← All terms

PCI DSS

PCI DSS is the security standard for organizations handling card payments. Requirement 12.6 makes ongoing security awareness training mandatory.

The Payment Card Industry Data Security Standard (PCI DSS) is the global security standard for every organization that stores, processes, or transmits payment card data — merchants, payment processors, and their service providers. It is maintained by the PCI Security Standards Council, founded by the major card brands, and compliance is enforced contractually through banks and payment networks rather than by governments. Non-compliance can mean fines, higher transaction fees, or losing the ability to accept cards at all — and after a data breach, the first question assessors ask is whether the entity was compliant at the time.

How it works

The current major version, PCI DSS 4.x, organizes its requirements into twelve headline areas covering network security, cardholder data protection, vulnerability management, access control, monitoring, and security policy. Scope is determined by the cardholder data environment: every system that touches card data, plus anything connected to it. Validation ranges from self-assessment questionnaires for smaller merchants to annual on-site assessments by a Qualified Security Assessor for the largest.

The standard is unusually direct about the human layer. Requirement 12.6 mandates a formal security awareness program that makes all personnel aware of the entity's security policy and their role in protecting cardholder data. Training must occur at hire and at least annually, personnel must acknowledge their responsibilities, and — new in version 4 — the program must cover threats and vulnerabilities that could impact cardholder data security, explicitly including phishing and related social engineering attacks, and must be reviewed and updated as the threat landscape changes.

How to defend and comply

Because attackers reach cardholder data through people — a phished credential, a persuaded help-desk agent — assessors increasingly look past attendance logs to program substance. A defensible Requirement 12.6 program pairs role-based security awareness training with regular phishing simulations that generate evidence of improving behavior, the same measured-program approach our guide to GDPR and security awareness training describes for European regulators. One well-run program can satisfy PCI DSS, ISO 27001, and the EU frameworks at once.

Related terms

ISO 27001ISO/IEC 27001 is the international standard for information security management systems — and it makes security awareness a required, auditable control.PhishingPhishing is a social engineering attack that uses fraudulent emails, websites, or messages to trick people into revealing sensitive information or installing malware.Social EngineeringSocial engineering is the practice of manipulating people into giving up confidential information, access, or taking actions that compromise security.Data BreachA data breach is an incident where confidential data is accessed, stolen or exposed by an unauthorized party — most often starting with a human mistake.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo