Skip to main content
Image coming soon

Deeper command of the PCI DSS control framework

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Deeper command of the PCI DSS control framework

Master the foundational structure behind secure payment processing and compliance assurance

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.

Who this is for

Senior learning and development leader in financial services with accountability for compliance training programs

Who this is not for

Entry-level trainers, auditors focused on check-the-box validation, or teams using generic PCI DSS slide decks without context

What you walk away with

  • Confidently explain the origin and intent behind every PCI DSS requirement
  • Map controls to internal policies and training modules with precision
  • Anticipate assessor questions and peer challenges with sourced reasoning
  • Design role-specific compliance curricula grounded in the full framework context
  • Lead internal updates ahead of version changes with full structural understanding

The 12 modules (with all 144 chapters)

Module 1. Structure of the PCI DSS framework
Break down the hierarchy of requirements, testing procedures, and guidance documents to see how the standard is organized and enforced.
12 chapters in this module
  1. Overview of PCI DSS versions
  2. Control objective types
  3. Scope definition mechanics
  4. Cardholder data environment mapping
  5. In-scope system identification
  6. Self-assessment vs ROC paths
  7. Roles in validation process
  8. Reporting structure to assessors
  9. Attestation of compliance flow
  10. Evidence collection standards
  11. Control implementation depth
  12. Common misinterpretations to avoid
Module 2. Requirement 1: Firewall configuration
Master the technical and policy expectations for network security controls protecting cardholder environments.
12 chapters in this module
  1. Perimeter firewall baseline
  2. Default deny principle
  3. Router configuration standards
  4. Stateful inspection requirements
  5. Rule documentation practices
  6. Change management integration
  7. Review frequency expectations
  8. Network diagram updates
  9. Third-party access rules
  10. Remote administration controls
  11. Time-bound access setup
  12. Audit logging for rule changes
Module 3. Requirement 2: System configuration
Understand secure configuration for servers and system accounts that process payment data.
12 chapters in this module
  1. Default password removal
  2. Vendor-supplied credentials
  3. System account naming
  4. Shared account restrictions
  5. Authentication protocol standards
  6. Wireless network security
  7. SSID broadcasting rules
  8. WPA2 WPA3 transition
  9. MAC address filtering
  10. Wireless intrusion detection
  11. Configuration baselines
  12. Secure image deployment
Module 4. Requirement 3: Protect stored data
Learn how encryption, tokenization, and data retention policies apply to sensitive cardholder information.
12 chapters in this module
  1. Primary account number handling
  2. PAN truncation rules
  3. Data retention policies
  4. Encryption key management
  5. Key rotation standards
  6. Cryptographic storage methods
  7. Tokenization implementation
  8. Masking in logs
  9. Database security standards
  10. Archive storage controls
  11. Data lifecycle mapping
  12. Destruction certification
Module 5. Requirement 4: Encrypt transmission
Implement secure data transfer protocols across open networks and internal segments.
12 chapters in this module
  1. Strong cryptography definition
  2. SSL TLS deprecation
  3. Approved encryption standards
  4. Public network protections
  5. Wireless encryption
  6. End-to-end encryption
  7. Point-to-point encryption
  8. Key strength requirements
  9. Certificate validation
  10. Man-in-the-middle prevention
  11. Session timeout standards
  12. Protocols to avoid
Module 6. Requirement 5: Malware protection
Deploy anti-virus and endpoint protection controls across systems in the CDE.
12 chapters in this module
  1. Malware types covered
  2. Automated signature updates
  3. On-access scanning
  4. Quarantine procedures
  5. Exclusion documentation
  6. Review of scan logs
  7. Policy exception tracking
  8. Endpoint detection rules
  9. File integrity monitoring
  10. Change alert thresholds
  11. Rootkit detection
  12. System-specific rules
Module 7. Requirement 6: Secure development
Apply secure coding practices and vulnerability management to payment applications.
12 chapters in this module
  1. Software development lifecycle
  2. Code review standards
  3. Patch management
  4. Vulnerability scanning
  5. Web application firewalls
  6. Input validation rules
  7. Error handling standards
  8. Secure configuration
  9. Third-party component review
  10. Penetration testing
  11. Threat modeling
  12. Change control integration
Module 8. Requirement 7: Access control
Enforce role-based access to cardholder data with documented policies and technical enforcement.
12 chapters in this module
  1. Least privilege principle
  2. Role definition process
  3. Access approval workflow
  4. User provisioning
  5. Access review frequency
  6. Segregation of duties
  7. Emergency access rules
  8. Time-bound access
  9. Access request forms
  10. Revocation procedures
  11. Shared account monitoring
  12. Administrator access controls
Module 9. Requirement 8: Authentication
Implement strong authentication mechanisms for all users with access to CDE systems.
12 chapters in this module
  1. Password complexity
  2. Minimum length standards
  3. Expiration policies
  4. Reuse restrictions
  5. Multi-factor authentication
  6. Physical access integration
  7. Token device management
  8. Biometric authentication
  9. Authentication failure lockout
  10. Reset process security
  11. Service account controls
  12. Remote access authentication
Module 10. Requirement 9: Physical security
Secure physical access to locations where cardholder data is processed or stored.
12 chapters in this module
  1. Facility access controls
  2. Visitor sign-in procedures
  3. Badging systems
  4. Camera coverage
  5. Media handling
  6. Secure disposal
  7. Equipment inventory
  8. Data center access
  9. Lockable cabinets
  10. Media storage rooms
  11. Shipping and receiving
  12. Monitoring frequency
Module 11. Requirement 10: Logging and monitoring
Establish reliable logging, monitoring, and alerting for all system access and changes.
12 chapters in this module
  1. Event types logged
  2. Timestamp accuracy
  3. Log retention period
  4. Centralized collection
  5. Integrity protections
  6. Review frequency
  7. Security incident criteria
  8. Log storage security
  9. Time synchronization
  10. Monitoring tools
  11. Alert response process
  12. Forensic readiness
Module 12. Requirement 11: Vulnerability scanning
Conduct regular internal and external scans to detect system weaknesses.
12 chapters in this module
  1. External scan frequency
  2. Approved scanning vendors
  3. Internal scan schedules
  4. Penetration testing scope
  5. Vulnerability severity levels
  6. Remediation timelines
  7. Reporting to assessors
  8. False positive handling
  9. Patch validation
  10. Scan coverage confirmation
  11. Critical system exceptions
  12. Documentation standards

How this maps to your situation

  • Onboarding new compliance staff
  • Updating internal training materials
  • Preparing for external audit
  • Designing role-specific learning tracks

Before vs. after

Before
Relied on surface-level overviews and generic training materials for PCI DSS
After
Confidently lead deep-dive sessions with engineering and security teams using full structural command of the framework

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 3 hours per module, designed for flexible completion across 4-6 weeks.

How this compares to the alternatives

Unlike generic compliance webinars or outdated slide decks, this course delivers structured, chapter-by-chapter command of the PCI DSS framework with direct applicability to training design and internal guidance.

Frequently asked

Who is this course designed for?
Learning and development leaders in financial services who own or contribute to compliance training, especially around payment security.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Will this help me train technical teams?
Yes, each requirement is broken down with technical precision so you can create accurate, confident training for engineers, auditors, and operations teams.
$199 one-time. Approximately 3 hours per module, designed for flexible completion across 4-6 weeks..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours