Cybersecurity Governance, Risk, and Compliance

PCI DSS Compliance Basics

A practical introduction to payment card security, PCI DSS v4.0.1, and audit-ready compliance work

PCI DSS Compliance Basics logo
Quick Course Facts
18
Self-paced, Online, Lessons
18
Videos and/or Narrated Presentations
6.5
Approximate Hours of Course Media
About the PCI DSS Compliance Basics Course

PCI DSS Compliance Basics is a practical Cybersecurity course for anyone who needs to understand payment card security, PCI DSS v4.0.1, and audit-ready compliance work. You will learn how the standard applies to merchants, service providers, payment flows, cloud environments, and the systems that store, process, or transmit cardholder data.

Build Practical PCI DSS Compliance Skills For Payment Security

  • Learn the foundations of payment card security, including account data, sensitive authentication data, and compliance responsibilities.
  • Understand PCI DSS v4.0.1, its six control objectives, and the 12 core requirements used in real compliance programmes.
  • Develop practical skills for scoping, segmentation, access control, encryption, logging, vulnerability management, and security testing.
  • Prepare for audit-ready compliance work with SAQs, ROCs, AOCs, evidence collection, assessor collaboration, and sustainable governance practices.

A practical introduction to payment card security, PCI DSS v4.0.1, and audit-ready compliance work.

This Cybersecurity course gives you a clear, structured path through PCI DSS Compliance Basics, starting with why the standard exists and how it protects payment card data. You will examine who must comply, how cardholder data environments are defined, and how merchants, service providers, acquirers, card brands, and assessors fit into the compliance process. The course also explains how PCI DSS v4.0.1 is organized so you can connect individual requirements to real operational and technical controls.

As you progress, you will learn how to scope the cardholder data environment, reduce scope through segmentation, and evaluate connected systems that may affect compliance. Lessons cover network security controls, secure configuration, stored account data protection, encryption, malware defence, secure development, vulnerability management, MFA, access control, physical security, logging, monitoring, ASV scans, and penetration testing.

The course also focuses on the governance and evidence side of PCI DSS compliance. You will learn how policies, procedures, risk analysis, control ownership, SAQs, ROCs, AOCs, third-party relationships, cloud providers, and ecommerce payment flows support a sustainable compliance programme. By the end, you will be better prepared to participate in PCI DSS v4.0.1 projects, support audit-ready compliance work, and apply Cybersecurity practices that protect payment environments with confidence.

Course Lessons

Full lesson breakdown

Lessons are organized by topic area and each includes descriptive copy for search visibility and student clarity.

Foundations of Payment Security

3 lessons

This lesson introduces PCI DSS as the payment card industry’s global baseline for protecting payment account data. It explains why the standard exists, who it applies to, what kinds of data it is desi…

Lesson 2: Payment Card Data, Account Data, and Sensitive Authentication Data

20 min
This lesson explains the data categories at the center of PCI DSS v4.0.1: account data , cardholder data , and sensitive authentication data . Learners will distinguish full PAN from related cardholde…

Lesson 3: Who Must Comply: Merchants, Service Providers, Acquirers, and Card Brands

18 min
This lesson clarifies who participates in the PCI DSS compliance ecosystem and why responsibility is shared across merchants, service providers, acquirers, processors, payment brands, and supporting t…

The Standard and Its Structure

2 lessons

Lesson 4: PCI DSS v4.0.1 at a Glance

19 min
This lesson gives learners a practical map of PCI DSS v4.0.1: what the standard is, who it applies to, how it is organized, and how to read its requirements without getting lost in audit language. Lea…

Lesson 5: The Six Control Objectives and 12 Requirements

22 min
This lesson explains how PCI DSS v4.0.1 is organized: six high-level control objectives supported by 12 principal requirements. The structure matters because PCI compliance work is not a random checkl…

Scope, Risk, and Architecture

2 lessons

Lesson 6: Scoping the Cardholder Data Environment

24 min
This lesson explains how to define the cardholder data environment, or CDE, before applying PCI DSS controls. Learners will identify where cardholder data is stored, processed, or transmitted; recogni…

Lesson 7: Segmentation, Connected Systems, and Scope Reduction

22 min
This lesson explains how PCI DSS scope expands beyond the systems that directly store, process, or transmit cardholder data. Learners will distinguish the cardholder data environment, connected-to sys…

Core Technical Controls

4 lessons

Lesson 8: Network Security Controls and Secure System Configuration

23 min
This lesson explains how PCI DSS v4.0.1 treats two foundational technical control areas: network security controls and secure system configuration. Learners will connect Requirement 1 and Requirement …

Lesson 9: Protecting Stored Account Data

21 min
This lesson explains how PCI DSS v4.0.1 expects organizations to protect stored account data under Requirement 3. The focus is practical: identify where account data exists, minimize storage, prohibit…

Lesson 10: Encrypting Transmission of Cardholder Data

18 min
This lesson explains how PCI DSS v4.0.1 expects organizations to protect cardholder data while it is moving across open, public, or otherwise untrusted networks. Learners will focus on practical trans…

Lesson 11: Malware Defence, Secure Development, and Vulnerability Management

24 min
This lesson covers three connected parts of PCI DSS v4.0.1 vulnerability management: defending systems from malware, building and changing software securely, and finding and fixing known security weak…

Access and Monitoring

2 lessons

Lesson 12: Identity, Authentication, MFA, and Access Control

23 min
This lesson explains how PCI DSS v4.0.1 treats identity, authentication, multi-factor authentication, and access control as everyday operating controls, not just technical settings. Learners will conn…

Lesson 13: Physical Access, Logging, Monitoring, and Audit Trails

22 min
This lesson explains how PCI DSS v4.0.1 treats physical access control, audit logging, monitoring, and audit trails as connected safeguards for the cardholder data environment. Learners will see how f…

Validation and Evidence

2 lessons

Lesson 14: Security Testing, ASV Scans, and Penetration Testing

24 min
This lesson explains how PCI DSS v4.0.1 treats security testing as validation evidence, not just a technical activity. Learners will distinguish internal vulnerability scanning, external ASV scanning,…

Lesson 16: SAQs, ROCs, AOCs, and Working with Assessors

23 min
This lesson explains how PCI DSS validation documents fit together: Self-Assessment Questionnaires, Reports on Compliance, Attestations of Compliance, and the evidence packages that support them. Lear…

Governance and Operations

1 lesson

Lesson 15: Policies, Procedures, Risk Analysis, and Control Ownership

21 min
This lesson explains the governance work that keeps PCI DSS compliance operating between assessments: documented policies, usable procedures, risk analysis, and clear control ownership. Learners will …

Applied Compliance Scenarios

2 lessons

Lesson 17: Third Parties, Cloud Providers, and Ecommerce Payment Flows

22 min
This lesson applies PCI DSS v4.0.1 to three areas that commonly create confusion: third-party service providers, cloud-hosted environments, and ecommerce payment flows. Learners will distinguish outso…

Lesson 18: Building a Sustainable PCI DSS Compliance Programme

24 min
This lesson turns PCI DSS from an annual project into an operating programme. Learners will see how to assign ownership, maintain evidence, manage change, monitor control health, and prepare for asses…
About Your Instructor
Professor Daniel Martin

Professor Daniel Martin

Professor Daniel Martin guides this AI-built Virversity course with a clear, practical teaching style.