PCI DSS
acronymgovernance & risksecurity
Stands for: Payment Card Industry Data Security Standard
The payment-card industry's security standard for anyone who stores, processes, or transmits cardholder data.
PCI DSS is set by the PCI Security Standards Council (the card brands) and defines a baseline of network, encryption, access-control, and monitoring requirements. It is contractual rather than governmental, but non-compliance carries fines and lost processing rights. It is a common scope item on vendor trust centers even when the vendor never directly handles card data, because customers deploy their products in cardholder environments.
Also known as: pci dss, pci-dss, pci, cardholder data