• Skip to primary navigation
  • Skip to main content
  • Skip to footer
Logo of Agilient Security Consultants, Australia

Agilient Security Consultants Australia

Cybersecurity & Risk Management Specialists

Menu
  • Home
  • Industries
      • Aviation
      • Defence & Defence Industry
      • Government
      • Health & Hospitals
      • Corrections and Detention
      • Maritime
      • Aged Care Facilities
      • Mining, Oil & Gas
      • Public Venues & Events
      • Rail
      • Research and Education Industry
      • Telecommunications
      • Utilities
    • advice-colleagues-communication-newIndustries
  • Services
      • Cybersecurity
      • Protective Security
      • Business Resilience
      • Building Security Consultants
      • Security Audits
      • Pandemic Planning
      • Electronic Security
      • IT Disaster Recovery Plan
      • Security Consultants
      • CCTV and Security Cameras
      • Duress Alarms
      • Security Risk Assessment Consultants
      • Managed Security Service Provider
      • Protection against Vehicles as a Weapon
    • training-1Services
  • Solutions
    • banner-menuUnisys Solutions
    • CTO-Blog-110619-Header-GraphicLookingGlass Solutions
    • menu-bg-2Dell Technologies (RSA) Solutions
    • Sightline-Visualization-menuSightline Solutions
  • Resources
    • menumanagers-dealing-customer-agreTraining
    • working-together-newJoin The Tribe
    • Webinars_3-1.jpgUpcoming and Past Events
    • hacking-detected-shutterstock_newResources
  • Articles
  • About
    • About Us
      We are an Australian owned and operated security company specialising in risk, cybersecurity, protective security, crisis and business continuity management services.
    • frequently-asked-questions-smallFAQ’s
    • bg-menu-government-institutionsConsultant Registration
  • Contact Us
Contact Us

Payment Card Industry Data Security Standard (PCI DSS)

You are here: Home / Security News / Payment Card Industry Data Security Standard (PCI DSS)

The Payment Card Industry Data Security Standard (PCI DSS) is an information security standard for businesses that handle branded credit cards from the major card schemes such as MasterCard, Visa and American Express.

The PCI DSS is required by those handling cardholder data, whether you are a start-up or a global enterprise. The compliance framework is an industry- mandated set of standards, with the intention to keep consumer card data safe while it’s being used by the service providers.

PCI DSS Framework

The PCI DSS compliance framework applies to all businesses that store, process or transmit cardholder data. Each PCI member has their own compliance program to protect their cardholder’s data.

There are six primary requirements for correct compliance within the PCI DSS framework:

  • Build and maintain a secure network
    • A firewall configuration must be installed to help protect sensitive cardholder data
    • Creation of a unique password to maximise system security
  • Protect cardholder data
    • Cardholder data that is kept in storage must be protected from unauthorized alteration
    • Data should be encrypted when transmitting to open networks, to avoid third parties
  • Maintain a vulnerability management program
    • Anti-virus software must be used
    • All systems and applications that are being used to process information must be made secure
  • Implement strong access control measures
    • Access to cardholder information should be completely restricted
    • Unique identifiers must be assigned to individuals with computer systems access
  • Regularly monitor and test networks
    • Access to any resource within the network must be fully monitored
    • Tests should be regularly applied for all security systems
  • Maintain an information security policy
    • Implement a security policy for all employees and contractors

Merchant Levels

The PCI DSS contains a set of requirements to help organisations prevent payment data breaches and payment card fraud. There are four PCI merchant levels, with each level determined by the number of transactions the organisation handles each year. The levels are:

  1. Merchants processing more than 6 million Visa, MasterCard, or Discover transactions annually via any channel.
  2. Merchants processing between 1 million and 6 million Visa, MasterCard or Discover transactions per year via any channel.
  3. Merchants processing between 20,000 and 1 million Visa e-commerce transactions annually.
  4. Merchants processing less than 20,000 Visa or MasterCard e-commerce transactions annually.

Merchants in Level 1 handle the largest number of transactions, and have resource-intensive requirements which need outside validation, whereas in Level 4 the process is much simpler and less expensive.

PCI DSS Version 4.0

PCI-DSS 4.0 is the latest version of the Payment Card Industry Data Security Standard, and was released on 31st March 2022. Like all versions of PCI DSS, version 4.0 is a comprehensive set of guidelines aimed at securing systems involved in the processing, storage, and transmission of credit card data. The organization that is responsible for PCI DSS has set four objectives to guide the creation of Version 4.0:

  1. Ensure the standard continues to meet the security needs of the payments industry
  2. Add flexibility and support of additional methodologies to achieve security
  3. Promote security as a continuous process
  4. Enhance validation methods and procedures

For more information about PCI DSS v4.0, and how your organisation can comply with requirements, please contact us.

Author: Mahdi Kobeissi, Cyber Security Consultant

Tweet
Share

Security News access control,  American Express,  credit card payments,  credit cards,  data encryption,  MasterCard,  PCI DSS,  PCI Standards,  Visa,  vulnerability management program

Looking for a security partner? Get in touch with Agilient.

Looking for practical and cost-effective security and risk solutions for your government department, agency or company? Speak with Australia’s leading senior security, risk and resilience experts.


Looking for a pandemic planning partner? Get in touch with Agilient.

Looking for practical and cost-effective risk management solutions for your government department, agency or company? Speak with Australia’s leading senior risk and emergency management experts.



Footer

Agilient is a proud member of

Ai Group Defence Council
Australian Industry & Defence Network
Australian Security Industry Association
Sydney Aerospace & Defence Interest Group

Company and Licensing Details:

ABN: 37 157 911 441
NSW Security Master Licence # 410783087
ACT Security Master Licence # 17502184
Vic Security Registration # 878-460-40S
Qld Security Firm Licence # 3834422

Join The Tribe

Sign up to receive our regular Agilient newsletter including the latest security, risk and resilience updates

Sign up now

Copyright © 2022 Agilient – Level 14, 275 Alfred St, North Sydney NSW 2060 Australia – 1300 341 692