Companion-course connectionSecurity Logging and Monitoring
Security logging records relevant activity, while monitoring evaluates that activity for conditions that require attention, investigation, or action.
Open article →Companion-course connectionAlert Actionability Engineering
Alert actionability engineering designs alerts so a responder can understand the condition, impact, evidence, urgency, owner, and next safe step.
Open article →Companion-course connectionCardholder Data Environment
The cardholder data environment includes the people, processes, and technologies that store, process, or transmit cardholder data or sensitive authentication data, together with connected or security-impacting components in scope.
Open article →Companion-course connectionManagement Plane Security
Management plane security protects the interfaces, protocols, identities, networks, and workflows used to configure infrastructure and security systems.
Open article →Companion-course connectionPCI Cryptographic Key Control Evidence
PCI cryptographic key control evidence demonstrates that key generation, distribution, storage, access, rotation, replacement, revocation, destruction, and split knowledge or dual control operate as designed.
Open article →Companion-course connectionPCI File Integrity Monitoring
PCI file integrity monitoring detects unauthorized changes to critical system files, configuration files, content, and other security-relevant objects and routes meaningful alerts for investigation.
Open article →Companion-course connectionPCI Point-to-Point Encryption
PCI point-to-point encryption protects account data from the point of interaction through decryption within a validated solution, using controlled devices, applications, keys, and operational responsibilities.
Open article →Companion-course connectionPrimary Account Number Storage Protection
Primary account number storage protection reduces retained payment data and renders stored PAN unreadable through approved methods while controlling display, access, keys, backups, and recovery.
Open article →Companion-course connectionAgentic AI Authorization
Agentic AI authorization ensures every tool call and consequential action is permitted for the initiating identity, current context, resource, and purpose.
Open article →Companion-course connectionAnonymization and Pseudonymization
Anonymization aims to prevent data from being linked to an identifiable person, while pseudonymization replaces direct identifiers but retains a controlled path to re-link the data.
Open article →Companion-course connectionApproved Scanning Vendor Scans
Approved Scanning Vendor scans provide externally performed vulnerability scanning for applicable internet-facing systems under PCI scanning rules, with defined scope, evidence, dispute, remediation, and passing criteria.
Open article →Companion-course connectionAuthentication Factors
Authentication factors are independent categories of evidence used to prove control of an identity, commonly something known, possessed, or inherent to the user.
Open article →