PCI DSS Standard and Compliance Online Training

所在平台: Udemy

课程主页: https://www.udemy.com/course/pci-dss-standard-and-compliance-fundamentals/

课程评论:没有评论

第一个写评论        关注课程

课程简介

课程名称:PCI DSS标准与合规在线培训 课程概述: 本在线课程旨在全面理解支付卡行业数据安全标准(PCI DSS)及其合规要求。课程涵盖PCI DSS标准的12项要求,旨在保护敏感支付卡数据,帮助组织防止数据泄露。课程首先介绍PCI DSS的基础知识,包括其范围和目的,以及组织可达到的不同合规级别。学员将学习到涉及安全网络架构、访问控制和事件响应等领域的12项标准要求。 课程内容: 1. **第1部分**:介绍PCI DSS标准的背景、历史、定义及合规的必要性。 2. **第2部分**:解析PCI DSS中常用术语,例如商户、服务提供商、合格安全评估师(QSA)等。 3. **第3部分**:深入探讨PCI DSS的适用范围及其6个目标和12项要求,包括卡交易流程的8个步骤。 4. **第4部分**:讲解目标1(构建和维护安全网络),涵盖防火墙配置及系统密码管理要求。 5. **第5部分**:关注目标2(保护持卡人数据),涵盖存储数据保护及数据加密要求。 6. **第6部分**:介绍目标3(维护漏洞管理程序),涉及防病毒软件和系统应用程序的安全性维护。 7. **第7部分**:讨论目标4(实施强有力的访问控制措施),包括数据访问限制和物理访问控制要求。 8. **第8部分**:分析目标5(定期监测和测试网络),探讨网络资源和数据访问的监控及安全测试流程。 9. **第9部分**:讨论目标6(维护信息安全政策),强调为所有员工制定信息安全政策的必要性。 10. **第10部分**:讲解PCI合规验证方法,包括合规级别、合规验证及报告要求。 课程适合信息安全、IT行业专业人员,以及希望了解如何保护敏感支付卡数据并遵守PCI DSS标准的任何人。通过学习本课程,学员将对PCI DSS标准及其必要控制措施有全面的理解。

课程评论(0条)

课程详情

This online course on PCI DSS Standard and Compliance is designed to provide a comprehensive understanding of the Payment Card Industry Data Security Standard (PCI DSS) and how to comply with its requirements. The course covers the 12 requirements of the PCI DSS standard, which are designed to protect sensitive payment card data and help organizations prevent data breaches.The course starts by introducing the basics of PCI DSS, including its scope and purpose, as well as the different levels of compliance that organizations can achieve. You will learn about the 12 requirements of the standard, which cover areas such as secure network architecture, access controls, and incident response.Throughout the course, you will learn about the best practices and technologies that can be used to help organizations comply with the PCI DSS standard, including firewalls, intrusion detection systems, and encryption.You will also learn about the various tools and resources that are available to help organizations assess their compliance with the standard, including PCI DSS self-assessment questionnaires (SAQs) and on-site assessments.The course also covers the various reports that organizations are required to submit to demonstrate their compliance with the standard, including the Attestation of Compliance (AOC) and the Report on Compliance (ROC).The course is suitable for professionals working in the field of information security, IT, or related fields, as well as anyone interested in learning more about how to protect sensitive payment card data and comply with the PCI DSS standard. By the end of the course, you will have a comprehensive understanding of the PCI DSS standard and how to implement the necessary controls to comply with it.For easy understanding complete course is divided in 10 Sections and topics covered in respective sections are defined as follows:In Section 1 following topics are coveredBackground - PCI DSS StandardHistory - PCI DSS StandardWhat do mean by PCI DSSWhy you should get PCI CompliantConfusion around PCI DSSIn Section 2 following topics are covered wherein most common terminologies used in PCI DSS are covered.What do Merchants, Provider or Issuers Mean ?What is a Qualified Security Assessor (QSA)?Who is ISA (Internal Security Assessor) ?What is (SAQ) Self-Assessment Questionnaire ?What is (AOC ) Attestation of Compliance ?What is (RoC) Report on Compliance ?In Section 3 following topics are covered wherein concepts like PCI DSS Scope and Its Requirements are covered in detailHow Card transaction work (Explained in 8 Steps)PCI DSS ApplicabilitySystems In Scope of PCI DSS6 Goals and 12 requirementsImp- Structure of PCI DSS StandardIn Section 4 is about Goal 1 (Build and Maintain a Secure Network) wherein underlying Requirements are covered in detailReq 1: Install and maintain a firewall configuration to protect cardholder dataReq 2: Don't use vendor-supplied defaults for system passwordsIn Section 5 is about Goal 2 (Protect Card Holder data) wherein underlying Requirements are covered in detailReq 3: Protect stored cardholder dataReq 4: Encrypt transmission of cardholder data across open, public networksIn Section 6 is about Goal 3 (Maintain a Vulnerability Management Program) wherein underlying Requirements are covered in detailReq-5: Use and regularly update antivirus software or programsReq-6: Develop and maintain secure systems and applicationsIn Section 7 is about Goal 4 (Implement Strong Access Control Measures) wherein underlying Requirements are covered in detailReq-7: Restrict access to cardholder data by business need to knowReq-8: Assign a unique ID to each person with computer accessReq-9: Restrict physical access to cardholder dataIn Section 8 is about Goal 5 (Goal-5: Regularly Monitor and Test Networks) wherein underlying Requirements are covered in detailReq-10: Track and monitor all access to network resources and cardholder dataReq-11: Regularly test security systems and processesIn Section 9 is about Goal 6 (Goal-6: Maintain an Information Security Policy) wherein underlying Requirements are covered in detailReq-12: Maintain a policy that addresses information security for all personnelIn Section 10 we have covered following topics which helps you to understand as how Verification of PCI Compliance can be doneLevels of PCI Compliance/Merchant LevelsScanning by ASV (APPROVED SCANNING VENDOR)Verifying Compliance with PCIValidating a Requirement is in PlaceMeeting the reporting requirement of PCI DSS

课程标签

0人关注该课程

主题相关的课程