More information

Why PCI DSS

Standard based on a consortium of Visa, MasterCard and American Express

It is required on all levels of electronic payment cards. PCI DSS compliance - compliance with the standard is divided into multiple levels, depending on whether you handle payment card information or your applications only connect to a payment gateway.

Why choose TX for PCI DSS training?

TAYLLORCOX is an internationally accredited certification body for a number of standards, including ISMS ISO/IEC 27001. It is this standard that has been used to compile the PCI DSS requirements.

Naturally we have a Qualified Security Assessor (QSA) who has extensively implemented PCI Compliance in a number of organisations.

Unique in the country, this course will help you understand the standard as a whole, but also show you how to plan and execute a cost-effective and time-saving project to implement PCI DSS or meet the Council's requirements.

Risks of PCI DSS

Undocumented information system

In many of our clients, we have encountered a situation when, due to the fact that various parts of the system were historically created over many years and their development was not properly documented, the client was often unable to explain to us what specific data actually passes through the various parts of the information system.

Storage of sensitive post-authorization payment transactions

Under no circumstances may merchants store sensitive data (such as the full card number) after a payment transaction has been authorised, for example in event logs, backups or directly in the database.

Information security compliance issues

PCI DSS is an information security standard and requires a comprehensive solution to this issue within an organisation. However, we often encounter a situation with our clients where information security is not adequately addressed. Typical examples may include missing or inadequate event logging (logging and monitoring), lack of a process for regularly updating security patches, inadequate control over change management, or lack of security awareness among company employees.