A tailored course, built for your situation
Sources and specific examples on hand when peers push back on PCI DSS decisions
Strengthen your position with documented reasoning, precedent, and control-specific justifications.
Who this is for
Mid-level compliance and risk practitioners in financial services with 4, 6 years of experience, focused on audit readiness, control implementation, and cross-functional influence without formal authority.
Who this is not for
Entry-level analysts needing foundational training, consultants selling external audits, or leadership seeking board-level summaries.
What you walk away with
- Map every PCI DSS requirement to a documented control rationale with cited sources
- Respond to peer challenges with specific examples from real audit findings and remediations
- Build reusable justification templates tied to testing frequency, scope boundaries, and exception logic
- Trace control design choices back to NIST CSF patterns and EBA guidance references
- Confidently lead internal reviews without escalating every variance
The 12 modules (with all 144 chapters)
- Defining network segmentation per PCI DSS 1.1
- Common segmentation failures in audit reports
- Router ACLs as evidence for boundary controls
- Firewall rule naming conventions auditors accept
- Network diagrams that survive technical review
- When micro-segmentation exceeds PCI scope
- Case: Payment gateway segmentation at Tier 1 bank
- Case: Shared services that trigger scope creep
- How NIST CSF maps to segmentation controls
- Documenting design decisions for QSA review
- Testing frequency for segmentation validation
- Tools that generate acceptable evidence
- Password policies for network infrastructure
- Disabling default accounts and services
- Using AAA frameworks in device access
- RADIUS integration with central auth
- Secure boot settings on switches
- Logging best practices for routers
- Firmware update policies
- Configuration drift detection
- Auditor checklist for device hardening
- Case: Failed audit due to SNMP exposure
- How to justify exceptions safely
- Template: Secure device configuration playbook
- Defining PAN according to PCI DSS 3.3
- Tokenization vs masking vs truncation
- Database field tagging strategies
- DLP scanning for PAN in logs
- False positive reduction in PAN detection
- Application-level PAN handling
- Encryption at rest for archived data
- Case: Intermittent PAN logging in debug mode
- Audit trail for PAN access attempts
- File transfer monitoring for PAN
- How QSAs test PAN storage controls
- Template: PAN handling policy with examples
- TLS 1.2 vs 1.3 in payment flows
- Certificate lifecycle management
- Approved encryption algorithms
- Load balancer SSL offloading
- Session timeout settings
- OCSP checking in real time
- Certificate pinning in mobile apps
- Case: Expired cert causing revocation
- How to handle legacy system constraints
- Testing tool output for encryption
- Documentation auditors accept
- Template: TLS configuration checklist
- Defining critical systems for AV
- Approved antivirus solutions
- Exclusion lists and auditor pushback
- Log forwarding to SIEM
- Real-time scanning settings
- Scheduled scan frequency
- Case: False positives in payment middleware
- Case: AV conflict with CICS
- How to handle immutable systems
- Documentation of exceptions
- Testing AV response to malware
- Template: AV policy with scope details
- Secure coding standards for payment apps
- Input validation techniques
- Output encoding to prevent XSS
- Authentication in microservices
- Session management best practices
- Error handling without leaks
- Code review checklist for PCI
- SAST integration in pipelines
- Case: Vulnerability in QR code parser
- How to handle OSS components
- Third-party library vetting
- Template: Secure app development checklist
- Defining roles in payment systems
- Segregation of duties rules
- Access request workflows
- Approval hierarchies
- Emergency access controls
- Time-bound access grants
- Case: Excessive access in middleware team
- Access review frequency
- Reporting on inactive accounts
- Integration with IAM systems
- Audit trail for access changes
- Template: RBAC matrix example
- Defining MFA scope per PCI DSS
- User types requiring MFA
- Approved MFA methods
- Service account exceptions
- Third-party vendor access
- Mobile app login flows
- Case: MFA bypass in legacy interface
- How to handle emergency break-glass
- Documentation for auditors
- Testing MFA enforcement
- Integration with Azure AD
- Template: MFA policy with scope
- Defining critical areas per PCI
- Access badge logging systems
- Visitor access procedures
- Camera retention policies
- Alarm systems for data centers
- Case: Unauthorized access attempt
- How auditors verify logs
- Badge audit trail generation
- Escort requirements for vendors
- Physical access review frequency
- Integration with HR offboarding
- Template: Physical access log
- Event types requiring logging
- User login and logout tracking
- Privilege escalation events
- Configuration changes
- Log format standards
- Centralized log collection
- Storage duration: 1 year minimum
- Case: Missing logs during breach
- Log integrity protections
- Time synchronization requirements
- How QSAs sample logs
- Template: Logging policy with examples
- External scan frequency: quarterly
- Internal scan frequency
- Approved scanning tools
- Scope definition for scans
- Handling false positives
- Remediation timelines
- Case: Unpatched flaw in middleware
- How to justify delayed fixes
- Reporting scan results to management
- Integration with ticketing systems
- Documentation for auditors
- Template: Scan schedule calendar
- Required policies per PCI DSS
- Policy review cycle: annually
- Distribution to staff
- Enforcement mechanisms
- Version control for policies
- Linking policies to controls
- Case: Incomplete policy triggers finding
- How to reference NIST sources
- Training on policy updates
- Third-party attestation
- Maintaining policy exceptions
- Template: Security policy with annotations
How this maps to your situation
- Responding to auditor questions on control design
- Justifying scope decisions during internal reviews
- Defending exception approvals with precedent
- Leading cross-functional alignment on control implementation
Before vs. after
What's included with your purchase
- 12 modules with 12 chapters each (144 chapters)
- Downloadable templates and worked examples for every module
- Hand-built implementation playbook delivered alongside course access
- 30-day money-back guarantee
Delivery and format
- Course and learning environment access provisioned within 24 hours of purchase
- Hand-built implementation playbook delivered alongside course access
Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.
Time investment: Approximately 4 hours per module, designed to be completed at your pace over 6, 8 weeks.
How this compares to the alternatives
Unlike generic PCI DSS overviews, this course focuses on defensibility, giving you the specific reasoning, sources, and examples needed to stand by your decisions when challenged by peers or auditors.
Frequently asked
Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.