◦ Reference · Framework

PCI-DSS

Payment Card Industry Data Security Standard, currently v4.0. Governs cardholder data inside the cardholder data environment, from point-of-sale to back-office processing. Merchants, processors, acquirers, and QSAs are all in scope, and v4.0 added explicit requirements on script integrity, web redirect hygiene, e-commerce 3DS, and targeted risk analyses. Attention is triggered by skimmer deployment, payment-script tampering, tokenization gaps, and any data-flow change that brings new systems into the CDE.

/pci-dss