CHAPTER 5: HOW DO YOU COMPLYWITH THE REQUIREMENTS OF THESTANDARD?

All organisations must comply. There are two options for demonstrating compliance: an annual on-site security audit and a quarterly network scan or completion of a Self-Assessment Questionnaire, in some cases together with an annual network scan. Which option applies to any one organisation is determined by transaction volume and whether or not there has previously been a security breach.

Two groups of organisations must demonstrate compliance with PCI DSS: merchants and service providers.

Merchant PCI DSS compliance criteria

Compliance requirements are dependent on a merchant’s activity level. There are four levels, based on the annual number of credit/debit card transactions. ...

Get PCI DSS A Pocket Guide, Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.