Companion-course connectionPCI Attestation of Compliance
A PCI Attestation of Compliance is the signed declaration that identifies the assessed entity, validation method, applicable environment, and compliance status supported by the associated assessment.
Open article →Companion-course connectionSensitive Authentication Data Handling
Sensitive authentication data handling prevents storage of prohibited authentication data after authorization and tightly controls any transient processing needed to complete a payment.
Open article →Companion-course connectionCardholder Data Environment
The cardholder data environment includes the people, processes, and technologies that store, process, or transmit cardholder data or sensitive authentication data, together with connected or security-impacting components in scope.
Open article →Companion-course connectionPayment Data Flow Mapping
Payment data flow mapping records where account data is captured, transmitted, processed, stored, displayed, backed up, logged, tokenized, and destroyed across every payment channel.
Open article →Companion-course connectionPayment Page Script Inventory
A payment page script inventory records each script authorized to execute in the consumer’s browser, including source, owner, purpose, integrity, dependencies, approval, and monitoring status.
Open article →Companion-course connectionPCI DSS Customized Approach
The PCI DSS customized approach allows an entity to meet a requirement’s customized objective through controls designed for its environment, supported by targeted risk analysis and rigorous validation.
Open article →Companion-course connectionPCI Point-to-Point Encryption
PCI point-to-point encryption protects account data from the point of interaction through decryption within a validated solution, using controlled devices, applications, keys, and operational responsibilities.
Open article →Companion-course connectionPrimary Account Number Storage Protection
Primary account number storage protection reduces retained payment data and renders stored PAN unreadable through approved methods while controlling display, access, keys, backups, and recovery.
Open article →Companion-course connectionApplication Allowlisting
Application allowlisting permits only approved executables, scripts, libraries, installers, or other code to run under defined rules.
Open article →Companion-course connectionCloud Compliance and Assurance
Cloud compliance and assurance map obligations to provider, customer, and shared controls and collect evidence that those controls are designed and operating effectively.
Open article →Companion-course connectionEngineering Workstation Hardening
Engineering workstation hardening protects systems that configure controllers, logic, firmware, safety parameters, and other high-impact OT assets.
Open article →Companion-course connectionOAuth 2.0
OAuth 2.0 is an authorization framework that lets a client obtain limited access to a resource on behalf of a user or itself without receiving the user's password.
Open article →