preview

PCI SSC Project Report

Better Essays

Abstract
The paper’s scope sets out to analyze the particulars of IS standards by analyzing two standards from the ISO/IEC 27000 collection of standards that may directly directs the proceedings of the PCI SSC Standards namely; The ISO/IEC 27001 standards and the ISO/IEC 27002, the first two in the family series. The paper introduces the backgrounds of The Payment Card Industry Security Standards Council (PCISS) while giving the rapid industrial advancement from the usage of physical draws of transactions and asset holding to the digital age of credit card usage. Furthermore, the paper writes down a brief description of the structure and the design of the respective standards while clearly stating their functions. Through a critical …show more content…

The association puts forward assertions of their independence from the listed card vendors that constitute the council. Under its umbrella, there exist a number of standards with requirement stipulations including numerous sub-requirements that contain an abundance of directives against which enterprises in the card industry can gauge their own payment card security strategies, guidelines, and procedures (Calder & Williams, 2016). The present paper discusses two International Security Management Standards namely; The ISO/IEC 27001 standards and the ISO/IEC 27002 that may be applicable to the confines of PCI Security.
b) The ISO 27001
ISO/IEC 27001 is the most popular IS the ISO/IEC 27000 standard series. As per its credentials, ISO 27001 is meant to offer an archetypal for implementing, establishing, monitoring, improving, maintaining, reviewing, and operating an ISMS. ISO 27001 is technology-neutral and utilizes a rundown list of risk-based approaches (Disterer, 2013; ISO, 2014). Its specifications describe a six-part process of planning:
a. Defining a policy of security.
b. Defining the ISMS scope.
c. Conducting an assessment of risk.
d. Managing recognized risks.
e. Selecting controls to be implemented and control objectives.
d. Preparing applicability statement.
Like other ISMSs, ISO/IEC 27001 certification can be done but not compulsory. Some establishments decide on the implementation of the ISO to profit from its

Get Access