pci-dss-compliance
Installation
SKILL.md
PCI DSS Compliance
Overview
PCI DSS (Payment Card Industry Data Security Standard) v4.0 applies to any organization that stores, processes, or transmits cardholder data (CHD). Maintained by the PCI Security Standards Council, it has 12 requirements across 6 goals. Non-compliance can result in fines of $5,000–$100,000/month and loss of card processing privileges.
Key Terms
- CHD (Cardholder Data): PAN, cardholder name, expiration date, service code
- SAD (Sensitive Authentication Data): Full magnetic stripe, CVV/CVC, PIN — NEVER store SAD post-authorization
- CDE (Cardholder Data Environment): Systems that store, process, or transmit CHD
- PAN (Primary Account Number): The 16-digit card number
Scoping: Minimize the CDE
The most effective compliance strategy is reducing scope — minimize the number of systems in the CDE.