The document discusses the Payment Card Industry Data Security Standard (PCI-DSS) version 2. It provides an overview of PCI-DSS requirements for different types of entities that process, store, or transmit cardholder data. It notes that while all entities must implement PCI-DSS controls, validation of compliance is only mandatory for merchants, service providers, acquiring banks, and in some cases issuing banks. The document also lists documentation resources and guidelines related to PCI-DSS compliance and virtualization.