How to Learn about PCI Compliance
When business owners or IT directors first become aware they need to comply with the Payment Card Industry Data Security Standard (PCI DSS) and haven’t gone through the process before, a period of learning, head scratching and sorting through the various PCI DSS requirements begins. A similar trend applies for software vendors when they begin to understand the PA-DSS.
So when it comes to PCI compliance newbies, what’s the easiest way to get educated?
PCI Security Standards Council Website – First read through the PCI Security Standards Council website, becoming familiar with the different PCI compliance standards. The recently published Quick Guide is a good place to start.
Read PCI Compliance Related Blogs – Blogs are great for providing tips and in-depth analysis on the standards, technologies and strategies to help comply, etc. Here are few of our favorites:
Storefront BacktalkAnton Chuvakin “Security Warrior”
Treasury Institute for Higher Education (great for educators)
Read and Post Questions on PCI Compliance Forums – Post questions you have about PCI compliance on forums. It’s amazing how much expert advice you will receive for free. Or if you don’t have any specific questions yet surf the forums simply to gain more knowledge. PCI Knowledge Base and Society of Payment Security Professionals are the best PCI compliance forums.
Listen to Podcasts and Attend Webinars – The PCI Security Council and several companies offer webinars and podcasts about PCI compliance. Attend them live or download them later on, commonly for free.
Join LinkedIn Groups or Facebook Pages – Similar to forums, engage with a group of professionals working towards PCI compliance and experts in the field on social networking sites. Check out the PCI DSS Forum group on LinkedIn or the Understanding PA-DSS Facebook page.
Attend PCI DSS Training - The PCI Security Standards Council offers a two day training course based directly on the PCI SSC Qualified Security Assessor (QSA) training program. Attendees will learn what the QSAs learn so they can better prepare for an on-site PCI DSS assessment or perform the assessment internally. In addition to the QSA training materials, the Standards training course will also cover how to develop an internal PCI DSS compliance program to sustain PCI compliance after the on-site assessment is complete. This is mainly for large companies.
SANS also offers a general course on PCI DSS compliance and the Treasury Institute for Higher Education hosts a PCI workshop for higher education institutions. Glenbrook offers a Payments Boot Camp that dives deeply into the current trends and issues of the U.S. payment system.
