Understanding the Payment Card Industry
Data Security Standard version 1.2
For merchants and organizations that store, process or transmit cardholder data
Contents
Copyright 2008 PCI Security Standards Council, LLC. All Rights Reserved.
This Quick Reference Guide to the PCI Data Security Standard is provided by the PCI Security
Standards Council to inform and educate merchants and other organizations that process, store or transmit cardholder data. For more information about the PCI SSC and the standards we manage, please visit www.pcisecuritystandards.org.
The intent of this document is to provide supplemental information, which does not replace or supersede PCI Security Standards Council standards or their supporting documents. Full details can be found on our Web site.
03/09
Contents
Introduction: Protecting Cardholder Data with PCI Security Standards ................................... 4
Overview of PCI Requirements ...................................................................................................................... 6
PCI Data Security Standard (PCI DSS).................................................................................................... 8
Payment Application Data Security Standard (PA DSS).................................................................. 10
PIN Transaction Security Requirements (PTS) .................................................................................... 10
Security Controls and Processes for PCI DSS Requirements ............................................................. 11
Build and Maintain a Secure Network................................................................................................... 12
Protect Cardholder Data ............................................................................................................................ 14
Maintain a Vulnerability Management Program