Introduction
Introduction to PCI 4.0
()
What you should know as background for this course
()
How this course is designed to help you learn
()
Requirement 1: Install and Maintain Network Security Controls
Network security: Creating strong network security controls
()
Network security: Controlling traffic appropriately
()
Requirement 2: Apply Secure Configurations to All System Components
Secure configurations: Building hardening standards
()
Requirement 3: Protect Stored Account Data
Stored PANs: Which data can you store and how?
()
Cryptographic controls for stored PAN data
()
Key management policies and procedures
()
Requirement 4: Protect CHD with Strong Cryptography during Transmission over Public Networks
Safely sending PAN data using strong cryptography
()
Requirement 5: Protect All Systems and Networks from Malicious Software
Anti-malware options and anti-phishing
()
Requirement 6: Develop and Maintain Secure Systems and Software
Secure development
()
Security vulnerabilities and protecting public sites
()
Change management requirements
()
Requirement 7: Restrict Access to System Components and Cardholder Data by Business Need to Know
Designing access controls
()
Access control systems
()
Requirement 8: Identify Users and Authenticate Access to System Components
Basic user ID requirements
()
Strong authentication for PCI
()
Multifactor authentication requirements
()
System and application account requirements
()
Requirement 9: Restrict Physical Access to Cardholder Data
Managing physical access
()
Managing physical media
()
Managing physical payment devices
()
Requirement 10: Log and Monitor All Access to System Components and Cardholder Data
Collecting audit logs
()
Reviewing audit logs
()
Time synchronization for logs
()
Critical security control failures
()
Requirement 11: Test the Security of Systems and Networks Regularly
Protecting wireless access points
()
Vulnerability scanning
()
Penetration testing
()
Network intrusions and unexpected file changes
()
Requirement 12: Support Information Security with Organizational Policies and Programs
Information security policy and acceptable use
()
Risk management and tracking PCI compliance
()
Tracking PCI scope, maintaining awareness, and screening
()
Third-party service provider risks
()
Incident response
()
Conclusion
Next steps to meet PCI 4.0
()