment Card...
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE COUNSELOR

Checklist for meeting the PCI Data Security Standard


Diana Kelley
07.05.2005
Rating: -2.60- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   







Meeting the PCI Standard







[IMAGE]Read the PCI Standard in full and perform a security gap analysis. Identify any gaps between existing practices in your organization and those outlined by the PCI requirements.




[IMAGE]Create an action plan for on-going compliance and assessment. Once the gaps are identified, companies must determine the steps needed to close the gaps and protect cardholder data. It could mean adding new technologies to shore up firewall and perimeter controls, or increasing the logging and archiving procedur...


es associated with transaction data.




[IMAGE]Implement, monitor and maintain the plan. Compliance is not a one-time event. Regardless of merchant or service provider level, all entities must complete annual self-assessments using the PCI Self Assessment Questionnaire.




[IMAGE]Call in outside experts as needed. Visa has published a Qualified Security Assessor List of companies that can conduct on-site CISP compliance audits for Level 1 Merchants, and Level 1 and 2 Service Providers. MasterCard has a Compliant Security Vendor List of SDP-approved scanning vendors.








































For more information about PCI Security Standard Compliance, read our tip, Meeting the PCI requirements mitigates threats.

About the author Diana Kelley is a Senior Analyst with Burton Group. She has extensive experience creating secure network architectures and business solutions for large corporations and delivering strategic, competitive knowledge to security software vendors.

Complying with the PCI Security Standard ensures that your organization can continue to do business with the PCI. Here's a quick round up of ways to ensure compliance.

Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Compliance Counselor,   Security Audit, Compliance and Standards,   Data Privacy and Protection,   Infosec-Related Regs,   PCI Data Security Standard,   Compliance,   Security Awareness Training and Internal Threats,   Information Security Management,   Web Authentication and Access Control,   Enterprise Identity and Access Management,   Biometric Technology,   User Authentication Services,   Enterprise Single Sign-On (SSO),   PKI and Digital Certificates,   Security Token and Smart Card Technology,   PCI Data Security Standard,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


<< PREVIOUS | NEXT >>: Data Protection, Encryption and the Payment Card...
VIEW ALL IN THIS CATEGORY

RELATED CONTENT
Compliance Counselor
Identity lifecycle management for security and compliance
Interpreting 'risk' in the Massachusetts data protection law
FTC Red Flags Rules: How to create an identity theft prevention plan
Creating a HIPAA employee training program
Data protection tips for corporate compliance leaders
PCI DSS compliance requirements: Ensuring data integrity
Understanding PCI DSS compliance requirements for log management
Are 'strong authentication' methods strong enough for compliance?
Strategies for using technology to enable automated compliance
Common PCI questions: Web application firewalls or source code review?

Data Privacy and Protection
Quiz: Compliance-driven role management
Interpreting 'risk' in the Massachusetts data protection law
Strategies for using technology to enable automated compliance
How to prepare for a FERPA audit
How to find virtual machines for greater virtualization compliance
Quiz: Virtualization and compliance
Compliance in the cloud
Researchers predict SSNs, crack algorithm putting identities at risk
How to write a risk methodology that blends business, security needs
PCI compliance requirement 3: Protect data
Data Privacy and Protection Research

PCI Data Security Standard
Hashing for fun and profit: Demystifying encryption for PCI DSS
PCI Data Security Standard: Swiping back
PCI Data Security Standard: 12-step program for compliance
PCI Data Security Standard: How to survive an audit
Data Protection, Encryption and the Payment Card Industry Data Security Standards (PCI DSS)
Meeting the PCI Data Security Standard requirements mitigates threats

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
cypherpunk  (SearchSecurity.com)
Data Encryption Standard  (SearchSecurity.com)
P3P  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts