PCI DSS
Payment Card Industry Data Security Standard
The security standard for organizations handling payment card data.
Payment Card Industry Data Security Standard is a contractual set of requirements that organizations handling cardholder data must meet to protect that data and reduce fraud. It mandates controls such as network segmentation, encryption, access restriction, vulnerability management, and logging, with validation through self-assessment or external audit depending on transaction volume. It is an industry mandate enforced by the card brands rather than a government law, which distinguishes it from regulations like HIPAA or GDPR. Reducing the scope of the cardholder data environment lowers compliance burden.
Looking PCI DSS up is step one. Getting tested on it is step two.
A free account opens all 4 Domain 1 objectives, 271 exam-style questions with a lesson and a lab on each, a placement check that skips what you already know, and a dated plan. No card.
Not affiliated with or endorsed by CompTIA.
