
PCI DSS
Payment Card Industry Data Security Standard for protecting cardholder data.
Overview
PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards established by the PCI Security Standards Council. It applies to all organizations that accept, process, store, or transmit credit card information. The standard defines 12 high-level requirements organized into six control objectives. CodeMiners' PCI DSS compliance ensures that systems handling payment data meet all applicable requirements for network security, data protection, vulnerability management, access control, monitoring, and security policy.
Governing Body
PCI Security Standards Council (PCI SSC), founded by Visa, Mastercard, American Express, Discover, and JCB
Scope of Certification
Covers all systems, processes, and personnel involved in storing, processing, or transmitting cardholder data. Includes network security, access control, encryption, vulnerability management, monitoring, and incident response specific to payment environments.
Audit and Assessment Process
Compliance is validated through a Report on Compliance (ROC) conducted by a Qualified Security Assessor (QSA), or through a Self-Assessment Questionnaire (SAQ) for smaller merchants. Quarterly external vulnerability scans by an Approved Scanning Vendor (ASV) are also required.
Key Requirements
- Install and maintain a firewall configuration to protect cardholder data
- Do not use vendor-supplied defaults for system passwords
- Protect stored cardholder data with encryption
- Encrypt transmission of cardholder data across open networks
- Use and regularly update anti-virus software
- Develop and maintain secure systems and applications
- Restrict access to cardholder data by business need to know
- Assign a unique ID to each person with computer access
- Restrict physical access to cardholder data
- Track and monitor all access to network resources and cardholder data
- Regularly test security systems and processes
- Maintain an information security policy
Compliance Entitlements
- Secure handling and processing of payment card data
- Compliance with all 12 PCI DSS requirements
- Required for any system that touches credit card information
- Regular compliance validation through qualified assessments
Client Benefits
- Ensures payment data processed by CodeMiners meets card brand security requirements
- Reduces client liability for payment data breaches
- Required for clients accepting credit card payments
- Demonstrates mature payment security practices to acquiring banks and payment processors
Related Certifications
Build With an Award-Winning Team
65+ Clutch badges. 20+ certifications. 200+ verified reviews.
Start Your Project