O Oluma Cyber Security Framework Files · No. 06 Standard · Payment Card Security PCI DSS The rulebook for anyone who touches a credit card number — twelve requirements standing between a business and the most attacked data on earth. v4.0.1 · 202412 Requirements6 Goals4 Merchant Levels PCI 12 REQ6 GOAL4 LVL How we’ll read this 01 The Problem02 Why It Exists03 The Story04 How It Works05 Example06 Who Uses It07 Career08 Strengths & Challenges09 Takeaway 01 The Problem Five card brands, five conflicting rulebooks Card numbers are pure gold to attackers — instantly sellable, endlessly reusable. Yet in the early 2000s, each card brand ran its own security program, so a single merchant could face five overlapping, conflicting sets of requirements at once. The result was predictable: confusion, patchy protection, and a steady stream of breaches dumping millions of card numbers. What the industry lacked was one standard everyone agreed on. 02 Why It Was Created One standard, enforced by the money Visa, Mastercard, American Express, Discover, and JCB merged their separate programs into a single standard and, in 2006, formed the PCI Security Standards Council to maintain it. One rulebook, for every business that touches a card. The core ideaDon’t pass another law — make it a contract. If you want to accept cards, your bank and the card brands require PCI DSS. Compliance becomes the price of admission to the payment system. That’s the quiet power of PCI: it’s not government regulation, but for anyone processing payments it’s effectively mandatory. 03 The Story Behind It From alignment to continuous security 2004The brands alignPCI DSS 1.0 united five competing card-brand programs into a single Data Security Standard. 2006A council to own itThe PCI Security Standards Council was formed to maintain, evolve, and govern the standard independently of any one brand. 2022 · v4.0The biggest update in a decadeIntroduced the flexible “customized approach,” pushed security toward a continuous, business-as-usual practice, and added modern defenses against e-skimming and phishing. 2024–25 · v4.0.1Now fully mandatoryA June 2024 clarification revision. Then on March 31, 2025, all 51 future-dated requirements became mandatory — MFA everywhere, payment-page script controls, authenticated scans, 12-character passwords. 04 How It Works 6 goals, 12 requirements, and scope is everything The standard groups into six goals and twelve requirements, which fan out into hundreds of sub-requirements. But the real game is scope: everything that stores, processes, or transmits card data is your Cardholder Data Environment — and the smaller you make it, the smaller your burden. Build & maintain secure networksProtect account dataVulnerability managementStrong access controlMonitor & testSecurity policy How you prove it depends on your merchant level (set by transaction volume): smaller merchants complete a Self-Assessment Questionnaire; the largest need a full Report on Compliance from a Qualified Security Assessor. The twelve requirements: 1 Install & maintain network security controls 2 Apply secure configurations 3 Protect stored account data 4 Encrypt data in transit 5 Protect against malware 6 Develop & maintain secure systems 7 Restrict access by need-to-know 8 Identify users & authenticate access 9 Restrict physical access 10 Log & monitor all access 11 Test security regularly 12 Maintain a security policy It’s a contract, not a lawPCI DSS is enforced by acquiring banks and card brands. Fall out of compliance and you face fines, higher processing fees, or losing the ability to take cards — penalties that hit the business directly. 05 Real-World Example An online shop shrinks its way to compliance A growing e-commerce store dreads a full audit — until it realizes the smartest move is to handle less card data, not secure more of it. Their scope-reduction playTouch fewer cards, answer fewer questions Hand card capture to a compliant processor via a hosted page Keep raw card numbers off their own servers entirely Add payment-page script monitoring (reqs 6.4.3 & 11.6.1) Turn on MFA for every admin and remote path Complete the smaller SAQ their setup now qualifies for By pulling card data out of scope, a terrifying full assessment shrinks into a short, achievable questionnaire. 06 Who Uses It Everyone who takes a payment 🛒Retail & e-commerceAny store, online or off, that accepts card payments — from a single terminal to a global checkout. 💳Processors & fintechPayment gateways, processors, and platforms that move cardholder data on others’ behalf. ☁️SaaS & hostingService providers whose systems store or touch card data as part of what they deliver. It’s its own regime, but the discipline it demands overlaps neatly with broader security programs. overlaps ISO 27001SOC 2NIST CSFCIS Controls 07 Career Relevance Where security meets the checkout PCI work is everywhere money moves — retail, banking, fintech, hospitality. It’s also concrete: scope a Cardholder Data Environment, segment a network, complete an SAQ or ROC, and you’ve produced something a business can literally bank on. QSA / ISAAssess & certifyQualified and internal assessors validate compliance and sign the reports acquirers rely on. GRC analystScope & evidenceDefine the CDE, drive segmentation, and assemble the evidence that keeps annual validation painless. Security engineerBuild the controlsImplement the technical requirements — encryption, logging, MFA, script integrity — that the standard demands. Understanding scope reduction alone makes you valuable: it’s the difference between a business sweating an audit and sailing through one. 08 Strengths & Challenges Honest trade-offs ✦ Strengths Prescriptive and clear — you know exactly what’s required Globally enforced by banks and card brands Protects data attackers want most v4 pushes toward continuous, not once-a-year, security Scope reduction gives real control over effort ⚠ Challenges Rigid — less room for risk-based judgment Scope creep is punishing and easy to trigger Annual validation is ongoing work Contractual enforcement varies by acquirer Not a full security program on its own 09 Final Takeaway If your business touches a card, PCI DSS isn’t homework — it’s the price of admission.Twelve requirements, six goals, and one insight that decides everything: control your scope. Master what falls inside the Cardholder Data Environment and what you can keep out, and the most feared audit in commerce becomes routine.