The Payment Card Industry Data Security Standard (PCI DSS) must be met by all organizations (merchants and service providers) that transmit, process or store payment card data. It is a contractual obligation applied and enforced - by means of fines or other restrictions - directly by the payment providers themselves. As the cybercrime market evolves, attackers, targets and techniques do as well. The majority of data breaches still occur because basic controls are not in place, or because those that were present were not consistently implemented across an organization. If obvious weaknesses are left exposed, chances are the attacker will exploit them. The objective of this revised practical guide is to give entities advice and tips on the entire PCI implementation process. It provides a roadmap, helping entities to navigate the broad, and sometimes confusing, PCI DSS v2, and shows them how to build and maintain a sustainable PCI compliance program. This latest revision also includes increased guidance on how to ensure your compliance program is 'sustainable' and has been based on real-life scenarios, which should help to ensure your PCI compliance program remains compliant. Although the guide starts with sections on why and what is PCI, it is not intended to replace the 'publicly available' PCI information. This book looks to serve those who have been given the responsibility of PCI, and does not attempt to provide all the answers. It should be read, absorbed and digested only with a good helping of other PCI 'publicly available' information. In other words, it will help an organization or individual, get started, and hopefully furnish the reader with enough of the fundamental basics to create, design and build the organization's own PCI compliance framework.
"synopsis" may belong to another edition of this title.
Steve Wright is a consultant and lecturer with extensive experience in the design and implementation of security architecture and information security governance frameworks, including PCI DSS. Steve has successfully executed information security projects for several UK government agencies and completed many consulting engagements for global corporations in sectors including business process outsourcing, manufacturing, telecoms, IT and healthcare. He currently manages a successful security management practice, and is a lecturer and trainer on Information Risk Management and many British Computer Society ISEB courses.
"About this title" may belong to another edition of this title.
Shipping:
US$ 10.64
From United Kingdom to U.S.A.
Seller: Better World Books Ltd, Dunfermline, United Kingdom
Condition: Good. Ships from the UK. Former library book; may include library markings. Used book that is in clean, average condition without any missing pages. Seller Inventory # GRP104735071
Quantity: 2 available
Seller: The Book Spot, Sioux Falls, MN, U.S.A.
Paperback. Condition: New. Seller Inventory # Abebooks486391
Quantity: 1 available