PCI DSS

E184232

PCI DSS (Payment Card Industry Data Security Standard) is a global set of security requirements designed to protect cardholder data and reduce credit card fraud for organizations that handle payment card information.

All labels observed (13)

How this entity was disambiguated

Statements (62)

Predicate Object
instanceOf information security standard
payment card security standard
abbreviationFor Payment Card Industry Data Security Standard
linked to: PCI DSS
appliesTo acquiring banks
merchants
organizations that process cardholder data
organizations that store cardholder data
organizations that transmit cardholder data
payment processors
service providers handling payment card data
cardBrandsInvolved American Express
Discover
JCB
linked to: JCB Co., Ltd.

Mastercard
Visa
category compliance
cybersecurity
complianceValidatedBy Internal Security Assessor
Qualified Security Assessor
Self-Assessment Questionnaire
contains 12 high-level requirements
operational security requirements
technical security requirements
developedBy PCI Security Standards Council
fullName Payment Card Industry Data Security Standard
linked to: PCI DSS
geographicScope global
governedBy PCI Security Standards Council
hasVersion PCI DSS v1.0
linked to: PCI DSS

PCI DSS v1.1
linked to: PCI DSS

PCI DSS v1.2
linked to: PCI DSS

PCI DSS v2.0
linked to: PCI DSS

PCI DSS v3.0
PCI DSS v3.1
linked to: PCI DSS

PCI DSS v3.2
linked to: PCI DSS

PCI DSS v3.2.1
linked to: PCI DSS

PCI DSS v4.0
linked to: PCI DSS
industry payment card industry
introduced 2004
isMandatoryFor American Express merchants under card brand rules
Discover merchants under card brand rules
JCB merchants under card brand rules
Mastercard merchants under card brand rules
Visa merchants under card brand rules
purpose protect cardholder data
reduce credit card fraud
secure payment card transactions
relatedStandard PA-DSS
PCI SSF
linked to: PA-DSS
requires access control measures
encryption of cardholder data over open public networks
information security policy
network segmentation or compensating controls where applicable
protection of stored cardholder data
regular monitoring and testing of networks
secure system configuration
use of anti-virus software
use of firewalls
riskAddressed credit card fraud
identity theft related to card data
payment card data breach
scope cardholder data
sensitive authentication data

How these facts were elicited

Referenced by (26)

Full triples — surface form annotated when it differs from this entity's canonical label.

PCI Security Standards Council developsStandard PCI Data Security Standard
linked to: PCI DSS
Amazon S3 supportsCompliance PCI DSS
PCI DSS fullName Payment Card Industry Data Security Standard
linked to: PCI DSS
PCI DSS abbreviationFor Payment Card Industry Data Security Standard
linked to: PCI DSS
PCI DSS hasVersion PCI DSS v1.0
linked to: PCI DSS
PCI DSS hasVersion PCI DSS v1.1
linked to: PCI DSS
PCI DSS hasVersion PCI DSS v1.2
linked to: PCI DSS
PCI DSS hasVersion PCI DSS v2.0
linked to: PCI DSS
PCI DSS hasVersion PCI DSS v3.1
linked to: PCI DSS
PCI DSS hasVersion PCI DSS v3.2
linked to: PCI DSS
PCI DSS hasVersion PCI DSS v3.2.1
linked to: PCI DSS
PCI DSS hasVersion PCI DSS v4.0
linked to: PCI DSS
Payment Application Data Security Standard relatedTo PCI Data Security Standard
linked to: PCI DSS
PA-DSS relatedTo PCI DSS
PCI PIN Transaction Security relatedTo PCI Data Security Standard
linked to: PCI DSS
PTS relatedTo PCI DSS
Point-to-Point Encryption Standard relatedTo PCI Data Security Standard
linked to: PCI DSS
P2PE relatedStandard PCI DSS
Qualified Security Assessor program focusesOnStandard PCI Data Security Standard
linked to: PCI DSS
Amazon Connect supportsCompliance PCI DSS (for certain configurations)
linked to: PCI DSS
AWS Config supportsComplianceStandards PCI DSS (via rules and conformance packs)
linked to: PCI DSS