Séminaires en ligne sur la norme Payment Card Industry sur la sécurité des données (PCI DSS)
Malgré la perspective d'amendes et de sanctions, de nombreux commerçants ne sont pas conformes à la norme PCI. De nombreuses raisons expliquent ceci, notamment le manque de sensibilisation, une mauvaise étude préliminaire de l'environnement des données du titulaire de la carte (CDE) et la sous-évaluation de la complexité technique de la norme.
Protégez les profits en gérant les risques liés au paiement par carte
Les sanctions en cas de non mise en place des précautions adéquates sont à présent plus sévères pour de nombreuses organisations. Selon la nouvelle législation européenne, une violation de données du titulaire de la carte contenant des informations pouvant permettre d'identifier l'individu peut avoir des conséquences selon le PCI DSS et le Règlement Général Européen sur la Protection des Données (RGPD).
IT Governance a lancé une série de séminaires en ligne afin d'aider les entreprises à gérer et réduire les risques liés au paiement par carte.
Requirement 12 of the PCI DSS requires organisations to actively manage their data protection responsibilities by establishing, updating and communicating security policies and procedures aligned with the results of regular risk assessments.
Read more >>
Security technologies can only go so far in protecting an organisation and helping maintain compliance. Policies are needed to address the weak link in security: people.
If people don’t know or understand what’s expected of them, they can put cardholder data at risk, regardless of the other security measures you have in place. Policies play an important role in securing data. They are the foundation for everything else as they provide direction and instruction, and assign responsibility.
Join our QSAs to understand how to develop PCI policies, including:
- The differences between a policy, a form and a procedure;
- How to identify which policies and clauses you need to address; and
- How to clearly state the tasks and responsibilities your company has when handling payment card data.
|
PCI DSS compliance, especially for RoCs and some SAQs, requires internal and external vulnerability scans, and frequent penetration tests.
Read more >>
Payment card data is a prized commodity for cyber criminals and is usually the main target of attacks against commercial environments. Indeed, the 2017 Trustwave Global Security Report found that more than half of the incidents investigated targeted payment card data.
Penetration testing has long been used to help prevent data breaches, understand security weaknesses and test security controls.
This webinar will cover:
- The Standard’s requirements for security testing;
- The differences between a penetration test and a vulnerability assessment;
- The PCI DSS v3.2 requirements for penetration testing and segmentation; and
- How to conduct a penetration testing programme.
|