Fundamentals of PCI-DSS v4.0.0

所在平台: Udemy

课程主页: https://www.udemy.com/course/fundamentals-pci-dss/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:PCI-DSS v4.0.0 基础知识 课程概述: 随着支付欺诈事件的增加,数据安全变得愈发重要。PCI-DSS(支付卡行业数据安全标准)为处理卡数据的组织制定了一系列严格标准,指导它们如何存储和传输这些数据。本课程旨在填补现有课程的空白,将技术知识与实际应用结合在一起,提供全面的学习体验。 课程内容包括: 1. PCI-DSS相关术语的解释,如CDE(卡数据环境)、CHD(卡持有者数据)、SAD(敏感认证数据)等,以及商户分类的等级(1-4级)。 2. PCI-DSS自2004年以来的发展历程及其更新周期。 3. 针对商户的评估流程,包括SAQ(自我评估问卷)和ROC(报告的合规性)工作原理,及不同类型SAQ的应用。 4. 从授权、身份验证到结算的支付过程解剖,以及发卡行、收单行和卡组织的角色。 5. 12项PCI-DSS要求的概述及其与6个目标的关系。 6. 各项要求的深入内容,包括防火墙配置、数据保护、传输加密、恶意软件防护、开发安全性、访问控制、物理安全及网络监控等。 课程邀请: 课程提供30天无风险退款保证,确保适合您的需求。可以通过免费预览视频检查课程是否符合您的期待。如果您希望提升支付欺诈预防的知识,欢迎加入我们。期待在课程中见到您!

课程评论(0条)

课程详情

SECURE YOUR DATA, SECURE YOUR KNOWLEDGEYou may know that payment fraud has risen over time, and unfortunately is not slowing down.The PCI-DSS, or Payment Card Industry Data Security Standards, are a set of strict standards for any organisation dealing with card data.They tell you how to store and transmit these data.However, you'll hardly find a course that both covers the technical knowledge, but also practical applications and examples.In short, most PCI-DSS courses are either only about the tech, or about the business.If only you could find a course that combined both...Well.that's what this course aims to change.LET ME TELL YOU.EVERYTHINGSome people - including me - love to know what they're getting in a package.And by this, I mean, EVERYTHING that is in the package.So, here is a list of everything that this course covers:You'll learn about the clarification of all terms used in the PCI-DSS, including what is the CDE, what is CHD, SAD, whether an organisation must take an ROC or SAQ, as well as some "general" payment industry terms such as what is an issuing bank and an acquiring bank;You'll learn about the history of the PCI-DSS since 2004, with several iterations and its own release lifecycle;You'll learn about the merchant assessment process, based on their classification from Level 1-4, and how both SAQs and ROCs work, as well as the 8 different types of SAQs, and the types of machines/merchants they target, including the SAQ A and SAQ A-EP, the SAQ B and SAQ B-IP, the SAQ C and SAQ C-VT, the SAQ P2PE and SAQ SPoC, and finally, the most general SAQ-D;You'll learn about the anatomy of a payment process, involving a cardholder and a merchant, from authorisation to authentication, clearing and settlement, and the role of the issuing bak, the acquiring bank and the card company;You'll learn about an overview of all 12 PCI-DSS requirements, as well as their relationship with the 6 goals;You'll learn all about Requirement 1 (Have a Firewall), including firewall configurations and standards, documentation on network topology and card data flows, setting up a DMZ, rejecting unsecured traffic, and more;You'll learn all about Requirement 2 (No Defaults), about removing default passwords/accounts/strings from devices, but also isolating server functionality and removing unnecessary ports/services/apps that may present vulnerabilities;You'll learn all about Requirement 3 (Protect Stored Data), about using strong encryption to protect cardholder data, as well as having proper data retention policies, data purging, as well as masking plaintext PANs, not storing SAD, and using proper key management and key lifecycle procedures;You'll learn all about Requirement 4 (Protect Transmitted Data), about using strong encryption when transmitting CHD across public networks such as cellular or satellite, as well as masking plaintext PANs in transit, especially across IM channels;You'll learn all about Requirement 5 (Prevent Malware), about having an antivirus solution on all commonly affected computers in order to prevent malware, as well as access control policies to prevent disabling AV software;You'll learn all about Requirement 6 (Develop Securely), about doing vulnerability ranking and timely patch installation for both internal and 3rd-party applications, as well as including security requirements in the SDLC, as well as training developers to protect against common exploits such as code injections, buffer overflows and many others;You'll learn all about Requirement 7 (Need-to-Know Access), about limiting access to CHD by personnel as much as possible, defining permissions by role, and having a formal mechanism for access control to consolidate this, such as LDAP, AD or ACLs;You'll learn all about Requirement 8 (Identify Access), about tying each action to a unique user, including forcing unique IDs, automatic logouts on inactivity, lockouts on wrong password attempts, removing inactive accounts, limiting third-party access, forbidding the use of shared IDs, forcing physical security measures to be used only by the intended user, and more;You'll learn all about Requirement 9 (Restrict Physical Access), about authorising and distinguishing visitors, enforcing access control to rooms with CHD, as well as the proper transport, storage and disposal of physical media containing CHD, with different sensitivity levels;You'll learn all about Requirement 10 (Monitor Networks), about logging. Having a logging solution that is operating, logging specific events (such as all failed operations, all admin operations, all operations on CHD, etc), logging specific elements in each event (such as the user ID, the operation status, the affected resource, etc), as well as having a single time synchronisation mechanism for all logs, FIM (File Integrity Monitoring) on logs, frequent log review and proper log retention;You'll learn all about Requirement 11 (Test Regularly), about performing regular scans for Access Points (APs), both authorised and non-authorised ones, as well as regular vulnerability scanning and regular penetration testing (from inside and outside, and multiple layers), as well as having FIM (File Integrity Monitoring) on all critical files, as well as having an IDS/IPS (Intrusion Detection/Prevention System) to prevent attacks;You'll learn all about Requirement 12 (Have an InfoSec Policy), which covers roles, responsibilities and owners at levels of the organisation, including varied topics such as technology usage policies, employee screening, employee awareness, third-party selection criteria, regular risk and vulnerability assessments, among others;You'll learn about a review of all 12 requirements and general patterns among them, such as "denying everything" by default, using common sense for certain parameters, enforcing change management on all changes, and always prioritising security (both logical and physical);MY INVITATION TO YOURemember that you always have a 30-day money-back guarantee, so there is no risk for you.Also, I suggest you make use of the free preview videos to make sure the course really is a fit. I don't want you to waste your money.If you think this course is a fit and can take your fraud prevention knowledge to the next level.it would be a pleasure to have you as a student.See you on the other side!

课程标签

0人关注该课程

主题相关的课程