Companion-course connectionSOC Service Catalog and Coverage Model
A SOC service catalog and coverage model state what monitoring, investigation, response, intelligence, hunting, and support services exist, who receives them, and when they operate.
Open article →Companion-course connectionPCI Targeted Risk Analysis
A PCI targeted risk analysis uses documented threat, likelihood, impact, asset, control, and operating context to justify certain frequencies or support customized-approach controls.
Open article →Companion-course connectionPrimary Account Number Storage Protection
Primary account number storage protection reduces retained payment data and renders stored PAN unreadable through approved methods while controlling display, access, keys, backups, and recovery.
Open article →Companion-course connectionCardholder Data Environment
The cardholder data environment includes the people, processes, and technologies that store, process, or transmit cardholder data or sensitive authentication data, together with connected or security-impacting components in scope.
Open article →Companion-course connectionPCI Report on Compliance
A PCI Report on Compliance records the assessor’s scope, methods, evidence, observations, testing, findings, and conclusion for an on-site PCI DSS assessment.
Open article →Companion-course connectionAnonymization and Pseudonymization
Anonymization aims to prevent data from being linked to an identifiable person, while pseudonymization replaces direct identifiers but retains a controlled path to re-link the data.
Open article →Companion-course connectionData Masking and Tokenization
Data masking and tokenization replace or transform sensitive values so systems and users can work with lower-exposure representations.
Open article →Companion-course connectionNatural Language Processing
Natural language processing converts human language into representations that support classification, extraction, generation, translation, and dialogue.
Open article →Companion-course connectionPayment Terminal Security
Payment terminal security protects point-of-interaction devices through approved design, inventory, deployment, physical inspection, tamper awareness, access control, maintenance, and replacement procedures.
Open article →Companion-course connectionPCI Attestation of Compliance
A PCI Attestation of Compliance is the signed declaration that identifies the assessed entity, validation method, applicable environment, and compliance status supported by the associated assessment.
Open article →Companion-course connectionPCI Tokenization and Scope Reduction
PCI tokenization replaces account data with substitute values while preserving tightly controlled tokenization, detokenization, key, vault, and administrative components that remain security-critical.
Open article →Companion-course connectionPCI Point-to-Point Encryption
PCI point-to-point encryption protects account data from the point of interaction through decryption within a validated solution, using controlled devices, applications, keys, and operational responsibilities.
Open article →