
PCI DSS A Practical Guide to Implementing and Maintaining Compliance
IT Governance Publishing(Editor)
IT Governance Publishing
3rd Edition
Published on 19. April 2011
Book
Paperback/Softback
264 pages
978-1-84928-186-7 (ISBN)
Description
The Payment Card Industry Data Security Standard (PCI DSS) must be met by all organisations (merchants and service providers) that transmit, process or store payment card data. It is a contractual obligation applied and enforced - by means of fines or other restrictions - directly by the payment providers themselves. As the cybercrime market evolves, attackers, targets and techniques do as well. The majority of data breaches still occur because basic controls are not in place, or because those that were present were not consistently implemented across an organisation. If obvious weaknesses are left exposed, chances are the attacker will exploit them. The objective of this revised practical guide is to give entities advice and tips on the entire PCI implementation process. It provides a roadmap, helping entities to navigate the broad, and sometimes confusing, PCI DSS v2, and shows them how to build and maintain a sustainable PCI compliance programme. This latest revision also includes increased guidance on how to ensure your compliance programme is 'sustainable' and has been based on real-life scenarios, which should help to ensure your PCI compliance programme remains compliant.
Although the guide starts with sections on why and what is PCI, it is not intended to replace the 'publicly available' PCI information. This book looks to serve those who have been given the responsibility of PCI, and does not attempt to provide all the answers. It should be read, absorbed and digested only with a good helping of other PCI 'publicly available' information. In other words, it will help an organisation or individual, get started, and hopefully furnish the reader with enough of the fundamental basics to create, design and build the organisation's own PCI compliance framework.
Although the guide starts with sections on why and what is PCI, it is not intended to replace the 'publicly available' PCI information. This book looks to serve those who have been given the responsibility of PCI, and does not attempt to provide all the answers. It should be read, absorbed and digested only with a good helping of other PCI 'publicly available' information. In other words, it will help an organisation or individual, get started, and hopefully furnish the reader with enough of the fundamental basics to create, design and build the organisation's own PCI compliance framework.
More details
Edition
3rd Revised edition
Language
English
Place of publication
Ely
United Kingdom
Target group
Professional and scholarly
Edition type
Revised edition
Product notice
Paperback (trade)
Illustrations
black & white illustrations
Dimensions
Height: 218 mm
Width: 138 mm
Thickness: 14 mm
Weight
331 gr
ISBN-13
978-1-84928-186-7 (9781849281867)
Copyright in bibliographic data and cover images is held by Nielsen Book Services Limited or by the publishers or by their respective licensors: all rights reserved.
Schweitzer Classification
Other editions
Additional editions

E-Book
04/2011
IT Governance Publishing
€45.49
Available for download
Person
Steve Wright is a consultant and lecturer with extensive experience in the design and implementation of security architecture and information security governance frameworks, including PCI DSS. Steve has successfully executed information security projects for several UK government agencies and completed many consulting engagements for global corporations in sectors including business process outsourcing, manufacturing, telecoms, IT and healthcare. He currently manages a successful security management practice, and is a lecturer and trainer on Information Risk Management and many British Computer Society ISEB courses.