Library Hours
Monday to Friday: 9 a.m. to 9 p.m.
Saturday: 9 a.m. to 5 p.m.
Sunday: 1 p.m. to 9 p.m.
Naper Blvd. 1 p.m. to 5 p.m.
     
Limit search to available items
Results Page:  Previous Next
Author Seaman, Jim.

Title PCI DSS : an integrated data security standard guide / Jim Seaman. [O'Reilly electronic resources]

Imprint Berkeley, CA : Apress, 2020.
QR Code
Description 1 online resource (549 pages)
text file
PDF
Contents Intro -- Table of Contents -- About the Author -- About the Technical Reviewer -- Introduction -- A Tribute To -- Chapter 1: An Evolving Regulatory Perspective -- Introduction -- Revolution or Evolution? -- Europe -- Canada -- United States -- Australia -- China -- Japan -- Argentina -- Malaysia -- Brazil -- India -- Financial Services -- Data Privacy Hierarchy -- PCI DSS Validation Requirements -- Recommendations -- Behaviors -- Leadership -- Consent or Legitimate Use -- Conclusion -- Key Takeaways -- Risks -- Chapter 2: The Evolution of PCI DSS
Associated Costs (Non-compliance/Data Breach) -- Introduction -- PCI DSS Controls Framework Architecture -- Primary (Core) Ring -- Secondary Ring -- Tertiary Ring -- Quaternary Ring -- Quinary Ring -- Senary (Outer) Ring -- Historic References -- Build and Maintain a Secure Network -- Protect Cardholder Data -- Maintain a Vulnerability Management Program -- Implement Strong Access Control Measures -- Regularly Monitor and Test Networks -- Maintain an Information Security Policy -- Reality Bites -- Recommendations -- Conclusion -- Key Takeaways -- Risks -- Chapter 3: Data Life Support System
Introduction -- Concept -- Lessons Learned -- Layered Defenses -- 24/7 Monitoring -- Physical Security -- Incident Response -- Blood Life-Cycle Management -- Recommendations -- Conclusion -- Key Takeaways -- Risks -- Chapter 4: An Integrated Cyber/InfoSec Strategy -- Introduction -- Components of an Effective Strategy -- Data Privacy -- Cyber Security -- External Attack Surface Reconnaissance -- Information Gathering -- PCI DSS Applicable Controls -- External Technologies -- Information Security -- Physical Security -- Resilience -- What Is Resilience? -- Recommendations -- Conclusion
Key Takeaways -- Risks -- Chapter 5: The Importance of Risk Management -- Introduction -- What Is a Risk Assessment? -- Background -- Scenario Development -- Think Like an Attacker -- Risk Scenarios -- Risk Assessment Process -- Reality Bites -- Recommendations -- Conclusion -- Key Takeaways -- Risks -- Chapter 6: Risk Management vs. Compliance -- The Differentiator -- Introduction -- PCI DSS Is Not a Legal Requirement ... -- ... But Should Be a Business Requirement? -- Concept -- How Is This Achieved? -- Qualitative vs. Quantitative Risk Assessment -- Qualitative Risk Assessments
Quantitative Risk Assessments -- Risk Appetite/Tolerance -- Case Studies -- Case Study 1: Telephone-Based Payments Risk Balance Case -- Case Study 2: Enhanced PCI DSS Program Through Integration into Enterprise Risk Management (ERM) -- Reality Bites -- Recommendations -- Conclusion -- Key Takeaways -- Risks -- Chapter 7: PCI DSS Applicability -- PCI DSS Overview -- Introduction -- The Precious Cargo -- Structure of a Payment Card -- Precious Cargo Categories -- Front of Payment Card Breakdown -- Rear of Payment Card Breakdown -- Personal Identification Number (PIN)/PIN Blocks -- CHD Storage
Note Accessing Applicability
Bibliography Includes bibliographical references and index.
Summary Gain a broad understanding of how PCI DSS is structured and obtain a high-level view of the contents and context of each of the 12 top-level requirements. The guidance provided in this book will help you effectively apply PCI DSS in your business environments, enhance your payment card defensive posture, and reduce the opportunities for criminals to compromise your network or steal sensitive data assets. Businesses are seeing an increased volume of data breaches, where an opportunist attacker from outside the business or a disaffected employee successfully exploits poor company practices. Rather than being a regurgitation of the PCI DSS controls, this book aims to help you balance the needs of running your business with the value of implementing PCI DSS for the protection of consumer payment card data. Applying lessons learned from history, military experiences (including multiple deployments into hostile areas), numerous PCI QSA assignments, and corporate cybersecurity and InfoSec roles, author Jim Seaman helps you understand the complexities of the payment card industry data security standard as you protect cardholder data. You will learn how to align the standard with your business IT systems or operations that store, process, and/or transmit sensitive data. This book will help you develop a business cybersecurity and InfoSec strategy through the correct interpretation, implementation, and maintenance of PCI DSS. You will: Be aware of recent data privacy regulatory changes and the release of PCI DSS v4.0 Improve the defense of consumer payment card data to safeguard the reputation of your business and make it more difficult for criminals to breach security Be familiar with the goals and requirements related to the structure and interdependencies of PCI DSS Know the potential avenues of attack associated with business payment operations Make PCI DSS an integral component of your business operations Understand the benefits of enhancing your security culture See how the implementation of PCI DSS causes a positive ripple effect across your business.
Subject Computer security.
Computer Security
Sécurité informatique.
Computer security
Other Form: Print version: Seaman, Jim. Pci Dss : An Integrated Data Security Standard Guide. Berkeley, CA : Apress L.P., ©2020 9781484258071
ISBN 9781484258088 (electronic bk.)
1484258088 (electronic bk.)
Standard No. 10.1007/978-1-4842-5808-8 doi
10.1007/978-1-4842-5
Patron reviews: add a review
Click for more information
EBOOK
No one has rated this material

You can...
Also...
- Find similar reads
- Add a review
- Sign-up for Newsletter
- Suggest a purchase
- Can't find what you want?
More Information