RSI Security

How Many PCI Controls are There?

tool

Companies that process payments through cards and other electronic means open themselves up to cybercrime risks. Hackers target card information for direct theft and fraud and payment processors can also fall victim to cyberattacks. To mitigate these risks, the Security Standards Council (SSC) of the Payment Card Industry (PCI) has devised numerous controls across several security standards to keep companies and consumers safe. But this begs the question: how many PCI controls are there, and what are PCI controls in the first place?

 

How Many PCI Controls are There?

The SSC has developed controls to protect most forms of electronic payment — with or without an actual card. While the PCI DSS applies to most companies, its controls are far from the only ones to have on your radar. Controls are constantly evolving to keep pace with changing technologies and hackers’ ability to compromise them.

In the sections that follow, we’ll enumerate all the major PCI controls, including:

Not sure what all these abbreviations mean? We’ll also provide an overview that contextualizes each framework. Let’s dive in.


Download Our PCI DSS Checklist

 

The Main PCI DSS Controls

For most companies, there are 12 main PCI controls to implement. These 12 requirements, spread across six groups, make up the core of the PCI DSS v.3.2.1, current as of May 2018:

These controls apply to all companies that process payments via cards. They also apply to any company that stores, transmits, or comes into contact with protected cardholder data.

 

Assess your PCI compliance

 

Additional PA DSS Controls

The other set of widely applicable PCI controls comprises 14 requirements of the Payment Application DSS (v.3.2). As of May 2016, its controls break down as follows:

These requirements apply primarily to the software developers themselves. But companies that implement and integrate these payment applications may also need to follow the 14 controls.

 

Additional PCI Controls

Another significant set of PCI controls is in the Point to Point Encryption (P2PE) v3.0. There are five  P2PE domains, each of which has one main requirement that breaks down into multiple sub-requirements for a total of 19 total controls:

 

PTS HSM and POI Controls Breakdown

Finally, the PCI PIN Transaction Security (PTS) frameworks add unique controls for select stakeholders. The Hardware Security Module (HSM) comprises the following:

And the other half of PTS, Point of Interaction (POI), adds the following PCI controls:

Taken together, the controls of the PTS frameworks apply to manufacturers that “specify and implement device characteristics… for personal identification number (PIN) entry terminals,” per the SSC’s guide to understanding differences across the various PCI security standards.

 

Maintaining Full PCI Compliance

Given the sheer volume and complexity of PCI’s controls across all frameworks, many companies may find compliance challenging. RSI Security offers a suite of PCI advisory services focused mainly on PCI DSS certification. Our team of experts has been helping companies of all sizes implement PCI controls for over a decade.

To return to the first question posed above: how many PCI controls are there? It can be as few as 12, depending on which standard(s) you’re required to follow. No matter how many or what kinds of PCI controls apply to your company, contact RSI Security today for assistance.

 


Speak with a PCI Compliance expert today – Schedule a free consultation

 

Exit mobile version