Open In App

What is PCI DSS?

Pre-requisites: What is an Online Transaction?

The payment card industry data security standard (PCI DSS) is controlled by the PCI security standard council. The purpose behind this standard is to reduce payment theft and fraud which are caused due to vulnerability in security. 



Organizations which require card payments stores information of customer. For such organizations it is mandatory to maintain and follow this standard. This standard Install and maintain a secure network and systems, Protect cardholder data, Maintain a vulnerability management program, Implement strong access control measures, Regularly monitor and test networks and maintain an information security policy. 

It also applies across organization  or to a subset of the organization that transmits or stores the card holder data away from the rest of applications. It is applied to all people, processes and technologies that are involved in the processing, transmission, or storage of cardholder data. 



PCI DSS is not just an electronic system but includes all the systems including paper records such as receipts, mail order forms etc., and recordings of phone conversations if, they capture cardholder data being read out to call center operators. This standard needs all applicable merchants and member service providers(MSPS) who are involved with storage, processing or transmitting of cardholder data. IT governance advises on the applicability of the PCI DSS to the organization. 

Advantages of PCI DSS

Disadvantages of PCI DSS

Article Tags :