This document summarizes the Payment Card Industry Data Security Standard (PCI DSS) version 3.2.1 from May 2018. It provides an overview of the 12 requirements of the PCI DSS, which are aimed at building and maintaining secure networks, protecting cardholder data, maintaining vulnerability management, implementing strong access control, monitoring networks regularly, and maintaining information security policies. It also provides context on the applicability of the PCI DSS and relationship with the Payment Application Data Security Standard. The document defines what payment card and authentication data are in scope to be protected and provides guidance on the scope of system components covered by the PCI DSS requirements.
Introduces PCI Data Security Standard (DSS) v3.2.1, providing security requirements for cardholder data.
Highlights changes from previous PCI DSS versions to v3.2.1, detailing the evolution of standards over time.
Lists sections in the PCI DSS documentation including requirements, assessment processes, and best practices.
Summarizes the 12 core PCI DSS requirements on securing cardholder data, maintaining a secure network, and implementation best practices.
Outlines resources available for PCI DSS compliance, including templates, FAQs, and training materials.
Defines entities subject to PCI DSS, detailing types of cardholder data and requirements for protection.
Explains how PCI DSS relates to Payment Application Data Security Standards (PA-DSS) during assessments.
Describes the scope of PCI DSS relevant to systems and components involved in cardholder data processes.
Recommends segmenting networks to reduce PCI DSS assessment scope and enhance cardholder data protection.
Details considerations for engaging third-party service providers handling cardholder data.
Discusses how to incorporate PCI DSS into daily business processes to ensure ongoing compliance.
Guidelines for assessors sampling business facilities and system components during compliance reviews.
Guidelines on PCI DSS Report on Compliance (ROC) procedures and documentation requirements.
Details on installing firewalls and maintaining secure configurations to protect cardholder data.
Outlines practices to change vendor defaults and maintain secure configurations to protect systems.
Endorses limiting access to cardholder data to those with a legitimate business need based on job roles.Details policies for unique identification and authentication measures for users accessing systems.
Recommends securing physical access to systems processing cardholder data to prevent unauthorized access.
Emphasizes the need for regular monitoring, testing, and auditing of access to cardholder data and systems.
Calls for vulnerability assessments and penetration testing to identify and address security vulnerabilities.
Stresses having an effective incident response plan to manage and mitigate security breaches.Reiterates maintaining a strong information security policy that aligns with ongoing PCI compliance.
Highlights monitoring service providers’ PCI compliance and establishing formal agreements regarding data security.
Outlines additional validation requirements for entities designated by payment brands for PCI compliance.