Compliance & Frameworks
PCI DSS
Also known as: Payment Card Industry Data Security Standard, PCI
Definition
A global information-security standard for organizations that store, process, or transmit payment card data, maintained by the PCI Security Standards Council.
Examples
- A Level 1 merchant undergoing an annual on-site QSA assessment.
- A payment processor implementing point-to-point encryption and tokenization to reduce scope.
Related terms
Compliance
The discipline of meeting legal, regulatory, contractual, and internal security requirements through documented controls, evidence collection, and ongoing assessment.
ISO/IEC 27001
The international standard specifying requirements for an Information Security Management System (ISMS), against which organizations can be formally certified.
Encryption
The cryptographic transformation of plaintext into ciphertext using an algorithm and key so that only authorized parties can recover the original data.
Security Controls
Safeguards or countermeasures — technical, administrative, or physical — used to prevent, detect, or respond to threats against information assets.
SOC 2
SOC 2 — definition coming soon.
Vulnerability Scanning
Automated process that probes systems, applications, or containers against known vulnerability signatures to produce a list of potential weaknesses.