← Back to Skills Library

PCI DSS

Information Technology > Transaction security and virus protection

Description

PCI DSS (Payment Card Industry Data Security Standard) is a set of guidelines designed to ensure that all businesses that process, store, or transmit credit card information maintain a secure environment. This skill involves understanding the 12 key requirements of PCI DSS, implementing these controls, conducting self-assessments and formal risk assessments, and managing a compliance program. It also includes dealing with data breaches, maintaining an information security policy, and continuously improving the organization's security posture. Advanced proficiency requires the ability to train others on PCI DSS compliance and handle complex data breaches.

Expected Behaviors

✎
LEVEL 1

Fundamental Awareness

At this level, individuals are expected to have a basic understanding of PCI DSS and its purpose in the payment card industry. They should be familiar with the concept of PCI DSS but may not have practical experience or detailed knowledge about it.

🌱
LEVEL 2

Novice

Novices should be able to identify key components of PCI DSS and understand its 12 requirements. They should know the roles and responsibilities under PCI DSS and understand the consequences of non-compliance. However, they may lack hands-on experience.

🌍
LEVEL 3

Intermediate

Individuals at the intermediate level should be capable of implementing PCI DSS controls and conducting self-assessments. They should understand how to maintain a secure network, manage vulnerabilities, and implement strong access control measures.

⭐
LEVEL 4

Advanced

Advanced individuals are expected to manage a PCI DSS compliance program and conduct formal risk assessments. They should understand how to manage service providers, deal with data breaches, and monitor and test networks. They likely have significant hands-on experience.

🏆
LEVEL 5

Expert

Experts should be able to manage a comprehensive PCI DSS compliance program and train others on PCI DSS compliance. They should have experience handling complex data breaches and maintaining an information security policy. Experts are expected to continuously improve the security posture of an organization.

Micro Skills

✎
LEVEL 1

Fundamental Awareness

Familiarity with the concept of Payment Card Industry Data Security Standard
Knowledge of the origin and purpose of PCI DSS
Awareness of the basic structure of PCI DSS
Understanding of why PCI DSS was established
Knowledge of the benefits of complying with PCI DSS
Awareness of the risks associated with non-compliance
Understanding of how payment card transactions work
Familiarity with the key players in the payment card industry
Awareness of common threats and vulnerabilities in the payment card industry
🌱
LEVEL 2

Novice

Understanding the need to build and maintain a secure network
Protecting cardholder data
Maintaining a vulnerability management program
Implementing strong access control measures
Regularly monitoring and testing networks
Maintaining an information security policy
Understanding the difference between sensitive and non-sensitive data
Awareness of the need to protect both physical and digital data
Defining the cardholder data environment
Understanding the impact of third parties on scope
🌍
LEVEL 3

Intermediate

Understanding of how to install and maintain a firewall configuration
Knowledge of how to protect stored cardholder data
Experience in encrypting transmission of cardholder data across open, public networks
Ability to identify the scope for PCI DSS assessment
Understanding of how to gather documentation
Experience in evaluating the effectiveness of controls
Knowledge of how to use and regularly update anti-virus software
Experience in developing and maintaining secure systems and applications
Understanding of how to restrict access to cardholder data by business need-to-know
Ability to regularly test security systems and processes
Understanding of how to maintain a policy that addresses information security
Experience in identifying and classifying the risks associated with vulnerabilities
Understanding of how to restrict physical access to cardholder data
Knowledge of how to assign a unique ID to each person with computer access
Experience in tracking and monitoring all access to network resources and cardholder data
⭐
LEVEL 4

Advanced

Understanding of business objectives and constraints
Experience in developing a PCI DSS compliance plan
Understanding of how to monitor and adjust the PCI DSS compliance strategy
Understanding of risk identification techniques
Experience in evaluating risk levels
Understanding of service level agreements (SLAs)
Knowledge of how to address performance issues
Understanding of incident response procedures
Knowledge of legal and regulatory requirements
Understanding of penetration testing methodologies
Experience in addressing identified network vulnerabilities
🏆
LEVEL 5

Expert

Understanding of business objectives
Experience in project management
Knowledge of PCI DSS requirements
Understanding of adult learning principles
Experience in content development
Understanding of threat landscape
Experience in incident response
Understanding of information security principles
Experience in policy development
Understanding of audit principles
Experience in risk assessment

Skill Overview

  • Expert4 years experience
  • Micro-skills56
  • Roles requiring skill0

Sign up to prepare yourself or your team for a role that requires PCI DSS.

LoginSign Up