An Introduction to PCI DSS - ESP-P-015
- Track: Technical, Management.
- Level: Practitioner level - Those who must incorporate security conscious practices into their daily processes
- Overview
This course provides an introduction to PCI DSS and is suitable for anyone within an organisation that is involved in the implementation of the PCI DSS standard OR to establish whether PCI DSS applies to you. This foundation course is an important first step in planning your organisations’ PCI DSS plans.
- Outline
- Background
- Establishing the PCI project
- Information Security Policy
- Conducting a Gap Analysis
- Conducting a Risk Analysis
- Establish the Baseline
- Auditing
- Maintaining & Demonstrating Compliance- This course is suitable for
anyone involved in implementing PCI within an organisation.
- Course duration
- Half day
- Course cost
€375
- Course format
Instructor led. All Espion training courses are of small class size (max 8 attendees) to ensure an optimum teaching environment.
- Course dates
- There are currently no dates scheduled for this course.
.- Course location
Espion Training Centre
- Content
Unit 1: Background
a. What is PCI?
b. Why PCI?
c. How does PCI compliance work?
d. Getting started with PCIUnit 2: Establishing the PCI Project
a. Project initiation objective
b. DeliverablesUnit 3: Information Security Policy
Unit 4: Conducting a Gap Analysis
a. Gap analysis objectives
b. Gap analysis approach
c. PCI gap analysis reporting and security improvement planUnit 5: Conducting a Risk Assessment
a. The goal of the risk management process
b. The benefits of risk management
c. The elements of risk management processUnit 6: Establish the Baseline
a. Build and maintain a secure network
b. Maintain a vulnerability management programme
c. Implement strong access control measures
d. Regularly monitor and test networks
e. Maintain an information security policyUnit 7: Auditing
a. Initiation of the audit
b. Conduct the audit
c. Report the findingsUnit 8: Maintaining and demonstrating compliance
a. Validation requirements
b. How to meet these requirements
c. Using log management information for PCI compliance
d. Regular monitoring and testing
e. Demonstrating compliance